Privacy Policy
Last updated: Apr 24, 2026
This Privacy Policy describes how plnd, a California corporation (“plnd,” “we,” “our,” or “us”), collects, uses, discloses, and protects personal information in connection with the plnd platform, websites, mobile applications (including SiteOptix™), APIs, and related services (the “Service”). This Policy supplements and is incorporated into our Terms of Service.
1. Scope and Roles
This Policy applies to: (a) visitors to our public websites; (b) prospective customers and individuals who request information; and (c) authorized users of the Service (“Users”), including individuals working for our customer organizations (“Customers”).
1.1 Two Roles. Our role with respect to personal information differs depending on the context:
- As a Business / Controller.With respect to information about website visitors, prospects, and Users (e.g., name, email, role, login activity, payment information, marketing communications), we determine the purposes and means of processing and act as a “business” under the California Consumer Privacy Act, as amended (“CCPA”), and as a “controller” under the EU/UK General Data Protection Regulation (“GDPR”) to the extent it applies.
- As a Service Provider / Processor.With respect to data that Customers upload, generate, or store within the Service (“Customer Data”), we act as a “service provider” under the CCPA and a “processor” under the GDPR. The Customer is the business or controller and is responsible for the lawful basis for processing and for providing required notices and choices to data subjects. Our handling of Customer Data is governed primarily by our Terms of Service and any data processing addendum agreed with the Customer; this Policy describes our handling at a general level and does not modify those agreements.
1.2 Notice at Collection. Where required by applicable law, we present a short, just-in-time Notice at Collection at the point where personal information is collected (for example, at account signup, demo-request forms, the cookie consent interface, and the in-app permission prompts presented by the SiteOptix mobile application). Those notices identify the categories of personal information collected and the purposes of collection, and link to this Policy for the full disclosure.
2. Information We Collect
We collect the following categories of personal information, organized to correspond to the categories enumerated under California Civil Code § 1798.140:
- Identifiers. Name, email address, postal address, telephone number, employer, job title, account username, and IP address.
- Customer Records (Cal. Civ. Code § 1798.80(e)). Billing and payment information for paid accounts. We use third-party payment processors and do not store full payment card numbers.
- Commercial Information. Records of Subscription Plans, transactions, and usage of paid features.
- Internet or Network Activity Information. Browser and device type, operating system, pages viewed, referring URLs, search terms, login times, session duration, feature usage, error logs, and similar telemetry collected through cookies, log files, and SDKs.
- Geolocation Information.Approximate location derived from IP address for security and analytics. The SiteOptix™ mobile application may collect more precise device location only with the User’s permission and only for documented field-operations purposes.
- Audio, Visual, and Similar Information. Photographs and other media uploaded to the Service by Users, including site inspection photographs collected through SiteOptix™.
- Professional Information. Job role, organizational affiliation, and similar professional context.
- Inferences. Limited inferences derived from the foregoing to provide and improve the Service (e.g., relevance scoring, personalization of in-product content).
- Sensitive Personal Information.The CCPA classifies precise geolocation (location identifying a User within a radius of 1,850 feet or less) as Sensitive Personal Information. Where the SiteOptix mobile application collects precise device location with the User’s express permission, we treat that information as Sensitive Personal Information and use it solely to perform the field-operations functionality the User has requested (such as associating an inspection record, photograph, or measurement with a property location). We do not use Sensitive Personal Information to infer characteristics about any User, for advertising or profiling, or for any purpose for which California Civil Code § 1798.121 grants a right to limit. Other than precise geolocation collected through SiteOptix, we do not request or seek to collect Sensitive Personal Information; to the extent any such information is incidentally received as part of Customer Data, we process it only on the Customer’s documented instructions and do not use it for our own purposes.
Customer Data may include personal information about third parties (such as employees, contractors, vendors, and tenants) submitted by the Customer. We process such personal information solely on the Customer’s behalf in accordance with the Customer’s instructions and applicable agreements.
3. Sources of Information
We collect personal information from:
- Users directly when they create accounts, configure settings, upload data, or communicate with us;
- Customers when they enroll Authorized Users or upload Customer Data;
- automatic technologies (cookies, server logs, telemetry);
- third-party sources such as marketing data providers, identity verification providers, and our subprocessors; and
- public sources where relevant for due diligence or business research.
