Last Updated: August 26, 2026

Our Commitment

Pluro is committed to processing personal data in accordance with the
applicable requirements of the General Data Protection Regulation (GDPR)
and to supporting customers in meeting their applicable data protection
obligations.

We apply privacy and security controls designed to protect personal data,
limit processing to defined purposes, and provide individuals and customers
with appropriate transparency and control.

Measures We Maintain

Our GDPR-related privacy and security measures include:

  • Processing personal data only for specified, legitimate, and documented purposes.
  • Applying data minimization and limiting processing to the information
    necessary to provide, operate, secure, and support the Services.
  • Maintaining role-based access controls and logical separation between
    Customer accounts.
  • Protecting access to Customer information through authentication,
    confidentiality obligations, and restricted administrative access.
  • Maintaining information security controls under Pluro’s ISO/IEC 27001
    information security framework.
  • Using appropriate contractual, organizational, and technical safeguards
    with relevant service providers and Subprocessors.
  • Applying appropriate legal and contractual safeguards to international
    data transfers where required.
  • Supporting valid requests to access, correct, update, restrict, or delete
    personal data.
  • Retaining personal data only for as long as necessary for the applicable
    processing purpose, legal obligation, or contractual requirement.
  • Maintaining documented procedures for identifying, managing, and
    responding to information security incidents and Personal Data Breaches.

Customer Data

Customers retain legal ownership of their data. Pluro does not claim
ownership of Customer Data and processes it only to provide, operate,
secure, maintain, and support the agreed Services.

Where Pluro processes Personal Data on behalf of a business Customer,
processing is performed according to the Customer’s documented instructions,
the agreed scope of Services, applicable contractual terms, and applicable
data protection requirements.

Pluro does not sell Personal Data and does not use Customer Data for unrelated
marketing or advertising purposes without authorization.

Additional terms governing Pluro’s processing of Personal Data on behalf of
Customers are available in our
Data Processing Addendum (DPA).

Artificial Intelligence

Pluro may use supported third-party artificial intelligence services,
including OpenAI GPT, Google Gemini, and Anthropic Claude, to assist with
accessibility analysis and remediation recommendations when an AI-assisted
feature is activated by a Customer or Authorized User.

Pluro does not train, fine-tune, or host its own foundation models and does
not use Customer Data to train or fine-tune AI models.

AI processing is limited to the technical accessibility context required for
the requested action. Information provided to an AI provider may include a
DOM structure or relevant portions of accessibility scan results, as well as
a question or instruction voluntarily entered by the user in an AI-assisted
chat. Public webpage content contained in a DOM may incidentally include
Personal Data.

The Services are not designed to submit passwords, payment information,
information from private forms, or unrelated Personal Data to AI providers.
Pluro does not automatically submit chat questions on behalf of users.

Customer prompts submitted through the AI-assisted chat are not stored by Pluro.

Data Location and International Transfers

Pluro’s primary service infrastructure is hosted through Amazon Web Services
(AWS) in Germany. Pluro also uses Amazon CloudFront for content delivery and
service traffic.

Personal Data may be processed in Israel, Germany, and countries in which
authorized service providers or Subprocessors operate, only as necessary to
provide the Services.

Where a transfer of Personal Data requires a lawful transfer mechanism,
Pluro relies on an applicable adequacy decision or another appropriate
safeguard under applicable data protection law, including applicable
Standard Contractual Clauses where required.

Data Subject Rights

Subject to applicable law, individuals may have the right to:

  • Request information about how their Personal Data is processed;
  • Access Personal Data held about them;
  • Correct inaccurate or incomplete Personal Data;
  • Request deletion of Personal Data;
  • Restrict or object to certain processing activities;
  • Withdraw consent where processing is based on consent;
  • Request data portability where applicable; and
  • Submit a complaint to an applicable Supervisory Authority.

To submit a privacy request, contact
it@pluro.ai.

Where Pluro processes Personal Data on behalf of a Customer, Pluro will
provide reasonable assistance to that Customer in responding to valid Data
Subject requests relating to data processed through the Services.

Security and Incident Response

Pluro maintains technical and organizational measures designed to protect
Personal Data against unauthorized access, use, alteration, disclosure,
loss, or destruction.

Pluro also maintains documented incident response procedures as part of its
ISO/IEC 27001 information security management framework.

Where a Personal Data Breach affects Customer Personal Data, Pluro will
notify the affected Customer without undue delay and in accordance with
applicable legal and contractual requirements. Additional information may
be provided in phases as it becomes available during the investigation.

Related Privacy Documents

Notice to EU Residents

EU residents who wish to exercise their rights under the GDPR should review
our Privacy Policy and contact us at
it@pluro.ai.

Where the appointment of an EU representative is legally required based on
Pluro’s processing activities, Pluro will appoint such a representative and
publish the relevant contact details.

Regulatory Monitoring and Updates

Pluro monitors relevant guidance and developments issued by data protection
authorities and other regulatory bodies.

We may update our privacy, security, contractual, and operational practices
where necessary to reflect changes in applicable law, regulatory guidance,
technology, or the Services we provide.

Contact Us

For questions regarding this GDPR Commitment, Pluro’s privacy practices, or
the processing of Personal Data, contact:

Pluro Ltd.
Israeli company no. 516155447
30A Dov Gruner Street
Tel Aviv-Yafo, Israel
Email: it@pluro.ai
Website: https://pluro.ai/