LEGAL

Privacy Policy

This policy explains what personal data Plenix Cloud Ltd collects, why we hold it, who we share it with, how long we keep it, and the rights you have over it. It is written to meet the transparency requirements of Articles 13 and 14 of the UK GDPR and the EU GDPR.

LAST UPDATED · 29 JULY 2026

01Controller or processor — which one we are

Plenix plays two different roles depending on whose data is in question, and the distinction decides who you should go to about it. Getting this right matters more than anything else in this document.

SituationOur roleWho you contact
You visit this website, request a demo, or sign upWe are the controller. We decide why and how your data is used.Us — privacy@plenix.cloud
You are a Plenix customer and we hold your account and billing detailsWe are the controller for that account data.Us — privacy@plenix.cloud
You are an employee, client or contact recorded inside a customer’s Plenix tenantWe are a processor. The customer decides what is stored and why; we only act on their instructions.That organisation, as controller

If you are in someone else’s Plenix

If your employer, or a company you deal with, uses Plenix and your details are in their system, they are the data controller — not us. We cannot lawfully give you access to, correct or erase records inside their tenant without their instruction. Please contact them directly. If you reach us instead, we will tell you so and, where we can identify the organisation, pass your request to them promptly.

02Who we are

Plenix Cloud Ltd (trading as Plenix) provides a multi-tenant business management platform. Where this policy says “we”, “us” or “Plenix”, it means that company.

Legal entityPlenix Cloud Ltd
Registered number17386598 (England & Wales)
Registered office39 Harrow StreetGranthamNG31 6HF
Data protection contactprivacy@plenix.cloud
General enquirieshello@plenix.cloud

03What we collect

Data you give us

  • Account data — name, work email address, telephone number, job title, employer, and the credentials used to sign in.
  • Billing data — billing contact, billing address, VAT number, purchase order references, and the subscription and invoice history. Card numbers are collected and stored by our payment processor, not by us.
  • Enquiry data — anything you send in a demo request, sales chat, support ticket or email to us.
  • Customer Data — everything you and your users put into the platform. See section 5; we handle this as a processor.

Data we generate or observe

  • Usage and audit records — which features are used, by which account and when. The platform writes an audit entry for every change made to a record, because customers need that trail as much as we do.
  • Technical data — IP address, browser and device type, operating system, timestamps, and error diagnostics captured in server logs.
  • Security data — sign-in attempts, multi-factor authentication events, API key use, and rate-limit and abuse signals.

What this website does not do

The Plenix marketing site sets no cookies and runs no third-party analytics, advertising or tracking scripts. The sales chat widget stores a single conversation token in your browser’s session storage, which your browser discards when you close the tab. There is nothing here to consent to, which is why you are not being asked. See the Cookie Policy.

04Why we use it, and on what lawful basis

Every use of personal data needs a lawful basis under Article 6. Ours are set out in full below rather than summarised, so you can check them.

What we doLawful basis
Create and administer your account, provide the platform, and support youPerformance of a contract (Art 6(1)(b)).
Take payment, issue invoices and chase non-paymentPerformance of a contract, and legal obligation for tax and accounting records (Art 6(1)(b) and (c)).
Respond to a demo request, sales enquiry or questionLegitimate interests — replying to someone who contacted us (Art 6(1)(f)).
Keep the platform secure: authentication, logging, abuse prevention, incident investigationLegitimate interests in protecting our service and our customers, and legal obligation to secure personal data (Art 6(1)(f) and (c); Art 32).
Monitor reliability, fix faults and improve the product using aggregated usage dataLegitimate interests in operating and improving a service our customers depend on (Art 6(1)(f)).
Send service messages — outages, security notices, changes to terms, renewal remindersPerformance of a contract. These are not marketing and cannot be opted out of while you hold an account.
Send marketing about Plenix to business contactsLegitimate interests, or consent where required. Every message carries an unsubscribe link (PECR reg. 22).
Comply with law — tax records, lawful requests, defending legal claimsLegal obligation, and legitimate interests in establishing or defending claims (Art 6(1)(c) and (f)).

Where we rely on legitimate interests we have carried out a balancing assessment and concluded our interest does not override your rights. You can ask us for the reasoning behind any of them, and you can object — see section 10.

We do not sell personal data, we do not share it with data brokers, and we do not use it for automated decision-making that produces legal or similarly significant effects about you.

05Data inside your Plenix tenant

Plenix covers CRM, service desk, HR, payroll, accounting, device monitoring and more, so the data our customers put into it can be extensive and some of it can be sensitive — employee records, payroll figures, health and absence information, disciplinary records and identity documents among them.

We handle all of it as a processor, on the customer’s documented instructions, under the terms of our Data Processing Agreement. In practical terms that means:

  • Each customer’s data lives in a separate database, not a shared table with a tenant column. Requests are bound to a tenant at the point of authentication.
  • Personal data fields identified as sensitive are encrypted at the field level before they reach the database, in addition to encryption of the storage itself.
  • We do not use Customer Data to train machine-learning models, and we do not mine it for our own commercial purposes.
  • Our staff do not browse customer tenants. Access for support is on a least-privilege, need-to-know basis, is logged, and is normally only exercised at the customer’s request.

If you are a Plenix customer, you are the controller for this data. That makes you responsible for having your own lawful basis to hold it, for telling your own people about it, and for keeping it accurate and no longer than you need it.

