Data Processing & Security
Effective 2026-08-22 · Version 2026-08-22
This page describes the technical and organizational measures Princeton Analytica uses to protect customer data. It is provided for transparency and does not modify or expand any warranty or obligation set out in our Terms of Service.
1. 1. Infrastructure
The Service runs on enterprise-grade cloud infrastructure hosted in the United States. We rely on managed services for compute, storage, authentication, and networking rather than operating our own data centers.
2. 2. Encryption
Data at rest, including uploaded files, intermediate research artifacts, and generated reports, is encrypted using managed encryption keys and industry-standard algorithms. Data in transit is encrypted using TLS 1.2 or higher for all connections to our website, dashboard, and APIs.
3. 3. Storage and Access to Files
Uploaded files and generated reports are stored in private storage that is not publicly accessible. Downloads are served through short-lived, signed URLs that expire after a limited time, rather than permanent public links.
4. 4. Tenant Isolation and Authorization
Customer data is logically isolated by account, and access to any customer's data is enforced through server-side authorization checks tied to that customer's authenticated session. Internal systems follow the principle of least-privilege access: employees and automated services are granted only the access needed to perform their function.
5. 5. Logging and Monitoring
We maintain centralized audit and system logging and continuous monitoring for anomalous behavior across our infrastructure, supporting incident detection and after-the-fact investigation.
6. 6. Network Protections
Our web application is protected by a web application firewall (WAF) and rate limiting designed to mitigate common web attacks and abusive automated traffic.
7. 7. Payment Data
All payment card data is collected and processed directly by our payment processor, which maintains PCI DSS (Payment Card Industry Data Security Standard) compliance. We do not store full card numbers, CVV codes, or other sensitive card data on our own systems.
8. 8. Authentication
Customer accounts are authenticated using email and password credentials under a strong password policy, with optional multi-factor authentication (MFA) available for additional account security. We encourage customers to enable MFA where available.
9. 9. Data Retention and Deletion
Raw customer uploads are retained by default for 90 days and then automatically deleted. Intermediate research artifacts generated during report production are retained by default for 180 days and then automatically deleted. Generated reports remain available in your account library until you request deletion. Customers may request earlier deletion of their data by contacting privacy@princetonanalytica.com.
10. 10. Subprocessors
We rely on the following categories of subprocessors to provide the Service. We may update this list as our vendor relationships evolve.
- Cloud infrastructure provider — hosting, storage, compute, authentication, and AI processing
- Payment processor — PCI DSS-compliant payment processing
11. 11. Incident Response
We maintain internal procedures to investigate and respond to suspected security incidents affecting customer data. If we determine that a security incident has resulted in unauthorized access to your personal information, we will notify affected customers and relevant authorities as required by applicable law.
12. 12. Responsible Disclosure
If you believe you have discovered a security vulnerability affecting our Service, please report it to security@princetonanalytica.com. We ask that you give us a reasonable opportunity to investigate and address any reported issue before disclosing it publicly, and that you do not access or modify data that is not your own in the course of your research.
13. 13. Compliance Status
Our infrastructure and payment providers maintain independent third-party compliance certifications, including SOC 2 and PCI DSS, and our own controls are designed to align with recognized security frameworks. We will update this page as our compliance program evolves.