Privacy Policy

Effective: July 4, 2026 Last Updated: July 4, 2026 ProsDigital LLC
Compliance SOC 2 Criteria-Aligned COPPA 2025 FERPA BIPA NY CDPA CCPA/CPRA NJDPA PIPEDA Pending

1Introduction

ProsDigital LLC (“ProsDigital,” “we,” “us,” or “our”) operates the PortraitVision platform, accessible at portraitvision.net and portraitvision.info (collectively, the “Platform”). PortraitVision is a business-to-business (B2B) Software-as-a-Service (SaaS) portrait analytics platform serving school photography companies (“Customers”).

This Privacy Policy describes how ProsDigital collects, uses, stores, protects, and governs the data submitted to or generated by the Platform. It applies to all individuals and organizations that access, use, or interact with the Platform, including Customer personnel, school administrators, government agency reviewers, and prospective customers evaluating the Platform for compliance purposes.

We do not serve children directly. The Platform is a professional tool accessed exclusively by authorized business users. Portrait images of minors are processed as part of school photography services contracted by our Customers. ProsDigital does not knowingly collect personal information directly from children.

This Policy is designed to satisfy or exceed the requirements of:

2Who We Are and How to Contact Us

Data Controller / Service Provider

ProsDigital LLC
2230 Route 70 W, STE 2, #1401
Cherry Hill, NJ 08002-3338
United States

Privacy Inquiries

privacy@portraitvision.info

Requests relating to data access, deletion, correction, or compliance inquiries should be directed to the email above. We will acknowledge receipt within 5 business days and respond substantively within 30 calendar days.

3The Data We Collect and Process

3.1 What We Accept

PortraitVision is designed with data minimization as a core principle. The Platform accepts only the following data:

3.2 What We Do Not Collect or Accept

The Platform is expressly configured to reject and not process:

Our intake systems are designed to block the submission of these data categories. If any such data is inadvertently submitted, it is not retained and is purged upon detection.

3.3 Platform User Account Data

For registered Platform users (Administrators, Managers, and Users), we collect and maintain:

4How We Use the Data

PurposeData UsedLegal Basis
Processing portrait images for analytics services subscribed to by CustomersPortrait imagesContractual obligation
Generating anonymized reports using school name dataAnonymized school nameContractual obligation
Limited biometric matching for sequential image comparison (where subscribed)Facial geometry vectorsContractual obligation; Customer-obtained consent
Enforcing role-based access controlUser account dataLegitimate interest in platform security
Maintaining security audit logsLogin and action logsLegitimate interest in security
Responding to Customer support requestsAccount and submission dataContractual obligation
Investigating security incidentsLogs, metadataLegal obligation; legitimate interest

We do not use portrait image data or biometric data for advertising, marketing, sale to third parties, profiling of individual students across organizations, training AI models, or any purpose not explicitly subscribed to by the Customer.

5Biometric Data

5.1 Scope of Biometric Processing

PortraitVision uses biometric data solely to provide the portrait analytics features subscribed to by the Customer, including, where enabled, matching sequential images of the same student. Biometric data is not used to identify individuals for any other purpose.

Biometric data consists of mathematical facial geometry vectors derived from portrait images. These vectors are retained subject to the same customer-selected retention schedule that governs the underlying portrait images (see Section 6) and are never used to train AI models.

5.2 Customer Obligations and Consent

ProsDigital’s Terms of Service require all Customers to obtain appropriate written consent — including parental or guardian consent where required — before submitting student portrait images for any biometric processing service. ProsDigital does not independently obtain consent from parents or guardians; this obligation is contractually assigned to the Customer.

