plugzero logoPlugZero

Data Processing Addendum

Last updated: 1 September 2026, Version 1.0

Data Processing Addendum

Effective date: the date of execution below.

Version: 1.0 (2026-09-01)

Status

This is a working draft prepared for legal review by a UK data protection solicitor before publication. It is designed to satisfy the requirements of UK GDPR Article 28 (controller to processor), EU GDPR Article 28 (controller to processor), Article 26 (joint controllership) for AI-generated insights, EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller to processor) and the UK International Data Transfer Addendum (IDTA) to the EU SCCs.

Sections 1 to 12 are the controller to processor DPA. Schedules A to D are the SCC and UK Addendum, the sub-processor list, the Technical and Organisational Measures and the data subject rights procedure. Section 13 sets out the joint controller allocation for AI insights.

This document is not legal advice. Final execution requires review by a qualified UK solicitor.

Parties

This Data Processing Addendum (DPA) forms part of the master services agreement, terms of service or order form (Agreement) between:

  • Plughathon Limited (PlugZero, we, us), a company registered in England and Wales (Company No. 17033249), whose registered office is at Hull, East Riding of Yorkshire, England, acting as processor when processing Customer Personal Data on behalf of the Customer; and
  • The Customer identified in the Agreement (Customer, you, Controller).

If the Customer is established in the European Economic Area (EEA) and the processing is governed by Regulation (EU) 2016/679 (EU GDPR), PlugZero additionally acts under the Standard Contractual Clauses at Schedule A. If the Customer is established in the United Kingdom, PlugZero additionally acts under the UK International Data Transfer Addendum at Schedule B. The Customer acts as controller for Customer Personal Data.

1. Definitions

1.1 Customer Personal Data means any personal data (as defined in UK GDPR and EU GDPR Article 4) that PlugZero processes on behalf of the Customer in performance of the Agreement, including any data the Customer, its team members or its data subjects upload to, generate in or send through the PlugZero service.

1.2 Data Subject means an identified or identifiable natural person to whom Customer Personal Data relates.

1.3 Instructions means the documented instructions of the Customer, including this DPA, the Agreement, the service configuration set by the Customer and any subsequent written instructions given by an authorised representative of the Customer.

1.4 Personal Data Breach has the meaning given in UK GDPR and EU GDPR Article 4(12).

1.5 Sub-processor means any third party engaged by PlugZero to process Customer Personal Data on PlugZero behalf, as listed in Schedule C.

1.6 UK GDPR means the UK General Data Protection Regulation as defined in section 3(10) of the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), together with the EU GDPR as it forms part of UK law.

1.7 Other capitalised terms have the meanings given in UK GDPR and EU GDPR.

2. Roles and scope

2.1 The Customer is the controller. PlugZero is the processor. Each party shall comply with its respective obligations under UK GDPR and EU GDPR.

2.2 The Customer acknowledges that PlugZero may also be a joint controller with the Customer for the limited purpose of producing certain AI-generated outputs (sentiment, topic clusters, key drivers, SWOT, AI chat responses) where such outputs are subsequently used to make decisions about data subjects (Article 26 joint controllership). The allocation of obligations is set out in Section 13.

2.3 PlugZero shall process Customer Personal Data only on documented Instructions, including with regard to transfers, unless required to do otherwise by EU or UK law. If PlugZero is required by law to process Customer Personal Data otherwise, it shall inform the Customer of that legal requirement before processing (unless that law prohibits such information on important grounds of public interest).

3. Security of processing (Article 32)

3.1 PlugZero implements the Technical and Organisational Measures (TOMs) set out in Schedule D. PlugZero may update those measures from time to time, provided that the updated measures maintain a level of security appropriate to the risk.

3.2 PlugZero shall ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4. Sub-processors

4.1 PlugZero engages the sub-processors listed in Schedule C to process Customer Personal Data. PlugZero shall: (a) impose on each sub-processor data protection terms substantially no less protective than those in this DPA; (b) remain fully liable to the Customer for the performance of each sub-processor obligations; (c) maintain an up to date public list of sub-processors at https://plugzero.app/legal/subprocessors (or any successor URL notified to the Customer).

4.2 Change notification. PlugZero shall give the Customer at least 30 days written notice (by email to the Customer designated notification address and via in-app notice) before adding a new sub-processor or replacing an existing sub-processor that processes Customer Personal Data. The Customer may object on reasonable data protection grounds by written notice within the notice period. The parties shall work in good faith to resolve the objection. If the objection cannot be resolved, the Customer may terminate the affected services without liability and shall be entitled to a pro rata refund of any prepaid fees.

