How we handle your data, on paper.
A plain-language Data Processing Agreement covering the personal data Plooi handles on your behalf. EU-hosted by default, named sub-processors, no model training on your content. Sign-off requires a paid plan once we exit Closed Alpha — this version is here for legal review.
Parties
This agreement is between:
- Controller: the customer who created a Plooi workspace ("you").
- Processor: Plooi (registration in progress), the entity operating plooi.ai (see the imprint for current contact details).
Subject matter and duration
Plooi processes personal data on the Controller's behalf to deliver the Service set out in our terms. Processing lasts for the duration of the Controller's use of the Service plus the deletion window described below.
Nature and purpose
- Hosting Controller workspace data (notes, methods, outputs, metadata) in encrypted form.
- Authenticating Controller end-users and recording who did what.
- Routing AI requests through provider-specific clients on the Controller's behalf (Bring Your Own Key, or BYOK — the Controller supplies its own keys).
- Sending operational and transactional email (invites, notifications) to the Controller's end-users.
Categories of data and data subjects
Data subjects: the Controller's employees, collaborators, and research participants whose content the Controller chooses to import.
Categories of data: name, email, role, work outputs the Controller creates on the canvas, transcripts and research notes the Controller uploads, IP and user-agent in server logs (truncated, 30-day retention).
We do not collect special categories of data (Art. 9 GDPR) unless the Controller chooses to upload them as research material — which we strongly recommend against without an appropriate legal basis.
Processing on documented instructions
Plooi processes personal data only on the Controller's documented instructions, which for this purpose are: the act of using the Service in line with the terms; explicit instructions sent to privacy@plooi.ai; and any additional instructions agreed in writing. We notify the Controller if we believe an instruction would breach GDPR or other Union or Member State data-protection law.
Confidentiality
Plooi ensures that personnel authorised to process Controller personal data have committed themselves to confidentiality or are under appropriate statutory obligations.
Security measures (Art. 32)
- Encryption in transit (TLS 1.2+) and at rest (AES-256-GCM for sensitive at-rest blobs incl. BYOK provider keys).
- Row-level security on every Plooi-managed Postgres table that holds Controller data.
- Hardened edge functions with rate limiting, atomic idempotency on billing webhooks, and audit logs retained 90 days.
- Sentry-based error tracking with PII scrubbing on logs.
- Principle of least privilege for internal access; admin actions are audited.
- Annual review of these measures and ad-hoc updates after each audit pass.
Sub-processors
The Controller authorises the following sub-processors:
| Sub-processor | Service | Region |
|---|---|---|
| Supabase | Postgres database, storage, auth, edge functions | Frankfurt, Germany (EU) |
| Resend | Transactional email | Dublin, Ireland (EU) |
| Vercel | Marketing site & app hosting | EU edge regions |
| Sentry | Error monitoring (scrubbed) | EU instance |
| Stripe | Payment processing (when paid plans go live) | Ireland (EU) |
The Controller's chosen AI provider (Google Gemini, OpenAI, or Anthropic via BYOK) acts as its own processor under the Controller's contract with that provider — Plooi does not sub-contract that processing.
Changes to sub-processors
We notify the Controller in writing (email) at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds; if no resolution is found, the Controller may terminate the affected service without penalty.
International transfers
All sub-processors listed above are EU-based. We do not transfer Controller personal data outside the EEA without appropriate safeguards (Standard Contractual Clauses, adequacy decisions, or your explicit instruction).
Assistance with data-subject rights
Plooi assists the Controller in fulfilling its obligations to respond to requests under Art. 15-22 GDPR. The Controller can access, rectify, export and erase personal data of its end-users directly through the Service; for cases the UI doesn't cover, email privacy@plooi.ai.
Personal-data breach notification
In the event of a personal-data breach affecting Controller data, Plooi notifies the Controller without undue delay and at the latest within 72 hours of becoming aware of the breach, including the information required by Art. 33(3) GDPR.
Audits and information
Plooi makes available all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits are at the Controller's expense and scheduled with at least 30 days' notice; not more than once per 12 months unless a material incident occurred.
Return or deletion of data
At the choice of the Controller, Plooi deletes or returns all personal data to the Controller after the end of the provision of services and deletes existing copies. Standard deletion window: within 30 days of account closure. Statutory retention obligations override this to the minimum extent legally required.