Privacy policy
How HeavenApps Inc. handles personal data across the PRISM website, capture app and platform.
Effective 7 August 2026
1.Who we are
PRISM is a product of HeavenApps Inc. (“HeavenApps”, “we”, “us”), a company incorporated in Delaware, USA.
For personal data collected through this website and through direct enquiries, HeavenApps is the data controller. For personal data contained in scans that a customer captures and uploads, the position is different, and is set out in section 6.
Questions about this policy can be sent to [email protected].
2.Scope
This policy covers the PRISM marketing website, the PRISM iOS capture app, the PRISM web console and the PRISM API. Where a customer has signed a separate agreement or data processing agreement with us, that agreement governs to the extent it conflicts with this policy.
3.Information we collect
Information you give us. When you submit the contact form on this site, we collect your name, work email, company, role, the check or workflow you describe, the number of sites you indicate, and anything else you choose to write. We use it to respond to your enquiry.
Account information. If you hold a PRISM account, we hold your email address, name, role, the organisation you belong to and a hashed form of your password. We never store your password in a readable form.
Scan and spatial data. A PRISM capture records video, depth measurements, camera position and orientation, device motion and, where enabled on the device, the location of the capture. Video of a space can contain images of people who are present. See section 6.
Technical and diagnostic data. The platform records operational logs, including upload and processing events, error reports, crash diagnostics, device model, operating system and app version. These are used to keep the service working and to investigate faults.
Embedded video. Our product walkthrough is hosted on YouTube and embedded using YouTube’s privacy-enhanced mode. If you play it, Google receives your IP address and may set cookies. That processing is governed by Google’s privacy policy, not by ours.
4.How we use information
We use personal data to:
- respond to enquiries and arrange demonstrations;
- provide, operate, secure and support the PRISM platform;
- process scans and produce the findings a customer has configured;
- diagnose faults, monitor reliability and improve the service;
- meet legal, accounting and regulatory obligations; and
- send service communications about changes that affect you.
We do not sell personal data, and we do not use customer scan content to train models for other customers.
5.Legal bases
Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract, for providing the service to customers; legitimate interests, for responding to business enquiries, for security and for service improvement; consent, where you have given it, such as for optional cookies; and legal obligation, where the law requires us to retain or disclose information. You may object to processing based on legitimate interests as set out in section 11.
6.Scan data, and who controls it
When a customer captures a space with PRISM, the customer decides what to scan, when, and why. In that relationship the customer is the data controller and HeavenApps acts as a processor, handling scan data on the customer’s documented instructions in order to run the checks they have configured.
Because a capture is a video walk of a real space, it can include images of employees, contractors, visitors or members of the public. The customer is responsible for having a lawful basis for that capture, for providing any notice or signage required in the places they scan, and for complying with employment, works-council and surveillance rules that apply to them. This is restated as an obligation in our terms of use.
If you believe a PRISM scan taken by one of our customers contains images of you, contact that organisation directly. If you cannot identify them, write to [email protected] and we will make reasonable efforts to route your request to the right controller.
7.AI recognition
Running a check means sending sampled frames from a scan to a recognition service so that computer vision can identify the conditions the customer has asked about. That service may be one we operate, one the customer operates, or a third-party service the customer has nominated, and it is configured per account.
Which service is used therefore determines where those frames are processed. We will identify the service configured for your account on request, and it is covered by the subprocessor commitments in section 8 where we operate or engage it.
8.Sharing and subprocessors
We share personal data with service providers who process it on our behalf, including cloud hosting and storage, the recognition services described in section 7, and business tools used to manage enquiries. Each is bound by contract to protect the data and to use it only for the purposes we specify.
A current list of our subprocessors is available on request from [email protected].
We may also disclose data where required by law, to establish or defend legal claims, or in connection with a merger, acquisition or sale of assets, in which case we will give notice before your data becomes subject to a different privacy policy.
9.Storage, security and retention
Data is hosted on third-party cloud infrastructure, and we will confirm the provider and region for your account on request. Access to production systems is restricted to personnel who need it. Access to the platform is authenticated and governed by roles, credentials for configured recognition services are encrypted at rest, and passwords are stored only as salted hashes.
We keep personal data only for as long as it is needed for the purposes described above, or for as long as a customer’s agreement provides, and then delete or anonymise it. Customers can delete scans from the platform at any time.
No system is perfectly secure. We do not claim that our measures guarantee against every possible compromise, and we hold no security certification we have not published.
10.International transfers
Where personal data is transferred outside the UK or European Economic Area, we rely on an adequacy decision where one applies, and otherwise on standard contractual clauses together with any additional safeguards required. Details of the mechanism for a given transfer are available on request.
11.Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent you have given. Exercising these rights is free, and we will respond within the period the applicable law requires.
To make a request, write to [email protected]. If we act as a processor for a customer, we will refer your request to them. You also have the right to complain to your data protection authority; in the UK that is the Information Commissioner’s Office.
12.Cookies and analytics
This website sets no advertising or analytics cookies. The embedded product video described in section 3 is loaded from YouTube’s privacy-enhanced domain and only contacts Google if you press play.
The PRISM web console stores authentication tokens in your browser so that you stay signed in. These are necessary for the service to function and are not used for tracking.
If we add analytics later, we will update this section and, where consent is required, request it before anything is set.
13.Children
PRISM is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact [email protected] and we will delete it.
14.Changes to this policy
We may update this policy as the product and the law change. The effective date at the top of the page shows when it last changed, and we will give notice of material changes to customers through the service or by email.
15.Contact
Privacy questions, requests and complaints: [email protected].