4.3 The Customer consents generally to the engagement of sub-processors listed in Schedule C as at the effective date.

5. Data subject rights

5.1 PlugZero shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures (including the self-service tools in the PlugZero product) to fulfil the Customer obligation to respond to requests for exercising data subject rights under Articles 15 to 22 of UK GDPR and EU GDPR (access, rectification, erasure, restriction, portability, objection, automated decision making).

5.2 PlugZero self-service tools include: per-record right to access export (Article 15); per-record and per-project right to erasure (Article 17); per-record right to rectification (Article 16); structured, machine-readable export (Article 20).

5.3 If PlugZero receives a request directly from a data subject relating to Customer Personal Data, PlugZero shall forward the request to the Customer without undue delay and shall not respond to the data subject except to acknowledge receipt and direct them to the Customer, unless instructed otherwise in writing.

6. Personal data breaches

6.1 PlugZero shall notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 24 hours of becoming aware of it. The notification shall include: (a) the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; (b) the name and contact details of PlugZero data protection contact (operations@plughathon.com); (c) the likely consequences of the breach; (d) the measures taken or proposed to address the breach and mitigate its possible adverse effects.

6.2 PlugZero shall provide reasonable assistance to enable the Customer to comply with its obligations under Articles 33 (notification to the supervisory authority) and 34 (communication to data subjects) of UK GDPR and EU GDPR. The statutory 72-hour notification period to the ICO or supervisory authority runs from the moment the controller becomes aware. The 24-hour processor to controller notification above is intended to leave sufficient time for the Customer to triage and notify within 72 hours.

7. Data Protection Impact Assessments and prior consultation

PlugZero shall, on request, provide reasonable assistance to the Customer in connection with any data protection impact assessment required by Article 35 of UK GDPR and EU GDPR and any prior consultation with the ICO or other supervisory authority required by Article 36, taking into account the nature of the processing and the information available to PlugZero.

8. Return or deletion at end of services

8.1 On termination or expiry of the Agreement, PlugZero shall, at the Customer written election, delete or return all Customer Personal Data to the Customer, and delete any existing copies, unless EU or UK law requires storage.

8.2 PlugZero standard retention period following termination is 30 days to allow the Customer to export data. Thereafter PlugZero shall delete or anonymise the data and certify deletion on request.

9. Audit rights

9.1 PlugZero shall make available to the Customer all information necessary to demonstrate compliance with Article 28 and this DPA, and shall allow and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.

9.2 Audits shall be conducted: (a) on at least 30 days written notice; (b) no more than once per calendar year, except where mandated by a supervisory authority or following a Personal Data Breach; (c) during normal business hours and in a manner that does not unreasonably interfere with PlugZero operations; (d) at the Customer cost, unless the audit reveals material non-compliance, in which case PlugZero shall bear its own reasonable costs.

9.3 PlugZero may satisfy an audit request by providing a current SOC 2 Type II report, ISO 27001 certificate, ISO 42001 certificate (for AI management) or equivalent independent assurance, where applicable.

10. International data transfers

10.1 PlugZero may transfer Customer Personal Data outside the UK or EEA only in accordance with Chapter V of UK GDPR and EU GDPR and as set out in this Section.

10.2 For transfers from the EEA to the United States or other third countries, PlugZero and the Customer agree to the EU Standard Contractual Clauses (Module 2, controller to processor) set out in Schedule A. The SCCs are incorporated into and form part of this DPA.

10.3 For transfers from the UK to third countries, PlugZero and the Customer agree to the UK International Data Transfer Addendum set out in Schedule B, which applies the EU SCCs (as varied by the Addendum) to UK-restricted transfers.

10.4 Where a recipient sub-processor is certified under the EU-US Data Privacy Framework (DPF) and has opted in to the UK Extension to the DPF, transfers to that sub-processor may rely on adequacy regulations in lieu of SCCs or UK Addendum.

10.5 PlugZero shall conduct and maintain a Transfer Risk Assessment for each non-adequacy-country recipient and shall make it available to the Customer on request.

11. Data minimisation, purpose limitation, accuracy

11.1 PlugZero shall not process Customer Personal Data for any purpose other than as necessary to provide the service and comply with Instructions.

