Privacy Policy
1. Controller and contact
PrismaTV and Prisma Open are operated by Prismas e Quadriláteros. Privacy contact: geral.prismas@gmail.com.
2. Data categories
We may process account and contact data, device and activation identifiers, orders and payments, preferences, security and audit logs, support messages, Reports and technical evidence required by Prisma Open.
General Reports may be anonymous or include optional contact details. Formal rights claims require name/organization, email, declared capacity, rights identification and a good-faith statement. We do not request an identity document, personal address, phone number or signature at this stage.
3. Purposes and legal bases
Data is used to provide and activate the service, authenticate users, process payments, answer support and Reports, investigate origin/rights, protect infrastructure, prevent fraud and comply with applicable obligations.
Legal bases may include performance of the requested service, legitimate interests in security, integrity, legal defense and operational improvement, compliance with legal obligations and consent where required.
4. Prisma Open and Reports
The validator processes metadata, sanitized URLs, technical results, origin/rights evidence and decision history. It does not store video and must not retain private cookies, tokens or headers in Review Packs or Reports.
The Reports workflow stores only submitted and necessary data, server-side snapshots, evidence URLs, actions, internal notes and audit. The IP address is not stored as a field of the new Prisma Open form.
5. Providers and recipients
Depending on the feature, providers may include Vercel (website/panel), Turso/libSQL and VPS infrastructure (data and services), PayPal (payments), Google (login), Firebase Crashlytics (diagnostics) and Firebase Cloud Messaging (notifications). Broadcasters/CDNs receive normal connection data when the device plays an external source directly.
Each provider processes data according to its role and policies. International transfers, where applicable, depend on the provider mechanisms and remain subject to contractual and privacy review.
6. Retention
Data is kept only as long as necessary for the service, activation, support, investigation, security, audit, payments, disputes and legal obligations, then deleted or anonymized where no basis for retention remains.
Final periods by category still depend on the internal retention schedule and legal validation; this Policy does not invent one uniform period that would not match actual operations.
7. Rights
Where applicable, access, rectification, erasure, restriction, objection, portability and consent withdrawal requests may be sent to geral.prismas@gmail.com. Proportionate validation of the relationship with an account, device, payment or report may be required.
A complaint may be submitted to the Portuguese data protection authority, CNPD, at www.cnpd.pt.
8. Security and changes
We apply access control, server-side validation, encryption where applicable, minimization, sanitization, rate limits and audit. No system eliminates all risk.
This Policy may be updated when features, providers, processing or applicable requirements change. Material changes will be communicated appropriately.
