Last Updated: August 26, 2026
This Data Processing Addendum (the “DPA”) is incorporated by reference into Pluro’s Terms and Conditions, or any other agreement governing the use of the Pluro services between the Customer and Pluro Ltd. (the “Agreement”).
This DPA is entered into between the Customer, as defined in the Agreement (the “Customer”), and Pluro Ltd., Israeli company no. 516155447, of 30A Dov Gruner Street, Tel Aviv-Yafo, Israel (“Pluro”).
This DPA applies only to the extent that Pluro Processes Personal Data on behalf of the Customer in connection with the Services. If there is a conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA will prevail with respect to that subject matter.
1. Definitions
The terms “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process,” “Processing,” “Processor,” and “Supervisory Authority” have the meanings given to them in Regulation (EU) 2016/679, the General Data Protection Regulation (the “GDPR”).
“Subprocessor” means a third party engaged by Pluro to Process Personal Data on behalf of the Customer in connection with the Services.
“Services” means the Pluro platform and related services described in the Agreement, which may include accessibility scanning, analysis, reporting, controlled remediation, developer tools, AI-assisted functionality, support and operation of the platform.
2. Roles of the Parties
2.1 With respect to Personal Data Processed by Pluro on behalf of the Customer, the Customer is the Controller and Pluro is the Processor. If the Customer acts as a Processor on behalf of another Controller, Pluro will act as a Subprocessor.
2.2 Each party will comply with the obligations of the GDPR applicable to it in its respective role.
2.3 The Customer is responsible for the lawfulness of the Personal Data made available to Pluro, including establishing an appropriate legal basis for the Processing and providing any required privacy notices or obtaining any required consents.
3. Processing Instructions
3.1 Pluro will Process Personal Data only to provide the Services and in accordance with the Agreement, this DPA and the Customer’s lawful documented instructions.
3.2 The Customer’s use and configuration of the Services will constitute documented instructions to Pluro, provided that those instructions are consistent with the Agreement and this DPA.
3.3 If Pluro reasonably believes that an instruction from the Customer violates the GDPR, Pluro will inform the Customer without undue delay and may suspend the affected Processing until the matter is resolved.
3.4 Pluro may Process Personal Data where required by applicable law. Where legally permitted, Pluro will inform the Customer of that requirement before carrying out the Processing.
3.5 Pluro will not sell Customer Personal Data or use it for advertising, marketing or purposes unrelated to providing the Services, unless expressly authorized by the Customer or required by law.
4. Details of the Processing
4.1 Subject matter and purpose. Providing, operating, securing, maintaining and supporting the Pluro Services; creating and managing user accounts; performing accessibility scans; analyzing scan results; generating findings, recommendations and reports; managing remediation and verification workflows; and providing AI-assisted functionality when enabled by a user.
4.2 Duration. For the term of the Agreement and thereafter only as necessary to complete controlled deletion, maintain routine backup cycles, comply with legal obligations or establish, exercise or defend legal claims.
4.3 Categories of Personal Data may include:
- Names, business email addresses, job titles, company details and account information relating to Authorized Users;
- IP addresses, browser and device information, login times, account activity, operational logs, security logs and support information;
- Domain names, URLs, DOM structures, HTML elements and technical attributes, accessibility scan findings, technical identifiers, selectors, remediation records, evidence and reports;
- Personal Data that may appear incidentally in publicly available content on a scanned webpage; and
- Information voluntarily entered by a user in an AI-assisted chat or support request.
4.4 Categories of Data Subjects may include: Authorized Users and Customer representatives; visitors and users of websites that the Customer is authorized to scan; and individuals whose information appears in content submitted or made available to Pluro by the Customer.
4.5 Sensitive information. The Services are not designed to receive passwords, payment card information, health information or other special categories of Personal Data submitted through private forms. The Customer will not provide such information to Pluro unless expressly agreed in writing and subject to appropriate safeguards.
5. Artificial Intelligence Features
5.1 When the Customer or an Authorized User activates an AI-assisted feature, Pluro may provide an external AI provider with limited technical information required to perform the requested action. This information may include a DOM structure or relevant portions of accessibility scan results, as well as a question or instruction voluntarily entered by the user in the AI-assisted chat.
5.2 Pluro does not automatically submit chat questions on behalf of users. Processing through the AI-assisted chat occurs only after a user actively enters and submits content.
5.3 Pluro designs its AI workflows to limit information sent to the technical accessibility context required for the requested action. The Services are not designed to submit passwords, payment information or unrelated Personal Data to AI providers.
5.4 AI-generated results are recommendations and may require human review before implementation.
6. Confidentiality and Access
6.1 Pluro will ensure that personnel, contractors and providers authorized to Process Personal Data are subject to appropriate contractual or statutory confidentiality obligations.
6.2 Access to Personal Data will be limited to individuals who require access to operate, secure, maintain, develop or support the Services.
6.3 Authorized development and DevOps contractors may access Production environments and Customer Data where operationally necessary. Such access is subject to confidentiality, security and data protection obligations, appropriate access controls and role-based limitations.
7. Security
7.1 Taking into account the state of the art, implementation costs, the nature of the Processing and the risks to Data Subjects, Pluro will implement and maintain appropriate technical and organizational measures to protect Personal Data.
7.2 These measures may include, as appropriate:
- An information security management system aligned with the ISO/IEC 27001 framework;
- Encryption of communications;
- Role-based access controls and least-privilege access;
- Individual user accounts and authentication controls;
- Logical separation between Customer accounts;
- Relevant logging, monitoring and operational controls;
- Backup, recovery and business continuity procedures;
- Security incident management;
- Change management, secure development and security update procedures; and
- Access restrictions for authorized personnel, contractors and providers.