5.3 Compliance with State Biometric Laws

StateLawKey Obligation
IllinoisBIPA (740 ILCS 14)Written consent before collecting biometric data; private right of action
New YorkChild Data Protection Act (CDPA)Parental consent for under 13; informed consent for ages 13–17
TexasCUBI Act (Tex. Bus. & Com. Code § 503.001)Consent required before capturing biometric identifiers
WashingtonMy Health My Data Act (MHMDA)Biometric data treated as consumer health data; private right of action
CaliforniaCCPA/CPRA + AB 2273Biometric data is sensitive personal information; parental consent required
ColoradoColorado Privacy Act (amended 2024)Heightened biometric protections; duty of care for child users
New JerseyConsumer Data Protection ActExplicit consent required before processing biometric data
OregonConsumer Data Privacy ActOpt-in consent required before collecting facial biometric data
MarylandMaryland Online Data Privacy Act (2025)Bans sale of sensitive personal data including biometric information

Across all applicable jurisdictions, ProsDigital does not sell, lease, trade, or profit from biometric data; does not disclose biometric data to any third party; and destroys biometric data on the same schedule as the underlying portrait images. The legal landscape governing biometric data is evolving rapidly — our Terms of Service contain a forward-looking compliance section updated as new legislation is enacted.

6Data Retention and Deletion

6.1 Customer-Controlled Retention

ProsDigital does not unilaterally determine how long portrait images and associated data are retained. Each Customer selects a retention period at account configuration:

7Days
30Days
180Days
1Year

Upon expiration, the Platform automatically and permanently purges all portrait images, analytics data, and associated biometric vectors. This deletion is irreversible.

6.2 Early Deletion by Customers

Customers have access to self-service utilities that allow them to delete all portrait images, analytics results, and biometric data at any time prior to their automated expiration. Deletion performed via these tools is permanent and immediate.

6.3 Data Deletion Upon Account Termination

Upon account termination, portrait images and analytics data are eligible for deletion within a reasonable period. Customers are encouraged to export or retrieve data before terminating, as ProsDigital cannot guarantee recovery after deletion. Platform user account data (names, email addresses, login records) is retained for up to 90 days following termination for audit trail purposes, then permanently deleted.

6.4 Security Log Retention

Security and access logs are retained for a minimum of 12 months to support security monitoring and incident investigation, after which they are securely purged.

7Data Security and Infrastructure

7.1 Infrastructure

All Customer data is processed and stored on dedicated servers that ProsDigital LLC controls and maintains, located within the United States. ProsDigital maintains direct physical and administrative control over these servers.

Backup infrastructure is maintained within the United States, accessed via secure, encrypted connections solely in the event of a primary infrastructure failure. Backup servers are subject to identical security controls.

No Customer data is processed on or transmitted to third-party cloud platforms, public cloud providers, or sub-processors.

7.2 AI and Analytics Systems

AI systems performing portrait analytics and biometric matching operate on dedicated servers within ProsDigital’s controlled environment in the United States, connected via secure internal connections, and do not send data to external services.

7.3 Security Controls

7.4 Access Tiers

Administrator

Full account management, user provisioning, retention configuration, and data deletion authority

Manager

Operational access to submissions, reporting, and assigned project data

User

Standard access to submit portraits and access results within assigned scope

No user, regardless of tier, may access data outside their authorized scope. Administrators of one Customer account may not access data belonging to another Customer account.

8Children’s Privacy (COPPA)

PortraitVision does not operate a service directed at children and does not knowingly collect personal information directly from individuals under the age of 13. The Platform is a professional B2B service accessed exclusively by adult personnel of school photography companies.

Portrait images of minors are submitted by our Customers — school photography businesses — acting in their professional capacity pursuant to arrangements they have made with schools and families. ProsDigital processes these images solely as a data processor under the Customer’s direction and authority.

Our Customers are contractually required to obtain all necessary permissions and consents — including verifiable parental or guardian consent — before submitting portrait images to the Platform. This reflects the FTC’s 2025 COPPA Rule amendments, which shifted from an opt-out to an opt-in model for children under 13.

Prohibition on AI model training: Images of minors submitted to the Platform are never used to train, fine-tune, test, or otherwise improve ProsDigital’s AI or machine learning models. This prohibition is absolute and is codified in ProsDigital’s Terms of Service (Section 13.4).

9FERPA Compliance

Some Customers provide photography services to schools subject to the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99). In those contexts, portrait images of students may constitute education records under FERPA.

ProsDigital operates as a “school official” with legitimate educational interest as defined under FERPA when processing data on behalf of such Customers, consistent with 34 CFR § 99.31(a)(1). In this capacity:

Customers who serve federally-funded schools bear primary FERPA compliance responsibility and must execute a FERPA-compliant Data Processing Agreement with those schools before submitting portrait data to the Platform. Customers must also comply with applicable state student privacy laws, including California’s SOPIPA and equivalent statutes.

