Last Updated: July 20, 2026
Our Commitment
Pluro is committed to processing personal data in accordance with the
applicable requirements of the General Data Protection Regulation (GDPR)
and to supporting customers in meeting their applicable data protection
obligations.
We apply privacy and security controls designed to protect personal data,
limit processing to defined purposes, and provide individuals and customers
with appropriate transparency and control.
Measures We Maintain
Our GDPR-related privacy and security measures include:
-
Processing personal data only for specified, legitimate, and documented
purposes. -
Applying data minimization and limiting processing to the information
necessary to provide, operate, secure, and support the service. -
Maintaining role-based access controls and logical separation between
customer accounts. -
Protecting access to customer information through authentication,
confidentiality obligations, and restricted administrative access. -
Maintaining information security controls under Pluro’s ISO/IEC 27001
information security framework. -
Using appropriate contractual, organizational, and technical safeguards
with relevant service providers and subcontractors. -
Applying appropriate legal and contractual safeguards to international
data transfers where required. -
Supporting valid requests to access, correct, update, restrict, or delete
personal data. -
Retaining personal data only for as long as necessary for the applicable
processing purpose, legal obligation, or contractual requirement. -
Maintaining documented procedures for identifying, managing, and
responding to information security incidents and personal data breaches.
Customer Data
Customers retain legal ownership of their data. Pluro does not claim
ownership of customer data and processes it only to provide, operate,
secure, maintain, and support the agreed services.
Where Pluro processes personal data on behalf of a business customer,
processing is performed according to the customer’s documented instructions,
the agreed scope of services, applicable contractual terms, and applicable
data protection requirements.
Pluro does not sell personal data and does not use customer data for unrelated
marketing or advertising purposes without authorization.
Artificial Intelligence
Pluro may use third-party artificial intelligence services, including
OpenAI GPT, Google Gemini, and Anthropic Claude, to assist with accessibility
analysis and remediation recommendations.
Pluro does not train, fine-tune, or host its own foundation models and does
not use customer data to train or fine-tune AI models.
AI requests are generated through controlled accessibility workflows and are
limited to the technical context required for the relevant analysis. Pluro
does not intentionally submit personal data, passwords, payment information,
or unrelated customer information to AI providers.
Customer prompts are not stored by Pluro.
Data Location and International Transfers
Pluro’s primary service infrastructure is hosted on Amazon Web Services
(AWS) in Germany.
Where personal data is processed outside the European Economic Area or outside
the individual’s country of residence, Pluro applies appropriate safeguards
where required by applicable law.
Such safeguards may include applicable data processing terms, contractual
confidentiality obligations, access restrictions, encrypted transmission,
and protections provided by the relevant service provider.
Data Subject Rights
Subject to applicable law, individuals may have the right to:
- Request information about how their personal data is processed;
- Access personal data held about them;
- Correct inaccurate or incomplete personal data;
- Request deletion of personal data;
- Restrict or object to certain processing activities;
- Withdraw consent where processing is based on consent;
- Request data portability where applicable;
- Submit a complaint to an applicable supervisory authority.
To submit a privacy request, contact
info@pluro.ai.
Where Pluro processes personal data on behalf of a customer, Pluro will
provide reasonable assistance to that customer in responding to valid data
subject requests relating to data processed through the service.
Security and Incident Response
Pluro maintains technical and organizational measures designed to protect
personal data against unauthorized access, use, alteration, disclosure,
loss, or destruction.
Pluro also maintains documented incident response procedures as part of its
ISO/IEC 27001 information security management framework.
Where a confirmed personal data security incident affects customer data,
Pluro will notify the affected customer without undue delay and in accordance
with applicable legal and contractual requirements.
Notice to EU Residents
EU residents who wish to exercise their rights under the GDPR should review
our
Privacy Policy
and contact us at
info@pluro.ai.
Where the appointment of an EU representative is legally required based on
Pluro’s processing activities, Pluro will appoint such a representative and
publish the relevant contact details.
Regulatory Monitoring and Updates
Pluro monitors relevant guidance and developments issued by data protection
authorities and other regulatory bodies.
We may update our privacy, security, contractual, and operational practices
where necessary to reflect changes in applicable law, regulatory guidance,
technology, or the services we provide.
Contact Us
For questions regarding this GDPR Commitment or Pluro’s privacy practices,
contact:
Pluro
Email:
info@pluro.ai
Website:
https://pluro.ai/