Legals
Privacy Policy
Effective date: March 13, 2026
This privacy policy ("Policy") describes how Plutio LTD ("Plutio", "we", "us" or "our") collects, protects and uses the personal data that individual users and business entities ("User", "you" or "your") provide through the plutio.com website, the related domain names, web application, desktop application, mobile applications, browser extensions, and any of its products or services (collectively, "Website" or "Services").
The Policy also describes the choices available to you regarding our use of your personal data and how you can access and update this information. This Policy does not apply to the practices of companies, websites, and services that we do not own or control, or to individuals that we do not employ or manage. Please read this Policy carefully before providing any personal data to us.
Contents
1. About us
2. Automatic collection of information
3. Collection of personal data
4. Processing of content data
5. Data from third parties
6. Sensitive data
7. Managing personal data
8. Storing personal data
9. Information disclosure
10. International transfers
11. The rights of users
12. How to exercise users' rights
13. Complaints
14. Non-discrimination
15. Billing and payments
16. Privacy of children
17. Newsletters and service notices
18. Cookies and targeted advertising
19. Do Not Track signals
20. Links to other websites
21. Information security
22. Data breach
23. Changes and amendments
24. Contacting us
1. About us
The Website is owned and operated by Plutio LTD, a company registered in the United Kingdom with a registered place of business at 4th Floor Silverstream House, Fitzroy Street, London, W1T 6EB, United Kingdom.
We act in the capacity of a data controller and data processor with regard to the personal data processed through the Website in terms of the applicable data protection laws, including the UK Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), and the EU General Data Protection Regulation (EU GDPR). Our role depends on the specific situation in which your personal data is handled by us, as explained in detail below:
- Data controller. We are responsible for the collection and use of your personal data through the Website and we make decisions about the types of personal data that should be collected from you and the purposes for which such personal data should be used. Therefore, we act as a data controller with regard to the personal data collected directly through the Website (for example, when you create an account, subscribe to a plan, communicate with us, or browse our website). We comply with the data controller's obligations set forth in the applicable laws.
- Data processor. We act in the capacity of a data processor in situations when you upload digital files (such as images, videos, documents, and PDF files) or generate other data through the Services (the "Content") and that Content contains personal data. This includes, but is not limited to, projects, proposals, contracts, invoices, client information, messages, files, and scheduling data that you create or store within Plutio. We do not own, control, intentionally access, or make decisions about the Content. We process the Content only in accordance with the instructions issued by a respective data controller. To ensure that the Content is processed in accordance with the strictest data protection standards, we offer a data processing agreement (the "DPA"). To conclude the DPA, please contact us at legal@plutio.com.
2. Automatic collection of information
When you visit the Website, our servers and third-party analytics services automatically record information that your browser or device sends. This data may include information such as your device's IP address, browser type and version, operating system type and version, language preferences, the webpage you were visiting before you came to our Website, pages of our Website that you visit, the time spent on those pages, information you search for on our Website, access times and dates, and other statistics.
We use the following third-party analytics and tracking services to collect and analyse this information:
- Google Analytics 4 (GA4). We use Google Analytics 4, provided by Google LLC, to track page views, interactions with calls to action, and signup attribution. GA4 may collect your IP address, browser information, device information, and behavioural data relating to your use of the Website. Google's privacy policy is available at https://policies.google.com/privacy.
- DataFast Analytics. We use DataFast to collect website analytics data, including page views and visitor behaviour on the Website.
- ProfitWell (by Paddle). We use ProfitWell, provided by Paddle, to track revenue metrics, subscription analytics, and conversion data. ProfitWell's privacy policy is available at https://www.paddle.com/legal/privacy.
- Facebook Pixel. We use the Facebook Pixel, provided by Meta Platforms, Inc., to track page views, custom events, and to enable remarketing and targeted advertising on Facebook and Instagram. The Facebook Pixel may collect data about your browsing activity on our Website and use cookies to identify your browser. Meta's privacy policy is available at https://www.facebook.com/privacy/policy/.
- Plutio Internal Analytics. We use our own internal analytics to track interactions such as tag clicks, referral sources, and navigation patterns within the Website.
