Plank Privacy Policy

ТОО «Планк МД», БИН 260640029319 · version 1.1 (2026-09-18) · effective 2026-09-18

Plank Privacy Policy

1. Who We Are

The operator is Plank MD LLP — legal name under Kazakhstan law: Товарищество с ограниченной ответственностью «Планк МД» — BIN 260640029319, Kazakhstan, Almaty, Bostandyk district, 22 Liniya street, 13A, postal code 050046.

Privacy contact: support@plank.md.

2. Scope

This Policy applies to the Plank website, product, registration, workspace invitations, support, billing, legal acceptance records and user communications.

B2B workspace data is also governed by the Data Processing Terms or a separate DPA. Paddle and other payment providers process payment data under their own terms when they are the merchant of record.

3. Data We May Collect

We may process account data, business billing data, product usage data, technical data, support communications and connected-service data authorized by the user or customer.

Current product data categories include email address, name, hashed password, locale preference, onboarding information such as role, industry and work type, workspace files, chat messages, AI outputs, workspace settings, API keys or OAuth tokens for third-party AI providers, usage events, session information, device/browser type, payment metadata, photos or videos, audio data, other user content, user ID and product interaction events.

We should not collect identity document copies, biometric, medical, banking, state-secret, classified or other sensitive data unless there is a specific lawful basis and written agreement.

4. Legal Basis and Consent

We process personal data with consent, to perform a contract or public offer, to provide the service, to comply with accounting and tax duties, for security and support, to protect rights, and to comply with law.

Consent may be given by checkbox, registration, workspace invitation acceptance, payment, signed document, written confirmation or another method that allows confirmation.

Users may withdraw consent by contacting support@plank.md, unless continued processing is required by law, contract, accounting, taxes, security or legal defense.

5. Purposes

We process data to create and manage accounts, provide Plank workspaces and features, run AI functions, provide support, secure accounts, process billing and direct B2B documents, record legal acceptance, improve the product, send service and legal notices, comply with law and protect rights.

6. AI and Providers

Plank may use cloud infrastructure, databases, AI model providers, search providers, monitoring, support, payment, analytics and integration providers.

Plank uses the following providers (subprocessors): Supabase (EU) for database, authentication and file storage; Hetzner (EU) for compute infrastructure; Paddle (UK) for payment processing and billing as merchant of record; PostHog (EU) for product analytics; Cloudflare for browser-automation infrastructure used when the agent operates a browser on your instruction; and AI model providers configured by the user, including OpenAI, Anthropic, MiniMax, DeepSeek, Google, xAI, Groq and OpenRouter.

An up-to-date list of subprocessors is available at https://plank.md/dpa.

Plank does not use Customer Data to train third-party public models, and our AI model providers are prohibited from training their public models on Customer Data, unless expressly disclosed and agreed by the customer.

7. Storage, Security and Cross-Border Transfers

Data is stored on servers in the European Union through Supabase and Hetzner.

Plank uses TLS encryption in transit and encryption at rest for sensitive data, including credentials, API keys and OAuth tokens. Plank applies database-level access controls so users can access only their own data and workspace data they belong to.

Data may be transferred or made available outside Kazakhstan when Plank uses cloud infrastructure, AI providers, payment providers, analytics, support and connected services. Such transfers should have a lawful basis, required consent where applicable, and reasonable safeguards.

8. Disclosures

We may disclose data to service providers, payment providers, accountants, auditors, lawyers, government authorities, courts, regulators, direct B2B counterparties where necessary, and successors in a merger, sale, financing or reorganization subject to confidentiality and law.

9. Cookies and Analytics

Plank may use cookies, local storage and similar technologies for login, security, preferences, analytics and product improvement.

Plank uses essential cookies for authentication and session management and PostHog analytics cookies. Plank does not use advertising cookies and does not sell user data to third parties.

10. Retention

We retain data for as long as needed for the purposes in this Policy, unless a longer period is required by law, accounting/tax duties, security, backups, disputes or contracts.

When you delete your account, we delete your account and associated personal data within 30 days of your request, except where longer retention is required by law or for accounting, tax, security or legal-defense duties. Residual copies in backups are removed on the normal backup lifecycle. Workspace data shared with other members may remain in those workspaces after a user leaves.

11. Security

Plank uses reasonable legal, organizational and technical measures, including access control, TLS encryption in transit, encryption at rest for sensitive credentials such as API keys and OAuth tokens, logs, permission management, row-level database security, backups, vendor review and confidentiality controls.

Users must protect their passwords, devices, access keys, browser sessions and connected accounts.

12. User Rights

Users may request information, access, correction, deletion or blocking, consent withdrawal, data export in a portable format, restriction or objection where applicable, and information about third-party or cross-border transfers. Requests go to support@plank.md.

We aim to respond to requests within 30 days. Plank may verify identity and may refuse or limit a request where required or permitted by law, contract, security or retention duties.

13. Children

Plank is intended for business and professional use and is not intended for users under 18. Plank does not knowingly collect children's personal data. If a child has provided personal data, contact Plank so it can be deleted.

14. Changes

Plank may update this Policy at https://plank.md/privacy. Material changes may be notified through the website, product, email or another reasonable channel.

15. Contact

Operator: TOO “Plank MD” BIN: 260640029319 Address: Kazakhstan, Almaty, Bostandyk district, 22 Liniya street, 13A, postal code 050046 Email: support@plank.md Website: https://plank.md