Legal
Privacy Policy
How Pramaana Labs handles the information you share with us.
1. Introduction
Pramaana Labs, LLC ("the Company," "we," "us," or "our") operates the website parmaanalabs.com and the Pramaana audit-evidence and data-provenance platform (collectively, the "Service"). Pramaana is designed for internal audit and compliance teams at regulated enterprises: our core function is to accept customer-uploaded audit evidence -- financial exports, PDF board packages, email records, and working-paper files -- and construct a verified provenance chain that links each figure in a working paper back to its originating source document.
This Privacy Policy explains what personal information we collect in the course of providing the Service, how we use it, and the rights you have. It applies to information collected through the Service and through direct communications with us. The Company is based at 125 Summer Street, 16th Floor, Boston, MA 02110, and can be reached at [email protected].
2. Information We Collect
2.1 Information You Provide Directly
We collect information you submit to us through the Service, including:
- Contact details (name, work email, phone number) when you request a demo, submit a contact form, or sign up for early access;
- Professional context you choose to share (employer name, role, team size, audit-workflow description);
- The content of messages you send us, including questions about implementation, security review requests, or vulnerability disclosures;
- Account credentials (hashed password, registered work email) when you create a Pramaana account.
2.2 Audit Evidence and Platform Data
When your organization uses the Pramaana platform as a subscriber, authorized users upload audit evidence files -- PDF documents, Excel workbooks, email exports, SharePoint and Google Drive files, and similar records -- for provenance analysis. This upload content is processed solely to generate citation graphs and trace reports for your organization's internal use. We treat this material as confidential business data belonging to your organization and subject to any data-processing agreement in effect between the Company and your organization.
We also collect provenance metadata generated during trace operations: query timestamps, source-document references, confidence scores, and trace identifiers (e.g., "AUD-2025-Q3-0047"). These records form the immutable audit log that is central to the Service's integrity guarantees.
We do not use your uploaded audit evidence or working-paper files to train, update, or improve any machine-learning model. Your documents are your evidence; they are not training data.
2.3 Information Collected Automatically
When you visit parmaanalabs.com, we automatically collect limited technical information:
- IP address and approximate location (city and region level);
- Browser type, operating system, and device class;
- Pages visited, referring URLs, and time on page;
- Cookie and similar identifiers (see our Cookie Policy).
2.4 We Do Not Knowingly Collect Children's Data
parmaanalabs.com is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it promptly.
3. How We Use Information
Pramaana uses the information we collect to:
- Respond to inquiries, provide requested demos, and communicate about early-access enrollment;
- Operate, maintain, and improve the Service, including the trace engine, citation graph, and evidence-export features;
- Process and fulfill orders and subscriptions for the platform;
- Maintain immutable audit logs of trace queries for evidence-integrity purposes, which is a core feature of the Service rather than a secondary use;
- Send service and security notifications, and (with your consent where required) product updates or marketing communications;
- Detect, investigate, and prevent fraud, abuse, or unauthorized access to the platform;
- Comply with legal obligations applicable to a financial-technology service provider in Massachusetts.
We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.
4. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf -- such as cloud infrastructure, email delivery, and anonymized usage analytics -- under contractual confidentiality and data-processing terms;
- Authorities, when required by applicable law, court order, or to protect the rights, safety, or property of the Company, its customers, or the public;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy and notice to affected users.
We do not sell personal information to third parties. We do not disclose customer-uploaded audit evidence to any third party except as required by law or as directed by the customer organization under a data-processing agreement.
5. Cookies and Tracking
We use cookies and similar technologies to operate the site, remember preferences, and measure usage. We do not use cross-site behavioral advertising cookies. For details and opt-out choices, see our Cookie Policy.
6. Data Retention
We retain personal information only as long as needed for the purposes described in this Policy and to satisfy applicable legal or accounting obligations. Specifically:
- Contact and demo-inquiry records are retained for up to 36 months from last activity;
- Inactive marketing-list contacts are purged after 24 months;
- Server access logs are retained for 90 days, then aggregated;
- Subscriber audit-evidence files and citation graphs are purged within 72 hours of a project deletion request, with a confirmation log retained for record-keeping.
Massachusetts financial-services regulations and the internal-audit context of our customers may require us to maintain certain records for legally specified periods. Where such retention obligations apply, we retain the minimum data necessary to satisfy them.
7. Security
We apply administrative, technical, and physical safeguards designed to protect personal information and customer audit evidence. These include TLS 1.3 encryption in transit, AES-256-GCM encryption at rest for stored documents and citation graphs, append-only trace audit logs, least-privilege access controls, and optional single-tenant deployment for financial-services clients. No system is perfectly secure; we cannot guarantee absolute security and encourage customers with high-sensitivity audit data to review our security posture at security.parmaanalabs.com.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access to, correction of, deletion of, and the ability to limit certain processing of personal information we hold about you. To make a request, email [email protected] with a description of your request and sufficient detail for us to verify your identity. We will respond within the timeframe required by applicable law.
9. Massachusetts Residents
Massachusetts does not currently have a comprehensive consumer privacy statute comparable to California's CCPA or Virginia's VCDPA. As a matter of policy, the Company extends the following baseline rights to all U.S. residents regardless of state of residence.
9.1 Baseline Rights
- Right to Know: request the categories of personal information we have collected about you;
- Right to Delete: request deletion of personal information you have provided;
- Right to Correct: request correction of inaccurate personal information;
- Right to Opt Out of Marketing: unsubscribe from marketing emails or opt out via the link in each marketing message.
9.2 How to Exercise
Email [email protected] with a description of your request and enough detail for us to verify your identity. We respond within 45 days. Massachusetts residents may also submit complaints to the Massachusetts Attorney General's Office.
9.3 Sector-Specific Rights
Because Pramaana serves regulated financial-services and audit environments, you may also be protected by federal sector laws including the Gramm-Leach-Bliley Act (GLBA) and -- for certain data types -- the Bank Secrecy Act and related regulations. Those laws may give you additional rights with respect to the data they cover. Pramaana customers who are subject to PCAOB or SEC recordkeeping obligations remain solely responsible for their own compliance with those requirements; Pramaana's audit log features are designed to assist but do not substitute for each organization's own compliance program.
9.4 California Visitors
If you are a California resident, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. The Company does not sell personal information and does not "share" personal information for cross-context behavioral advertising.
To submit a CCPA/CPRA request, email [email protected] with the subject line "California Privacy Request."
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date at the top of this page and, where appropriate, a notice on the Service. Continued use of the Service after the effective date of a material change constitutes acceptance of the updated Policy.
11. Contact
Questions, requests, or complaints related to this Privacy Policy can be sent to:
Pramaana Labs, LLC125 Summer Street, 16th Floor
Boston, MA 02110
Email: [email protected]
Phone: +1 (617) 226-0471