Privacy Policy

Last updated: May 2, 2026

1. Introduction

Perspect Services Ltd (“Perspect”, “we”, “our”, or “us”) is committed to protecting personal data and respecting privacy. This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you visit perspect.finance, use the Prism investment operations platform at prism.perspect.finance, access the Investor Portal, use the Prism demo environment, communicate with Perspect, or otherwise interact with our services.

Prism is Perspect’s enterprise investment operations platform. It supports portfolio oversight, deal workflow, CRM, reporting, investor portal access, approvals, audit logging, integrations, tenant branding, data import/export and controlled AI-assisted workflows for private equity, venture capital, infrastructure, fund-of-funds, family office, fund management and related investment operations teams.

This policy applies to Prism Cloud, the managed Prism SaaS platform, and to Perspect’s website and related services. Where Prism is deployed as a standalone private deployment, data protection responsibilities may vary depending on the agreed deployment model, customer-controlled infrastructure, support scope and any separate data processing agreement or order form.

This policy is written with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (“PECR”) in mind. If you are based in the European Economic Area, EU GDPR may also apply to some processing activities.

2. Who We Are

Perspect Services Ltd
441 Sidcup Road
London
SE9 4ET
United Kingdom
Email: [email protected]

For privacy questions, data subject requests, supplier due diligence, data processing agreement queries or concerns about how personal data is handled, contact Perspect at [email protected].

3. Our Role as Controller and Processor

Perspect may act as either a controller or processor depending on the context.

  • Website and commercial relationship: Perspect usually acts as controller for personal data collected through perspect.finance, sales enquiries, billing administration, procurement conversations, support communications and website analytics.
  • Prism tenant data: For personal data entered, uploaded, imported or generated by a customer inside its Prism tenant, the customer will usually act as controller and Perspect will usually act as processor, processing that data on the customer’s behalf to provide the platform.
  • Investor Portal data: Where a fund manager or investment organisation gives LPs or external stakeholders portal access, the customer will usually decide what data is made available, and Perspect will process that data to operate the portal.
  • Private deployment: For private deployments, the controller/processor relationship, infrastructure responsibilities, support access and data processing scope should be confirmed in the relevant agreement.

4. Personal Data We Collect

4.1 Website Visitors

When you visit perspect.finance, we may collect:

  • Technical data: IP address, browser type, device type, operating system, referring URLs, pages visited, time and date of visit and basic diagnostic logs.
  • Usage data: Page views, navigation patterns, session duration and interaction information collected through analytics tools where consent has been provided.
  • Communications data: Name, email address, organisation, role, message content and any other information you provide through forms or email.
  • Cookie data: Cookie consent choices and analytics identifiers where non-essential analytics cookies are accepted.

4.2 Prism Platform Users

When you use Prism as an internal platform user, administrator, analyst, fund manager, operations user or finance user, we may process:

  • Identity data: Name, username, professional title, organisation, user ID and role.
  • Contact data: Work email address, telephone number and business contact details.
  • Authentication data: Login credentials, hashed passwords, SSO identifiers, session tokens, authentication events, IP addresses and access logs.
  • Role and permission data: User role, permission group, tenant access, approval rights, admin status and security settings.
  • Platform activity data: Records created, viewed, edited, approved, exported, imported, downloaded or deleted; workflow activity; report generation; document access; settings changes; audit events; and operational logs.
  • Customer Data: Fund records, portfolio data, deal records, investor records, CRM records, contacts, commitments, capital activity, documents, reporting outputs, comments, custom fields, integrations and other data entered into Prism by or on behalf of a customer.
  • Billing data: Subscription tier, billing contact, invoice details, payment status and subscription history. Full payment card details are processed by Stripe and are not stored by Perspect.

4.3 Investor Portal Users

When you access the Investor Portal as an LP, investor, adviser or other external stakeholder, we may process:

  • Identity data: Name, organisation, title, investor relationship and linked LP or investor record.
  • Contact data: Email address, telephone number and business contact information.
  • Authentication data: Login credentials, session tokens, access timestamps, IP addresses and device/browserAuthentication data: Login credentials, session tokens, access timestamps, IP addresses and device/browser data.
  • Portal activity data: Documents viewed or downloaded, reports accessed, notifications viewed, pages visited and audit records relating to portal use.
  • Watermarking data: Identifying information that may be applied to downloaded documents for security, traceability and redistribution deterrence.
  • Investor documents: Documents uploaded or made available through the portal, which may include KYC, onboarding, subscription, tax, legal, investor reporting or other materials containing personal data.

4.4 Demo Environment Users

When you use the public Prism demo environment, we may collect technical, usage, authentication and interaction data needed to operate the demo, protect the service, understand product interest and prevent misuse. The demo environment should use demonstration data only and should not be used to upload or process live customer data.

