Legals
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Plutio LTD ("Plutio", "Processor") and the customer identified on the account ("Customer", "Controller"). It applies whenever Plutio processes personal data on the Customer's behalf.
You do not need to sign anything. This DPA is incorporated into your agreement with Plutio automatically when you accept the Terms of Service. If your organisation requires a countersigned copy for its records, email dataprotection@plutio.com and we will provide one.
1. Roles and scope
When you store information about your own clients, contacts, team members and projects in Plutio, you decide what to collect and why. You are the controller of that data. Plutio stores and processes it on your instructions, and is your processor.
Separately, Plutio is a controller of the personal data it holds about you as its own customer, such as your account and billing details. That processing is governed by our Privacy Policy, not by this DPA.
In this DPA, "Data Protection Law" means the UK GDPR and the Data Protection Act 2018, Regulation (EU) 2016/679 (the EU GDPR), and any other data protection law applicable to the processing.
2. Processing details
Subject matter: provision of the Plutio business management platform.
Duration: the term of the Customer's subscription, plus the retention periods in clause 10.
Nature and purpose: hosting, storage, organisation, retrieval, transmission, display, backup and deletion of Customer Data, in order to provide the Services and any feature the Customer chooses to use.
Types of personal data: determined by the Customer, and typically including names, email addresses, postal addresses, telephone numbers, job titles, company names, billing and invoice details, payment records, time entries, messages and correspondence, file attachments and documents, calendar and meeting data, form and proposal responses, and any other content the Customer chooses to store.
Categories of data subject: determined by the Customer, and typically including the Customer's clients and prospective clients, the Customer's employees, contractors and collaborators, and the Customer's suppliers.
Special category data: Plutio is not designed to process special category personal data as defined in Article 9 of the UK GDPR. The Customer should not store such data in Plutio unless it has satisfied itself that it has a lawful basis and appropriate safeguards to do so.
3. Plutio's obligations
Plutio will:
- process Customer personal data only on the Customer's documented instructions, which are given by the Customer's use of the Services and by this DPA, unless required to do otherwise by law, in which case Plutio will inform the Customer first unless the law prohibits it;
- not sell Customer personal data, and not use it for its own purposes, including advertising, profiling, or the training of artificial intelligence models;
- ensure that people authorised to process the data are subject to an appropriate duty of confidentiality;
- implement and maintain the technical and organisational measures described in clause 5;
- tell the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law; and
- make available the information reasonably necessary to demonstrate compliance with this DPA.
4. The Customer's obligations
The Customer will:
- ensure it has a lawful basis for the personal data it stores in Plutio and for having Plutio process it;
- provide the privacy information its own data subjects are entitled to;
- ensure its instructions comply with Data Protection Law;
- manage access within its own workspace, including removing team members who no longer need access; and
- not store special category or criminal offence data without having satisfied itself that it may lawfully do so.
5. Security
Plutio maintains technical and organisational measures appropriate to the risk, including:
- encryption of data in transit using TLS 1.3, and encryption of data at rest;
- role-based access control within workspaces, and least-privilege access for Plutio personnel, with production access limited to those who require it;
- logical separation of customer workspaces;
- authentication controls including support for single sign-on, and password hashing;
- automated regular backups, held encrypted, with restoration testing;
- logging and monitoring of access to production systems;
- vulnerability management and timely patching of infrastructure and dependencies; and
- confidentiality obligations and security training for personnel.
Plutio may update these measures, provided the level of security is not materially reduced.
6. Sub-processors
The Customer gives Plutio general authorisation to engage sub-processors. The current list is published at plutio.com/legal/sub-processors.
Plutio will give at least 30 days' notice, by updating that page and by email to those who have subscribed to notifications, before adding or replacing a sub-processor that processes Customer personal data. The Customer may object on reasonable, documented data protection grounds within 30 days. If the parties cannot agree a resolution, the Customer may terminate the affected Services and Plutio will refund the unused remainder of the current billing period.
Plutio imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to the Customer for its sub-processors' performance.
7. International transfers
Plutio and its sub-processors may process Customer personal data outside the United Kingdom and the European Economic Area. Where they do, the transfer is made under one or more of: an adequacy decision or adequacy regulations; the European Commission's Standard Contractual Clauses; or the UK International Data Transfer Addendum to those Clauses.
Where the EU Standard Contractual Clauses apply, Module Two (controller to processor) is incorporated into this DPA by reference, with the Customer as data exporter and Plutio as data importer, the optional docking clause applying, clause 9 option 2 (general written authorisation) applying with a 30 day notice period, clause 11 optional independent dispute resolution not applying, clause 17 governed by the law of Ireland, and clause 18 disputes heard in the courts of Ireland. The Annexes are populated by clauses 2, 5 and 6 of this DPA and by the sub-processor list.
Where the UK Addendum applies, Tables 1 to 3 are populated by clauses 2, 5 and 6 of this DPA and the sub-processor list, and in Table 4 neither party may end the Addendum as set out in section 19.
Plutio applies supplementary measures including encryption in transit and at rest, and will challenge any government or law enforcement request for Customer personal data that it considers unlawful.
8. Assistance with data subject rights
Plutio provides self-service tools that allow the Customer to access, export, correct and delete personal data in its workspace directly, which will usually be the fastest way to answer a data subject request.
Where the Customer cannot do so through the Services, Plutio will provide reasonable assistance, taking into account the nature of the processing. If a data subject contacts Plutio directly about data held in a Customer's workspace, Plutio will not respond substantively, and will direct the request to the Customer without undue delay.
9. Personal data breaches
Plutio will notify the Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information. Plutio will provide further information as the investigation progresses and will assist the Customer with its own notification obligations.
10. Return and deletion
The Customer may export its data at any time during the subscription, from within the Services, in standard formats.
On termination or expiry, Customer data remains available for export for 30 days. After that period, Plutio will delete it from active systems within a further 30 days, and from encrypted backups within 90 days of deletion from active systems, unless retention is required by law. Plutio will confirm deletion in writing on request.
11. Audit
Plutio will make available to the Customer the information necessary to demonstrate compliance with Article 28 of the UK GDPR, including responding to reasonable security questionnaires and providing available third-party reports and certifications.
Where that is genuinely insufficient for the Customer's compliance obligations, the Customer may audit Plutio, at the Customer's cost, on 30 days' written notice, no more than once in any 12 month period unless required by a supervisory authority, during business hours, subject to confidentiality, and in a way that does not compromise the security or availability of other customers' data.
12. Liability and general
The limitations of liability in the Terms of Service apply to this DPA. Nothing in this clause limits either party's liability to a data subject under Data Protection Law.
In the event of conflict, this DPA prevails over the Terms of Service in relation to the processing of Customer personal data, and the Standard Contractual Clauses prevail over this DPA in relation to transfers to which they apply.
This DPA is governed by the law of England and Wales, except where the Standard Contractual Clauses require otherwise.
13. Contact
Data protection enquiries, requests for a countersigned copy, sub-processor notifications and audit requests: dataprotection@plutio.com.
Plutio LTD, 4th Floor Silverstream House, Fitzroy Street, London, W1T 6EB, United Kingdom.
This document was last updated on 4 September 2026.