Privacy Notice

Prior Foundry SAS

Last updated: 23rd July 2026

Who we are

Prior Foundry SAS. This notice explains how we handle personal information and what rights you have. It covers website visitors, contacts at our customers and suppliers, people whose information we handle in delivering our services, and job applicants. Our employees receive a separate notice. For some engagements you may also receive a shorter notice specific to that work. Where the two differ, the specific one applies.

Our role

Sometimes we decide how your information is used, and we are responsible for it. Sometimes a customer decides and we act only on their instructions, in which case they are responsible and we will pass your request to them. Sometimes we and a customer decide together — where that applies you will be told who they are, and you can exercise your rights against either of us. If you are unsure which applies, ask us.

What we collect and where it comes from

Website visitors

IP address, device and browser, pages viewed, approximate location — collected automatically via cookies. Name, email, organisation and message if you contact us.

Customer and supplier contacts

Name, job title, organisation, work contact details, correspondence, contract and payment details — from you, your organisation, or public sources.

Individuals whose information we handle for a customer

Contact details, records of consent, and the information relevant to the engagement, which may include your views, circumstances and any recordings or documents you provide. From you, or from the customer who engaged us.

Job applicants

CV, employment history, qualifications, right-to-work information, references, interview notes, and background checks where the role requires them.

If a customer gives us your details, we will tell you where we got them when we first contact you.

Sensitive information

Some information needs extra protection — health, disability, ethnicity, religion, political opinions, sex life or sexual orientation, genetic or biometric data, and criminal offences. We do not seek it unless it is relevant and we have told you so, but people sometimes share it unprompted. When that happens we apply the extra safeguards described below and remove it where it is not needed. Where the law requires, we rely on your explicit consent or another recognised condition, and we keep a document explaining how we comply.

Why we use your information

Run and secure our website

Our legitimate interest in a working, secure site

Analytics and non-essential cookies

Your consent

Respond to enquiries; manage customer and supplier relationships

Contract, or our legitimate interest in managing relationships

Deliver our services and produce the agreed outputs

Contract, our legitimate interests, or the customer's lawful basis

Collect information directly from you for an engagement

Your consent, or another basis we will tell you about

Use sensitive information

Your explicit consent, or another recognised condition

Make payments to you

Contract, and our legal obligation to keep tax records

Keep records to defend legal claims and meet legal duties

Our legitimate interests, and legal obligation

Recruit staff

Steps before a contract, and our legitimate interest in recruitment

Where we rely on consent you can withdraw it at any time, and it will not affect anything done beforehand. Where we rely on legitimate interests you can ask for a copy of our assessment.

Consent

We ask separately for each distinct purpose, so you can agree to some things and not others. We record what you agreed to, when, and how. Withdrawing is as easy as agreeing — email us and we will action it across our systems within five business days. Taking part is voluntary and refusing will not affect any service or relationship you have with us or with our customer.

Who we share it with

The customer who engaged us, where relevant to the work — normally in a form that does not identify you unless you have agreed otherwise. Service providers for cloud hosting, IT support, communications, payments and professional services, who act only on our instructions under written contract. Professional advisers, insurers and auditors. Authorities where the law requires it, or where there is a serious concern about someone's safety — we will tell you if that happens unless doing so would put someone at greater risk.


We do not sell your information, and we do not share it for targeted or cross-context behavioural advertising. We do not allow it to be used to train artificial intelligence models, by us or by any supplier.

Where it is held

We process and store information in the United Kingdom, the European Economic Area and the United States, with Customer consent for each location. Transfers between the UK and EEA are covered by adequacy arrangements, so no extra safeguards are needed. Transfers elsewhere use an approved safeguard — the Data Privacy Framework, the UK International Data Transfer Agreement, or the European Commission's Standard Contractual Clauses with the UK Addendum — plus an assessment of the destination country's laws. Ask us for a copy of the safeguard we rely on. For some engagements we agree to keep everything in one country; if that applies to you, we will say so.

How long we keep it


Website analytics 24 months


Enquiries 2 years from last contact


Customer and supplier records 3 years from end of contract


Information handled for an engagement For the engagement, then returned or deleted as agreed with the customer


Consent and withdrawal records 3 years


Payment records 6 years, as tax law requires


Unsuccessful job applications 6 months

Where we must keep something to defend a legal claim we keep it no longer than the relevant limitation period and use it for nothing else. Deletion is irreversible. Backups are not edited individually; they expire on a 30-day cycle, staying encrypted and used only for disaster recovery.