UTM and attribution tracking. When you arrive at our Website via a link that contains UTM parameters (such as utm_source and utm_campaign), we capture these parameters and attach them to any subsequent signup links. If you create an account and subscribe to a paid plan, this attribution data (including the referring page) may be passed to our payment processor Stripe and stored as part of your customer record. We use this data to understand how users discover Plutio and to measure the effectiveness of our marketing efforts.
Information collected automatically is used to identify potential cases of abuse, establish statistical information regarding Website usage, and measure marketing effectiveness. In most cases, such information is not considered to be personal data (except for your IP address and any online identifiers). The legal basis on which we rely when processing your IP address and online identifiers is "pursuing our legitimate business interests" (that is, to operate, analyse, and protect our Website) and, where required, "your consent" (for non-essential tracking technologies). We store such data as long as it is necessary for analysing and protecting our Website but no longer than 2 years.
3. Collection of personal data
When you use the Website, we collect only the personal data that is necessary for limited, specified, and legitimate purposes explicitly mentioned in this Policy. We do not use your personal data for purposes that are incompatible with the purposes for which it was collected. Below, you can find an overview of the types of personal data that we collect, the instances in which we do so, the purposes for which we use it, and the legal basis on which we rely when processing your personal data.
Personal data collected directly from you:
- User account. When you create your user account or request a free trial, we collect your (i) first name, (ii) last name, (iii) workspace name, (iv) workspace domain, (v) email address, and (vi) password. When you update your user account, we may also collect your (i) profile image, (ii) date of birth, (iii) biography, (iv) additional email address(es), (v) phone number, (vi) address(es), (vii) company name, (viii) website and social media links, (ix) tax identification numbers, (x) business logos, (xi) email sending preferences (such as sender name and reply-to address), and any other information that you decide to provide about yourself or your business. We use such data to (i) register and maintain your user account, (ii) enable your access to the Services, (iii) provide you with the requested services, (iv) customise our services for your needs, (v) contact you when necessary, (vi) send you commercial communication where permitted, and (vii) maintain our business records. The legal bases on which we rely are "performing a contract with you" and "pursuing our legitimate business interests" (that is, to analyse, grow, and administer the Website). We will store your personal data until your user account is deleted or terminated.
- Billing. When you make a payment, you will be asked to provide (i) cardholder name, (ii) credit card details (number, expiration date, CVC), and (iii) billing address. Please note that your payment data is processed directly by our third-party payment processors (Stripe, PayPal, or Square) and we do not store your credit card details on our servers. These payment processors make available to us only a limited portion of your payment data (such as the last four digits of your card, card brand, and billing address). We use such data to (i) process your payments, (ii) issue invoices, and (iii) maintain our business records. The legal bases on which we rely are "performing a contract with you" and "pursuing our legitimate business interests" (that is, to administer our business and comply with our legal obligations). We will store your billing-related personal data for the time period required by applicable law (in the UK, we are required to store accounting records for 6 years).
- Booking a demo. When you book a demo, we collect your (i) name, (ii) email address, and (iii) any other information that you decide to provide us. We use such data to (i) schedule your demo, (ii) contact you when necessary, and (iii) analyse and improve the Services. The legal bases on which we rely are "pursuing our legitimate business interests" (that is, to grow and promote our business) and "your consent" (for optional personal data). We store your personal data until we deliver your demo; if you decide to start using the Services, we will use your personal data to register your user account.
- Email enquiries. When you contact us by email, we collect your (i) name, (ii) email address, and (iii) any information that you decide to include in your message. We use such data to respond to your enquiries and provide you with the requested information. The legal bases on which we rely are "pursuing our legitimate business interests" (that is, to grow and promote our business) and "your consent" (for optional personal data).
- Live chat. When you use the live chat functionality on our Website, we collect any information that you decide to provide us. We use such data to respond to your enquiries and provide you with the requested information. The legal basis on which we rely is "your consent".
