Skip to main content Skip to main content

Prisma Hosted Systems Privacy Statement

This page describes how we process Personal Information in our hosted systems for our clients. Mediaocean LLC (“Mediaocean” or “we”) recognizes and respects privacy rights with regard to Personal Information. 

Where Personal Information is collected, stored or used by our client companies using these hosted systems, please note that we act only as a Data Processor. The client company is the Data Controller and is responsible for data protection obligations pertaining to its notification, collection, accuracy, and timely disposal. The client company is also responsible for arrangements to enable individuals to access their Personal Information, subject to confirmation of identification, for authorizing disclosure to Third Parties, and for breach notifications to relevant state or provincial agencies and to users, in case of a security incident. 

As a Data Processor, Mediaocean’s responsibilities for this data are to: 

  • Process the Personal Information only on documented instructions from our client.
  • Ensure that all persons we authorize to process the Personal Information understand and respect the confidential nature of this information.
  • Make provisions for the security, availability and integrity of data on our systems, including where we have appointed Sub-processors to help us deliver our services to our clients.
  • In the event that there is a security incident, provide our client with the information needed to make statutory breach notifications. 

 

Contact Information 

Mediaocean LLC, 120 Broadway, New York, NY 10271, United States; 
InfoSec&Compliance@mediaocean.com 

 

Categories of personal information in our hosted systems 

Our clients may ask us to process the following types of Personal Information:

  • User credentials, including user names and passwords;
  • Logs of actions taken within the systems, such as application logs, usage analysis, and audit trails;
  • Business contact details of client employees, and potentially their vendors’ or clients’ employees, for example to facilitate order or payment processes, or to ensure delivery of printed output to the correct individual;
  • In the case of Aura or the financial systems, information related to staff expense payments, timesheets, and similar matters.
  • Sensitive Information is not processed unless it is voluntarily provided. 

 

How we store information 

Personal Information processed in our hosted systems is stored at our secure data centers and at secure off-site storage facilities for back-up media. 

Staff involved in support, engineering and technical operations may be based in any location where Mediaocean group companies have offices (Australia, Canada, France, Germany, Netherlands, India, Malaysia, Singapore, UK, USA). Our staff may access data from any of those locations. However, staff are only given access to the data if they need it in order to be able to do their jobs, and only if they have completed mandatory training on security procedures. 

We retain Personal Information within our hosted systems in accordance with Mediaocean’s Data and Document Retention Policies. These policies define retention rules based on the nature of the information and the purpose for which it is required. We destroy or dispose of all Personal Information securely when it is no longer needed. 

 

How we keep information secure 

Mediaocean has a documented Information Security policy and we have implemented technical and organizational security measures to ensure the confidentiality, availability and integrity of Personal Information within our hosted systems. These include:

  • logical access controls
  • network security configurations
  • physical access controls
  • system software support and change control procedures
  • processing integrity measures including logging & monitoring systems
  • data retention practices including data replication, virtual and physical back-ups
  • resilience, recovery and continuity planning
  • applications software development and change control procedures
  • incident management
  • vendor management 

 

Individual Rights 

Individuals seeking access to, deletion of, or correction of their Personal Information held within Mediaocean’s hosted systems should contact the client company, which acts as the Data Controller. Mediaocean is not able to respond to Data Subject requests regarding Personal Information in these systems without prior authorisation from the client. 

 

Children under the age of 13 

Our hosted services are not intended for children under 13 years of age. No one under age 13 may provide any Personal Information to or on the website. We do not knowingly collect Personal Information from children under 13. If you are under 13, do not use or provide any information on this website or on or through any of its features. If we learn we have collected or received Personal Information from a child under 13 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 13, please contact us at Infosec&Compliance@mediaocean.com. 

 

Enquiries and complaints 

We commit to resolve complaints about privacy and our collection or use of Personal Information. If you have inquiries or complaints regarding this privacy policy or the handling of your Personal Information, please contact datasecurity@mediaocean.com

We will cooperate with the US Dept. of Commerce, the US Federal Trade Commission, the Office of the Privacy Commissioner of Canada, and any other relevant government agencies, and law enforcement and judicial authorities in investigating any privacy complaints or suspected violations of privacy laws or Mediaocean’s privacy commitments, as well as in rectifying any noncompliant practices. Employees or contractors who violate the terms of these principles may be subject to disciplinary consequences up to and including termination of employment or termination or non-renewal of contract, in addition to any other legal measures that may be taken by Mediaocean, its clients, or the affected individuals and their representatives.