4. How We Use Information
We use personal information for the following purposes:
- Service Delivery. To register accounts; authenticate Users; provide, operate, secure, and maintain the Service; generate Generated Output requested by Customers; and enable governance features such as authorization gating, audit logging, and access revocation.
- Customer Support. To respond to inquiries, troubleshoot issues, and communicate Service announcements.
- Billing and Administration. To process subscriptions, invoices, payments, and refunds, and to manage business records.
- Service Improvement.To analyze usage patterns, diagnose errors, and improve the performance, accuracy, and usability of the Service. Where we improve AI Features using Customer Data, such improvement is logically scoped to the Customer’s tenant and does not benefit other customers’ models. See Section 5.
- Security and Fraud Prevention. To detect, prevent, and respond to fraud, unauthorized access, abuse, and security incidents; to enforce our Terms; and to comply with legal process.
- Marketing. To send communications about the Service, with opt-out available in each marketing message.
- Legal Compliance. To comply with applicable law, valid legal process, and regulatory obligations, and to establish, exercise, or defend legal claims.
- Aggregated and De-Identified Information. To create and use aggregated or de-identified information that does not identify any individual.
Legal Bases (GDPR/UK GDPR). Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (Service Delivery, Customer Support, Billing); legitimate interests (Service Improvement, Security, business operations, B2B marketing — balanced against data-subject rights); legal obligation (compliance, tax records, legal process); and consent (for cookies in jurisdictions that require consent and for direct marketing where required).
5. AI Processing; No Training on Customer Data for Third Parties
The Service uses AI models, including third-party large language models, retrieval systems, and machine learning components (collectively, “AI Features”), to assist Users in generating draft documents and other outputs.
- Stateless inference.Customer Data submitted to AI Features for processing is not retained by our model providers for training general-purpose models. We contractually require our model-provider Subprocessors to process Customer Data on a “zero-retention” or comparable basis to the extent such configuration is offered.
- No cross-customer training.We do not use Customer Data to train, fine-tune, or otherwise improve any AI model that is made available to other customers, prospects, or third parties. Improvements to a Customer’s tenant-specific configurations remain logically scoped to that Customer’s tenant.
- Aggregated analytics. We may use aggregated and de-identified usage information to evaluate Service quality and identify product improvement opportunities. This information does not identify any individual or Customer.
6. Cookies and Similar Technologies
We use cookies, pixels, local storage, SDKs, and similar technologies to: (a) operate the Service (essential cookies for authentication, session management, and security); (b) remember preferences; (c) measure usage and performance (analytics); and (d) deliver and measure marketing communications. Where required by applicable law, we present a consent mechanism for non-essential cookies. Most browsers allow Users to manage cookies through browser settings. Disabling essential cookies may impair Service functionality. We do not currently respond to “Do Not Track” browser signals; we honor recognized opt-out preference signals (e.g., Global Privacy Control) where required by law.
7. Disclosures of Information
We disclose personal information as follows:
- To Subprocessors. Cloud hosting, storage, computation, monitoring, customer support, payments, identity verification, AI inference, analytics, communications, and security providers, in each case under written terms requiring confidentiality and use limited to providing services to us.
- To Customers. Information about Authorized Users is disclosed to the Customer that authorized the User.
- Among Customer-Authorized Recipients. Customer Data and Generated Output are distributed only as directed by the Customer (e.g., to Third-Party Recipients selected by the Customer through the Service).
- For Legal Compliance. To comply with applicable law, court orders, lawful subpoenas, or governmental requests; to enforce our agreements; or to protect the rights, property, or safety of plnd, our Users, our Customers, or others.
- In Corporate Transactions. In connection with a merger, acquisition, financing, reorganization, or sale of assets, in each case under appropriate confidentiality protections.
- With Consent. Where the User or Customer has consented to or directed the disclosure.
8. No Sale or Sharing of Personal Information
We do not sell personal information for monetary or other valuable consideration as defined under the CCPA, and we do not “share” personal information for cross-context behavioral advertising as defined under the CCPA. We have not done so in the preceding twelve (12) months and have no current plans to do so.
9. International Data Transfers
We are based in the United States and process information in the United States. Our Subprocessors may be located in other countries. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on appropriate transfer mechanisms, such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, as applicable.