- IP address. When you browse the Website, we or our third-party analytics service providers (as described in section 2 above) collect your IP address. We use your IP address to analyse the technical aspects of your use of the Website, prevent fraud and abuse, and ensure the security of the Website. The legal basis on which we rely is "pursuing our legitimate business interests" (that is, to analyse and protect the Website). We store your IP address for no longer than 2 years.
- Cookies. When you browse the Website, we collect cookie-related data. We track your cookie consent preferences using local storage on your device. For more information about our cookies and the purposes for which we use them, please refer to our Cookie Policy. The legal bases on which we rely are "pursuing our legitimate business interests" (that is, to protect and conduct our business) and "your consent" (for non-essential cookies).
4. Processing of content data
When you upload Content or generate Content through the Services, we process all information that can be found in the Content, including any personal data the Content contains. This may include, for example, your clients' names, contact details, business information, project details, financial information in invoices and proposals, contractual terms, scheduled appointments, and messages. We process the Content to (i) provide you with the requested services and (ii) perform our other contractual obligations. The legal basis on which we rely is "performing a contract with you". We store such personal data until you delete it or stop using the Services.
5. Data from third parties
We may receive information about you from third parties to whom you have previously provided your personal data, if those third parties have a lawful basis for disclosing your personal data to us. For example, if social media login is enabled, we will collect the personal data that your social media provider discloses to us (such as your name, email address, and photo). Please note that you can control what personal data is submitted to us by adjusting the privacy settings of your social media service provider. We will use such data as described in the section "User account" above.
6. Sensitive data
We do not collect or have access to any special categories of personal data ("sensitive data") from you, unless you decide, at your own discretion, to provide such data to us. Sensitive data is information that relates to your health, genetics, biometrics, religious and political beliefs, racial or ethnic origins, membership of a professional or trade association, sex life, or sexual orientation. If you choose to include sensitive data in the Content you upload to the Services, you are responsible for ensuring that you have a lawful basis for processing such data.
Refusal to provide personal data. You can choose not to provide us with your personal data when requested, but then you may not be able to take advantage of some of the Website's features. Users who are uncertain about what information is mandatory are welcome to contact us.
7. Managing personal data
You are able to delete or change certain personal data that we have about you. The personal data you can manage may change as the Website or the Services change. When you delete personal data, we may maintain a copy of the unrevised personal data in our records where we have a lawful basis for doing so (for example, to comply with our legal obligations or to resolve disputes). If you would like to delete your personal data or permanently delete your account, you can do so on the settings page of your account within the Services, or by contacting us at legal@plutio.com.
8. Storing personal data
We will retain and use your personal data for the period necessary to perform our contractual obligations to you, comply with our legal obligations, resolve disputes, and enforce our agreements, unless a longer retention period is required or permitted by law. For more details on the retention periods applicable to each type of personal data, please refer to sections 2 and 3 above. We may use any aggregated data derived from or incorporating your personal data after you update or delete it, but not in a manner that would identify you personally. Once the retention period expires, your personal data will be securely deleted. Therefore, the right to access, the right to erasure, the right to rectification, and the right to data portability cannot be enforced after the expiration of the retention period.
9. Information disclosure
1) Disclosure to data processors
From time to time, your personal data is disclosed to our service providers with whom we cooperate (our data processors). For example, we share your personal and non-personal data with entities that provide certain technical support services to us, such as database, analytics, payment processing, and communication services. We do not sell your personal data to third parties. The disclosure is limited to situations where your personal data is required for the following purposes:
- Ensuring the proper operation of the Website and Services;
- Ensuring the delivery of services that you purchase;
- Providing you with the requested information;
- Pursuing our legitimate business interests;
- Enforcing our rights, preventing fraud, and security purposes;
- Carrying out our contractual obligations;
- Complying with applicable laws and regulations; or
- If you provide your prior consent to such a disclosure.
