Skip to content
Plinta.

Data Processing Addendum

Last updated August 7, 2026

How Plinta processes your data as a processor, in the same register as every page here: nothing below is described in the present tense unless the running system does it. For a countersigned copy for your organization’s records, ask — that is a normal request and we expect it.

1. Roles

Your organization is the controller of the specification documents, submittal records, and correspondence it uploads. Plinta is the processor, acting on your instructions — the instructions being the product itself: you upload, we extract, track, check, and diff, and nothing else.

2. What is processed, and why

Specification, product-data, and addendum PDFs, and the text extracted from them: to produce the cited register, compliance findings, and addendum diffs you asked for. Register contents, revisions, and attachments: they are the product. Account data (name, work email): authentication and attribution in the audit trail. External reviewer identity (name, email, and per-action IP and user agent): delivering review links and evidence in disputes. Usage metadata (pages, costs, plan state): billing.

Retention follows the product’s lifecycle rules, stated in the Privacy Policy and repeated in section 5 here because a DPA is where controllers look for them.

3. Subprocessors

The complete vendor table — who, what they do, exactly what data reaches them — is published on the Privacy Policy and kept current there, so this page cannot drift from it. The material points: document text (not files) goes to an AI provider whose commercial terms exclude training on customer content, enforced by a check the processing worker runs at startup; transactional email carries recipient addresses and transmittal subjects; card data goes to Stripe and never touches our systems.

Adding a subprocessor that would see customer data is a change we notify account owners about before it happens, with time to object. We have deliberately not printed a fixed notice period here: that number belongs in the countersigned instrument, and publishing one we have not settled with counsel would be the kind of confident claim this product exists to avoid.

4. Security measures

Described control by control on the security page, each labelled In place or Not yet — database-enforced tenant isolation with an automated cross-tenant test suite, encryption at rest and in transit, role-based least privilege, append-only audit logging including staff access, hashed and revocable external-review tokens, per-user TOTP with an org-wide requirement option.

Equally material to a controller, the Not-yet list: no SOC 2 certification, no external penetration test, no SSO/SAML, no data-region choice, no customer-managed keys. A DPA that implied any of these would be false; this one does not.

5. Deletion and return

Deleting a document, project, or organization removes it from every path immediately and hard-purges rows, storage, and extracted text after a 14-day undo window; the purge sweeps the organization’s entire storage prefix and asserts it is empty before recording a receipt. Backups age out on a 30-day schedule, so the accurate deletion commitment is: immediate from live systems, within 30 days from backups.

Return, during the 14 days, is partly self-serve and partly manual — each project’s register exports to Excel from the app, and we produce anything beyond that (documents, audit trail) on request within the window. There is no organization-wide one-click export yet, and we say so rather than promise a mechanism that does not exist.

Two retentions survive deletion, disclosed here as they are in the Privacy Policy: append-only audit records including the name labels of deleted accounts (an audit trail that rewrites itself when someone leaves is worthless as dispute evidence), and the business records billing law requires. Removing a single document is removal from view, not erasure: the organization-level purge is the only self-service erasure that exists today.

6. International transfers

All processing runs in a single US region. We do not currently offer EU/UK transfer mechanisms (SCCs, transfer impact assessments); if your organization needs them, tell us before signing anything — that work happens with counsel, not by a paragraph appearing here.

7. Data subject requests

Requests route through your organization as controller: your team can read, correct, and export data in the app, and owners control deletion. Where the app cannot yet self-serve a request, we assist manually within the retention windows above. Requests that reach us directly about your workspace are forwarded to you.

8. Breach notification

We notify affected account owners without undue delay on becoming aware of a personal-data breach affecting their data, with what is known at the time and updates as the investigation proceeds. Our internal runbook treats any suspected cross-tenant exposure as a disclosure event from the first minute — suspicion, not confirmation, starts the clock.

9. Requesting a signed copy

Email support@getplinta.app and we will send the execution version.