This policy explains what personal data Prism Mapper collects, why, who we share it with, how long we keep it, and your rights. In short: we collect what we need to run your account and the studio, your projects stay in your own browser, payments are handled by Stripe, AI clips are made by Google’s Gemini API, and we don’t use advertising or analytics trackers.
1. Who we are
H4Z Development Services Limited, trading as Prism Mapper, is a private limited company incorporated in Gibraltar (company number 124216), whose registered office is at Suite 4, 2nd Floor, The West Wing, Montarik House, 3 Bedlam Court, Gibraltar GX11 1AA. In this policy, “we”, “us” and “our” mean H4Z Development Services Limited, trading as Prism Mapper. We are the “controller” of the personal data described here, which means we decide how and why it is used.
As a company incorporated in Gibraltar, we are primarily subject to the Gibraltar GDPR and the Gibraltar Data Protection Act 2004, regulated by the Gibraltar Regulatory Authority. Because we offer the service to people in the UK and the European Union, if you live there you also have rights under the UK GDPR or the EU GDPR where those laws apply.
For anything about your data, email hello@h4z.co.uk.
This policy covers the website at https://prismmapper.com and the studio at https://app.prismmapper.com.
2. What we collect
- Account details: your email address, your name if you give it, and your password (stored only in scrambled, hashed form by our sign-in provider). If you sign in with Google, we receive your name, email address and Google account ID from Google.
- Plan and billing status: your plan, whether your subscription is in a trial, active, cancelled or has a payment problem, its renewal dates, your billing currency, and your Stripe customer and subscription IDs. Payments are handled by Stripe: we never see or store your full card number.
- AI credits: your balance and a history of recent changes (what was added, spent or given back, and what for, such as “video clip”).
- Projects and media: your projects, and the images, videos and music you add, are saved in your own browser on your device, not on our servers. They pass through our app server only when you choose to send them somewhere, for example to the devices at your projector.
- Phone scans: when you scan a room with your phone, the scan images are uploaded to our app server so your studio can receive them.
- AI prompts and images: the text prompts you write, and any image you include (for example a picture of a surface), when you ask for an AI clip, and the clip that comes back.
- Basic technical logs: our app server logs each request’s type, address path, result and timing, without your IP address, tokens or content. Our hosting providers also keep their own short-term access logs, which include IP addresses.
- Country for pricing: when you visit the website, we look up your country from your IP address to show prices in your currency, and check it again at checkout. We don’t store your IP address or country for this.
- Messages: what you send us if you email us.
We don’t use advertising or analytics trackers, and we don’t sell your data.
3. Why we use it, and our lawful bases
The law requires a “lawful basis” for each use of personal data. Ours are:
- To provide the service you signed up for (contract): creating and running your account, signing you in to the studio, passing your phone scans and media to your devices, making the AI clips you ask for, keeping track of your plan and credits, taking payments and sending account emails (such as confirming your email or resetting your password).
- Our legitimate interests, which we’ve balanced against your rights: keeping the service secure and preventing fraud and abuse (for example, limits on AI use), fixing problems, showing prices in your local currency, and handling questions and complaints.
- Legal obligations: keeping billing and tax records, and responding to lawful requests from authorities.
We don’t send marketing emails. If we ever want to, we’ll ask for your consent first, and you’ll be able to withdraw it at any time.
4. Who we share it with
We use these service providers (“processors”) to run Prism Mapper. They may only use your data to provide their service to us:
- Netlify hosts the website and runs our sign-in (Netlify Identity, which also sends account emails) and stores account and credit records (Netlify Blobs).
- Fly.io hosts the studio’s app server, in London, UK. Phone scans, media you send to your devices and AI requests pass through it.
- Stripe takes payments and manages subscriptions and invoices. Stripe collects your card and billing details directly, and is also responsible for them as a controller for its own legal and fraud-prevention purposes.
- Google: if you choose “Continue with Google”, Google signs you in and shares your basic profile with us. For AI clips, we send your prompt and any image you include to Google’s Gemini API, which generates the clip. Don’t include personal information in prompts or images that you don’t want sent to Google.
