LEGAL

Sub-processors

These are the third parties that can access personal data we process on our customers’ behalf. Article 28(2) of the UK GDPR requires us to tell customers before we add one — so rather than bury the list in a contract annex, we publish it here.

LAST UPDATED · 29 JULY 2026

Where your data lives

Customer Data is stored in the United Kingdom. The providers below are the only routes by which any of it reaches another country, and each of those is covered by the transfer mechanism shown against it.

01Engaged for all customers

These underpin the service itself. They apply to every subscription and cannot be disabled.

ProviderPurposeData accessedLocation
Fasthosts Internet LimitedCloud infrastructure — application servers, databases and backups.All Customer Data stored in the platform, at rest.United Kingdom
IONOS SEOutbound transactional email (notifications, invoices, invitations).Recipient name and email address, message contents.United Kingdom / Germany
Stripe, Inc. / Stripe Payments UK LtdSubscription billing and card payment processing.Billing contact, billing address, payment card details (collected directly by Stripe).United Kingdom, EEA and United StatesUK IDTA / EU Standard Contractual Clauses

02Optional — engaged only if you enable the feature

None of these is engaged unless an administrator in your organisation turns on the relevant feature or connects the relevant integration. If you never enable AI, SMS, or a connector, the corresponding provider never receives your data.

ProviderPurposeData accessedLocation
GoCardless LtdDirect Debit (Bacs) collection where selected.Account holder name, bank account details, payment references.United Kingdom
PayPal (Europe) S.à r.l. et Cie, S.C.A.Alternative payment method where selected.Payer name, email address, transaction details.European Economic Area
Anthropic PBCAI assistant, semantic search, ticket triage and generated summaries — only where AI features are enabled.The content submitted to the AI feature, which may include Customer Data.United StatesUK IDTA / EU Standard Contractual Clauses
Twilio Inc. / Twilio Ireland LimitedSMS and text notifications — only where SMS is configured.Recipient mobile number, message contents.Ireland and United StatesUK IDTA / EU Standard Contractual Clauses
Microsoft Ireland Operations LimitedMicrosoft 365 connector — mailbox and calendar synchronisation, where connected by the Customer.Mailbox contents, calendar entries and directory data the Customer authorises.European Economic Area and United StatesEU Standard Contractual Clauses
Slack Technologies LimitedSlack connector — outbound notifications, where connected by the Customer.Notification contents sent to the Customer’s workspace.European Economic Area and United StatesEU Standard Contractual Clauses

03Notice of changes

  • We give at least 30 days’ notice before adding or replacing a sub-processor.
  • Notice is published on this page, and emailed to customers who have subscribed to sub-processor notifications. To subscribe, email privacy@plenix.cloud from your account’s administrator address.
  • Customers may object on reasonable data protection grounds within the notice period, under clause 5 of the DPA. If we cannot resolve the objection, you may terminate the affected service without penalty and receive a refund for the unexpired term.
  • Where a replacement is urgently required to preserve security or service continuity, we may act first and notify without undue delay.

04What is not on this list

  • Advertising and analytics networks — we use none. Our website sets no cookies and runs no third-party tracking. See the Cookie Policy.
  • Data brokers — we do not sell, rent or share personal data for anyone else’s marketing.
  • AI model training — our AI provider is contractually barred from training on content we send it.
  • Integrations you configure yourself — if you connect Plenix to your own systems using our API, webhooks or a connector, the destination is your choice and your responsibility as controller. It is not our sub-processor.

Questions about anything here, or a request for a provider’s own security documentation: privacy@plenix.cloud.