Skip to content
Plepto Back to plepto.com

Legal/Privacy Policy

Privacy Policy

Last updated 26 September 2026

This policy explains how Plepto collects and uses personal data: when you visit plepto.com, join our early-access list, chat with us, or use Plepto as a customer. It also explains the cookies we use, and your rights.

On this page

  1. Who we are
  2. What this policy covers
  3. Visitors, early access and chat
  4. Customers and account users
  5. People our customers contact
  6. How Plepto learns
  7. Who we share data with
  8. International transfers
  9. How long we keep data
  10. Your rights
  11. Cookies
  12. Security
  13. Children
  14. Changes to this policy
  15. Contact us

Who we are

Plepto is a trading name of Synoet Group Ltd, a company registered in England and Wales (company number 16433412), with its registered office at 82 James Carter Road, Suite A, Mildenhall, IP28 7DE, United Kingdom. In this policy, "we", "us" and "our" mean Synoet Group Ltd.

We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC001940. For any question about this policy or your personal data, email privacy@plepto.com.

What this policy covers

We handle personal data in two different roles:

  • As a controller, we decide how data about our website visitors, early-access sign-ups and customers' account users is used. This policy explains that use.
  • As a processor, we handle the data our customers put into Plepto, such as the details of the people they want to contact, on their behalf and under their instructions. Our Data Processing Agreement governs that use, and each customer is responsible for it. See People our customers contact.

We're also a controller when we create aggregated, de-identified insights to improve Plepto. See How Plepto learns.

Visitors, early access and chat

WhenWhat we collectWhyLegal basis
You join the early-access listYour work email address and the date you signed upTo email you when early access opens and about your access to PleptoYour consent. You can withdraw it at any time by unsubscribing.
You chat with usThe messages you send, and any name or email address you give usTo answer your questions and follow up if you ask us toOur legitimate interest in answering questions about Plepto, or steps you ask us to take before becoming a customer
You email usYour email address, the content of your email and any details you includeTo reply and keep a record of our conversationOur legitimate interest in responding to you, or a contract with you where one applies
You allow analytics cookiesWhich pages you visit, how you arrived, your device and browser type, and your approximate locationTo understand how the site is used and improve itYour consent, given through our cookie banner. You can change it at any time.
You visit the siteTechnical data our hosting provider records, such as your IP address, browser and the pages requestedTo deliver the site, keep it secure and protect it from abuseOur legitimate interest in running a secure website

Our chat may first be answered by an AI assistant, which says so at the start of the conversation and answers from our published help articles and website. You can ask to talk to a person at any time. We don't make decisions about anyone based solely on automated processing that have legal or similarly significant effects. Learn more in Cookies below.

Customers and account users

Plepto is for business use. When you or your organisation use Plepto, we collect:

What we collectWhyLegal basis
Account details: your name, work email, company, role and login detailsTo create and manage your account and let you sign in securelyPerforming our contract with you or your organisation
Billing details: plan, invoices and payment status. Card details are handled by our payment provider, Stripe, and never stored by usTo take payment, send invoices and keep financial recordsPerforming our contract, and our legal obligation to keep accounting records
Connected mailboxes: the email accounts you connect to send campaigns, and the access needed to send and read repliesTo send the campaigns you approve and show replies in your Unified InboxPerforming our contract
Usage data: how you use Plepto, such as the features used, settings and errorsTo run, secure, support and improve PleptoOur legitimate interest in providing and improving a reliable service
Support messages: what you send us through chat or emailTo help you and improve our supportPerforming our contract, and our legitimate interest in helping customers
Service emails: messages about your account, security, billing and important changesTo keep you informed about your servicePerforming our contract

We may also email account users about new features and offers, based on our legitimate interest in keeping customers informed, or your consent where the law requires it. You can opt out at any time with the link in those emails.

Google user data

When you connect a Google account, such as Gmail, we access only what Plepto needs to send the campaigns you approve and show replies in your Unified Inbox. Plepto's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google user data for advertising, we don't sell it, and we don't use it to develop, improve or train generalised AI or machine learning models.

People our customers contact

Our customers use Plepto to research and email people they want to do business with. For that data, the customer is the controller and decides who to contact and why. We process it only to provide Plepto to that customer, under our Data Processing Agreement.

If you received an email sent through Plepto, please contact the sender to exercise your rights, for example to stop further emails. You can also email us at privacy@plepto.com, and we'll pass your request to the right customer and help them respond.

How Plepto learns

Plepto learns from each customer's own campaigns, such as their edits, replies and results, to improve that customer's future campaigns.

To improve Plepto for all customers, we may also create aggregated, de-identified insights, such as which types of angles get replies from which types of roles and industries. These insights don't include names, contact details, company names or the content of emails, and can't be used to identify a customer or any person. We create them based on our legitimate interest in improving Plepto, in a way that removes anything that could identify someone, and we may use them to improve Plepto, including our models. Data we receive through Google APIs, for example from a connected Gmail account, is never used to create these insights or to develop, improve or train AI models, other than for features in the customer's own account.

We never use customers' content or the personal data of the people they contact to train AI models, and we use AI providers under terms that don't allow them to use it to train their own models.

