1. Introduction
Pluro (“Pluro,” “we,” “us,” or “our”) respects your privacy and is committed
to protecting personal data processed through our website, platform, and
related services.
This Privacy Policy explains what information we collect, how we use and
protect it, when it may be shared, how long it is retained, and the rights
available to individuals under applicable privacy and data protection laws.
This Privacy Policy applies to:
- The Pluro website available at https://pluro.ai/;
- The Pluro SaaS platform and customer portal;
- Accessibility scanning, analysis, reporting, and remediation services;
- Customer support, sales, communications, and related business activities.
This Privacy Policy forms part of, and should be read together with, our
Terms and Conditions,
Cookies Policy, and other applicable agreements.
2. About Pluro
Pluro provides a website accessibility workflow platform that supports
accessibility scanning, behavior analysis, AI-assisted recommendations,
controlled remediation, reporting, and developer workflows.
Pluro is operated from Israel. Our primary cloud infrastructure is hosted
through Amazon Web Services (AWS) in Germany.
For privacy-related questions or requests, contact us at
info@pluro.ai.
3. Our Role in Processing Personal Data
Depending on the circumstances, Pluro may act as:
- A data controller when processing information relating
to website visitors, prospects, customer contacts, and users of our
business services; or - A data processor when processing customer data on behalf
of a business customer and according to that customer’s documented
instructions.
Customers retain legal ownership of their data. Pluro does not claim ownership
of customer data and processes it only to provide, operate, secure, maintain,
and support the agreed services.
4. Information We Collect and Process
4.1 Information Provided Directly to Us
We may collect personal data that you provide when you create an account,
contact us, request information, subscribe to a service, communicate with
customer support, or enter into a commercial relationship with Pluro.
This information may include:
- First and last name;
- Business email address;
- Telephone number;
- Company name and position;
- Billing and commercial contact details;
- Account and authentication-related information;
- Communications, support requests, and correspondence.
Passwords are not stored in readable form.
4.2 Website and Accessibility Data
When customers use the Pluro platform, we may process information required
to perform accessibility scanning, analysis, reporting, and remediation,
including:
- Domain names and website URLs;
- The DOM structure of scanned webpages;
- HTML elements and relevant technical attributes;
- Accessibility scan findings and rule results;
- Technical element identifiers and selectors;
- Accessibility remediation records and status information;
- Reports and evidence relating to accessibility findings.
Website content may incidentally include personal information that is publicly
displayed on a scanned webpage. The service is not designed or intended to
collect passwords, payment card information, health information, or sensitive
personal information submitted by website visitors through private forms.
4.3 Technical and Usage Information
When you access our website or platform, certain technical information may
be collected automatically, including:
- IP address;
- Browser type and version;
- Device type and operating system;
- Language and regional settings;
- Date and time of access;
- Referring pages and URLs;
- Account activity and operational logs;
- Security, error, and performance information.
This information is used to operate, secure, monitor, troubleshoot, and
improve the availability and performance of the services.
4.4 Cookies and Similar Technologies
We may use cookies, pixels, and similar technologies on our public website.
Essential cookies may be used to provide secure and functional website
services. Non-essential cookies are used according to applicable consent
requirements.
Additional information is available in our
Cookies Policy.
5. Purposes of Processing
We process personal data for the following purposes:
- To create, authenticate, administer, and secure user accounts;
- To provide access to the Pluro platform and contracted services;
- To perform website accessibility scanning and analysis;
- To generate accessibility reports and remediation recommendations;
- To manage accessibility findings and controlled remediation workflows;
- To provide customer service, technical support, and account management;
- To process commercial transactions and maintain accounting records;
- To communicate service, security, contractual, or policy updates;
- To monitor service performance, reliability, and security;
- To prevent fraud, misuse, unauthorized access, and security threats;
- To comply with legal, regulatory, and contractual obligations;
- To establish, exercise, or defend legal claims;
- To improve the Pluro service using aggregated or non-identifying operational information.
Customer data is not used for unrelated marketing, advertising, or product
enhancement purposes without the customer’s authorization.
6. Legal Bases for Processing
Where applicable law requires a legal basis for processing, we rely on one
or more of the following:
- Performance of a contract: where processing is necessary
to provide the services requested by a customer or user. - Legitimate interests: where processing is necessary to
operate, secure, support, and improve our business and services, provided
those interests are not overridden by individual rights. - Consent: where consent is required, including for certain
cookies, marketing communications, or optional functionality. - Legal obligations: where processing is required to comply
with applicable law, regulation, court order, or governmental request.
7. Processing on Behalf of Customers
When Pluro processes personal data on behalf of a business customer, Pluro
processes that data according to:
- The customer’s documented instructions;
- The agreed scope of services;
- The applicable commercial agreement;
- Applicable privacy and data protection laws.
