Privacy Policy
Last updated: May 2, 2026
Perspect Services Ltd (“Perspect”, “we”, “our”, or “us”) is committed to protecting personal data and respecting privacy. This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you visit perspect.finance, use the Prism investment operations platform at prism.perspect.finance, access the Investor Portal, use the Prism demo environment, communicate with Perspect, or otherwise interact with our services.
Prism is Perspect’s enterprise investment operations platform. It supports portfolio oversight, deal workflow, CRM, reporting, investor portal access, approvals, audit logging, integrations, tenant branding, data import/export and controlled AI-assisted workflows for private equity, venture capital, infrastructure, fund-of-funds, family office, fund management and related investment operations teams.
This policy applies to Prism Cloud, the managed Prism SaaS platform, and to Perspect’s website and related services. Where Prism is deployed as a standalone private deployment, data protection responsibilities may vary depending on the agreed deployment model, customer-controlled infrastructure, support scope and any separate data processing agreement or order form.
This policy is written with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (“PECR”) in mind. If you are based in the European Economic Area, EU GDPR may also apply to some processing activities.
Perspect Services Ltd
441 Sidcup Road
London
SE9 4ET
United Kingdom
Email: [email protected]
For privacy questions, data subject requests, supplier due diligence, data processing agreement queries or concerns about how personal data is handled, contact Perspect at [email protected].
Perspect may act as either a controller or processor depending on the context.
When you visit perspect.finance, we may collect:
When you use Prism as an internal platform user, administrator, analyst, fund manager, operations user or finance user, we may process:
When you access the Investor Portal as an LP, investor, adviser or other external stakeholder, we may process:
When you use the public Prism demo environment, we may collect technical, usage, authentication and interaction data needed to operate the demo, protect the service, understand product interest and prevent misuse. The demo environment should use demonstration data only and should not be used to upload or process live customer data.
Where Prism is operated as a private deployment, the personal data Perspect can access may depend on the agreed deployment model. In some private deployments, Perspect may have limited or no routine access to customer-controlled data. In others, Perspect may process data for support, maintenance, migration, monitoring or implementation purposes under a separate agreement.
We do not intentionally collect personal data from children under 18. Prism is intended for business and professional use. We do not intentionally collect special category data except where it is included in documents or records uploaded by customers, such as KYC materials, identity documents, investor onboarding documents or similar files.
We collect personal data through:
We process personal data for the purposes and lawful bases set out below. The lawful basis may vary depending on the relationship, deployment model and whether Perspect is acting as controller or processor.
| Purpose | Typical Lawful Basis |
|---|---|
| Providing access to Prism, Prism Cloud, the Investor Portal and related services | Performance of a contract; legitimate interests; processor instructions |
| Creating and managing accounts, users, roles, permissions and tenant settings | Performance of a contract; legitimate interests; processor instructions |
| Authenticating users through passwords, sessions, SSO and security controls | Performance of a contract; legitimate interests in platform security |
| Operating the Investor Portal and controlling investor-facing access | Performance of a contract; legitimate interests; processor instructions |
| Maintaining audit logs, document access records, security logs and operational evidence | Legitimate interests in security, governance and compliance; legal obligation where applicable |
| Processing billing, invoices, subscriptions and payment status | Performance of a contract; legal obligation; legitimate interests |
| Responding to enquiries, support requests, procurement questions and security questionnaires | Legitimate interests; performance of a contract |
| Processing uploads, imports, exports, reports, documents and platform workflows | Performance of a contract; processor instructions |
| Providing AI-assisted extraction, drafting, summarisation, classification or analysis features | Performance of a contract; legitimate interests; processor instructions |
| Monitoring platform reliability, preventing misuse and protecting against security threats | Legitimate interests in security and service integrity |
| Analysing website usage through Google Analytics where accepted | Consent |
| Complying with legal, tax, accounting, regulatory and dispute-resolution obligations | Legal obligation; legitimate interests |
Prism may include AI-assisted features for document extraction, report commentary, portfolio analysis, operational review, summarisation, tagging, classification and drafting. These features are designed to assist users, not replace professional judgement.
When AI features are used, data submitted to the feature may be transmitted to and processed by Perspect and one or more AI providers. This may include prompts, uploaded documents, extracted text, financial records, report context, CRM context, portfolio data and other Customer Data needed to provide the feature.
Perspect may use AI providers including Anthropic, OpenAI and Google AI / Gemini, depending on product configuration, customer settings, provider availability and deployment model. AI provider usage may change over time.
We do not knowingly use Customer Data to train general AI models without customer permission. AI outputs should be reviewed by an authorised human user before being relied upon, published, exported, sent to investors or used in a durable finance workflow.
For private deployments, AI availability, AI provider routing, customer-controlled keys, disabled AI mode or local-only processing requirements should be agreed separately where relevant.