11.2 PlugZero shall not train, fine-tune or otherwise use Customer Personal Data to improve any general purpose AI model. PlugZero shall not aggregate Customer Personal Data across customers for benchmarking or any other cross-customer purpose.

11.3 PlugZero shall take reasonable steps to ensure Customer Personal Data is accurate and up to date, having regard to the nature and purposes of processing.

12. Customer obligations

12.1 The Customer shall ensure it has a lawful basis under Article 6 (and Article 9 for special category data, where applicable) for processing the Customer Personal Data it uploads or generates via the service.

12.2 The Customer shall not upload to the service any personal data that the Customer is not lawfully entitled to process.

12.3 The Customer shall be responsible for honouring data subjects rights and for notifying PlugZero of any restriction on processing that the Customer wishes to impose.

12.4 The Customer shall be the single point of contact for data subjects and supervisory authorities in respect of Customer Personal Data.

13. Joint controllership for AI-generated outputs (Article 26)

13.1 The parties acknowledge that, where Customer Personal Data is processed by an AI engine to produce outputs that the Customer subsequently uses to make decisions producing legal or similarly significant effects on data subjects (for example, credit, employment or insurance decisions), both the Customer and PlugZero may be joint controllers for that output.

13.2 Allocation of joint controller responsibilities:

  • Customer determines the ultimate purpose and the decision taken on the basis of the output, communicates the decision to the data subject, conducts any required DPIA, responds to data subject rights requests and bears primary responsibility for the lawfulness of the decision.
  • PlugZero determines the means of generating the output (model selection, prompt engineering, system instructions), ensures Article 50 transparency (labelling AI-generated outputs), maintains the model registry and version pinning, logs every AI call in the audit log and assists the Customer with data subject rights requests and DPIAs on request.
  • The Customer shall not represent the AI-generated output as having been produced solely by a human, or as the work of a named individual.

13.3 The Customer may switch off AI features entirely in account settings. Where the Customer switches off AI features, PlugZero ceases to be a joint controller for that processing.

14. Limitation of liability

14.1 The limitations and exclusions of liability in the Agreement apply to this DPA, except that nothing in this DPA shall limit either party liability for damages incurred by a data subject under Article 82 of UK GDPR and EU GDPR.

15. Order of precedence

In the event of any conflict between this DPA and the Agreement in respect of data protection matters, this DPA shall prevail.

16. Governing law

This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute arising out of or in connection with it, without prejudice to the Customer rights as a data subject under Article 79 of UK GDPR and EU GDPR.

Schedules

  • Schedule A: EU Standard Contractual Clauses (Module 2)
  • Schedule B: UK International Data Transfer Addendum
  • Schedule C: Sub-processor list
  • Schedule D: Technical and Organisational Measures (TOMs)
  • Schedule E: Lawful bases most commonly relied on by Customers (informative)

End of DPA body.


Schedule A: EU Standard Contractual Clauses (Module 2)

Annex to the PlugZero Data Processing Addendum

These Standard Contractual Clauses (SCCs) are the controller to processor clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module 2 (controller to processor). The SCCs are incorporated into and form part of the DPA between PlugZero and the Customer. Capitalised terms not defined in this Schedule have the meanings given in the SCCs.

Clause 1: Purpose and scope

(a) These SCCs apply to the processing of Customer Personal Data transferred from the Customer (data exporter, established in the EEA) to PlugZero (data importer, established in the United Kingdom, third country without an adequacy decision in respect of transfers from the EEA at the date of execution).

(b) The SCCs supplement the DPA and prevail over any conflicting provisions.

(c) Annexes I to IV form an integral part of the SCCs.

Clause 2: Effect and invariability of the SCCs

(a) These SCCs are without prejudice to the obligations under Regulation (EU) 2016/679 (GDPR) that the data exporter has to comply with.

(b) The SCCs may not be modified except by adding or updating the Annexes. The body of the SCCs cannot be varied.

Clause 7: Docking clause

The Customer may, at any time, accede to the SCCs by signing and delivering to PlugZero an accession agreement in the form required by PlugZero. PlugZero shall accept such accession unless it would cause the data importer to be in breach of applicable law.

Clause 9: Use of sub-processors

The data importer has the Customer general authorisation for the engagement of sub-processors as set out in Section 4 of the DPA and Schedule C. The data importer shall inform the data exporter of any intended additions or replacements of sub-processors at least 30 days in advance, giving the data exporter the opportunity to object on reasonable data protection grounds, in accordance with Clause 9(a) and Section 4.2 of the DPA.