10Data Sharing and Disclosure

ProsDigital does not sell, rent, lease, or share Customer data or portrait image data with any third party for any reason.

All data processing occurs on ProsDigital-owned and operated infrastructure. We use no sub-processors. We may disclose information only in these narrow circumstances:

11Your Rights

11.1 Rights of Platform Users

Registered Platform users may request access to, correction of, or deletion of their account data at any time by contacting privacy@portraitvision.info.

11.2 Rights of Customers

Customers have contractual rights to access, export, and delete their data via the Platform’s self-service tools or by contacting us directly.

11.3 California Residents (CCPA/CPRA)

California residents have the right to: know what personal information we collect and how it is used; request deletion; opt out of sale (we do not sell personal information); and non-discrimination for exercising these rights. Contact privacy@portraitvision.info. We will respond within 45 calendar days.

11.4 New Jersey Residents (NJDPA)

New Jersey residents have rights under the New Jersey Data Privacy Act consistent with those above. Contact privacy@portraitvision.info to exercise your rights.

12Security Incident Response and Breach Notification

12.1 Our Commitment

ProsDigital maintains a documented Security Incident Response Policy. In the event of a confirmed breach, we will act promptly and transparently.

12.2 Internal Detection and Response Timeline

1

Immediate — 24/7

Automated alerting triggers or manual discovery reported to on-call security team

2

Within 4 Hours

Internal triage and preliminary impact assessment completed

3

Within 24 Hours

Escalation to senior leadership; containment measures initiated

4

Within 48 Hours

Breach confirmed or ruled out; scope and affected accounts identified

5

Within 72 Hours of Confirmation

Customer notification process initiated for all confirmed breaches

12.3 Customer Notification

Affected Customers will be notified within 72 hours of confirmation via the Administrator email on file. Notification will include: the nature and categories of data affected; approximate date and time of the breach; steps taken to contain and remediate; recommended steps for the Customer; and a dedicated point of contact.

12.4 Regulatory Notification

ProsDigital will comply with all applicable state breach notification statutes. For breaches involving portrait images or biometric data of minors, we treat the matter with the highest priority and will initiate notification and regulatory consultation at the earliest practicable time.

12.5 Breach Record-Keeping

Records of all security incidents are maintained for a minimum of 5 years to support incident investigation and applicable legal and regulatory obligations.

13Cookies and Tracking Technologies

The PortraitVision Platform is a business application accessed by authenticated users. We use session cookies solely to maintain authenticated user sessions. We do not use third-party tracking cookies, advertising pixels, or behavioral tracking technologies. We do not share session data with any external party.

14International Users — Canada Addendum

Pending Activation

This section applies to Customers and users located in Canada. It is currently inactive and will become effective for Canadian Customers upon execution of a Customer Agreement with ProsDigital.

Applicable Law
Processing of personal information of Canadian residents is subject to Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
Consent
Canadian Customers must confirm they have obtained meaningful, informed consent from all relevant parties — including parental consent for portrait images of minors — consistent with PIPEDA’s consent requirements.
Breach Reporting
In the event of a breach creating “real risk of significant harm” to Canadian residents, ProsDigital will report to the Office of the Privacy Commissioner of Canada and notify affected individuals per PIPEDA’s breach of security safeguards regulations (SOR/2018-64).
Access and Correction Rights
Canadian individuals may request access to or correction of their information by contacting privacy@portraitvision.info.
Data Residency
Canadian Customers will be notified that data is stored and processed on servers located in the United States. By using the Platform, Canadian Customers consent to this cross-border transfer.

15Changes to This Policy

When we make material changes, we will: post the updated Policy with a new “Last Updated” date; notify registered Customer Administrators via email at least 30 days before the effective date; and maintain prior versions upon request.

Non-material changes (clarifications, formatting, broken link corrections) may take effect upon posting without advance notice. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.

16Contact Us

Mailing Address

ProsDigital LLC — Privacy Team
2230 Route 70 W, STE 2, #1401
Cherry Hill, NJ 08002-3338
United States

Email

privacy@portraitvision.info

Acknowledged within 5 business days. Substantive response within 30 calendar days.