How Princh protects user data
Privacy and data protection are of utmost importance for Princh.
The Princh software has been developed with Privacy by Design & Default as its guiding principles, forming the foundation of its architecture. This means that we do not process any personal data unless absolutely necessary. Princh exclusively processes the document title and print job information, with no visibility into the content of the document.
All data transmissions are end-to-end encrypted using TLS 1.2 or a superior version to prevent tampering and eavesdropping during data movement between users’ devices and Princh.
While documents are at rest, they are protected using XChaCha20 encryption (256-bit). When a user submits a document, it is encrypted using a key pair which is only stored and managed by the customer’s printer server or printer. This signifies that only the designated printer or printer server can decrypt a user’s document(s). Importantly, neither Princh nor any third party possesses the ability to decrypt user documents. Document data is retained for up to 24 hours to support the 'Release Print' function, which is remains available for 24 hours after the original print order is submitted through Princh. After this period, documents are automatically and securely erased.
Princh is ISO 27001:2022 certified meaning it has received formal approval from an accredited auditor confirming compliance with the ISO 27001:2022 controls. Examples of compliance measures include:
- Implementation of an access control policy to restrict information access based on the principle of granting users the minimum necessary access required for their job functions.
- Adoption of a password policy mandating passwords to be at least 16 characters, comprising both letters and numbers, with systems configured to prevent reuse by remember previous passwords.
- Documentation of managerial approval for all changes with significant impact.