4.5 Private Deployment Users

Where Prism is operated as a private deployment, the personal data Perspect can access may depend on the agreed deployment model. In some private deployments, Perspect may have limited or no routine access to customer-controlled data. In others, Perspect may process data for support, maintenance, migration, monitoring or implementation purposes under a separate agreement.

4.6 Data We Do Not Intentionally Collect

We do not intentionally collect personal data from children under 18. Prism is intended for business and professional use. We do not intentionally collect special category data except where it is included in documents or records uploaded by customers, such as KYC materials, identity documents, investor onboarding documents or similar files.

5. How We Collect Personal Data

We collect personal data through:

  • Direct interactions: when you complete a form, email us, subscribe, request information, create an account, upload data, configure Prism or use platform features.
  • Automated technologies: such as cookies, server logs, analytics tools, authentication systems and application logs.
  • Customer-provided data: when a customer creates your user account, imports your contact record, links you to an LP record, uploads documents or grants you portal access.
  • Third-party authentication providers: such as Azure AD, Okta or Google Workspace, where SSO is configured.
  • Payment and billing providers: such as Stripe, where payment status, subscription status and invoice information are processed.
  • Connected systems: where a customer uses Prism integrations, API ingest, webhooks or data imports to move data between Prism and external systems.

6. How We Use Personal Data and Lawful Bases

We process personal data for the purposes and lawful bases set out below. The lawful basis may vary depending on the relationship, deployment model and whether Perspect is acting as controller or processor.

Purpose Typical Lawful Basis
Providing access to Prism, Prism Cloud, the Investor Portal and related services Performance of a contract; legitimate interests; processor instructions
Creating and managing accounts, users, roles, permissions and tenant settings Performance of a contract; legitimate interests; processor instructions
Authenticating users through passwords, sessions, SSO and security controls Performance of a contract; legitimate interests in platform security
Operating the Investor Portal and controlling investor-facing access Performance of a contract; legitimate interests; processor instructions
Maintaining audit logs, document access records, security logs and operational evidence Legitimate interests in security, governance and compliance; legal obligation where applicable
Processing billing, invoices, subscriptions and payment status Performance of a contract; legal obligation; legitimate interests
Responding to enquiries, support requests, procurement questions and security questionnaires Legitimate interests; performance of a contract
Processing uploads, imports, exports, reports, documents and platform workflows Performance of a contract; processor instructions
Providing AI-assisted extraction, drafting, summarisation, classification or analysis features Performance of a contract; legitimate interests; processor instructions
Monitoring platform reliability, preventing misuse and protecting against security threats Legitimate interests in security and service integrity
Analysing website usage through Google Analytics where accepted Consent
Complying with legal, tax, accounting, regulatory and dispute-resolution obligations Legal obligation; legitimate interests

7. AI-Assisted Features

Prism may include AI-assisted features for document extraction, report commentary, portfolio analysis, operational review, summarisation, tagging, classification and drafting. These features are designed to assist users, not replace professional judgement.

When AI features are used, data submitted to the feature may be transmitted to and processed by Perspect and one or more AI providers. This may include prompts, uploaded documents, extracted text, financial records, report context, CRM context, portfolio data and other Customer Data needed to provide the feature.

Perspect may use AI providers including Anthropic, OpenAI and Google AI / Gemini, depending on product configuration, customer settings, provider availability and deployment model. AI provider usage may change over time.

We do not knowingly use Customer Data to train general AI models without customer permission. AI outputs should be reviewed by an authorised human user before being relied upon, published, exported, sent to investors or used in a durable finance workflow.

For private deployments, AI availability, AI provider routing, customer-controlled keys, disabled AI mode or local-only processing requirements should be agreed separately where relevant.

8. Cookies and Analytics

Our website and platform use cookies and similar technologies. Some cookies are strictly necessary for authentication, security, session management and cookie preference storage. Non-essential analytics cookies are used only where consent has been provided.

We use Google Analytics on the Perspect marketing website to understand website traffic and improve content. Analytics cookies are not intended to be used to track sensitive platform activity inside Prism.

You can manage cookie choices through the cookie banner and browser controls. For more detail, see our Cookie Policy.

9. Sharing Personal Data

We may share personal data with third parties where necessary to operate, secure, support and improve the Services, comply with law or perform contractual obligations.

Recipient / Processor Purpose Typical Location
DigitalOcean Cloud infrastructure and hosting for Prism Cloud United States / selected hosting regions
Cloudflare DNS, edge security, traffic protection and network services Global
Stripe Payment processing, subscription billing and invoice support United States / global
Microsoft Azure AD / Microsoft Entra SSO where configured by customers Global
Okta SSO authentication where configured by customers United States / global
Google Google Workspace SSO, Google Analytics and Google AI / Gemini where used United States / global
Anthropic AI-assisted platform features where configured or used United States
OpenAI AI-assisted platform features where configured or used United States
Email, SMTP and communications providers Transactional email, support communications and service notices United Kingdom / United States / global depending on provider

We may also disclose personal data to professional advisers, insurers, auditors, regulators, law enforcement, courts, public authorities, acquirers, successors or other parties where legally required or reasonably necessary to protect Perspect, customers, users, the Services or third parties.