Clause 11: Redress

(a) Data subjects may bring a claim for redress against the data exporter and/or the data importer.

(b) The parties acknowledge that the data subject may receive a copy of the SCCs from the data importer, with sensitive information redacted where appropriate.

(c) The data subject may be represented by a not for profit body under Article 80(1) of GDPR.

Clause 17: Governing law

These SCCs are governed by the law of one of the EU Member States in which the data exporter is established, or, failing that, the law of Ireland.

Clause 18: Choice of forum

Any dispute arising from the SCCs shall be resolved by the courts of an EU Member State in which the data exporter is established, or, failing that, of Ireland.

Annex I: List of parties

Data exporter (controller)

  • Name: The Customer as defined in the DPA.
  • Activities relevant to the transfer: use of the PlugZero service to analyse Customer Personal Data and produce AI-generated insights.
  • Signature and date: as set out in the DPA execution block.
  • Role: controller.

Data importer (processor)

  • Name: Plughathon Limited.
  • Address: Hull, East Riding of Yorkshire, England.
  • Contact details: operations@plughathon.com; Data Protection Officer (if appointed) at the same address.
  • Activities relevant to the transfer: hosting, processing and storage of Customer Personal Data on behalf of the Customer; AI inference for sentiment, topic clustering, key drivers, SWOT and chat as configured by the Customer.
  • Signature and date: as set out in the DPA execution block.
  • Role: processor.

Annex II: Technical and Organisational Measures

PlugZero implements the measures described in Schedule D of the DPA. This Annex incorporates Schedule D by reference and treats it as Annex II for the purposes of the SCCs.

In summary: TLS 1.2+ in transit; AES-256 at rest; per-tenant KMS key isolation in production; RBAC with mandatory MFA for admin accounts; SSO available on enterprise tier; immutable audit logging of access and modifications (login, file upload, file delete, share, AI call, data export, account delete); 12-month audit log retention; continuous vulnerability management; background checks for staff with production access; vendor due diligence for every sub-processor; documented breach response with 24-hour processor to controller notification and 72-hour controller to ICO notification.

Annex III: List of sub-processors

The sub-processors engaged at the date of execution are set out in Schedule C of the DPA. PlugZero shall notify the Customer in writing of any changes in accordance with Section 4.2 of the DPA and Clause 9 of the SCCs.

Annex IV: Data Subject Rights assistance

The data importer self-service tools and assistance procedures are set out in Section 5 of the DPA. This Annex incorporates Section 5 by reference.

Effective date and variation

These SCCs take effect on the effective date of the DPA and continue until the DPA terminates. The parties shall review and (if necessary) update the Annexes at least annually and whenever a material change in the processing occurs.

End of Schedule A.

The SCCs must be executed by both parties. The Customer signature block in the main DPA may incorporate these SCCs by reference, provided that the SCCs are appended in full.


Schedule B: UK International Data Transfer Addendum

Annex to the PlugZero Data Processing Addendum

This Schedule B is the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (the UK Addendum) issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 and approved by the European Data Protection Board for use in conjunction with the EU SCCs at Schedule A.

The UK Addendum is incorporated into and forms part of the DPA between PlugZero and the Customer. It varies the EU SCCs to make them effective for UK-restricted transfers from the Customer (data exporter, established in the United Kingdom) to PlugZero (data importer, established in the United Kingdom) and to PlugZero sub-processors (data sub-processors, established in third countries).

Tables

Table 1: Parties

RolePartyDetails
Data exporterThe CustomerAs set out in the DPA; established in the United Kingdom.
Data importerPlughathon LimitedEstablished in the United Kingdom; processes Customer Personal Data on the data exporter behalf.
Data sub-processorAs set out in Schedule CWhere the data sub-processor is established in a third country.

Table 2: Selected SCCs, modules and selected clauses

The EU SCCs at Schedule A apply, with the following selections:

  • Module: Module 2 (controller to processor).
  • Clause 7 (docking clause): included.
  • Clause 9 (sub-processors): Option 2, general written authorisation with right to object and a 30-day notice period.
  • Clause 11 (redress): included.
  • Clause 17 (governing law): the law of England and Wales.
  • Clause 18 (forum): the courts of England and Wales.