Who we share data with

We never sell personal data. We use trusted service providers who process personal data for us, under contract and only on our instructions. They include:

  • Hosting and infrastructure providers, which run our website, app and databases,
  • AI model providers, which help Plepto research, plan and write,
  • Data enrichment providers, which supply company and professional information our customers ask for,
  • Email service providers, which deliver our early-access and service emails,
  • Customer support tools, which run our chat and help centre,
  • Analytics providers, which measure how our website is used, only with consent, and
  • Our payment provider, Stripe, which processes payments.

We may also share personal data with our professional advisers, with authorities when the law requires it, or with a buyer or successor if our business is sold or reorganised, in which case this policy continues to apply to your data.

International transfers

Some of our providers may process personal data outside the UK and the European Economic Area, for example in the United States. When they do, the transfer is protected by the safeguards UK and EU data protection law require, such as adequacy regulations or decisions, the UK International Data Transfer Agreement, or standard contractual clauses with the UK Addendum.

How long we keep data

  • Early-access list: until you unsubscribe or ask us to delete your email, and no longer than 12 months after Plepto opens to everyone, unless you create an account.
  • Account data: while your account is open. When it closes, you have 30 days to reactivate it or export your data, and we then delete it within 90 days of closure, including from backups.
  • Billing records: for 6 years after the end of the financial year they relate to, as UK tax rules require.
  • Chats and emails: up to 2 years after our last exchange, unless we need them longer for a contract or legal reason.
  • Analytics data: for the period set in our analytics account, and never longer than 14 months.
  • Hosting logs: for the limited period our hosting provider keeps them for security.

Your rights

Under UK and EU data protection law, you have the right to:

  • access the personal data we hold about you,
  • have inaccurate data corrected,
  • have your data deleted,
  • restrict or object to how we use it, including for direct marketing,
  • receive your data in a portable format, and
  • withdraw your consent at any time, without affecting what we did before you withdrew it.

To use any of these rights, email privacy@plepto.com. We'll reply within one month. If a request is complex, we may need up to two more months, and we'll tell you if so. You don't have to give us personal data to browse our website, but we need your email to add you to our early-access list or reply to you, and account details to provide Plepto.

If you're unhappy with how we handle your data, you can complain to us at privacy@plepto.com. We'll acknowledge your complaint within 30 days, look into it without undue delay, keep you informed, and tell you the outcome. You can also complain to the UK Information Commissioner's Office at ico.org.uk or on 0303 123 1113, or to the data protection authority in the country where you live.

Cookies

Cookies are small files a website stores in your browser. Similar technologies, such as your browser's local storage, work in the same way, and "cookies" here covers both. On our website, we only use cookies that aren't strictly necessary when you allow them.

On our website

Necessary

These make the site work and can't be switched off.

NameProviderPurposeKept for
plepto-consent (local storage)PleptoRemembers your cookie choicesUntil you clear your browser storage
Security cookieOur hosting providerMay be set when the site checks for automated traffic, to protect itA short session

Analytics

These only run if you choose Accept all, or switch on Analytics in Cookie settings.

NameProviderPurposeKept for
_gaGoogle AnalyticsTells visits by different people apart2 years
_ga_<ID>Google AnalyticsKeeps track of your current visit2 years

Chat

Our chat only loads when you click Chat with us. Zendesk then stores identifiers in your browser so your conversation continues as you move between pages. Because you asked for the chat, these are necessary for it to work. See Zendesk's in-product cookie policy for details.

In the Plepto app

When you sign in to Plepto, we use strictly necessary cookies and local storage to keep you signed in, protect your account from misuse, and remember your settings. The app doesn't need your consent for these, because it can't work without them. We don't use advertising cookies in the app.

What we don't use

We don't use advertising cookies, and our early-access form doesn't set any cookies.

Your choices

On our website, you can accept all cookies, reject non-essential ones, or choose by category. You can change your choice at any time with , also at the bottom of every page. If you switch analytics off, we remove Google Analytics cookies from your browser.

You can also block or delete cookies in your browser settings. Blocking necessary cookies may stop parts of the site or app from working.

Security

We protect personal data with appropriate technical and organisational measures, including encrypted connections (HTTPS), encryption of our databases at rest, separation of each customer's data, and access limited to authorised team members. When you connect a mailbox with an app password or SMTP details, we store those credentials encrypted. When a mailbox connects through the provider's official sign-in (OAuth), we never see or store its password. No system is perfectly secure, but we work to keep data safe and will act promptly if something goes wrong.

Children

Plepto is a business service. It isn't intended for children, and we don't knowingly collect personal data from anyone under 18.

Changes to this policy

We'll update this policy when our services or the law change, and show the date of the latest version at the top. If a change significantly affects how we use your data, we'll tell you by email or in Plepto.

Contact us

The quickest way to reach us about privacy is by email at privacy@plepto.com.

Our registered office is Synoet Group Ltd, 82 James Carter Road, Suite A, Mildenhall, IP28 7DE, United Kingdom.

Plepto

© 2026 Plepto

LinkedIn contact@plepto.com
Privacy Terms DPA