LEGAL

Data Processing Agreement

These terms satisfy Article 28(3) of the UK GDPR and the EU GDPR, and govern our processing of personal data on your behalf. They form part of your agreement with Plenix Cloud Ltd and apply automatically — you do not need to sign anything for them to take effect.

LAST UPDATED · 29 JULY 2026

Need a countersigned copy?

Many procurement processes require an executed DPA on file. Email legal@plenix.cloud with your entity details and we will return a signed copy. If your organisation requires its own DPA template, send it over and we will review it.

01Scope and roles

For personal data contained in Customer Data, the Customer is the controller and Plenix is the processor. Where the Customer is itself a processor for a third party, Plenix acts as a sub-processor and these terms apply as if references to the controller were to that third party.

Plenix acts as a controller in its own right for account administration, billing, security monitoring and its own business records. That processing is described in the Privacy Policy, not here.

Terms defined in the Terms of Service have the same meaning here. “Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the UK GDPR.

02Processing instructions

Plenix processes personal data only on the Customer’s documented instructions. Those instructions are: the agreement between us, this DPA, the configuration choices the Customer makes in the Platform, and any further written instruction the parties agree.

  • Plenix will not process personal data for its own purposes, will not sell it, and will not use it to train machine-learning models.
  • If Plenix is required by law to process beyond the Customer’s instructions, it will inform the Customer first unless that law prohibits it on important grounds of public interest.
  • Plenix will tell the Customer if, in its opinion, an instruction infringes data protection law. Plenix is not obliged to give legal advice, and does not do so.

03Confidentiality of personnel

Plenix ensures that everyone authorised to process personal data is bound by an appropriate obligation of confidentiality, is subject to background screening proportionate to their access, and receives data protection and security training. Access is granted on a least-privilege, need-to-know basis, is individually attributable, is logged, and is revoked promptly when no longer required.

04Security of processing

Plenix implements and maintains the technical and organisational measures set out in Annex II, appropriate to the risk as Article 32 requires. Plenix may update those measures provided the level of protection is not reduced.

05Sub-processors

The Customer gives general authorisation for Plenix to engage the sub-processors listed in Annex III, and for changes to that list on the terms below.

  • Plenix imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, by written contract.
  • Plenix remains fully liable to the Customer for the performance of each sub-processor’s obligations.
  • Plenix gives at least 30 days’ notice before adding or replacing a sub-processor, published on the Sub-processors page, with email notice to customers who subscribe to it.
  • The Customer may object on reasonable data protection grounds within that period. The parties will work in good faith to resolve it; if they cannot, the Customer may terminate the affected part of the service without penalty and receive a refund of fees for the unexpired term.
  • Where an urgent replacement is needed to preserve security or continuity, Plenix may act first and notify without undue delay.

06Data subject rights

The Platform gives the Customer direct access to the personal data in its Tenant, so that the Customer can locate, correct, export and delete records itself and answer requests within the statutory deadline.

  • Where a data subject contacts Plenix directly about Customer Data, Plenix will not respond substantively. It will refer them to the Customer and, where it can identify the Customer, notify them without undue delay.
  • Taking into account the nature of the processing, Plenix assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests under Chapter III of the UK GDPR.

07Assistance to the Customer

Taking into account the nature of processing and the information available to it, Plenix assists the Customer in complying with its obligations under Articles 32 to 36 — security of processing, breach notification to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation.

08Personal data breaches

  • Plenix notifies the Customer without undue delay, and in any event within 24 hours of becoming aware of a personal data breach affecting Customer Data.
  • The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where the full picture is not yet available, Plenix provides information in phases rather than delaying the first notification.
  • Plenix takes reasonable steps to contain and remediate, preserves evidence, and cooperates with the Customer’s own notification obligations under Articles 33 and 34.
  • Plenix will not notify a supervisory authority or data subjects on the Customer’s behalf unless legally required or specifically instructed. Notification is not an admission of fault.

09Return and deletion

At the Customer’s choice, Plenix deletes or returns all personal data at the end of the provision of services, and deletes existing copies, unless law requires storage.

  • The Customer may export its data at any time during the subscription, and for 30 days after termination.
  • After that window, Customer Data is permanently deleted. Encrypted backups containing it are overwritten on their rotation cycle, within 35 further days.
  • Plenix will certify deletion in writing on request.

10Audits and information

Plenix makes available all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.

  • In the first instance Plenix provides its security documentation, control mapping and answers to security questionnaires — which will satisfy most requests without an on-site visit.
  • An on-site or remote audit may be requested once in any 12-month period, on 30 days’ written notice, during business hours, without unreasonable disruption, and subject to confidentiality. More frequent audits may be carried out where required by a supervisory authority or following a personal data breach affecting the Customer.
  • The auditor must not be a competitor of Plenix. Each party bears its own costs, save that the Customer reimburses Plenix’s reasonable costs for audits beyond the annual allowance.
  • Because the Platform is multi-tenant, an audit may not extend to any environment, data or documentation belonging to another customer.

11International transfers

Customer Data is stored in the United Kingdom. Where personal data is transferred outside the UK or the EEA to a country without adequacy, that transfer is made under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and the EU Standard Contractual Clauses (Module Two or Three as applicable), which are incorporated into this DPA by reference and take effect automatically for any such transfer.