Table 3: Appendix Information

The Annexes to the EU SCCs (Annexes I to IV) are set out in Schedule A. The same information is used for the UK Addendum, with the following modifications:

  • The data exporter is established in the United Kingdom.
  • References to Regulation (EU) 2016/679 (GDPR) are read as references to the UK GDPR (as defined in section 3(10) of the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025) to the extent that the transfer is a UK-restricted transfer.
  • References to EU supervisory authorities are read as references to the Information Commissioner (the ICO).
  • References to EU Member State law are read as references to the law of the United Kingdom.

Table 4: Ending the UK Addendum when the Approved Addendum Changes

If the UK Addendum is replaced or amended by the ICO, PlugZero may, with the Customer written agreement (which shall not be unreasonably withheld), update this Schedule B to refer to the new approved version. Until the Customer has agreed, the existing version continues to apply.

Mandatory clauses of the Approved Addendum

The parties agree that the mandatory clauses of the Approved Addendum (the body of the Addendum as published by the ICO, with Tables 1 to 4 as set out above) are incorporated into and form part of this DPA.

Conflict between the SCCs and the UK Addendum

If there is any conflict between the EU SCCs and the UK Addendum in respect of UK-restricted transfers, the UK Addendum prevails.

Effect of the UK Addendum

The UK Addendum takes effect on the effective date of the DPA and continues for the duration of the DPA. The UK Addendum automatically terminates when: (a) the EU SCCs are replaced by an alternative transfer mechanism approved by the European Commission and recognised by the ICO; or (b) the UK Information Commissioner approves an alternative transfer mechanism for the same transfer.

End of Schedule B.

The UK Addendum does not need to be signed in addition to the SCCs, as its incorporation by reference into the DPA with Tables 1 to 4 completed is sufficient. Available in the standard ICO format at ico.org.uk.


Schedule C: Sub-processors

Annex to the PlugZero Data Processing Addendum and the public sub-processor list at /legal/subprocessors

This Schedule is the authoritative list of sub-processors engaged by PlugZero to process Customer Personal Data. It is updated whenever a sub-processor is added, replaced or removed. Material changes are notified to Customers at least 30 days in advance, in accordance with Section 4.2 of the DPA.

Last updated: 2026-09-01.

Hosting and infrastructure

Sub-processorPurposeLocationTransfer mechanism
Amazon Web Services (AWS)Cloud compute, storage, KMS, CDNEU (eu-west-1, eu-west-2) and US (us-east-1); EU region by default for EU/UK customersEU SCCs Module 2 + UK Addendum
Vercel Inc.Frontend hosting, edge functionsGlobal edge; US origin for build artefactsEU SCCs Module 2 + UK Addendum; DPF for eligible processing

Payments

Sub-processorPurposeLocationTransfer mechanism
Stripe Payments Europe Ltd. / Stripe Inc.Subscription billing, invoice generation, fraud detectionUS / EEA (depending on Customer entity)EU SCCs Module 2 + UK Addendum

AI / LLM inference (opt-in)

Sub-processorPurposeLocationTransfer mechanism
Google LLC (Gemini API)Default LLM for AI chat, sentiment aggregation, topic clustering, key driver analysis, SWOTUS (default); EU endpoint available on requestEU SCCs Module 2 + UK Addendum; training opt-out
Anthropic PBC (optional)LLM for AI chat and insightsUS (default); EU via AWS Bedrock on requestEU SCCs Module 2 + UK Addendum; training opt-out
OpenAI, L.L.C. (optional)LLM for AI chat and insightsUS (default)EU SCCs Module 2 + UK Addendum; training opt-out

Default policy. PlugZero sends data to AI sub-processors only when the Customer actively uses an AI feature. AI processing is opt-out at the project level (Customer can disable AI features entirely). When AI features are enabled, the Customer may choose between US inference (default) and EU in-region inference where available. Free or consumer tier LLM plans are never used for business data.

