Privacy Policy
What personal data Pleaxy collects, why, who we share it with and how long we keep it. We don't sell your data, we don't use it to train AI, and this site has no tracking cookies.
Last updated October 4, 2026
Who we are and how to reach us
Pleaxy is provided by Pleaxy Inc., a Delaware corporation, 1318 SE 26th Street, Bellevue, WA 98005, USA (“Pleaxy”, “we”, “us”). This policy covers the Pleaxy website, web app, API and MCP server.
For any privacy question or request, email support@pleaxy.ai.
Our two roles: controller and processor
We handle personal data in two different capacities.
- As a controller we decide how the data is used. This covers the data needed to run your account and our business: sign-up and sign-in details, the billing contact, website and API logs, and messages and support cases you send us. When a case includes the status of an invoice, purchase order, contract, supplier or buyer you named, we read it from the workspace within your own permissions and copy it into the case only to answer you.
- As a processor we act on our customer's instructions. This covers everything a company puts into its Pleaxy workspace: employees, supplier contacts, purchase orders, invoices, contracts, supplier documents, approval history and cloud billing data. The company whose workspace it is is the controller, and we act only on its instructions. Our Data Processing Agreement (DPA), which we are finalising, will set out those terms — email support@pleaxy.ai if you need one.
- Buyers and suppliers are separate customers. Each workspace belongs to its own company. When a buyer and a supplier connect, see each other's company profile details, and exchange purchase orders, invoices or documents, the sharing happens at their direction, and each company is responsible for what it shares and what it does with what it receives.
If your employer or a trading partner put your data into Pleaxy, please send questions or requests to them first. If you contact us, we will pass your request on and help them respond.
What we collect
- Account data: name, work email, job title, role and workspace membership. Your password is handled by Amazon Cognito using a protocol (SRP) that never sends it to Pleaxy's servers — we never see it.
- Company profile: company name, logo, billing email and address, tax ID, and the primary contact's name and email. Your company name, logo, region, currency, billing email and billing address are visible to the companies you are connected with (see Who we share data with).
- Workspace records: purchase orders, invoices, contracts, catalogues and approval history. Approval history includes the approver's name, user ID and the time of each decision.
- Supplier documents a supplier uploads, such as W-9 and W-8BEN tax forms (which contain tax identification numbers), certificates of insurance and bank letters (which contain bank account details).
- Cloud billing data from cloud accounts a customer connects: billing and usage records, which are mostly about the company rather than individuals.
- AI assistant messages: what you type to the assistant and its replies — see The AI assistant.
- Support cases: when you open a case in Pleaxy, your name and work email (taken from your account), the subject, description and messages you write, and diagnostics we add: your plan, your role, the app version, the status of any invoice or purchase order you name (including the other company's name and the current approval step), of any contract you name (its title, status, dates and the other company's name, but not its terms or prices), or of any supplier or buyer you name (its name and where its onboarding stands, but not its questionnaire answers or contact details), and any error code. Your Help assistant conversation is included only if you tick “Attach this conversation”. Administrators of your workspace can see the cases opened in it.
- Help article feedback: when you answer “Did this answer your question?” on a help article, your answer, any note you add, your user ID, the workspace and the article. We use it only to improve our help articles.
- Billing data for paid plans: the billing contact's email and company name. Card and bank payment details go directly to Stripe; Pleaxy never receives them.
- Technical logs: when your browser or integration calls our API, we log the IP address, the endpoint requested, the method, the result and the time.
- Messages you send us: if you email support@pleaxy.ai or sales@pleaxy.ai, we get your email address and whatever the message contains.
We do not collect special-category data, such as health data, and ask you not to upload it.
How we use it, and our legal bases
For data we control, we use it to:
- Provide the Service — create and secure accounts, send sign-up, verification and invitation emails, run the product, and bill paid plans. Legal basis: performance of our contract with you or your company.
- Keep Pleaxy secure and working — detect abuse and attacks, enforce rate limits, debug errors and monitor performance. Legal basis: our legitimate interest in a secure, reliable service.
- Support you — answer your support cases and emails. We use cases, and any conversation attached to them, only to answer and follow up on them, to keep support secure and within its limits, and where the law requires. We don't use them for marketing, to write help articles, or to train or evaluate AI models. Legal basis: legitimate interest, or contract.
- Meet legal duties — keep billing and tax records and respond to lawful requests. Legal basis: legal obligation.
We do not send marketing emails today. If we start, we will follow the law on consent, and every email will include a way to opt out.
For data we process for customers, we use it only to provide the Service as that customer instructs.
We don't make decisions about you that have legal or similarly significant effects based solely on automated processing. Any automatic approval in Pleaxy follows rules the customer sets, and those rules apply to purchases, not to people.
The AI assistant
- The in-app assistant uses Anthropic's Claude model, served by Amazon Bedrock (AWS), which we call from our own AWS account.
- What is sent. To answer you, the assistant sends your messages, the conversation so far, and the workspace records it looks up to Amazon Bedrock. Those records can include names, supplier details and amounts. The assistant only sees what your role can see.
- Saved to your account. We save your Pleaxy Assistant conversations under your own user, in the workspace you used, so you can come back to them, search and rename them. Other people in the workspace can't see them. You can delete a conversation at any time, and each one is deleted automatically 180 days after its last message. We also keep a count of messages, for usage limits, for about 8 days, and any action the assistant proposes, which expires after 10 minutes and is then deleted automatically.