How we protect it

We encrypt information at rest and in transit to current standards. Access is limited to those who need it, protected by multi-factor authentication and reviewed regularly. Our staff are trained before they handle personal information and annually after, are bound by confidentiality obligations, and are background-checked where their role requires. We test our security regularly, including annual independent penetration testing.

Your rights


In the UK and EEA you can ask for a copy of your information; have it corrected or deleted; restrict or object to how we use it; receive it in a portable format; and withdraw consent. We respond within one month, or up to three for complex requests, and will tell you if we need longer.


In the United States, depending on your state, you can ask what we hold and where it came from; correct or delete it; obtain a portable copy; opt out of sale, sharing and targeted advertising (we do none of these); limit our use of sensitive information; and appeal if we refuse. We confirm receipt within 10 business days and respond within 45 days, extendable once. You may use an authorised agent. We will not treat you differently for exercising any right.


To make a request: send an email to info@priorfoundry.com. We may ask you to confirm your identity, and will not ask for more than we need to do so.

Occasionally we cannot do everything you ask — for example where information has been irreversibly anonymised, or where the law requires us to keep it. We will explain why.

Automated decisions and children

We do not make decisions about you by automated means alone, and we do not carry out profiling with legal or similarly significant effects. Where software assists us, a person reviews the result.

Our services are not directed at children and we do not knowingly collect their information through our website. Where an engagement involves under-18s we obtain consent from a parent or guardian where required and apply additional safeguards, explained in the notice for that work.

Contact and complaints


Privacy enquiries and rights requests: info@priorfoundry.com


Privacy Lead: Keshav Sivakumar, keshav@priorfoundry.com

Please tell us first if you are unhappy. You can also complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113), to your EEA supervisory authority, or in the US to your State Attorney General. Where we deliver work jointly with a customer, you may complain to them too.

Changes

We review this notice at least annually and publish updates here within 30 days of any significant change. Where a change materially affects you and we hold your contact details, we will tell you directly.

Prior Foundry Inc.

Last updated: 23rd July 2026

Who we are

Prior Foundry Inc., 418 Broadway, 4150, Albany, NY, 12207. This notice explains how we handle personal information and what rights you have. It covers website visitors, contacts at our customers and suppliers, people whose information we handle in delivering our services, and job applicants. Our employees receive a separate notice. For some engagements you may also receive a shorter notice specific to that work. Where the two differ, the specific one applies.

Our role

Sometimes we decide how your information is used, and we are responsible for it. Sometimes a customer decides and we act only on their instructions, in which case they are responsible and we will pass your request to them. Sometimes we and a customer decide together — where that applies you will be told who they are, and you can exercise your rights against either of us. If you are unsure which applies, ask us.

What we collect and where it comes from

Website visitors

IP address, device and browser, pages viewed, approximate location — collected automatically via cookies. Name, email, organisation and message if you contact us.

Customer and supplier contacts

Name, job title, organisation, work contact details, correspondence, contract and payment details — from you, your organisation, or public sources.

Individuals whose information we handle for a customer

Contact details, records of consent, and the information relevant to the engagement, which may include your views, circumstances and any recordings or documents you provide. From you, or from the customer who engaged us.

Job applicants

CV, employment history, qualifications, right-to-work information, references, interview notes, and background checks where the role requires them.

If a customer gives us your details, we will tell you where we got them when we first contact you.

Sensitive information

Some information needs extra protection — health, disability, ethnicity, religion, political opinions, sex life or sexual orientation, genetic or biometric data, and criminal offences. We do not seek it unless it is relevant and we have told you so, but people sometimes share it unprompted. When that happens we apply the extra safeguards described below and remove it where it is not needed. Where the law requires, we rely on your explicit consent or another recognised condition, and we keep a document explaining how we comply.

Why we use your information

Run and secure our website

Our legitimate interest in a working, secure site

Analytics and non-essential cookies

Your consent

Respond to enquiries; manage customer and supplier relationships

Contract, or our legitimate interest in managing relationships

Deliver our services and produce the agreed outputs

Contract, our legitimate interests, or the customer's lawful basis

Collect information directly from you for an engagement

Your consent, or another basis we will tell you about

Use sensitive information

Your explicit consent, or another recognised condition

Make payments to you

Contract, and our legal obligation to keep tax records

Keep records to defend legal claims and meet legal duties

Our legitimate interests, and legal obligation

Recruit staff

Steps before a contract, and our legitimate interest in recruitment

Where we rely on consent you can withdraw it at any time, and it will not affect anything done beforehand. Where we rely on legitimate interests you can ask for a copy of our assessment.

