Privacy Notice
Last updated: 1 September 2026 — Version 2.0
Prepared in accordance with Articles 13 and 14 of the UK GDPR and EU GDPR.
At PlugZero (a product of Plughathon Limited) we believe your data belongs to you. This notice explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have under data-protection law.
1. Who is the controller
The data controller for personal data collected through this website and the PlugZero service is:
- Plughathon Limited (the "controller", "we", "us", "our"), a company registered in England and Wales.
- Registered office: [registered office address]
- Company number: [Companies House number]
- Data Protection Officer (or data-protection lead): [name / role]
- Contact: privacy@plugzero.app
If you upload your own data to PlugZero for analysis, you are the controller for that data and we act as your processor under a Data Processing Addendum (Article 28 UK GDPR / EU GDPR). This notice does not affect that arrangement — for information about how we process data on your behalf, see our Data Processing Addendum.
2. How to contact us
For any privacy question, request or complaint, contact:
- Email: privacy@plugzero.app
- Post: Plughathon Limited, [registered office address]
We aim to acknowledge privacy requests within 30 days in line with the requirements of the Data (Use and Access) Act 2025.
3. What personal data we collect
We collect only the personal data we need to operate the PlugZero service, communicate with you, and comply with the law. We never sell personal data.
3.1 Account data
- Name, email address, password (hashed using Argon2id or equivalent).
- Authentication metadata: last login, MFA enrolment, OAuth provider (if used).
- Billing data: subscription tier, invoice history, payment method (card data is held by our payment processor, never by us).
3.2 Customer Data (data you upload)
- Files (CSV, Excel, PDF, DOCX, JSON) you upload to a project.
- Configuration of your analyses, dashboards, reports, and AI chat history.
- Comments, sharing settings, and team memberships.
Customer Data is processed on your instructions as processor (Article 28). See our DPA for details.
3.3 Service usage data
- Server logs (IP address, user agent, request URL, response code) — retained 30 days for security and abuse prevention.
- Crash reports and error metadata (Sentry) — retained 90 days.
- Audit log (login, file upload, share, AI call, export, delete) — default 12 months; available to enterprise customers on request.
3.4 Marketing-site data
- Cookies (see Section 12 — strictly necessary only by default; analytics and marketing cookies require your consent under UK PECR).
- If you submit a contact form or sign up for product updates, your name, email, company, and message content.
4. Why we use your personal data (purposes and lawful bases)
UK GDPR Article 6 requires us to identify a lawful basis for each processing purpose. Our bases are:
| Purpose | Categories of data | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Provide and operate the PlugZero service to you | Account data, Customer Data | (b) Performance of a contract |
| Process payments, issue invoices | Billing data | (b) Performance of a contract |
| Detect and prevent fraud, abuse, security incidents | Server logs, audit log | (f) Legitimate interests |
| Comply with legal obligations (tax, anti-money-laundering, lawful requests) | Billing data, account data | (c) Legal obligation |
| Respond to support requests | Account data, support message content | (b) Performance of a contract |
| Send product updates and security notices | Email address | (f) Legitimate interests (existing customers — soft opt-in under UK PECR) |
| Marketing communications to prospective customers | Email address | (a) Consent — opt-in only; unsubscribe link in every message |
| Improve the service via anonymised usage analytics | Aggregated, anonymised usage data | (a) Consent (cookie banner) |
Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) and concluded that our interests are not overridden by your rights and freedoms. You can request a copy of any LIA by emailing privacy@plugzero.app.
5. AI and automated decision-making (UK GDPR Art. 22 + EU AI Act Art. 50)
PlugZero offers AI-powered features including AI chat, sentiment analysis, topic clustering, key-driver analysis, and SWOT summaries. When you use these features:
- No training on your data. We do not use Customer Data to train, fine-tune, or otherwise improve any AI model.
- Sub-processor opt-out. Our contracts with AI sub-processors prohibit them from training on your data.
- Transparency. Every AI-generated widget displays an "AI-generated" badge. Clicking the badge opens a disclosure showing the model, version, provider, region, and training opt-out status (Article 50 of the EU AI Act).
- Automated decision-making. Outputs are not a substitute for human judgement. Do not use AI outputs as the sole basis for decisions that produce legal or similarly significant effects on individuals (UK GDPR Article 22 / EU GDPR Article 22).