2) List of our data processors
We use a limited number of data processors. Our data processors agree to ensure an adequate level of protection of your personal data that is consistent with this privacy policy and the applicable data protection laws. The data processors that have access to your personal data are:
- MongoDB (https://www.mongodb.com) — database service provider, located in the United States;
- Stripe (https://stripe.com) — payment processing service provider, located in the United States;
- PayPal (https://www.paypal.com) — payment processing service provider, located in the United States;
- Square (https://squareup.com) — payment processing service provider, located in the United States;
- Google LLC (https://about.google) — analytics service provider (Google Analytics 4), located in the United States;
- DataFast — analytics service provider;
- Paddle / ProfitWell (https://www.paddle.com) — revenue and subscription analytics service provider, located in the United States;
- Meta Platforms, Inc. (https://www.facebook.com) — advertising and remarketing service provider (Facebook Pixel), located in the United States;
- Builder.io (https://www.builder.io) — content management service provider for our marketing website, located in the United States;
- Gleap (https://www.gleap.io) — customer feedback and support service provider; and
- Our independent contractors and consultants.
3) Disclosure of non-personal data
Your non-personal data may be disclosed to third parties for any purpose. For example, we may share it with prospects or partners for business or research purposes, for improving the Services, responding to lawful requests from public authorities, or developing new products and services.
4) Legal requests
If we are contacted by a public authority, we may need to disclose information about you to the extent necessary for pursuing a public interest objective, such as national security or law enforcement.
5) Successors
In case the Website or our business is sold partly or fully, or in the event of a merger or acquisition, we will provide your personal data to a purchaser or successor entity and request the successor to handle your personal data in line with this Policy. We will notify you of any changes of the data controller.
6) Selling personal data
We do not directly sell your personal data to third parties. However, some of your personal data, including online identifiers (such as cookie-generated data and IP addresses), may be shared with advertising partners for the purposes of targeted advertising, remarketing, and measuring advertising effectiveness (for example, through Facebook Pixel and Google Analytics).
10. International transfers
Some of our data processors listed above are located outside the country in which you reside. In particular, several of our data processors are located in the United States. If you reside in the United Kingdom or the European Economic Area (EEA), we may need to transfer your personal data to jurisdictions outside the UK or EEA.
When we transfer personal data internationally, we rely on one or more of the following safeguards to ensure that your personal data is adequately protected:
- Adequacy decisions. We may transfer your personal data to countries that have been deemed to provide an adequate level of data protection by the UK Secretary of State or the European Commission, as applicable.
- Standard Contractual Clauses (SCCs). Where an adequacy decision does not apply, we use Standard Contractual Clauses approved by the UK Secretary of State (for UK transfers) or the European Commission (for EEA transfers) to ensure that our data processors provide appropriate safeguards for your personal data.
- Other appropriate safeguards. Where applicable, we may rely on other lawful transfer mechanisms permitted under the UK GDPR or EU GDPR, such as binding corporate rules or derogations for specific situations.
We will not transfer your personal data internationally if no appropriate level of protection can be granted. You may contact us at legal@plutio.com to obtain further details about the specific safeguards applied to the international transfer of your personal data.
11. The rights of users
Under the UK GDPR and EU GDPR, you may exercise certain rights regarding your personal data processed by us. In particular, you have the following rights:
- Right of access. You have the right to learn if your personal data is being processed by us, obtain disclosure regarding certain aspects of the processing, and obtain a copy of the personal data undergoing processing.
- Right to rectification. You have the right to verify the accuracy of your personal data and ask for it to be updated or corrected.
- Right to erasure. You have the right, under certain circumstances, to obtain the erasure of your personal data from us.
- Right to data portability. You have the right to receive your personal data processed by us in a structured, commonly used, and machine-readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
- Right to restriction of processing. You have the right, under certain circumstances, to restrict the processing of your personal data.
- Right to object. You have the right to object to the processing of your personal data if the processing is carried out on a legal basis other than consent, including processing based on legitimate interests.
- Right to withdraw consent. Where you have previously given your consent to the processing of your personal data, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint. You have the right to submit a complaint to a supervisory authority regarding our processing of your personal data, as described in section 13 below.
12. How to exercise users' rights
Any requests to exercise your rights can be directed to us through the contact details provided at the end of this Policy. These requests can be exercised free of charge and will be addressed by us as early as possible but no later than 30 days from receipt. In complex cases, we may extend this period by a further 60 days, in which case we will notify you of the extension and the reasons for it within the initial 30-day period.
