Data protection

Privacy policy

How Pleyos expects to process account, organization, project, and security data.

Last updated: May 1, 2026

Controller and contact

Built Different S.L. acts as the controller for website and account administration data. For privacy requests, contact privacy@pleyos.com.

Data we process

Pleyos processes only the information needed to operate the platform, secure workspaces, and support organizations.

  • Account data such as name, email, identity-provider identifiers, and preferences.
  • Organization and project data such as memberships, roles, issues, comments, workflows, and activity.
  • Security data such as IP addresses, sessions, audit events, and access logs.
  • Operational communications such as invitations, notifications, and support messages.

Purposes and legal basis

Data is processed to provide the service, manage organizations and permissions, secure the platform, comply with legal obligations, and improve reliability. The expected legal bases are contract performance, legal obligation, and legitimate interest in security and product operation.

Subprocessors and transfers

Pleyos may use infrastructure, email, identity, storage, observability, and AI service providers. Where data leaves the European Economic Area, appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms should apply.

AI assistance

Future Pleyos AI capabilities are intended to support users, not to make legal or similarly significant automated decisions. Users remain able to review, edit, accept, or reject suggestions.

Retention and rights

Data is retained while accounts or organizations remain active and as needed for legal, security, or audit obligations. You may request access, correction, deletion, restriction, objection, and portability by contacting privacy@pleyos.com.