- Hugging Face: the studio’s room-scanning AI runs on your own device. The first time you use it, your browser downloads the AI model files from Hugging Face, which, like any website, sees your IP address. No scans or project data are sent to it.
We may also share data if the law requires it, to protect our rights or others’ safety, or with a buyer if our business is sold (they would have to keep it protected in the same way).
5. International transfers
We are based in Gibraltar, and our providers process data in other countries: our app server is in the UK (London), and Netlify, Stripe, Google and Hugging Face are based in, or use servers in, the United States and other countries. Gibraltar data protection law allows transfers to the UK and the European Economic Area, which it recognises as giving adequate protection. For transfers to other countries, we rely on the safeguards the law allows, such as adequacy decisions (including the EU–US Data Privacy Framework and its UK extension, for providers certified under them) or standard contractual clauses, which our providers include in their data processing terms. Where the UK GDPR or EU GDPR applies to your data, we rely on the equivalent UK or EU safeguards. Contact us for more detail.
6. How long we keep it
- Account, plan and credit records: while your account is open. When you ask us to close it, we delete them within 30 days, except what we must keep by law.
- Billing records (invoices and payments, held by Stripe and us): six years after the end of the financial year they relate to, or longer if tax or company law requires.
- Phone scans: deleted from our server as soon as your studio has received them, and at the latest after 2 hours.
- Media sent to your devices: kept on our server only while your session is in use, and deleted after 6 hours without use or when the session ends (at most 12 hours after it was last used).
- AI clips: a finished clip is kept on our server for 30 minutes so your studio can download it, then deleted. Google keeps prompts, images and clips under its Gemini API terms, for a limited period, for example to detect abuse.
- Your projects: they stay in your browser until you delete them or clear your browser’s data. We don’t have a copy.
- Logs: kept for a short period, typically no more than 30 days, unless needed to investigate a security problem.
- Emails with us: for as long as needed to deal with your request, and up to two years afterwards.
7. Your rights
Under data protection law (the Gibraltar GDPR, and the UK GDPR or EU GDPR where they apply to you), you have the right to:
- ask for a copy of the personal data we hold about you (access);
- have inaccurate data corrected (rectification);
- have your data deleted (erasure), including closing your account;
- ask us to restrict how we use your data;
- object to uses based on our legitimate interests;
- receive data you gave us in a common, machine-readable format, or have it sent to another provider (portability);
- withdraw consent at any time, where we rely on consent.
To use any of these rights, email hello@h4z.co.uk from the address on your account (or tell us how we can confirm it’s you). It’s free, and we’ll reply within one month (we may extend this by two more months for complex requests, and we’ll tell you if we do). Some rights have exceptions, for example where we must keep billing records.
You can manage billing and see your invoices on your account page, and change your password with “Forgot password?” on the log-in page.
8. Complaints
If you’re unhappy with how we’ve handled your data, please tell us first at hello@h4z.co.uk so we can try to put it right. You also have the right to complain to our data protection regulator, the Gibraltar Regulatory Authority (Data Protection), at gra.gi, or to the data protection regulator where you live: in the UK, the Information Commissioner’s Office (ICO) at ico.org.uk; in the EU, your country’s data protection authority.
9. Children
Prism Mapper isn’t for children under 13, and we don’t knowingly collect their data. Anyone under 18 needs a parent’s or guardian’s permission to use it. If you think a child under 13 has given us personal data, contact us and we’ll delete it.
10. Keeping your data safe
We use encrypted connections (HTTPS) throughout, keep payment details with Stripe, keep AI keys and secrets on our servers only, and keep data we hold on our server for as short a time as we can. No system is completely secure, so please use a strong, unique password. If a breach is likely to put you at high risk, we’ll tell you.
12. Changes to this policy
We’ll update this policy when what we do with your data changes, for example if we add a new service provider. The date at the top shows when it was last updated. If a change is significant, we’ll tell you by email or in the service before it takes effect.