Transactional email

Sub-processorPurposeLocationTransfer mechanism
Postmark / ActiveCampaign LLCTransactional email (account, billing, security alerts)USEU SCCs Module 2 + UK Addendum

Observability and security

Sub-processorPurposeLocationTransfer mechanism
Sentry.io (Functional Software, Inc.)Error and crash reportingUSEU SCCs Module 2 + UK Addendum
Cloudflare, Inc.CDN, DDoS protectionGlobalEU SCCs Module 2 + UK Addendum

Customer support and CRM (optional, for marketing site enquiries only)

Sub-processorPurposeLocationTransfer mechanism
HubSpot, Inc. (if enabled)CRM for marketing leadsUSEU SCCs Module 2 + UK Addendum; DPA executed
Google LLC, Google Analytics 4Marketing site usage analytics (measurement ID G-9SR1NCJGF2), loaded only after analytics opt-in via the cookie consent bannerUS / EEAEU SCCs Module 2 + UK Addendum; UK-US Data Bridge where Google is certified

Change notification

When a new sub-processor is added or a material change is made, PlugZero will:

  1. Publish the change on the public sub-processor list page (https://plugzero.app/legal/subprocessors) at least 30 days before the change takes effect.
  2. Email the Customer designated notification address at least 30 days before the change takes effect.
  3. Provide an in-app banner announcing the change.

The Customer may object on reasonable data protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected services without liability and obtain a pro rata refund under Section 4.2 of the DPA.

Customer side sub-processors

The Customer is responsible for maintaining its own list of sub-processors where it acts as a controller and uses PlugZero as a processor. PlugZero does not, of itself, cause the Customer data subjects to be processed by any party not named in this Schedule, except as required to perform the service.

End of Schedule C.


Schedule D: Technical and Organisational Measures (TOMs)

Annex to the PlugZero Data Processing Addendum

PlugZero implements the following technical and organisational measures to ensure a level of security appropriate to the risk of the processing of Customer Personal Data, in accordance with Article 32 of UK GDPR and EU GDPR.

1. Encryption

1.1 In transit

  • All client connections are served over TLS 1.2 or higher (TLS 1.3 preferred). HTTP Strict Transport Security (HSTS) is enabled.
  • Internal service to service traffic uses mutually authenticated TLS over the provider private network.

1.2 At rest

  • All stored Customer Personal Data and uploaded files are encrypted at rest using AES-256.
  • Production keys are managed by AWS KMS (or equivalent). Keys are rotated annually; rotation is logged.
  • For enterprise tier, per-tenant KMS keys are available on request (crypto-shred on tenant deletion).

1.3 In use

  • Production secrets are stored in a managed secret store and never committed to source.
  • Database credentials are rotated quarterly.

2. Access control

2.1 Customer side

  • Role-based access control (RBAC): owner, admin, editor, viewer per project; team-level roles for cross-project access.
  • Multi-factor authentication (MFA) is mandatory for all owner and admin accounts.
  • Single Sign-On (SAML 2.0 / OIDC) is available on the enterprise tier.

2.2 PlugZero staff

  • Production access is granted only to staff with a documented business need (least privilege).
  • All production access is via single sign-on plus MFA.
  • Access is reviewed quarterly. Privileged sessions are logged and reviewed.

3. Logging and monitoring

  • All of the following events are recorded in the immutable audit log: login, logout, login failed, password reset, file upload, file download, file delete, project share, project unshare, dashboard share, dashboard unshare, report share, report unshare, AI call (with model and version), AI chat (with prompt length, no content), data export, account delete, consent change, sub-processor change, API key create/revoke, admin action.
  • Audit log retention: default 12 months; configurable up to 7 years on enterprise tier.
  • Where integrity is required, the audit log entries are chained with HMAC-SHA-256 (key in the AUDIT_LOG_HMAC_KEY environment variable) to enable external tamper verification.
  • Anomaly detection on authentication events (impossible travel, brute force, bulk download).

4. Vulnerability management

  • Annual third party penetration test; remediation tracked to closure.
  • Continuous vulnerability scanning of dependencies (Dependabot, Snyk or equivalent).
  • A vulnerability disclosure and responsible disclosure programme is published at https://plugzero.app/security.
  • Mean time to patch critical vulnerabilities: target 48 hours for high severity issues, 7 days for medium.

5. Secure development

  • Source code is reviewed before merging into the main branch (mandatory peer review).
  • Static analysis and secret scanning in CI.
  • Dependency pinning and reproducible builds in production.

6. Backup and resilience

  • Production data is backed up daily; backups are encrypted; backups are retained for 30 days.
  • Recovery time objective (RTO): 4 hours. Recovery point objective (RPO): 1 hour.
  • Annual disaster recovery exercise.

7. Sub-processor due diligence

  • Each sub-processor is subject to a documented due diligence review before engagement and annually thereafter, covering: security certifications (ISO 27001, SOC 2 Type II where available); data residency confirmation; sub-processor list; breach notification commitments; insurance.
  • A signed DPA with Article 28 wording and an SCCs and UK Addendum package (where applicable) is in place with every sub-processor.