Pluro will not process such data for an additional purpose unless expressly
authorized by the customer or required by applicable law.
A separate Data Processing Agreement or additional data processing terms may
be executed where required by the nature of the engagement.
8. Artificial Intelligence Services
Pluro may use external artificial intelligence services to assist with
accessibility analysis and the generation of remediation recommendations.
Supported providers may include:
- OpenAI GPT;
- Google Gemini;
- Anthropic Claude.
Pluro does not develop, train, fine-tune, or host its own foundation models.
Customer data is not used by Pluro to train or fine-tune AI models.
Pluro does not provide an unrestricted public prompt interface. AI requests
are generated through controlled accessibility workflows and are limited to
the technical accessibility context required to perform the requested
analysis.
Pluro is designed not to submit personal data, passwords, payment information,
or unrelated customer information to AI providers. Customer prompts are not
stored by Pluro.
AI-generated results are treated as recommendations. They do not constitute
legal advice or an independent determination of accessibility compliance.
Context-dependent or higher-risk recommendations may require human review
before implementation.
9. Sharing Information with Third Parties
We do not sell personal data.
We may share limited information with third parties only where necessary for
the provision, operation, security, maintenance, or support of the services.
These third parties may include:
- Amazon Web Services: for cloud infrastructure, hosting,
storage, backups, and related security services. - Authorized development, DevOps, and support providers:
where access is operationally required to maintain or support the service. - Communication, analytics, and customer-support providers:
where used in connection with the public Pluro website or customer
communications. - AI service providers: where AI-assisted accessibility
functionality is enabled and only for the limited technical context
required for the relevant request. - Professional advisers: including legal, accounting,
insurance, and security advisers where reasonably necessary. - Public authorities: where disclosure is required by law,
regulation, court order, or valid governmental request.
Employees, contractors, subcontractors, and service providers who may access
customer or personal data are subject to confidentiality, information
security, and data protection obligations appropriate to their role.
10. Subcontractors and Service Providers
Pluro may engage authorized subcontractors and service providers to provide,
operate, maintain, secure, or support the services.
Access by subcontractors is limited according to their specific role and
operational need. Relevant subcontractors are required to comply with
confidentiality, privacy, and information security obligations aligned with
Pluro’s ISO/IEC 27001 information security framework and the services they
perform.
Subcontractor access permissions are reviewed periodically and as part of
Pluro’s applicable ISO/IEC 27001 control and audit processes.
11. Data Location and International Transfers
Pluro’s primary service infrastructure is hosted on AWS in Germany.
Personal data may be processed outside Israel where necessary to provide,
operate, secure, or support the services. Any international processing is
limited to the information required for the relevant purpose.
Where required by applicable law, international transfers are subject to
appropriate contractual, organizational, and technical safeguards. These may
include applicable data processing terms, contractual confidentiality
obligations, access restrictions, encrypted transmission, and safeguards
provided by the relevant service provider.
Pluro does not intentionally transfer personal data to AI providers. AI
services are used to process limited technical accessibility context that is
designed not to include personal data.
12. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes
described in this Privacy Policy, provide and support the services, comply
with legal obligations, resolve disputes, and enforce agreements.
Retention periods may include:
- Customer account and service data: retained for the
duration of the service relationship and only for as long as required to
provide, operate, secure, and support the service. - Website scan and remediation data: retained during the
service relationship and deleted upon an authorized customer request or
following termination, subject to applicable legal, contractual, and
backup-retention requirements. - Business contact information: retained while the
relationship remains active and for a reasonable period following the
last interaction. - Billing and transaction records: retained for the period
required by applicable tax, accounting, and legal requirements. - Security and operational logs: retained for a period
appropriate to their security, troubleshooting, and operational purpose. - Analytics and cookie data: retained according to the
applicable tool configuration and our Cookies Policy. - Customer AI prompts: not stored by Pluro.
Where information is stored in backups, it may remain temporarily until the
applicable backup-retention cycle expires. During that period, it is isolated
from ordinary use and retained only for recovery and security purposes.
13. Data Deletion and Return
Upon receiving a formal deletion request from an authorized customer
representative, Pluro will:
- Verify the identity and authority of the requesting party;
- Identify the relevant customer account and associated data;
- Determine whether any legal or contractual retention requirement applies;
- Delete the applicable data through controlled administrative procedures;
- Inform the customer when the deletion process has been completed.
Upon termination of the engagement, Pluro will, according to the customer’s
documented instructions and the applicable agreement, return available
customer data where applicable and delete relevant personal data, scan data,
and remediation data from active systems.
Data subject to legal, contractual, security, or backup-retention requirements
may remain temporarily until the applicable retention period expires.