For those clauses: the Customer is data exporter, Plenix is data importer, this DPA’s Annexes I to III populate the corresponding Annexes of the clauses, the governing law and forum are those of England & Wales, and the optional docking clause applies. Plenix carries out transfer risk assessments and applies supplementary measures — encryption in transit and at rest, data minimisation, and a policy of challenging overbroad government access requests and disclosing only what is legally compelled.

12Liability and precedence

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where those limits cannot lawfully apply. If there is a conflict between this DPA and any other part of the agreement, this DPA prevails on data protection matters. If there is a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.

13Annex I — Details of processing

Subject matterProvision of the Plenix business management platform under the agreement between the parties.
DurationThe term of the subscription, plus the retention and deletion periods in section 9.
Nature and purposeHosting, storage, structuring, retrieval, transmission, backup, analysis and deletion of Customer Data, in order to deliver the modules the Customer has enabled and to support the Customer.
Categories of data subjectThe Customer’s employees, workers, contractors and applicants; the Customer’s clients and their contacts; suppliers and their contacts; end users of the Customer’s portal; and any other individual whose data the Customer chooses to record.
Categories of personal dataIdentity and contact details; employment, role and organisational data; payroll, pay, pension and tax data; time, attendance, leave and expense records; financial and billing data; communications content including email and tickets; device, network and telemetry data; authentication and audit records; documents and attachments uploaded by the Customer.
Special category dataThe Platform’s HR, compliance and health-and-safety features can hold data concerning health (sickness absence, occupational health, accident records) and, where the Customer chooses to record it, data revealing racial or ethnic origin, religious belief or trade union membership for equality-monitoring purposes, together with criminal-offence data in vetting records. Plenix does not require any of it. Where such data is processed, the Customer is responsible for its Article 9 or 10 condition, and Plenix applies the heightened measures in Annex II.
Frequency of transferContinuous, for the duration of the subscription.
Competent supervisory authorityThe UK Information Commissioner’s Office, or where the EU Standard Contractual Clauses apply, the authority of the exporter’s EEA establishment.

14Annex II — Technical and organisational measures

The measures below are implemented and maintained. The full control set, and its mapping to ISO/IEC 27001 Annex A and ISO/IEC 27701, is on the Security page.

Pseudonymisation and encryption

  • TLS 1.2 or higher for all data in transit, with HTTP Strict Transport Security.
  • Encryption at rest for databases, file storage and backups.
  • Application-level field encryption for sensitive personal data, so that plaintext is not present in the database.
  • Secrets and credentials held in an encrypted vault, never in source control.

Confidentiality, integrity, availability and resilience

  • A separate database per tenant, with every request bound to a single tenant at authentication.
  • Role-based access control, enforced server-side on every request, with multi-factor authentication and optional SSO.
  • An immutable audit trail of record changes, and retained security and access logging.
  • Network segmentation, restricted administrative access and hardened server configuration.
  • Automated dependency and patch management, with security patching prioritised by severity.
  • Rate limiting, input validation and protections against common web application attacks.

Restoring availability after an incident

  • Automated encrypted backups on a defined schedule, held separately from production.
  • Documented restoration procedures, tested periodically, with defined recovery objectives.
  • Health monitoring and alerting, with a documented incident response and escalation process.

Testing and assessing effectiveness

  • Security review of changes before release, and automated testing in the deployment pipeline.
  • Periodic vulnerability scanning, and penetration testing of the production platform.
  • A published route for responsible disclosure of vulnerabilities.

Organisational measures

  • Documented information security and data protection policies, reviewed at least annually.
  • Confidentiality obligations, screening and security training for personnel with access.
  • Joiner, mover and leaver process with prompt revocation of access.
  • Supplier due diligence and written data protection terms before a sub-processor is engaged.
  • Data protection by design and by default in the development process, with impact assessments where required.

15Annex III — Authorised sub-processors

The current list, with the purpose, data and location for each, is maintained on the Sub-processors page and forms part of this Annex. Those marked as optional are engaged only where the Customer enables the relevant feature.

Sub-processorPurposeLocationEngaged
Fasthosts Internet LimitedCloud infrastructure — application servers, databases and backups.United KingdomAll customers
IONOS SEOutbound transactional email (notifications, invoices, invitations).United Kingdom / GermanyAll customers
Stripe, Inc. / Stripe Payments UK LtdSubscription billing and card payment processing.United Kingdom, EEA and United StatesAll customers
GoCardless LtdDirect Debit (Bacs) collection where selected.United KingdomOptional feature
PayPal (Europe) S.à r.l. et Cie, S.C.A.Alternative payment method where selected.European Economic AreaOptional feature
Anthropic PBCAI assistant, semantic search, ticket triage and generated summaries — only where AI features are enabled.United StatesOptional feature
Twilio Inc. / Twilio Ireland LimitedSMS and text notifications — only where SMS is configured.Ireland and United StatesOptional feature
Microsoft Ireland Operations LimitedMicrosoft 365 connector — mailbox and calendar synchronisation, where connected by the Customer.European Economic Area and United StatesOptional feature
Slack Technologies LimitedSlack connector — outbound notifications, where connected by the Customer.European Economic Area and United StatesOptional feature