Plainco
Privacy Policy
Last updated: 9 October 2026
Translation of the Spanish original. If there is any difference, the Spanish version prevails.
1. Who the controller is
Plainco (“Plainco”, “we”) offers a platform to understand, sign and keep track of contracts. This policy explains what personal data we process, why, and what rights you have.
The controller of your account data is:
- Contact
- hello@plainco.io
2. What data we process
- Account and organisation data: name, email, company name and role within the organisation.
- Contract data: the documents you upload and the data we extract from them (parties, amounts, dates, obligations and risks). If you are an accounting firm or manage properties, this may include data about the buildings, communities or businesses you manage.
- Signature data: if you send or receive a contract for signature, each signer’s name and email, the signature, the date and time, and technical details of the device (browser). These are used to generate a signature certificate that accompanies the document.
- Payment data: billing name and subscription details. Card details are handled directly by Stripe: we never see or store them.
- Usage data: technical logs needed to run the platform and keep it secure (for example, sign-ins and errors).
- Support access data: if you give our support team temporary access, we log what was viewed, by whom and when. You can ask us for that log.
3. Why we process it and on what legal basis
- To provide the service (analyse, store and manage your contracts): performance of our contract with you.
- To charge for and manage your subscription: performance of our contract with you.
- To send service emails (invitations, alerts, signing codes, receipts): performance of our contract with you.
- To detect and prevent fraud or abuse and keep the platform secure: our legitimate interest.
- To improve the product from aggregated usage patterns that do not identify you: our legitimate interest.
- Anything you expressly authorise (for example, support access to your account): your consent, which you can withdraw at any time.
4. Automated analysis (AI)
When you upload a contract, its text is processed with OpenAI so that an AI model can read it and extract structured information (parties, amounts, dates, obligations and risks). OpenAI processes it on our behalf, with GDPR safeguards and without using it to train its models.
It is an automated process: nobody reviews every extraction, but you can view, edit or correct any data point, and the original document is never altered. The result is for guidance only and makes no decisions with legal effects on you.
5. Who we share data with (subprocessors)
We work with a small number of providers, who act on our instructions and only for the purpose stated:
- Supabase, on AWS in Frankfurt (Germany): database, document storage and sign-in.
- Fly.io, in Paris (France): servers that run the web application.
- OpenAI (USA): processes contract text for the AI analysis.
- Resend (USA): sends service emails.
- Mailgun (EU): receives the contracts you email to your Plainco inbound address, if you use that feature.
- Stripe (Ireland and USA): handles payments and billing.
If you connect an integration, such as Holded, we exchange with that account the data needed to keep it in sync.
We do not sell your personal data to anyone.
6. International transfers
Your data and documents are stored in the EU (Frankfurt). Some providers, such as OpenAI, Resend and Stripe, may process data in the USA. In those cases the transfer relies on GDPR safeguards: the EU-US Data Privacy Framework where the provider is certified under it and, in any case, the European Commission’s Standard Contractual Clauses.
7. How long we keep it
For as long as your account is active. When you close it, we keep contracts and signature records only for as long as the law requires or as needed to handle claims (for example, about a signed contract). After that, they are deleted or anonymised.
8. Your rights
You can access, rectify or erase your data, restrict or object to its processing, and ask for a copy to take with you (portability). To exercise any of these rights, write to us at hello@plainco.io.
If you believe we have not respected your rights, you can complain to the Spanish Data Protection Agency (www.aepd.es).
9. Security
We apply technical and organisational measures appropriate to the sensitivity of the data: encrypted connections, encryption at rest, access control per organisation and a log of any staff access to customer data (see “Support access data”).
11. Minors
Plainco is a service for businesses and professionals. It is not directed at anyone under 18.
12. Changes to this policy
If we make significant changes, we will let you know in the platform or by email before they apply. For any question about this policy: hello@plainco.io.