We do not sell personal data.

10. International Data Transfers

Some service providers used by Perspect may process personal data outside the United Kingdom. Where personal data is transferred internationally and UK GDPR requires safeguards, we use appropriate transfer mechanisms such as the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, adequacy regulations or other legally recognised safeguards.

Where a customer uses Prism in connection with data from the EEA or another jurisdiction, the customer is responsible for ensuring that its own use of Prism complies with applicable transfer, data protection and notice requirements.

For private deployments, international transfer arrangements may depend on the agreed hosting location, support access, sub-processors and maintenance model.

11. Data Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration and disclosure. These measures may include:

  • Encryption: TLS for data in transit and encrypted storage for hosted infrastructure, with additional application-layer encryption for selected secrets where applicable.
  • Access controls: role-based access controls, tenant scoping, authentication controls, SSO support and administrative permissions.
  • Audit logging: recording significant platform events, document access, report generation, approval decisions, configuration changes and security-relevant activity.
  • Document controls: authenticated downloads, portal restrictions and watermarking where configured.
  • Operational safeguards: monitoring, backups, controlled deployment processes, provider security controls and environment separation.
  • AI governance: tenant-level AI settings, usage controls and review-oriented workflows where available.

No system is completely secure. Customers remain responsible for their own users, devices, exported files, downloaded documents, identity provider configuration, private deployment environment and connected third-party systems.

12. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including providing the Services, maintaining security, complying with legal obligations, resolving disputes and enforcing agreements.

Data Category Typical Retention Period
Active Prism account and tenant data For the duration of the active subscription or deployment agreement
Tenant data after Prism Cloud cancellation Typically retained for 90 days after the end of the paid period, unless a different period is required by law or agreed in writing
Billing, invoice and accounting records Up to 7 years where required for tax, accounting or legal purposes
Audit logs and security logs Typically up to 7 years, subject to customer settings, legal requirements and deployment model
Investor Portal document access records Typically up to 7 years, subject to customer settings, legal requirements and deployment model
KYC, investor identity and onboarding documents Controlled by the customer as controller; may be retained for legal, AML/KYC or fund administration periods where applicable
Website analytics data According to the configured analytics retention period and cookie consent status
Support, sales and enquiry correspondence Typically up to 3 years from last interaction, unless needed for an ongoing relationship, dispute or legal obligation

Where a customer controls data inside its Prism tenant, the customer may set or request retention and deletion arrangements subject to platform capabilities, legal obligations and contractual terms.

13. Your Legal Rights

Subject to applicable law, you may have the following rights in relation to your personal data:

  • Right of access: to request a copy of personal data held about you.
  • Right to rectification: to request correction of inaccurate or incomplete personal data.
  • Right to erasure: to request deletion of personal data where there is no lawful reason to continue processing it.
  • Right to restrict processing: to request restriction of processing in certain circumstances.
  • Right to data portability: to receive certain personal data in a structured, commonly used and machine-readable format.
  • Right to object: to object to processing based on legitimate interests in certain circumstances.
  • Right to withdraw consent: where processing is based on consent, such as analytics cookies.
  • Rights related to automated decision-making: where applicable under data protection law.

To exercise these rights, contact [email protected]. If your personal data is processed inside a customer-controlled Prism tenant, we may need to refer your request to the relevant customer because they may be the controller of that data.

We may need to verify your identity before responding. We will respond within the timeframe required by applicable law, subject to any permitted extension.

14. Complaints

If you are unhappy with how we handle personal data, please contact us first at [email protected] so we can try to resolve the issue.

You also have the right to lodge a complaint with the UK’s data protection regulator:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk

15. Third-Party Links and Customer-Controlled Systems

The Perspect website and Prism platform may contain links or integrations to third-party websites, services or customer-controlled systems. This Privacy Policy does not apply to third-party websites or services that Perspect does not control. Customers are responsible for reviewing the privacy, security and compliance implications of third-party systems they connect to Prism.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in Prism, Perspect’s services, deployment models, subprocessors, legal requirements or data protection practices. When we make material changes, we will update the “Last updated” date and, where appropriate, notify platform administrators or affected users.

Continued use of the Services after a policy update indicates acknowledgement of the updated Privacy Policy.

17. Contact Us

If you have questions, concerns or requests relating to this Privacy Policy or the way personal data is handled, please contact:

Perspect Services Ltd
441 Sidcup Road
London
SE9 4ET
United Kingdom
Email: [email protected]