Plenetic

Privacy Policy

Last updated: July 2026

Controller

The controller responsible for data processing on this website and in the Plenetic service is:

Plenetic GmbH Carlsfund 1F 38723 Seesen Germany

Email: info@plenetic.com

Data We Collect

We process the following categories of personal data:

Waitlist form: When you request early access, we collect your name, email address, company, language preference, and confirmation that you accept our Terms of Service. We forward this information by email to Plenetic so we can process your request and contact you. We do not store waitlist submissions in a separate application database (legal basis: Art. 6(1)(b) GDPR — steps prior to entering into a contract).

Contact form: When you use the imprint contact form, we collect your name, email address, and message, and forward them by email to Plenetic to respond to your inquiry (legal basis: Art. 6(1)(b) GDPR — steps prior to a contract / responding to your request, and Art. 6(1)(f) GDPR — legitimate interest in communicating with inquirers).

Account and authentication: When you sign in, we process account data such as email address, name, and session information to provide the service (legal basis: Art. 6(1)(b) GDPR — contract performance).

Customer and business content: In the signed-in workspace, customers may store business data (for example contacts, deals, documents, and related records). For that content, the customer organization is typically the controller. Plenetic acts as a processor under Art. 28 GDPR and processes such data on the customer’s instructions under a data processing agreement (AVV/DPA). See the “Data processing agreement” section below.

Server logs: Our hosting infrastructure processes IP addresses, browser/user-agent data, and timestamps as part of standard HTTP request logging. This supports security, troubleshooting, and abuse prevention (legal basis: Art. 6(1)(f) GDPR — legitimate interest).

Error monitoring: See the Sentry section below.

We do not use automated decision-making or profiling that produces legal or similarly significant effects within the meaning of Art. 22 GDPR. No data protection officer is currently appointed; contact the controller for privacy requests.

Cookies and Local Storage

We use cookies and local storage in accordance with TDDDG §25 and GDPR. They fall into three groups:

Necessary

Required for the site and signed-in service to work.

NamePurposeRetention
plenetic_consentRemembers your cookie choice365 days
Auth / session cookiesKeep you signed inSession

Optional

Only if you choose “Accept all”.

NamePurposeRetention
NEXT_LOCALELanguage preference (EN/DE)365 days
UmamiAggregated page views on marketing pagesSee analytics section
Sentry Session ReplayError diagnostics via session replay (no default PII)See Sentry section

Workspace UI

Interface preferences in the signed-in app.

NamePurposeRetention
themeLight / dark preference (local storage)Until changed
sidebar_stateSidebar open / closed7 days

You can change your cookie choice anytime via cookie settings in the footer.

Usage Analytics (Umami)

If you choose "Accept all", we load a self-hosted Umami analytics script on our public marketing pages (including the blog) to understand aggregated page views and referrers. Umami runs on our own infrastructure via Elestio on a Hetzner server in Nürnberg, Germany. The tracker is not loaded if you choose "Necessary only" (legal basis: Art. 6(1)(a) GDPR and TDDDG §25 — consent).

Error Monitoring (Sentry)

We use Sentry to detect and diagnose application errors and performance issues. Sentry is configured with an EU data ingest endpoint (Germany). By default we do not send default PII (such as IP address as a user identifier). Basic error and performance monitoring supports the security and reliability of the service (legal basis: Art. 6(1)(f) GDPR — legitimate interest).

Session Replay is loaded only if you choose “Accept all” in the cookie banner, because it accesses information on your device (legal basis: Art. 6(1)(a) GDPR and TDDDG §25 — consent). Without that consent, Replay remains disabled.

Hosting and Infrastructure

The Plenetic website and application are hosted on Amazon Web Services (AWS) in the EU region eu-north-1 (Stockholm). AWS processes IP addresses and standard HTTP request data as part of providing the hosting service. Application data is stored in EU-hosted databases and object storage (including AWS S3 for files).

Recipients and Processors

Depending on how you use Plenetic, the following service providers may process data on our behalf:

Amazon Web Services (AWS) — Hosting, compute, and file storage (EU, eu-north-1).

Mailgun (EU) — Transactional email, including waitlist, contact-form, and authentication emails.

Umami (self-hosted via Elestio / Hetzner, Nürnberg) — Optional marketing analytics after consent.

Sentry (EU ingest, Germany) — Error and performance monitoring (Session Replay only with consent).

We only share data as needed to operate the service, comply with law, or with your instruction. Primary processing takes place in the EU.

Data processing agreement (AVV / DPA)

Where Plenetic processes personal data on behalf of a customer organization in the signed-in workspace, Plenetic acts as a processor under Art. 28 GDPR. We conclude a data processing agreement (Auftragsverarbeitungsvertrag / DPA) with customers as required. Please contact info@plenetic.com to request or conclude an AVV/DPA.

Retention

We keep personal data only as long as needed for the purposes described above. Waitlist and contact-form emails are handled in ordinary business email retention. Account and workspace data are retained for the duration of the customer relationship and deleted or anonymized afterwards according to contractual and legal requirements. Server logs and error reports are retained only as long as needed for security and troubleshooting.

Your Rights

Under the GDPR, you have the right to:

Access (Art. 15) — Request a copy of your personal data.

Rectification (Art. 16) — Request correction of inaccurate data.

Erasure (Art. 17) — Request deletion of your data in certain circumstances.

Restriction (Art. 18) — Request limitation of processing in certain cases.

Data portability (Art. 20) — Receive your data in a structured, commonly used format.

Object (Art. 21) — Object to processing based on legitimate interests.

Withdraw consent (Art. 7(3)) — Withdraw consent at any time where processing is based on consent.

To exercise these rights, contact us at info@plenetic.com.

Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Plenetic GmbH is:

Die Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen) Prinzenstraße 5 30159 Hannover Germany

Website: www.lfd.niedersachsen.de

Contact

For questions about this privacy policy or to exercise your rights, please contact us at info@plenetic.com or by post at the address above.