- Not used for training. Under AWS's terms for Bedrock, AWS does not use your prompts and replies to train models and does not share them with Anthropic. We do not use them to train models either.
- You stay in control. The assistant can only propose approvals, recorded payments, invoice rejections, discrepancy resolutions and rule changes, and a person confirms each one. When you ask it to, it can also reject a purchase order, create a purchase order or turn one into an invoice without a separate confirmation step — see our Terms. It acts only within the permissions of the person using it.
- The Help assistant on the Help page runs on the same model and service. It is read-only. It reads our help articles, your plan, your Pleaxy Assistant usage, your role, your connection health and any one invoice or purchase order you name, only as your role can see them.
- Help assistant conversations stay in your browser tab (its session storage) and are gone when you close the tab — unless you attach one to a support case, when we keep it with the case (see How long we keep data). We keep daily message counts for usage limits for about 8 days, and a monthly total of messages and tokens for each workspace, with no personal data, for about 13 months.
- Not used for training or evaluation. Neither assistant's conversations, nor support cases, are used to train or evaluate AI models.
Where your data is stored, and international transfers
Pleaxy stores and processes data in the United States, on AWS in the US East (N. Virginia) region — including the AI assistant, which calls Amazon Bedrock in that region. Our sub-processors are US companies.
If you are in the EU, EEA, UK or Switzerland, using Pleaxy means your data is transferred to the US.
- For customer data we process, our DPA will protect the transfer with the European Commission's Standard Contractual Clauses, together with the UK Addendum for UK data.
- For data we control, we transfer it as needed to provide the Service you signed up for.
Pleaxy is not certified under the EU-US Data Privacy Framework.
How long we keep data
| Data | How long |
|---|---|
| Workspace records and account data | Unless a different period is listed below, for as long as the account is open. After it closes, deleted within 30 days, unless the customer asks for earlier deletion or the law requires us to keep something. |
| Backups | Deleted data drops out of our backups within 35 days. |
| Supplier documents | Until removed from the workspace. Removal erases every stored version. |
| Removed users | Deleting a user removes their sign-in. Their name and user ID stay in the approval history of documents they acted on. |
| Membership changes | When someone is invited to a workspace (including when an invitation is resent, cancelled, accepted or declined), changes role, or is removed, or when an API key is revoked because the person who created it was removed from the workspace or lost administrator access, we keep a record of the change: who made it, the email address and user ID of the person affected, their previous and new role, and the name of any revoked API key. We keep this record on the workspace owner's behalf, as part of securing their workspace: we use it to investigate security incidents and to answer their support requests. Each entry is deleted automatically about 13 months after it is created, or earlier if the workspace's data is deleted after the account closes. Backup copies are removed within a further 35 days. |
| API access logs (including IP address) | 30 days |
| Application logs | 90 days |
| Infrastructure audit logs (AWS CloudTrail) | 365 days |
| Pleaxy Assistant | Saved conversations: until you delete them, or automatically 180 days after the last message. Message counts are kept for about 8 days; proposed actions expire after 10 minutes and are then deleted automatically. |
| Help article feedback | Your answer to “Did this answer your question?” and any note you add: about 13 months after you last answered for that article. |
| Support cases | The case and its messages: 24 months after the case is closed. Diagnostics and any attached Help assistant conversation: 90 days after the case is closed. A case waiting on your reply closes automatically after 30 days. Help assistant message counts: about 8 days. Each is deleted automatically within a few days of the time shown. |
| Help assistant monthly totals | Message and usage totals per workspace, with no personal data: about 13 months. |
| In-app notifications | 90 days |
| Billing and tax records | As long as tax and accounting law requires, typically several years. |
How we protect data
- Data is encrypted in transit (HTTPS only) and at rest, using AWS-managed keys.
- Every request is checked against the caller's workspace and role.
- Approvals are recorded with who made them — or that they were automatic — and when.
Our Security page describes our controls in detail, including what we have not done yet. If a breach affects your data, we will notify affected customers without undue delay, give them the information they need to meet their own obligations, and notify regulators where the law requires it.
Your privacy rights
Depending on where you live — for example under the GDPR and UK GDPR, US state privacy laws such as California's, and the laws of Canada and Argentina — you may have the right to access your personal data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw consent where we rely on consent.
- How to ask. Email support@pleaxy.ai. We may need to verify who you are, and we will reply within the time the law requires — usually one month. We won't treat you differently for using your rights.
- Data in a company's workspace. We handle that data for the company, so we will pass your request to it and help it respond (see Our two roles).
- Administrators can remove users from their workspace themselves. Workspace-wide exports and deletions are done on request, by email.
- Complaints. If you're in the EU, EEA or UK, you can complain to your local data protection authority — for example the ICO in the UK. We would appreciate the chance to help first.
Children
Pleaxy is a business service for people at work. It is not meant for anyone under 18, and we don't knowingly collect children's data.
Changes to this policy
We will update this policy when our practices change — for example when we add a sub-processor or a new kind of data. The “Last updated” date at the top shows the current version, and for material changes we will notify account holders by email or in the app before the change takes effect.