PLENIVO

Privacy Policy

Version 2.0 — 28 July 2026

1. Who we are and our role

Plenivo (Dutch Chamber of Commerce 42027446, based in the Netherlands) provides workforce planning software for technical service companies. For data that client organisations (“tenants”) enter into the platform — such as employees, schedules and work orders — the client organisation is the data controller and Plenivo is the processor under the GDPR. For data you provide to us directly (e.g. via the demo form or email), Plenivo is the controller. We conclude a data processing agreement with every client organisation.

2. What data we process

Within the platform, on behalf of the client organisation: employees’ name, email address, phone number and role; username and encrypted password (bcrypt); planning, project, work order and hours data; photos, materials and digital signatures added by technicians; GPS location at departure/arrival (only if the client organisation has activated this module); login history (time and IP address) and technical logs. Via the website: the details you submit in the contact/demo form (name, company, email, phone, message).

3. Purposes and legal basis

We process platform data solely to deliver the service: showing schedules, generating work orders and invoices, producing reports and providing support (legal basis: performance of the contract with the client organisation). Form data is used to contact you (legal basis: legitimate interest / pre-contractual phase). We never use personal data for advertising and never sell it to third parties.

4. Sub-processors and recipients

We use a limited number of sub-processors: EU-based hosting providers (servers in Germany), a DNS/CDN provider and an email service for system mail (quotes, invoices, notifications). If the client organisation activates an accounting integration (such as Moneybird, e-Boekhouden.nl, SnelStart or AFAS), invoice and contact data is transferred to that service at the client organisation’s initiative. We conclude processing agreements with sub-processors; a current list is available via admin@plenivo.nl.

5. Transfers outside the EEA

Personal data is stored on servers within the European Economic Area. No structural transfers to countries outside the EEA take place. Should this become necessary for a specific service, it will only happen with appropriate safeguards (such as EU Standard Contractual Clauses).

6. Retention periods

We retain platform data for the duration of the client agreement. After termination, all tenant data is deleted within 30 days, unless the client organisation requests earlier deletion or export. Backups are overwritten after at most 30 additional days. Form data is kept for a maximum of 12 months after the last contact. Statutory retention obligations (such as tax retention periods for invoices) may require longer periods.

7. Security

We take appropriate technical and organisational measures: TLS encryption (HTTPS) for all traffic, passwords stored hashed only (bcrypt), two-factor authentication (2FA) available for all accounts, role-based access control per tenant, strict separation between client environments, daily encrypted backups, DKIM/DMARC-secured email and continuous monitoring. Access to production data is limited to authorised staff and is logged.

8. Cookies and local storage

The marketing website uses no tracking or advertising cookies and no third-party analytics. The application only uses functional storage (such as a session token and interface preferences in localStorage) necessary to keep you logged in and remember your settings.

9. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection. If you work for an organisation that uses Plenivo, please address your request first to your organisation’s administrator (the controller); we support that handling. You can also reach us directly at admin@plenivo.nl. We respond within 30 days. You also have the right to lodge a complaint with your data protection authority.

10. Data breaches

In the event of a personal data breach, we inform the affected client organisation(s) without undue delay and at the latest within 48 hours of discovery, including the nature of the breach, the data involved and the measures taken, so the controller can meet its notification obligations.

11. Minors

Plenivo is a business service and not aimed at persons under 16. We do not process minors’ data other than employees entered by the client organisation (e.g. apprentice technicians), under that organisation’s responsibility.

12. Changes

We may update this privacy policy. For substantive changes we inform client organisations by email and state the new version and date on this page. The current version is always available at plenivo.nl/privacy.html.

13. Contact

Plenivo · Chamber of Commerce (NL) 42027446 · VAT NL003237037B11
Email: admin@plenivo.nl (privacy) · info@plenivo.nl (general)
Website: plenivo.nl