8. Personnel

  • Background checks for staff with production data access (criminal record, right to work, identity).
  • All staff complete data protection training on induction and annually thereafter.
  • Confidentiality clauses in every employment contract.

9. Breach response

  • Documented 24-hour processor to controller notification procedure (Section 6 of the DPA).
  • Documented 72-hour controller to ICO notification playbook.
  • Tabletop breach response exercise at least annually.
  • Designated data protection lead and escalation tree (operations@plughathon.com).

10. AI governance

  • AI model registry pins model id and version and region for every AI call. The registry is reviewed and re-approved at every change.
  • No training on customer data. This is contractually guaranteed and technically enforced at the configuration layer for every LLM provider.
  • Provenance labelling. Every AI-generated widget carries a visible badge with a modal disclosing the model, version, provider, region, training opt-out and purpose (EU AI Act Art. 50).
  • Prompt and response retention. Default 30 days and configurable, never used for provider side training.
  • In-region inference. EU customers may opt into EU endpoints where commercially available.

11. Privacy by design and by default (Article 25)

  • The default project setting is no public sharing. Sharing is opt-in by the owner.
  • The default AI setting is enabled (Customer primary value); the Customer may disable AI features per project.
  • The default cookie setting on the marketing site is strictly necessary only; analytics and marketing cookies require explicit opt-in (UK PECR).
  • The default retention for failed uploads is 30 days; the default retention for deleted projects is 30-day grace period, then permanent deletion.

12. Independent assurance

PlugZero will obtain (or is obtaining):

  • SOC 2 Type II, annual and covering security and availability criteria.
  • ISO/IEC 27001:2022 for the Information Security Management System.
  • ISO/IEC 42001:2023 for the AI Management System.

Current certificates are linked from https://plugzero.app/security.

End of Schedule D.


Schedule E: Lawful bases (informative)

Annex to the PlugZero Data Processing Addendum

This Schedule is informative and does not form part of the DPA. It sets out the lawful bases that Customers (acting as controllers) most commonly rely on when processing Customer Personal Data through the PlugZero service. Customers must determine their own lawful basis for each processing purpose and document it in their own record of processing activities (Article 30).

Common scenarios and likely lawful bases

ScenarioLikely Article 6 basisNotes
Customer uploads its own employee survey responses and runs analysisLegitimate interests (Article 6(1)(f)) or consent (6(1)(a)) depending on contextIf responses are pseudonymous, legitimate interests is usually defensible. If responses identify named individuals and are used to take employment decisions, consent is required and special category data rules (Art. 9) may apply.
Customer uploads customer list data (names, contact details, purchase history)Legitimate interests (Article 6(1)(f))Perform a balancing test (LIA). Provide a clear opt-out at the point of data collection.
Customer processes survey data subjects free text responses that may include sensitive attributes (health, ethnicity, sexual orientation)Explicit consent (Article 9(2)(a)) and a separate Article 6 basisSpecial category data. Document the consent record. Customers should consider whether the analytical purpose can be achieved with less special category data.
Customer uses PlugZero AI chat to query its own internal knowledge baseLegitimate interests (Article 6(1)(f))LIA. Ensure internal staff are informed of AI processing.
Customer processes data to fulfil a contract with the data subject (for example service delivery)Contract (Article 6(1)(b))Limited to data strictly necessary for the contract.
Customer processes data to comply with a legal obligation (for example anti-money-laundering)Legal obligation (Article 6(1)(c))Document the specific law.
Customer processes data to protect a data subject vital interests (for example medical emergency)Vital interests (Article 6(1)(d))Rare in PlugZero typical use cases.

What Customer must not do

The Customer must not upload to the service any data for which the Customer cannot identify a lawful basis, or any data that is subject to a processing restriction, without first removing or anonymising it. PlugZero will not be responsible for unlawful Customer uploads.

Special category and criminal offence data

Customers must not upload special category personal data (Article 9(1), for example health, ethnicity, religion, sexual orientation, political opinions, trade union membership, biometric or genetic data) or criminal offence data (Article 10) without:

  • a separate written agreement with PlugZero; and
  • an additional Article 9(2) condition documented in the Customer ROPA.

End of Schedule E.

To execute this DPA, email operations@plughathon.com from the address associated with your account.

Related: Sub-processor list · Privacy Notice · Terms of Service