- EU AI Act classification. Our AI features are classified as limited risk (transparency obligations). They are not high-risk AI systems under the EU AI Act. We deploy third-party models as deployers under Article 26 of that Act.
- Switching off AI. You can disable AI features entirely in project settings; if disabled, no Customer Data is sent to AI sub-processors.
7. International transfers
PlugZero primarily stores and processes data in the European Economic Area and the United Kingdom. Some sub-processors (payment processing, LLM inference where you opt in to non-EU endpoints) are located in the United States. Where we transfer personal data outside the UK or EEA, we rely on one of the following safeguards:
- UK–US Data Bridge — adequacy regulations for US recipients certified under the EU–US Data Privacy Framework and opted into the UK extension.
- EU–US Data Privacy Framework — for EEA transfers to eligible US recipients.
- EU Standard Contractual Clauses (Module 2 — controller-to-processor) — Commission Implementing Decision (EU) 2021/914.
- UK International Data Transfer Addendum — issued by the ICO under section 119A of the Data Protection Act 2018.
A Transfer Risk Assessment is on file for each non-adequacy-country recipient and is available on request to privacy@plugzero.app.
8. How long we keep personal data
- Account data — for as long as your account is active, plus 30 days after deletion (in case of accidental deletion), then permanently erased.
- Billing data — 7 years (HMRC requirement, UK).
- Customer Data (uploaded by you) — for as long as you keep the project, plus 30-day grace period after deletion; you can export or delete at any time.
- Audit log — default 12 months; up to 7 years on enterprise tier.
- Server logs — 30 days.
- Support correspondence — 3 years from last contact.
- Marketing-leads data — until you unsubscribe, plus 30 days.
9. Your rights under UK GDPR / EU GDPR
You have the following rights. To exercise any of them, contact privacy@plugzero.app. We will respond within one month (extendable by two further months for complex requests).
- Right of access (Article 15) — request a copy of the personal data we hold about you.
- Right to rectification (Article 16) — correct incomplete or inaccurate data.
- Right to erasure / "right to be forgotten" (Article 17) — request deletion, subject to legal exceptions.
- Right to restriction of processing (Article 18).
- Right to data portability (Article 20) — receive your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21) — to processing based on legitimate interests and to direct marketing.
- Rights related to automated decision-making and profiling (Article 22) — see Section 5 above.
- Right to withdraw consent (Article 7(3)) — where processing is based on consent.
- Right to lodge a complaint (Article 77) — with a supervisory authority. In the UK, that is the ICO (https://ico.org.uk). In the EEA, the local data-protection authority.
- Right to an effective judicial remedy (Article 79).
10. Security
We implement appropriate technical and organisational measures to protect personal data, including:
- TLS 1.2+ in transit, AES-256 at rest, KMS-managed encryption keys.
- Role-based access control with mandatory MFA for admin accounts.
- Immutable audit logging of all access and modifications.
- Independent penetration testing and vulnerability management.
- Documented 24-hour processor-to-controller breach notification.
Full details are in our Security overview and the TOMs schedule of our DPA.
11. Children
PlugZero is a B2B analytics service and is not intended for children. We do not knowingly collect data from children under 18. If you believe a child has provided us personal data, please contact privacy@plugzero.app.
13. Changes to this notice
We will update this notice when our processing changes materially. The "Last updated" date at the top reflects the current version. For significant changes, we will email existing customers and display an in-app banner at least 30 days before the change takes effect, mirroring our sub-processor change-notice commitment.
14. Complaints
If you are unhappy with how we handle your personal data, please contact us first at privacy@plugzero.app so we can put it right. You also have the right to lodge a complaint with a supervisory authority:
- UK: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, SK9 5AF — https://ico.org.uk
- EEA: your local data-protection authority — see the EDPB directory at edpb.europa.eu
15. Related documents
- Data Processing Addendum (DPA) — for customers who upload personal data.
- Sub-processor list — who we share data with, and how.
- Terms of Service — the contract for using PlugZero.
- Security overview — how we protect data.
- Cookie preferences — change your cookie choices at any time.
Need to execute a DPA?
Request our Data Processing AddendumWant to exercise your data rights?
Email privacy@plugzero.app