In order to verify the legitimacy of your request, we may ask you to provide us with an identifying piece of information that allows us to correctly identify you in our system. We will not use the information provided for verification for any other purpose.
If we receive a request from a data subject asking to exercise the data subject's rights with regard to the Content, we will forward such a request to the respective data controller (our client) and assist the data controller in responding to the request as required by applicable law.
13. Complaints
If you would like to make a complaint about the way in which we process your personal data, we kindly ask you to contact us first at legal@plutio.com and express your concerns. If we receive your complaint, we will investigate it and provide you with our response as soon as possible.
If you are not satisfied with the outcome of your complaint, you have the right to lodge a complaint with the relevant supervisory authority. For users in the United Kingdom, the supervisory authority is:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: https://ico.org.uk
Telephone: 0303 123 1113
For users in the European Economic Area, you have the right to lodge a complaint with the data protection authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
14. Non-discrimination
We do not discriminate against you if you decide to exercise your rights under this Policy or applicable data protection law. This means that we will not (i) deny any goods or services, (ii) charge you different prices or rates, (iii) deny any discounts or benefits, (iv) impose penalties, or (v) provide you with a different level or quality of Services as a result of you exercising your data protection rights.
15. Billing and payments
We use third-party payment processors to assist us in processing your payment information securely. Our primary payment processor is Stripe, and we also support payments via PayPal and Square. These third-party processors' use of your personal data is governed by their respective privacy policies. We do not store your full credit card details on our servers.
When you subscribe to a paid plan, attribution data (such as the source of your signup and referring page) may be stored as metadata on your customer record with our payment processor. This data is used solely for internal analytics and marketing attribution purposes.
We recommend that you review the privacy policies of our payment processors:
- Stripe: https://stripe.com/privacy
- PayPal: https://www.paypal.com/webapps/mpp/ua/privacy-full
- Square: https://squareup.com/legal/privacy
16. Privacy of children
We do not knowingly collect any personal data from children under the age of 16. If you are under the age of 16, please do not submit any personal data through our Website or Services. We encourage parents and legal guardians to monitor their children's internet usage and to help enforce this Policy by instructing their children never to provide personal data through our Website or Services without their permission.
If you have reason to believe that a child under the age of 16 has provided personal data to us through our Website or Services, please contact us at legal@plutio.com. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information promptly.
17. Newsletters and service notices
If we have your email address, we may, from time to time, send you newsletters to keep you updated about the latest developments related to the Services, promotions, and special offers. You will receive our newsletters in the following instances:
- If we receive your express ("opt-in") consent to receive marketing messages;
- If you voluntarily subscribe to our newsletter; or
- If we decide to send you information closely related to the services already purchased by you (soft opt-in under applicable law).
You can opt out from receiving our commercial communication at any time free of charge by clicking on the "unsubscribe" link included in our newsletters or by contacting us directly (our contact details are available in the section "Contacting us" below).
If necessary, we will send you important informational notices, such as confirmation receipts, payment information, technical or administrative emails, security alerts, and other administrative updates. Please note that such notices are sent on an "if-needed" basis and they do not fall within the scope of commercial communication that may require your prior consent. You cannot opt out from service-related notices.
18. Cookies and targeted advertising
The Website uses "cookies" and similar technologies (such as local storage) to help personalise your online experience and to enable certain Website functionality. We use local storage on your device to record your cookie consent preferences. For more information on our use of cookies, please read our Cookie Policy.
We use session cookies secured with encryption (via iron-session) to manage your browsing session on the Website. These are essential cookies that are necessary for the operation of the Website.
In addition to using cookies and related technologies as described above, we also permit certain third-party companies to help us tailor advertising that we think may be of interest to users and to collect and use other data about user activities on the Website. In particular:
- Facebook Pixel (Meta Platforms, Inc.). We use the Facebook Pixel to track page views and custom events on our Website for the purposes of remarketing and measuring advertising effectiveness on Facebook and Instagram. The Facebook Pixel places cookies on your browser and collects data about your browsing activity.
