PRINCETON ANALYTICADecision-grade intelligence

Data Processing & Security

Effective 2026-08-21 · Version 2026-08-21

This document is a starter policy template prepared for general informational purposes. It is not legal advice and has not been reviewed by an attorney. Princeton Analytica should have qualified legal counsel licensed in the applicable jurisdiction review and, where appropriate, revise this document before it is relied upon as a binding legal or policy instrument.

This page describes the technical and organizational measures Princeton Analytica uses to protect customer data. It is provided for transparency and does not modify or expand any warranty or obligation set out in our Terms of Service.

1. 1. Infrastructure

The Service runs on Amazon Web Services (AWS) infrastructure, primarily in the us-east-1 (Northern Virginia) region. We rely on AWS's managed services for compute, storage, authentication, and networking rather than operating our own data centers.

2. 2. Encryption

Data at rest, including uploaded files, intermediate research artifacts, and generated reports, is encrypted using AWS Key Management Service (KMS)-managed encryption keys. Data in transit is encrypted using TLS 1.2 or higher for all connections to our website, dashboard, and APIs.

3. 3. Storage and Access to Files

Uploaded files and generated reports are stored in private storage that is not publicly accessible. Downloads are served through short-lived, signed URLs that expire after a limited time, rather than permanent public links.

4. 4. Tenant Isolation and Authorization

Customer data is logically isolated by account, and access to any customer's data is enforced through server-side authorization checks tied to that customer's authenticated session. Internal systems follow the principle of least-privilege access: employees and automated services are granted only the access needed to perform their function.

5. 5. Logging and Monitoring

We use AWS CloudTrail and Amazon CloudWatch to log administrative and system activity and to monitor for anomalous behavior across our infrastructure, supporting incident detection and after-the-fact investigation.

6. 6. Network Protections

Our web application is protected by a web application firewall (WAF) and rate limiting designed to mitigate common web attacks and abusive automated traffic.

7. 7. Payment Data

All payment card data is collected and processed directly by Stripe, a payment processor that maintains its own PCI DSS (Payment Card Industry Data Security Standard) compliance. We do not store full card numbers, CVV codes, or other sensitive card data on our own systems.

8. 8. Authentication

Customer accounts are authenticated through Amazon Cognito using email and password credentials, with optional multi-factor authentication (MFA) available for additional account security. We encourage customers to enable MFA where available.

9. 9. Data Retention and Deletion

Raw customer uploads are retained by default for 90 days and then automatically deleted. Intermediate research artifacts generated during report production are retained by default for 180 days and then automatically deleted. Generated reports remain available in your account library until you request deletion. Customers may request earlier deletion of their data by contacting privacy@princetonanalytica.com.

10. 10. Subprocessors

We rely on the following categories of subprocessors to provide the Service. We may update this list as our vendor relationships evolve.

  • Amazon Web Services (AWS) — hosting, storage, compute, authentication (Cognito), and AI processing (Amazon Bedrock)
  • Stripe — payment processing

11. 11. Incident Response

We maintain internal procedures to investigate and respond to suspected security incidents affecting customer data. If we determine that a security incident has resulted in unauthorized access to your personal information, we will notify affected customers and relevant authorities as required by applicable law.

12. 12. Responsible Disclosure

If you believe you have discovered a security vulnerability affecting our Service, please report it to security@princetonanalytica.com. We ask that you give us a reasonable opportunity to investigate and address any reported issue before disclosing it publicly, and that you do not access or modify data that is not your own in the course of your research.

13. 13. Compliance Status

Princeton Analytica has not yet completed a SOC 2 or similar third-party compliance audit. We rely on the security capabilities of our underlying infrastructure providers (including AWS and Stripe, which maintain their own compliance certifications) together with the practices described on this page. We will update this page if and when our own compliance certifications change.