Privacy & data policy
Palena holds your compliance work — assessment answers, evidence documents, signed agreements. This page states exactly what we store, where it sits, who else touches it, and how long it stays. Written to be checked against the platform, not to be reassuring.
- Last updated
- August 23, 2026
- Operator
- MC3 Technologies
- Hosting
- United States
What this covers
This policy covers the Palena platform and the compliance engagements MC3 Technologies runs through it. MC3 Technologies is the operator and, for the personal data on the platform, the party responsible for it.
Palena accounts are not self-service. An MC3 administrator creates each account and emails an invitation containing a one-time temporary password; there is no public sign-up. That means the first personal data we hold about you — your name, work email and company — reached us from your organization, not from a form you filled in.
Two kinds of account exist, and the difference matters for who can see what: members complete their own organization's assessments, and MC3 administrators can read and act on client work across the platform in order to review it.
Data we hold
Grouped by what it is, annotated with where it physically sits. Your password is deliberately absent from every group below: we never receive or store it.
Identity and account
Your credentials are held by the sign-in system, separately from the platform database. MC3 cannot read your password or your authenticator secret, and cannot recover either — only reset them.
- Email address, name, and company nameSign-in system + database
- Password and multi-factor authenticator secretSign-in system only
- Account role, registration date, and last sign-in timeOur database
- Organization memberships, and who added you to oneOur database
- Administrative notes an MC3 administrator writes about an accountOur database
Compliance and assessment content
The substance of the work. This is business and compliance data about your organization rather than personal data, though onboarding answers name individual points of contact.
- Onboarding answers: company details, business address, CAGE code, DUNS/UEI, NAICS code, and named points of contactOur database
- Control assessment answers, progress, and the questionnaire version answered underOur database
- Submissions, their review status, and which administrator acted on eachOur database
- Review findings, from MC3 reviewers and from the AI screening passOur database
- Engagement records: program, level, dates, and primary contactOur database
Evidence and signed documents
Uploaded files are held in encrypted storage, filed under a location the server works out itself — your browser never gets to name where a file goes. Access is only ever through a link that expires.
- Evidence files you upload against a control or an evidence requestEncrypted file storage
- Generated agreements — NDA, advisory contract — and their signed copiesEncrypted file storage
- E-signature audit record: signer, server timestamp, IP address, browser identification string, and a cryptographic fingerprint of the exact signed fileOur database
- Support ticket attachments you add to a requestEncrypted file storage
Assistant and support
- Chat transcripts with the in-app assistant, including cleared conversations, which are archived rather than erasedOur database
- Support tickets: your name, email, description, category, and priorityDatabase + ticket tracker
Operational records
The trail that makes the platform auditable, which is itself a CMMC requirement. It records actions, not browsing.
- Audit log of privileged and lifecycle actions: who did what, to which record, whenOur database
- Background job records for document generation, AI review, and notificationsOur database
- Rate-limit counters, keyed to your account or to a requesting IP addressOur database
- Server and application logs, and error reports from failed requestsOperational logs
- Outbound notification emails we send youEmail delivery
How it is protected
Specific, current settings rather than adjectives. These are the protections a reviewer can ask us to evidence.
Access
- Multi-factor authentication is required for every account, not offered as an option.
- Passwords must be at least 12 characters, and sign-ins are risk-scored — a login from an unexpected place is challenged, and passwords known to have leaked elsewhere are rejected.
- MC3 staff sign in through the company directory, so administrator access follows employment — when someone leaves, their access goes with them.
- Every API request is authenticated by verifying its token signature at the edge of the application before any handler runs, and access to each record is re-checked against your organization.
Storage
- The database is encrypted at rest, is not reachable from the public internet, and is backed up on a rolling seven-day window.
- The evidence bucket is encrypted at rest, blocks all public access, and keeps object versions so a bad overwrite is recoverable.
- File access uses signed links that expire in minutes — fifteen for a download, one for an upload — rather than any permanently readable URL.
- Support ticket attachments that never get attached to a ticket are swept and deleted automatically.
What our error reports contain
When a request fails, the platform records an error report so the failure can be diagnosed, and that report includes what was being sent at the time. Sign-in tokens, session cookies, and anything named like a credential are stripped out before it is stored, and the AI pipeline deliberately records usage counts rather than content — but a report about a failed save can still contain the answer or message that was being saved. We treat those reports as client data, and they stay on infrastructure MC3 runs itself rather than going to an outside service.
AI review and the assistant
Palena uses a large language model, run as a managed service inside our cloud provider's US infrastructure, for two features. Both send your content to that service, so both are stated plainly here.
The in-app assistant
Your message is sent to the model along with context about the page you are on. That context is read server-side from your own assessment or submission — the browser sends only a reference to which record you are viewing, never the data itself.
