LEGAL
Legal & Compliance
Plenix holds payroll, health, client and financial records for the organisations that run on it. That obliges us to be precise about what we do with data, and to publish it rather than hand it over only when a buyer asks. Everything is here, written to be read.
LAST UPDATED · 29 JULY 2026 · DATA HOSTED IN THE UNITED KINGDOM
Privacy Policy
What personal data we collect, why, on what lawful basis, how long we keep it, and the rights you have over it. Covers our role as controller for our own customers and as processor for data inside a tenant.
Read →Terms of Service
The agreement that governs your use of Plenix — subscriptions, fees, acceptable use, ownership of your data, availability, liability and termination.
Read →Data Processing Agreement
Our Article 28 processing terms, including security measures, sub-processor authorisation, breach notification within 24 hours, audit rights and international transfer clauses. Incorporated automatically — no signature needed, though we will countersign on request.
Read →Sub-processors
Every third party that can access personal data we process for you, what they do, where they are, and the transfer mechanism that applies. Thirty days’ notice before the list changes.
Read →Security & Compliance
Tenant isolation, encryption, access control, audit logging and incident response, mapped to ISO/IEC 27001:2022 and ISO/IEC 27701. Includes the shared responsibility model and how to report a vulnerability.
Read →Cookie Policy
Short, because there is little to say: this website sets no cookies and runs no analytics or advertising trackers. The platform sets only what is strictly necessary to keep you signed in.
Read →Who to write to
If your personal data sits inside another organisation’s Plenix tenant — because you are their employee, customer or contact — that organisation is the controller and your request goes to them first. We will help them answer it.