The Article 28 GDPR agreement between your business and Plentia for the data about your customers and suppliers that you keep in Plentia.
Draft pending legal review. It was written by the person who builds Plentia, who is not a lawyer, following article 28.3 of the GDPR and the Spanish Data Protection Agency guidelines cited. A lawyer will review it before the first customer is charged.
Last updated: 26/09/2026
You accept this agreement when you create your account, by ticking the relevant box on the sign-up form. It forms part of the terms of service. You can save and print it from this page.
Article 28.3 of the General Data Protection Regulation (EU) 2016/679 (GDPR) requires a contract setting out the subject matter, duration, nature and purpose of the processing, the type of personal data, the categories of data subjects and the obligations and rights of the controller. Each section below gives the letter of the article it meets.
Plentia processes, on your behalf, personal data about other people that you enter into Plentia or that Plentia reads from the shops you connect. It does so only to provide the service described in the terms.
Your own account data is not covered by this agreement: for that data Plentia is the controller, and it is governed by the privacy policy.
This agreement lasts as long as your account. When it ends, the section “When it ends” applies.
With that data, automatically and at your request, Plentia:
The purpose is to provide the service to you. Plentia does not use that data for anything of its own: no advertising, no profiling, no selling, no model training.
| Data subjects | Data |
|---|---|
| Your customers | Name, tax ID, country, whether they are a consumer or a business, address, EU VAT number and its validation, email, phone, notes you write. The details on your invoices. |
| Your suppliers | Name, tax ID, EU VAT number, address, email, phone, website, notes. The details on their invoices and receipts. |
| Buyers in your shops | Name, ID in the shop, delivery city, postcode, region and country, campaign parameters (UTM) of the last visit, amounts, refunds and shipments with their tracking number. |
| Contact persons at customers and suppliers | Name, job title, email, phone and notes of calls or meetings. |
| People you give access to your account | Email, permissions, dates and a log of the changes they make. |
Plentia is not designed for special categories of data (such as health or beliefs). Do not put them in notes or documents.
As controller, you:
Plentia processes the data only on your documented instructions. Your instructions are this agreement, the terms of service and what you do in the dashboard: entering data, connecting a shop, issuing an invoice, requesting an export.
Plentia does not transfer the data outside the European Economic Area except through the listed subprocessors and with the safeguards stated there, or where a law requires it. In that case, it tells you first, unless the law forbids it.
If Plentia believes an instruction of yours breaches data protection law, it tells you straight away.
Anyone Plentia authorises to process the data commits in writing to confidentiality, including after their relationship with Plentia ends.
Plentia does not look at the content of your account unless it needs to in order to handle a support request from you, fix a fault in the service, or because the law requires it.
These are the measures Plentia applies today:
You give us a general authorisation to use the subprocessors on the published list. In return:
If someone exercises their rights (access, rectification, erasure, objection, restriction or portability), Plentia helps you respond:
Plentia helps you comply with articles 32 to 36 of the GDPR with the information it holds: security measures, breaches, impact assessments and prior consultation with the authority.
If Plentia becomes aware of a breach affecting your data, it tells you by email without undue delay and within 48 hours at the latest of becoming aware of it. It gives you the information it has at that point: what happened, which data and people may be affected, the likely consequences and what has been done. Anything missing follows once it is known.
The GDPR requires the processor to give notice “without undue delay” (art. 33.2), and the controller to notify the authority within 72 hours where feasible (art. 33.1). The Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) guidelines (in Spanish) say the processor’s deadline “must be under 72 hours in any case”.
Return. In Settings you can download a ZIP with your data at any time. It is built in your browser and includes:
The ZIP does not include contact notes, contact persons and reminders, shipments, refunds, the calendar, brands, the change log or the logo. If you need any of these, ask at [email protected] and we will send them in a commonly used format.
Deletion. When you finish and ask us by email, we delete the data, except what a law requires to be kept. That data is blocked: set aside so that nobody uses or sees it, and destroyed when the period ends (Spain’s data protection act, Ley Orgánica 3/2018 (LOPDGDD), art. 32). Verifactu invoicing records cannot be deleted or changed. Today deletion is not automatic: it is done on request.
Plentia gives you all the information needed to show that it complies with this agreement, including its subprocessors’ agreements. It also allows audits and inspections by you or an auditor you appoint, with reasonable notice, under a confidentiality commitment and without putting other customers’ data at risk.
This agreement is governed by Spanish law and the GDPR. For any dispute, the provisions of the terms of service apply.
Sources: GDPR, arts. 28 and 32 to 36; AEPD, guidelines for contracts between controllers and processors; LOPDGDD, art. 32. Consulted on 26/09/2026.