Our website and platform use cookies and similar technologies. Some cookies are strictly necessary for authentication, security, session management and cookie preference storage. Non-essential analytics cookies are used only where consent has been provided.
We use Google Analytics on the Perspect marketing website to understand website traffic and improve content. Analytics cookies are not intended to be used to track sensitive platform activity inside Prism.
You can manage cookie choices through the cookie banner and browser controls. For more detail, see our Cookie Policy.
We may share personal data with third parties where necessary to operate, secure, support and improve the Services, comply with law or perform contractual obligations.
| Recipient / Processor | Purpose | Typical Location |
|---|---|---|
| DigitalOcean | Cloud infrastructure and hosting for Prism Cloud | United States / selected hosting regions |
| Cloudflare | DNS, edge security, traffic protection and network services | Global |
| Stripe | Payment processing, subscription billing and invoice support | United States / global |
| Microsoft | Azure AD / Microsoft Entra SSO where configured by customers | Global |
| Okta | SSO authentication where configured by customers | United States / global |
| Google Workspace SSO, Google Analytics and Google AI / Gemini where used | United States / global | |
| Anthropic | AI-assisted platform features where configured or used | United States |
| OpenAI | AI-assisted platform features where configured or used | United States |
| Email, SMTP and communications providers | Transactional email, support communications and service notices | United Kingdom / United States / global depending on provider |
We may also disclose personal data to professional advisers, insurers, auditors, regulators, law enforcement, courts, public authorities, acquirers, successors or other parties where legally required or reasonably necessary to protect Perspect, customers, users, the Services or third parties.
We do not sell personal data.
Some service providers used by Perspect may process personal data outside the United Kingdom. Where personal data is transferred internationally and UK GDPR requires safeguards, we use appropriate transfer mechanisms such as the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, adequacy regulations or other legally recognised safeguards.
Where a customer uses Prism in connection with data from the EEA or another jurisdiction, the customer is responsible for ensuring that its own use of Prism complies with applicable transfer, data protection and notice requirements.
For private deployments, international transfer arrangements may depend on the agreed hosting location, support access, sub-processors and maintenance model.
We implement technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration and disclosure. These measures may include:
No system is completely secure. Customers remain responsible for their own users, devices, exported files, downloaded documents, identity provider configuration, private deployment environment and connected third-party systems.
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including providing the Services, maintaining security, complying with legal obligations, resolving disputes and enforcing agreements.
| Data Category | Typical Retention Period |
|---|---|
| Active Prism account and tenant data | For the duration of the active subscription or deployment agreement |
| Tenant data after Prism Cloud cancellation | Typically retained for 90 days after the end of the paid period, unless a different period is required by law or agreed in writing |
| Billing, invoice and accounting records | Up to 7 years where required for tax, accounting or legal purposes |
| Audit logs and security logs | Typically up to 7 years, subject to customer settings, legal requirements and deployment model |
| Investor Portal document access records | Typically up to 7 years, subject to customer settings, legal requirements and deployment model |
| KYC, investor identity and onboarding documents | Controlled by the customer as controller; may be retained for legal, AML/KYC or fund administration periods where applicable |
| Website analytics data | According to the configured analytics retention period and cookie consent status |
| Support, sales and enquiry correspondence | Typically up to 3 years from last interaction, unless needed for an ongoing relationship, dispute or legal obligation |
Where a customer controls data inside its Prism tenant, the customer may set or request retention and deletion arrangements subject to platform capabilities, legal obligations and contractual terms.
Subject to applicable law, you may have the following rights in relation to your personal data:
To exercise these rights, contact [email protected]. If your personal data is processed inside a customer-controlled Prism tenant, we may need to refer your request to the relevant customer because they may be the controller of that data.
We may need to verify your identity before responding. We will respond within the timeframe required by applicable law, subject to any permitted extension.
If you are unhappy with how we handle personal data, please contact us first at [email protected] so we can try to resolve the issue.
You also have the right to lodge a complaint with the UK’s data protection regulator:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk
The Perspect website and Prism platform may contain links or integrations to third-party websites, services or customer-controlled systems. This Privacy Policy does not apply to third-party websites or services that Perspect does not control. Customers are responsible for reviewing the privacy, security and compliance implications of third-party systems they connect to Prism.
We may update this Privacy Policy from time to time to reflect changes in Prism, Perspect’s services, deployment models, subprocessors, legal requirements or data protection practices. When we make material changes, we will update the “Last updated” date and, where appropriate, notify platform administrators or affected users.
Continued use of the Services after a policy update indicates acknowledgement of the updated Privacy Policy.
If you have questions, concerns or requests relating to this Privacy Policy or the way personal data is handled, please contact:
Perspect Services Ltd
441 Sidcup Road
London
SE9 4ET
United Kingdom
Email: [email protected]