7.3 Pluro’s primary service infrastructure is hosted through Amazon Web Services in Germany. Pluro also uses Amazon CloudFront for content delivery and service traffic.
8. Personal Data Breaches
8.1 Pluro will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed on behalf of that Customer.
8.2 To the extent reasonably available, the notification will include a description of the nature of the breach; the categories and approximate number of affected Data Subjects and records; the likely consequences; and the measures taken or proposed to address and mitigate the breach.
8.3 Pluro will take reasonable steps to investigate, contain, remediate and mitigate the effects of the breach. Information may be provided in phases as it becomes available. A notification under this section does not constitute an admission of fault or liability.
9. Data Subject Rights and Customer Assistance
9.1 If Pluro receives a request from a Data Subject relating to Personal Data Processed on behalf of the Customer, Pluro will refer the Data Subject to the Customer or notify the Customer, where legally permitted. Pluro will not respond on behalf of the Customer unless instructed by the Customer or required by law.
9.2 Taking into account the nature of the Processing and the information available to Pluro, Pluro will provide reasonable assistance to the Customer in responding to valid Data Subject requests and in meeting applicable obligations under Articles 32 through 36 of the GDPR, to the extent relevant to the Services.
10. Subprocessors
10.1 The Customer provides Pluro with general written authorization to engage Subprocessors as necessary to provide the Services.
10.2 Relevant Subprocessors may include:
- Amazon Web Services, including Amazon CloudFront, for infrastructure, hosting, backup and content delivery;
- Authorized development and DevOps providers for development, maintenance, security and operational support;
- Supported external AI providers, including OpenAI, Google Gemini and Anthropic Claude, only when the Customer or an Authorized User activates a relevant AI-assisted feature; and
- Support, communication and monitoring providers where required to operate the Services and where they Process Personal Data on behalf of Pluro.
10.3 A current list of relevant Subprocessors is available upon request by contacting it@pluro.ai.
10.4 Pluro will impose appropriate contractual data protection, confidentiality and security obligations on each relevant Subprocessor. Pluro will remain responsible for the performance of the Subprocessor’s obligations to the extent required by the GDPR.
10.5 Pluro may add or replace Subprocessors. Before a new Subprocessor begins Processing Customer Personal Data, Pluro will provide notice through a reasonable method or update its Subprocessor information. The Customer may raise a reasonable, documented objection based on data protection concerns, and the parties will work in good faith to identify a commercially reasonable solution.
11. International Data Transfers
11.1 Personal Data may be Processed in Israel, Germany and countries in which authorized Subprocessors operate, only as necessary to provide the Services.
11.2 Where a transfer of Personal Data subject to the GDPR requires a lawful transfer mechanism, the parties will rely on a valid adequacy decision of the European Commission or another appropriate safeguard under Chapter V of the GDPR, including applicable Standard Contractual Clauses approved by the European Commission, as appropriate.
11.3 Pluro will require relevant Subprocessors to maintain an appropriate lawful mechanism for international transfers where required by the GDPR.
12. Return and Deletion
12.1 Upon termination of the Agreement or a valid authorized request from the Customer, Pluro will delete or return, as applicable and in accordance with the capabilities of the Services and the Customer’s instructions, Personal Data Processed on behalf of the Customer, unless retention is required by law.
12.2 Personal Data may remain for a limited period in routine backups until the applicable backup cycle expires. During that period, it will remain protected and will not be used for ordinary Processing except where required for recovery, security or legal purposes.
13. Information and Audits
13.1 Upon reasonable request and subject to confidentiality, Pluro will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant certifications, security documentation or vendor questionnaire responses, subject to availability and appropriate internal approval.
13.2 If that information is insufficient and an additional audit is required under the GDPR, the Customer may request an audit on reasonable advance notice and at reasonable intervals. An audit must not compromise the security of Pluro, other customers, confidential information, trade secrets or ordinary business operations, and will generally be limited to once in any 12-month period.
13.3 Pluro may satisfy an audit request by providing an ISO/IEC 27001 certificate, a third-party audit report or summary, or other appropriate documentation. Any direct audit, where required, will be subject to a mutually agreed scope and will be conducted at the Customer’s expense, unless a material breach by Pluro reasonably requires a different arrangement.
14. Liability
Each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement. Nothing in this DPA limits liability that cannot lawfully be limited or excluded.
15. Term and Updates
15.1 This DPA becomes effective when the Agreement applies to the Customer and remains in effect for as long as Pluro Processes Personal Data on behalf of the Customer.
15.2 Pluro may update this DPA to reflect changes in applicable law, the Services, providers or security measures. Where an update materially affects the Processing of Personal Data of an active Customer, Pluro will provide reasonable advance notice where practicable.
15.3 Provisions relating to confidentiality, security, deletion, liability and data protection will survive termination to the extent required by their nature or applicable law.
16. Governing Law and Jurisdiction
The governing law and jurisdiction applicable to this DPA will be those specified in the Agreement, without prejudice to the rights of Data Subjects or the powers of competent Supervisory Authorities under the GDPR.
17. Contact
For questions, requests or notices regarding this DPA or the Processing of Personal Data on behalf of a Customer:
Pluro Ltd.
Israeli company no. 516155447
30A Dov Gruner Street
Tel Aviv-Yafo, Israel
Email: it@pluro.ai
Website: https://pluro.ai/