Plank Data Processing Terms

ТОО «Планк МД», БИН 260640029319 · version 1.0 (2026-06-22) · effective 2026-06-23

Plank Data Processing Terms

1. Purpose

These Data Processing Terms govern processing of Customer Data when an organization or individual entrepreneur uses Plank as a workspace for files, documents, messages, instructions, connected services, browser sessions and AI features.

They supplement the Terms of Use, Privacy Policy, public offer, invoice, order form, specification or separate agreement. If the parties sign a separate DPA, that signed DPA controls in case of conflict.

2. Roles

The Customer decides what data to submit, what services to connect, which users to invite and how to use Plank.

Plank / TOO “Plank MD” processes data to provide the service, support, security, billing and contractual performance.

3. Data Categories

Customer may submit account and user data, employee/client/contractor/vendor data, documents, spreadsheets, PDFs, images, photos, videos, audio recordings, email, messages, calendars, CRM/project/task data, browser session data, API data, prompts, instructions, AI outputs, logs, technical data, API keys, OAuth tokens and other credentials for connected services or AI providers when configured by the user.

4. Processing Activities

Plank may receive, store, index, search, analyze, summarize, transform, process with AI, generate documents/reports/dashboards/automations/scripts, call connected services on Customer instruction, provide support, back up, restore, export, delete and log data for security and audit.

5. Customer Obligations

Customer is responsible for lawful basis, consents and notices; user authority; workspace permissions; connected services; protection of credentials and access keys; human review of outputs; and avoiding prohibited or specially regulated data unless expressly agreed in writing.

6. Plank Obligations

Plank will process data to provide and support the service, use reasonable technical and organizational safeguards, restrict internal access to people with a need to know, use providers only for legitimate product purposes, preserve confidentiality and reasonably assist with export, deletion, security and data-subject requests subject to product capabilities and contract terms.

7. Providers and Subprocessors

Plank may use cloud, database, AI model, search, monitoring, security, support, payment, analytics and integration providers.

Plank uses the following subprocessors: Supabase (EU), Hetzner (EU), Paddle (UK), PostHog (EU), Cloudflare (browser-automation infrastructure), and user-configured AI model providers including OpenAI, Anthropic, MiniMax, DeepSeek, Google, xAI, Groq and OpenRouter.

An up-to-date list of subprocessors is available at https://plank.md/dpa.

Plank does not allow third-party model providers to train public models on Customer Data, and those providers are prohibited from training their public models on Customer Data, unless expressly disclosed and agreed.

8. Cross-Border Transfers

Data may be processed outside Kazakhstan through cloud infrastructure, AI providers, support, analytics, payments and connected services. Customer authorizes such transfer as needed to use Plank, subject to applicable law and agreed terms.

9. Security

Working safeguards include access controls, authentication, session management, TLS encryption in transit, encryption at rest for sensitive credentials such as API keys and OAuth tokens, backups, logging, monitoring, row-level database security, logical workspace separation, provider review as the product matures, and confidentiality controls.

10. Security Incidents

If Plank confirms a security incident affecting Customer Data, Plank will notify Customer without undue delay and provide available information needed to assess impact.

11. Data Subject Requests

Customer is primarily responsible for requests from data subjects whose data Customer submitted to Plank. Plank will provide reasonable assistance through product functionality or support where technically feasible and consistent with security, law and contract terms.

12. Export and Deletion

Customer may request export through product tools or support. After termination or verified deletion request, Plank will delete or de-identify data within a period no longer than necessary for the agreed purposes or as required by applicable law, unless retention is required by law, accounting/tax duties, security, backups, disputes or contract terms.

After account deletion or a verified deletion request, personal data is deleted within 30 days, except where longer retention is legally required or required for accounting, tax, security or legal-defense duties. For B2B workspace data, shared workspace data may remain available to other workspace members until the workspace itself is deleted.

Backup deletion follows the normal backup lifecycle.

13. Audits and Information

For standard customers, Plank may provide security and processing information through public docs, questionnaires or support. Custom audits require a separate written agreement.

14. Contact

Privacy: support@plank.md Legal: support@plank.md Website: https://plank.md