1. Who we are
Plott (“we”, “us”) operates the Plott SaaS platform at plott.uk. We are the “controller” for the personal data we process about our customers and their colleagues. Customers (typically construction, architecture, planning or property firms) are the controller for any personal data they upload and for their own outreach communications.
2. What personal data we process
- Account data: name, work email, role, company name, and identifiers required to sign you in securely.
- Billing data: records needed to manage your subscription, tax and billing status, and billing address. Payment card details are processed only by our payment provider; we do not store your full card number.
- Product usage: information about how you use the service, content you create, and operational records needed to run the product and keep it safe.
- Uploaded assets: company logos, signatures, and documents you add to the service.
- Third-party data about property and planning: information from public registers and our data partners where needed to provide the product.
3. Lawful bases (UK GDPR Art.6)
- Contract — for operating your account and providing the service you subscribe to.
- Legitimate interests — for security, anti-abuse, analytics, and product improvement.
- Legal obligation — for statutory accounting, anti-money-laundering and tax records.
- Consent — for optional analytics cookies and marketing emails, where applicable.
4. Sub-processors
We use vetted service providers to host the platform, store data, authenticate users, process payments, send email, and perform similar functions. We do not publish vendor names on the public website; the current register is provided to customers under contract (and on request for diligence). See /legal/subprocessors for how we provide this information, and we notify customers of material changes in line with our agreements and applicable law.
5. Data retention
- Account + product data: retained while your subscription is active, and up to 90 days after cancellation to handle reactivation and statutory obligations.
- Data we obtain from third parties to provide the product: kept only as long as needed for the service and our records obligations.
- Billing records: retained for 7 years as required by UK tax law.
- Operational and security records: retained for a defined period, then deleted or anonymised where we no longer need them.
6. International transfers
Primary data storage is in the EEA / UK. Where personal data is transferred outside the UK, we use transfer mechanisms and safeguards recognised under UK GDPR (for example, the UK Addendum to the EU standard contractual clauses) where required.
7. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict processing, portability, and to object to processing. Email us at privacy@plott.uk. We respond within 30 days. You can also complain to the UK Information Commissioner's Office at ico.org.uk.
8. Security
We encrypt data in transit and at rest, apply access controls across our systems, and protect accounts and data in line with good industry practice. Further detail is available to customers under contract.
9. Contact
Plott Ltd, registered in England & Wales. Privacy enquiries: privacy@plott.uk.