- Google Analytics 4 (Google LLC). We use GA4 to understand how visitors interact with our Website, including page views, click behaviour, and signup attribution.
These companies may deliver ads that might also place cookies and otherwise track user behaviour. You can control how such advertising is shown to you or opt out from targeted advertising by managing your cookies as described in our Cookie Policy and by consulting the following resources:
- Digital Advertising Alliance: https://youradchoices.com
- Network Advertising Initiative: https://www.networkadvertising.org
- Your Online Choices (for users in the EU/UK): https://www.youronlinechoices.eu
19. Do Not Track signals
Some browsers incorporate a Do Not Track feature that signals to websites you visit that you do not want to have your online activity tracked. Tracking is not the same as using or collecting information in connection with a website. For these purposes, tracking refers to collecting personal data from consumers who use or visit a website or online service as they move across different websites over time. Our Website does not currently respond to Do Not Track signals. However, some third-party sites and services may keep track of your browsing activities when they serve you content, which enables them to tailor what they present to you.
20. Links to other websites
Our Website contains links to other websites that are not owned or controlled by us. Please be aware that we are not responsible for the privacy practices of such other websites or third parties. We encourage you to be aware when you leave our Website and to read the privacy statements of each and every website that may collect personal data.
21. Information security
We secure information you provide on computer servers in a controlled, secure environment, protected from unauthorised access, use, or disclosure. We maintain reasonable administrative, technical, and physical safeguards in an effort to protect against unauthorised access, use, modification, and disclosure of personal data in our control and custody. We implement the following security measures:
- Secured networks and infrastructure;
- Use of virtual private networks (VPN);
- Encryption of data in transit and at rest;
- SSL/TLS protocol for all data transmission;
- Encrypted session management;
- Strong password requirements;
- Limited access to personal data by authorised staff only;
- Anonymisation and pseudonymisation of personal data where possible;
- Careful selection and monitoring of data processors; and
- Regular security reviews and assessments.
However, no data transmission over the Internet or wireless network can be guaranteed to be completely secure. Therefore, while we strive to protect your personal data, you acknowledge that (i) there are security and privacy limitations of the Internet which are beyond our control; (ii) the security, integrity, and privacy of any and all information and data exchanged between you and our Website cannot be fully guaranteed; and (iii) any such information and data may be viewed or tampered with in transit by a third party, despite best efforts.
22. Data breach
In the event we become aware that the security of the Website has been compromised or users' personal data has been disclosed to unrelated third parties as a result of external activity, including but not limited to security attacks or fraud, we reserve the right to take reasonably appropriate measures, including investigation and reporting, as well as notification to and cooperation with law enforcement authorities.
In accordance with the UK GDPR, we will report any personal data breach to the Information Commissioner's Office without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
In the event of a data breach, we will make reasonable efforts to notify affected individuals if we believe that there is a high risk to their rights and freedoms as a result of the breach, or if notice is otherwise required by law. When we do, we will post a notice on the Website, send you an email, and provide information about the nature of the breach, the likely consequences, and the measures we have taken or propose to take to address it.
23. Changes and amendments
We may update this Policy from time to time at our discretion and will notify you of any material changes to the way in which we treat personal data. When changes are made, we will revise the effective date at the top of this page. We may also provide notice to you in other ways at our discretion, such as through the contact information you have provided.
Any updated version of this Policy will be effective immediately upon the posting of the revised Policy unless otherwise specified. Your continued use of the Website or Services after the effective date of the revised Policy (or such other act specified at that time) will constitute your acknowledgement of those changes. However, we will not, without your consent, use your personal data in a manner materially different from what was stated at the time your personal data was collected.
24. Contacting us
If you would like to contact us to understand more about this Policy or wish to contact us concerning any matter relating to your individual rights and your personal data, you may use the following contact details:
Plutio LTD
4th Floor Silverstream House, Fitzroy Street
London, W1T 6EB
United Kingdom
Email: legal@plutio.com
This Policy was last updated on March 13, 2026.