Consent

We ask separately for each distinct purpose, so you can agree to some things and not others. We record what you agreed to, when, and how. Withdrawing is as easy as agreeing — email us and we will action it across our systems within five business days. Taking part is voluntary and refusing will not affect any service or relationship you have with us or with our customer.

Who we share it with

The customer who engaged us, where relevant to the work — normally in a form that does not identify you unless you have agreed otherwise. Service providers for cloud hosting, IT support, communications, payments and professional services, who act only on our instructions under written contract. Professional advisers, insurers and auditors. Authorities where the law requires it, or where there is a serious concern about someone's safety — we will tell you if that happens unless doing so would put someone at greater risk.

We do not sell your information, and we do not share it for targeted or cross-context behavioural advertising. We do not allow it to be used to train artificial intelligence models,

by us or by any supplier.

Where it is held

We process and store information in the United Kingdom, the European Economic Area and the

United States, with Customer consent for each location. Transfers between the UK and EEA are

covered by adequacy arrangements, so no extra safeguards are needed. Transfers elsewhere

use an approved safeguard — the Data Privacy Framework, the UK International Data Transfer

Agreement, or the European Commission's Standard Contractual Clauses with the UK

Addendum — plus an assessment of the destination country's laws. Ask us for a copy of the

safeguard we rely on. For some engagements we agree to keep everything in one country; if

that applies to you, we will say so.

How long we keep it

Website analytics 24 months

Enquiries 2 years from last contact

Customer and supplier records 3 years from end of contract

Information handled for an engagement For the engagement, then returned or deleted

as agreed with the customer

Consent and withdrawal records 3 years

Payment records 6 years, as tax law requires

Unsuccessful job applications 6 months

Where we must keep something to defend a legal claim we keep it no longer than the relevant

limitation period and use it for nothing else. Deletion is irreversible. Backups are not edited

individually; they expire on a 30-day cycle, staying encrypted and used only for disaster

recovery.

How we protect it

We encrypt information at rest and in transit to current standards. Access is limited to those who

need it, protected by multi-factor authentication and reviewed regularly. Our staff are trained

before they handle personal information and annually after, are bound by confidentiality

obligations, and are background-checked where their role requires. We test our security

regularly, including annual independent penetration testing.

Your rights

In the UK and EEA you can ask for a copy of your information; have it corrected or deleted;

restrict or object to how we use it; receive it in a portable format; and withdraw consent. We

respond within one month, or up to three for complex requests, and will tell you if we need

longer.

In the United States, depending on your state, you can ask what we hold and where it came

from; correct or delete it; obtain a portable copy; opt out of sale, sharing and targeted

advertising (we do none of these); limit our use of sensitive information; and appeal if we refuse.

We confirm receipt within 10 business days and respond within 45 days, extendable once. You

may use an authorised agent. We will not treat you differently for exercising any right.

To make a request: send an email to info@priorfoundry.com. We may ask you to confirm your

identity, and will not ask for more than we need to do so.

Occasionally we cannot do everything you ask — for example where information has been

irreversibly anonymised, or where the law requires us to keep it. We will explain why.

Automated decisions and children

We do not make decisions about you by automated means alone, and we do not carry out

profiling with legal or similarly significant effects. Where software assists us, a person reviews

the result.

Our services are not directed at children and we do not knowingly collect their information

through our website. Where an engagement involves under-18s we obtain consent from a

parent or guardian where required and apply additional safeguards, explained in the notice for

that work.

Contact and complaints

Privacy enquiries and rights requests: info@priorfoundry.com

Privacy Lead: Keshav Sivakumar, keshav@priorfoundry.com

Please tell us first if you are unhappy. You can also complain to the Information

Commissioner's Office (ico.org.uk, 0303 123 1113), to your EEA supervisory authority, or in

the US to your State Attorney General. Where we deliver work jointly with a customer, you may

complain to them too.

Changes

We review this notice at least annually and publish updates here within 30 days of any

significant change. Where a change materially affects you and we hold your contact details, we

will tell you directly.