Transcripts are stored on our servers against your account. Earlier versions of Palena kept chat history only in your browser; that is no longer true, and it is the main reason this policy was rewritten. Clearing the chat starts a new conversation and archives the old one rather than deleting it.
AI evidence screening
When a submission is screened, your control answers and the evidence files attached to them are sent to the model. PDFs and images are sent as files; office documents are converted to text on our servers first, so that what the model was shown is inspectable rather than opaque. There is a hard cap on how many files one screening pass will send.
The screening pass produces findings for an MC3 reviewer. It is an aid to that reviewer and does not by itself decide the outcome of your assessment — a person approves or returns every submission.
Content sent to the model is processed to return a response and is not used to train it. We do not sell your data, and we do not use your compliance content to build products for anyone else.
Who else processes it
The complete list of outside services that receive platform data, and what each one gets. Anything not on this list does not receive it.
- Amazon Web ServicesUS regionsHosts the entire platform — sign-in, the database, file storage, outbound email, and operational logs. Our infrastructure provider, processing data on our instruction rather than for its own purposes.
- Managed AI serviceUS, same providerRuns the model behind the assistant and evidence screening. Receives chat messages, assessment answers, and the contents of evidence files, as described in the previous section.
- monday.comVendor infrastructureReceives support tickets you file — your name, email, and the description, category and priority you entered — so MC3 can track them. Attachments stay in our own encrypted storage; monday.com gets only an encrypted link to them.
- YouTubeVendor infrastructureServes engagement closeout videos where an engagement includes one. Embeds use the privacy-preserving player, which sets no cookies until you press play.
Beyond that list, we disclose data in three situations: when a law or a valid legal request requires it; when an authorized MC3 administrator needs it to review or support your engagement; and, if MC3 Technologies were ever merged with or acquired by another company, as part of that transfer. We will not sell, rent, or trade it.
How long we keep it
Some of this is bounded by an automatic process. Some of it is kept for as long as the engagement record needs to stand. Where the honest answer is "indefinitely, on purpose", it says so.
Retention periods
- Account record, assessment answers, and submissionsWhile the account is active
- Evidence files and generated documentsLife of the engagement record
- Signed agreements and their signature audit recordIndefinite, by design
- Audit log of privileged actionsIndefinite, by design
- Chat transcripts, including cleared onesIndefinite, no automatic purge
- Superseded versions of a replaced file90 days
- Database backups7 days, rolling
- Unattached support ticket attachments24 hours
The two indefinite entries are deliberate and we would rather explain them than soften them. A signed NDA or advisory contract is a legal artifact, and the record of who signed it, when, and over exactly which bytes is what makes it hold up; an audit trail that can be pruned is not an audit trail. Both are protected against deletion at the database level, which means they survive the deletion of the account that produced them.
Your choices
What you can do yourself in the product, and what currently requires asking us. We have separated the two rather than listing rights the platform does not yet implement.
In the product
- Review and correct your profile from your account page.
- Read every assessment, submission, and piece of evidence held for your organization.
- Export a submission, with its answers, as a document.
- Clear the assistant conversation, and remove evidence you uploaded while a submission is still open for editing.
By request
- Deletion of your account and its associated data. There is no self-service delete; write to us and we will action it manually.
- A full copy of the personal data we hold about you, beyond the per-submission export.
- A copy of the chat transcripts stored against your account, or their deletion.
- Questions about a specific record, including who has accessed it.
Two limits on a deletion request, so it is clear before you make one. Signed agreements, their signature audit records, and the audit log are retained as described above and are not deleted with the account. And where your data forms part of your employer's compliance record, we may need to keep it on that organization's instruction — we will tell you if that applies and put you in contact with them.
Cookies and browser storage
Palena runs no analytics, no advertising tags, and no third-party tracking scripts. There is no cross-site tracking to opt out of and no consent banner, because there is nothing to consent to. What the product does store on your device is functional, and all of it is cleared by clearing your site data.
Stored on your device
- Your sign-in session, so you are not asked to log in on every pageRequired to stay signed in
- Light or dark theme preferencePreference
- A cached copy of your profile, so pages render before the network respondsCache
- Interface state: which panels you left open, which assessments you have already seenInterface state
- Unsaved review notes and in-progress answers, so a reload does not lose themDraft recovery
- Evidence files staged for upload before you submit themUpload staging
Changes and contact
When this policy changes we update the page and move the "Last updated" date at the top. That date is set by hand in the same change as the text, so it marks a real revision rather than today's date. If a change materially affects how we handle data you have already given us, we will tell you directly rather than relying on you noticing.
Get in touch
One address covers privacy questions, access and deletion requests, and anything else on this page. A request about your own data is answered by a person at MC3, not a form.
MC3 Technologies · mc3technologies.com