10. Data Security
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit (TLS 1.2 or later) and at rest using industry-standard protocols, role-based access controls, logical tenant isolation, audit logging, vulnerability management, and personnel security practices. No security measure is perfect, and we cannot guarantee absolute security. In the event of a confirmed Security Incident affecting Customer Data, we will notify the affected Customer without undue delay in accordance with our Terms of Service and any applicable data processing addendum.
11. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal, accounting, or reporting obligations, and to resolve disputes and enforce our agreements. Specifically:
- Account information is retained for the duration of the account relationship and for a limited period thereafter for business-record purposes.
- Customer Data is retained for the term of the applicable subscription and during the post-termination Export Window described in our Terms of Service. Following the Export Window, Customer Data is deleted from active systems, subject to backup-rotation schedules and legal hold requirements.
- Audit and provenance logs generated by the Service to evidence governance actions (e.g., authorization gating, denial events, access revocations) may be retained for a longer period to provide auditability and to defend against claims, and may be retained even after Customer Data deletion in a form that does not include the underlying substantive content.
- Marketing and prospect data is retained until the recipient unsubscribes or requests deletion.
- Logs and security records are retained for periods consistent with our security and audit programs.
12. Your Rights and Choices
Subject to applicable law and verification of identity, individuals may have the following rights:
- Access — to know what personal information we hold about you and to receive a copy in a portable format;
- Correction — to correct inaccurate personal information;
- Deletion — to request deletion of personal information, subject to exceptions (e.g., legal-hold, fraud-prevention, contract-performance);
- Opt-Out of Sale or Sharing — although we do not sell or share personal information as defined under the CCPA, we honor opt-out preference signals where required;
- Limit Use of Sensitive Personal Information— precise geolocation collected through SiteOptix is used solely to perform field-operations functionality requested by the User and is not used for inference, profiling, advertising, or other purposes that would trigger the right to limit under California Civil Code § 1798.121. Where applicable law nonetheless requires us to honor a request to limit, we will do so;
- Withdraw Consent — where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing;
- Lodge a Complaint — with the data protection authority in your jurisdiction; and
- Non-Discrimination — we will not discriminate against you for exercising any privacy right.
12.1 How to Exercise Your Rights. Submit requests to [email protected]. We will verify your identity using reasonable means before responding (e.g., by confirming control of the email address or account). For requests concerning Customer Data, please contact the Customer that controls that data; we will refer such requests to the appropriate Customer and assist as required by our agreement with that Customer.
12.2 Authorized Agents. California residents may use an authorized agent to submit requests, accompanied by appropriate proof of authorization.
12.3 Response Timing. We aim to respond within the time periods required by applicable law (typically 45 days under the CCPA, with one 45-day extension where reasonably necessary; one month under the GDPR, with extensions as permitted).
13. Customer Data: Roles and Responsibilities
Where personal information is included in Customer Data, the Customer determines the purposes and means of processing and is responsible for: (a) providing required privacy notices to and obtaining required consents from data subjects; (b) honoring data-subject rights requests; (c) instructing us regarding processing through configuration and use of the Service; and (d) ensuring that the Customer’s collection, use, and sharing of personal information complies with applicable law. We process Customer Data on the Customer’s behalf as a service provider/processor in accordance with our Terms of Service and any data processing addendum.
14. Children’s Privacy
The Service is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from individuals under 13 (or under 16 in jurisdictions where that is the applicable age threshold). If you believe we have inadvertently collected such information, please contact [email protected] and we will delete it.
15. Third-Party Sites and Services
The Service may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing personal information.
16. Changes to This Policy
We may update this Policy from time to time. We will post any updated version with a new “Last Updated” date. Where required by applicable law, we will provide additional notice (e.g., by email or through the Service) for material changes. Continued use of the Service after the effective date of an update constitutes acknowledgment of the revised Policy.
17. How to Contact Us
For privacy questions, concerns, or rights requests:
- Email: [email protected]
- Postal address: available upon request to the email above
- For Customer Data inquiries, please contact the relevant Customer; we will assist as required by our agreement with that Customer.
If you are in the European Economic Area, the United Kingdom, or Switzerland and have a concern that we have not addressed satisfactorily, you may contact the supervisory authority in your jurisdiction.