06Who we share it with

We share personal data with the service providers listed on our Sub-processors page, and with nobody else except as set out below. Each one is bound by a written contract that meets Article 28 and may only act on our instructions.

  • Infrastructure and platform providers — hosting, email delivery, payment processing. 3 of these are engaged for every customer; the rest only if you enable the relevant feature.
  • Professional advisers — accountants, auditors, insurers and lawyers, where they need it and under a duty of confidence.
  • Authorities — where we are legally required to disclose. We will tell the affected customer unless we are legally prohibited from doing so.
  • A buyer or successor — if the business is sold or reorganised, under confidentiality, and with this policy continuing to apply to the data transferred.

07International transfers

Customer Data is stored in the United Kingdom. Some of the providers we use process limited personal data in the European Economic Area and the United States.

Where a transfer leaves the UK or the EEA and the destination is not covered by adequacy regulations, we rely on the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) and the EU Standard Contractual Clauses, together with a transfer risk assessment and supplementary technical measures — principally encryption in transit and at rest, and minimising what crosses the border in the first place. The specific mechanism for each provider is named on the Sub-processors page.

08How long we keep it

We keep personal data only as long as we need it for the purpose it was collected, then delete it or irreversibly anonymise it.

CategoryRetentionWhy
Customer Data held in a live tenantFor the duration of the subscriptionPerformance of the contract — we hold it for as long as you use the service.
Customer Data after termination30 days, then deleted from the live platformAn export window so you can retrieve your data, after which your tenant database is deleted from the live platform. Encrypted offsite backups are retained on a rolling daily/weekly/monthly generational schedule and age out within 7 months of the backup being taken.
Account and billing records7 years from the end of the relationshipUK statutory retention for accounting and tax records (Companies Act 2006, VAT Act 1994).
Security and audit logs12 monthsLegitimate interests — detecting, investigating and evidencing security incidents.
Sales enquiries and demo requests24 months from last contactLegitimate interests — responding to and following up an enquiry you made.
Support correspondence3 years from resolutionLegitimate interests — service history, recurring fault diagnosis and dispute handling.

Deletion is final

When a subscription ends we keep the tenant available for 30 days so you can export your data. After that it is deleted and cannot be recovered, and it ages out of encrypted backups within a further 35 days. Export before you cancel.

09How we protect it

We apply technical and organisational measures appropriate to the risk, as Article 32 requires. The full control set — and how it maps to ISO/IEC 27001 and ISO/IEC 27701 — is on the Security page. In summary:

  • Encryption in transit (TLS 1.2+) and at rest, plus field-level encryption of sensitive personal data.
  • Per-tenant database isolation, with every request bound to a single tenant.
  • Role-based access control, multi-factor authentication, and single sign-on for customers who want it.
  • An immutable audit trail of changes, and retained security logging.
  • Encrypted, tested backups with a documented restoration process.
  • A documented incident response procedure, including the 72-hour breach notification duty under Article 33.

No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please report it to security@plenix.cloud — see our disclosure policy.

10Your rights

Where we are the controller of your data, you have the right to:

  • Be informed — which is what this document is for.
  • Access a copy of the personal data we hold about you.
  • Rectification of anything inaccurate or incomplete.
  • Erasure, where we have no overriding reason to keep it.
  • Restriction of processing while a dispute about it is resolved.
  • Portability — a machine-readable copy of data you gave us.
  • Object to processing based on legitimate interests, and to direct marketing at any time, absolutely.
  • Withdraw consent where consent was the basis, without affecting what was lawful before you withdrew it.

Write to privacy@plenix.cloud. We will respond within one month, extendable by two further months for complex requests — we will tell you if that applies and why. There is no charge unless a request is manifestly unfounded or excessive. We may need to verify your identity before we act, and we will ask for no more information than that requires.

Requests about data in a customer’s tenant

If your request concerns records held inside an organisation’s Plenix tenant, we are the processor and must refer you to them. We will forward the request where we can identify the controller, and we assist our customers in answering these within the statutory deadline — but we cannot act on it ourselves.

11AI features

Some parts of Plenix — the assistant, semantic search, ticket triage and generated summaries — send content to a third-party AI provider to produce a result. These features are off unless enabled, and can be disabled by an administrator at any time.

  • Only the content needed for the specific request is sent, and only when the feature is invoked.
  • Our AI provider is contractually prohibited from using that content to train its models.
  • Output is a suggestion. It is not used to make any decision about a person automatically, and it should be reviewed before it is relied on.
  • The provider and its processing location are named on the Sub-processors page.

12Children

Plenix is a business platform. It is not directed at children and we do not knowingly collect data from anyone under 16 through this website or the sign-up process. If a customer records data about a child within their own tenant — a student, an apprentice, a service user — they do so as controller and are responsible for the additional protections that requires.

13Changes to this policy

We update this policy when what we do changes. The revision date is shown at the top. For changes that materially affect how we handle your personal data we will give existing customers reasonable notice by email or in-app before they take effect — and where the law requires consent for a change, we will ask for it rather than assume it.

14Contact and complaints

For anything in this policy, or to exercise a right, contact privacy@plenix.cloud. We would rather hear from you first and put something right.

You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner’s Office — ico.org.uk/make-a-complaint, helpline 0303 123 1113. If you are in the EEA, you may complain to the supervisory authority in the country where you live, work, or where the issue occurred.