Data Protection Policy
Effective date: [Effective Date] · Last updated: [Last Updated Date]
This Data Protection Policy summarizes how Twin Raven Studios, Inc. ("we," "us") protects personal data processed through the Portanus platform ("the Service"). It is a public summary intended for transparency; a more detailed internal policy is maintained separately and governs our day-to-day operations. This summary works alongside our Privacy Policy and our Data Processing Agreement.
1. Our data-protection principles
We handle personal data in line with widely recognized data-protection principles:
- Lawfulness, fairness, and transparency — we process data on a lawful basis and explain how we use it.
- Purpose limitation — we collect data for specified, legitimate purposes and do not use it in incompatible ways.
- Data minimization — we limit data to what is necessary for those purposes.
- Accuracy — we take reasonable steps to keep data accurate and up to date.
- Storage limitation — we retain data only as long as needed for the purpose or as required by law.
- Integrity and confidentiality — we protect data with appropriate technical and organizational safeguards.
- Accountability — we maintain records and controls to demonstrate compliance.
2. Roles: controller and processor
For most personal data in the Service, the Customer organization is the data controller and determines the purposes and means of processing. We act as a data processor, processing personal data on the Customer's documented instructions to provide and secure the Service. Where we determine purposes for our own limited operational data (for example, account administration), we act as a controller for that data, as described in our Privacy Policy.
3. Safeguards
We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, role-based access control with enforced multi-factor authentication for privileged accounts, tenant isolation, and audit logging. These measures are described in our Security & Vulnerability Disclosure overview. The Service is designed and operated to meet the requirements of SOC 2, the HITRUST CSF, and HIPAA, with formal attestation and certification in progress.
4. Data subject rights
Individuals may have rights regarding their personal data, such as access, correction, deletion, and restriction, depending on applicable law. Because the Customer organization is typically the controller of personal data in the Service, individuals should direct rights requests to the Customer organization that holds their data. When we receive a request directed to us as a processor, we will refer it to the relevant Customer and support that Customer in responding.
5. International transfers
Where personal data is transferred across borders, we use appropriate safeguards and transfer mechanisms as required by applicable law. The specific mechanisms applicable to a Customer are addressed in the Data Processing Agreement.
6. Sub-processors
We use a limited set of vetted sub-processors to help deliver the Service. We perform diligence on these vendors, bind them to appropriate data-protection obligations, and enter into Business Associate Agreements where HIPAA applies. Our current sub-processor information is made available to Customers as described in the Data Processing Agreement.
7. Breach response
We maintain processes to detect, investigate, and respond to security incidents involving personal data. In the event of a personal data breach affecting Customer Data, we will notify the affected Customer without undue delay and provide information reasonably available to support the Customer's own notification obligations.
8. Data migration engagements
When we perform a data migration on a Customer's behalf, or a Customer uses our migration tools, additional safeguards apply to the data being moved:
- Isolation — migration processing runs entirely within the Customer's own tenant environment; migrated data is never pooled with, or exposed to, another Customer.
- Integrity of intake — each source file we receive is fingerprinted (SHA-256) on arrival, and a per-record dry run is produced for the Customer's review and sign-off before any data is written to the workspace.
- Reversibility — records created by a migration are batch-identified so that an import can be rolled back.
- Retention of migration materials — source files and the record-level import reports (which may contain personal data) are retained only for the period needed to complete and verify the engagement, and are then purged on a defined schedule after the engagement closes. The migration dossier — a summary of counts, mappings, exclusions, and reconciliation that does not reproduce raw personal data — is retained as the engagement's audit record.
- AI assistance — where AI is used to assist a migration (for example, to suggest column mappings or cluster data-quality issues), it proposes configuration only and never writes to Customer Data; a person reviews each suggestion, and a deterministic pipeline performs the actual processing. The assistant can be run in a headers-only mode that transmits no cell values. AI processing is performed through a vetted sub-processor under the obligations described in section 6, and every AI request is logged and cost-attributed.
9. How this relates to our other policies
This summary complements our Privacy Policy, which describes our data practices in more detail, and our Data Processing Agreement, which sets out the contractual data-protection terms between us and our Customers. Questions can be directed to legal@twinravenstudios.com.
This document is a public summary provided for transparency and is not legal advice. It should be reviewed and tailored by qualified counsel and aligned with your internal data-protection policy, master agreement, and Data Processing Agreement before use.
PORTANUS