14. Information Security
Pluro implements technical and organizational measures designed to protect
personal data against unauthorized access, use, alteration, disclosure, loss,
or destruction.
These measures may include:
- Role-based access controls;
- Individual authenticated user accounts;
- Tenant-based logical separation between customer accounts;
- Access restrictions based on operational need;
- Multi-factor authentication where enabled;
- IP allow-listing where enabled;
- Encrypted communication channels;
- Restricted administrative and production access;
- Security monitoring and logging;
- Controlled deployment and change-management processes;
- Backup and recovery procedures;
- Confidentiality obligations for personnel and service providers;
- Controls maintained under Pluro’s ISO/IEC 27001 framework.
No internet-based service can guarantee absolute security. Users are also
responsible for protecting their account credentials and accessing the
service through appropriately secured devices and networks.
15. Account and Access Management
Each customer is assigned a separate customer account. The customer’s
designated account administrator is responsible for managing users and access
permissions within that customer account.
Customer administrators may review, update, restrict, or revoke user access
according to the customer’s internal access governance requirements.
Access by Pluro personnel and authorized service providers is limited to
individuals who require access to operate, secure, maintain, or support the
service. Such access is subject to confidentiality obligations and appropriate
access controls.
16. Security Incident Response
Pluro maintains documented security incident response procedures as part of
its ISO/IEC 27001 information security management framework.
The incident response process includes procedures for:
- Identifying and documenting suspected incidents;
- Assessing severity and potential customer impact;
- Escalating incidents to relevant management, DevOps, development, and support personnel;
- Containing and investigating the incident;
- Remediating vulnerabilities and restoring normal operations;
- Documenting corrective actions and lessons learned;
- Notifying affected customers where required.
Pluro will notify an affected customer without undue delay and no later than
72 hours after becoming aware of and confirming a personal data security
incident involving that customer’s data, subject to applicable legal and
contractual requirements.
17. Individual Privacy Rights
Depending on the individual’s location and the applicable law, privacy rights
may include:
- The right to request information about the processing of personal data;
- The right to access personal data;
- The right to correct inaccurate or incomplete personal data;
- The right to request deletion of personal data;
- The right to restrict certain processing activities;
- The right to object to certain processing activities;
- The right to withdraw consent where processing is based on consent;
- The right to receive personal data in a portable format where applicable;
- The right to submit a complaint to an applicable supervisory authority.
To exercise an applicable privacy right, contact
info@pluro.ai.
We may request information necessary to verify the identity and authority of
the requesting party before responding.
18. Assistance to Business Customers
Where Pluro acts as a processor on behalf of a customer, Pluro will provide
reasonable assistance in responding to valid requests relating to personal
data processed through the service.
Subject to applicable law and technical feasibility, this may include:
- Locating relevant personal data;
- Providing available data to the customer;
- Correcting or updating personal data;
- Restricting or deleting applicable personal data;
- Providing relevant information regarding the processing performed by Pluro.
Privacy inquiries and complaints are handled through Pluro’s customer support
process and may be escalated to management, development, or DevOps personnel
where necessary.
19. Children’s Privacy
Pluro’s website and services are intended for business and professional use
and are not directed to children.
We do not knowingly collect personal data directly from children under the
age of 16. If we become aware that such information has been collected without
appropriate authorization, we will take reasonable steps to delete it.
Concerns regarding information relating to a minor may be submitted to
info@pluro.ai.
20. Third-Party Websites and Services
Our website may contain links to third-party websites or services that are
not controlled by Pluro.
This Privacy Policy does not apply to information collected independently by
those third parties. We recommend reviewing the privacy policy of any external
website or service before providing personal data.
21. Security Documentation and Customer Reviews
Customers are not granted a general right to conduct direct audits of Pluro’s
systems, facilities, personnel, or operations.
Subject to confidentiality, reasonable scope, availability, and internal
approval, Pluro may provide relevant security and privacy documentation,
certifications, audit-related materials, and questionnaire responses.
22. Material Changes to Data Processing
Pluro may update its services and data processing practices from time to time.
Where a material change may significantly affect the processing, location,
security, or permitted use of customer personal data, Pluro will provide the
affected customer with reasonable advance notice where practicable.
23. Updates to This Privacy Policy
We may update this Privacy Policy to reflect changes in our services, business
practices, technology, or applicable legal requirements.
The updated version will be identified by the “Last Updated” date displayed
at the beginning of this page. Material updates may also be communicated
through the website, platform, or directly to affected customers.
We encourage users and customers to review this Privacy Policy periodically.
24. Contact Us
For questions, requests, complaints, or concerns regarding this Privacy Policy
or Pluro’s processing of personal data, contact:
Israel
Email:
info@pluro.ai
Website:
https://pluro.ai/