Skip to content
Plepto Back to plepto.com

Legal/Data Processing Agreement

Data Processing Agreement

Last updated 26 September 2026

This Data Processing Agreement ("DPA") explains how we handle the personal data you put into Plepto. It forms part of our Terms of Service and applies automatically, without a signature, whenever we process personal data on your behalf.

On this page

  1. Scope and roles
  2. Processing on your instructions
  3. Aggregated insights
  4. Our personnel
  5. Security
  6. Subprocessors
  7. International transfers
  8. Helping you meet your obligations
  9. Personal data breaches
  10. Deletion and return
  11. Information and audits
  12. Your responsibilities
  13. General
  14. Annex 1: Details of processing
  15. Annex 2: Security measures
  16. Annex 3: Subprocessors

1. Scope and roles

This DPA is between you, the customer, and Synoet Group Ltd, trading as Plepto. It applies to personal data we process on your behalf to provide Plepto ("customer personal data"), such as the details of the people you research and contact, and the emails and replies in your campaigns.

For customer personal data, you are the controller and we are your processor, under the UK GDPR, the Data Protection Act 2018 and, where it applies, the EU GDPR ("data protection law"). Details of the processing are in Annex 1.

2. Processing on your instructions

We process customer personal data only on your documented instructions, which are our Terms of Service, this DPA and how you use and configure Plepto. If the law requires us to process customer personal data in another way, we'll tell you before we do, unless the law forbids it. If we think an instruction breaks data protection law, we'll tell you.

3. Aggregated insights

You authorise us to create aggregated, de-identified insights from how Plepto is used, such as which types of angles get replies from which types of roles and industries, and to use them to improve Plepto for all customers, including our models. These insights never include names, contact details, company names or the content of emails, and can't identify you, your company or any person. We act as a controller when we create these insights, as our Privacy Policy explains, and once created they're no longer personal data. Data we receive through Google APIs is never used to create these insights, or to develop, improve or train AI models other than for features in your own account, in line with the Google API Services User Data Policy.

We never use customer personal data or your content to train AI models, and we use AI providers under terms that don't allow them to use it to train their own models.

4. Our personnel

Only authorised team members who need access to provide or support Plepto can access customer personal data, and they're bound by confidentiality.

5. Security

We implement appropriate technical and organisational measures to protect customer personal data, as required by Article 32 of the UK GDPR and EU GDPR. They're described in Annex 2, and we may update them as long as the level of protection doesn't decrease.

6. Subprocessors

  • You give us general authorisation to use subprocessors in the categories listed in Annex 3. We'll give you the names and locations of our current subprocessors on request.
  • We'll tell you by email at least 30 days before adding or replacing a subprocessor. If you object on reasonable data protection grounds, we'll work with you to find a solution. If we can't, you may close your account and we'll refund any prepaid fees for the unused period.
  • We put a written contract in place with each subprocessor, with data protection obligations at least as protective as this DPA, and we remain responsible for their performance.

7. International transfers

We are based in the UK, which the EU recognises as providing adequate data protection. When we or our subprocessors transfer customer personal data outside the UK or the European Economic Area, we make sure the transfer is protected by a safeguard that data protection law recognises, such as adequacy regulations or decisions, the UK International Data Transfer Agreement, or the EU standard contractual clauses with the UK Addendum.

8. Helping you meet your obligations

Taking into account the nature of the processing, we'll help you:

  • respond to requests from people exercising their rights. If we receive a request about your data, we'll pass it to you and won't respond ourselves unless you ask us to,
  • carry out data protection impact assessments and consult regulators where needed, and
  • meet your security and breach notification obligations.

9. Personal data breaches

If we become aware of a personal data breach affecting customer personal data, we'll notify you without undue delay, and where possible within 48 hours. We'll give you the information we have to help you meet your own obligations, and take reasonable steps to contain the breach and reduce its effects.

10. Deletion and return

You can export your data while your account is active, and for 30 days after it closes. We then delete customer personal data within 90 days of closure, including from backups, unless the law requires us to keep it.

11. Information and audits

We'll make available the information reasonably needed to show that we meet this DPA, and answer reasonable security and data protection questionnaires. If that isn't enough, you may audit our compliance once a year, on at least 30 days' written notice, during business hours, under confidentiality and at your cost, in a way that doesn't disrupt our business or other customers' data.

12. Your responsibilities

  • You're responsible for having a lawful basis for the processing, and for giving the people you contact any information the law requires.
  • Your instructions to us must follow data protection law.
  • Don't put special category data, such as health, political or religious information, or data about children, into Plepto.

13. General

If this DPA and the Terms of Service conflict about personal data, this DPA applies. The liability limits in the Terms of Service apply to this DPA. This DPA is governed by the law of England and Wales. Questions about this DPA: privacy@plepto.com.

Annex 1: Details of processing

ItemDetails
Subject matter and durationProviding Plepto to you, for as long as your account is open, plus the export and deletion period in section 10
Nature and purposeStoring, researching, enriching, analysing and organising the people and companies you want to contact; planning campaigns; generating, sending and tracking the emails you approve; showing replies and suggesting responses; and creating aggregated, de-identified insights under section 3
People concernedThe people you research and contact (your prospects and business contacts), and the users of your account
Types of personal dataNames, business email addresses, job titles and roles, employer and company information, professional profile information, publicly available business signals, the content of emails and replies, and campaign activity such as sends, replies and opt-outs
Special category dataNone. You must not provide it.

Annex 2: Security measures

  • Encryption in transit: all connections to Plepto use HTTPS.
  • Encryption at rest: our databases are encrypted.
  • Separation: each customer's data is kept separate, with access controls that stop one customer from seeing another's data.
  • Access control: only authorised team members who need it can access production data.
  • Mailbox connections: When you connect a mailbox with an app password or SMTP details, we store those credentials encrypted. When a mailbox connects through the provider's official sign-in (OAuth), we never see or store its password.
  • Subprocessors: chosen for their security and bound by written data protection terms.

Annex 3: Subprocessors

We use subprocessors in these categories. The names and locations of our current subprocessors are available on request at privacy@plepto.com.

CategoryWhat they do
Hosting and infrastructureRun Plepto and store its data
AI model providersHelp Plepto research, plan, write and classify replies
Data enrichment providersSupply company and professional information you ask for
Email deliverySend service emails such as sign-in and account messages
Customer supportHandle support conversations
MonitoringHelp us detect errors and keep Plepto reliable
Plepto

© 2026 Plepto

LinkedIn contact@plepto.com
Privacy Terms DPA