Legal
Privacy Policy
Last updated: 17 July 2026
This policy explains what personal data Plug & Play processes, why, who it is shared with, how long it is kept, and the rights you have under the EU General Data Protection Regulation (GDPR).
Who is responsible for your data
Plug & Play (“we”, “us”) provides an embeddable, document-grounded customer-support assistant. For the personal data described here we act as the data controller for our own account and website data, and as a data processor for the content our customers place in their workspaces.
The registered legal entity operating the Plug & Play service and its address will be identified here. Until then, you can reach us for any privacy question or request at contact@plugandplay.gr. We are based in Greece and the service is provided under Greek and EU law.
Information we process
Account data: your sign-in email and authentication details (handled by our authentication provider), plus workspace profile details such as the business name, assistant configuration, team-member invitations, and billing status.
Knowledge base content: when an administrator uploads a document or adds a web page by its URL, we store the file or page name and its extracted text so the assistant can search it.
Conversation data: when a website visitor chats with an assistant, we store the visitor's messages, the assistant's responses, the conversation title, any rating, and related analytics such as which questions went unanswered. If a conversation is escalated to a human operator, we also store the handoff and any callback request.
Technical data: we and our infrastructure providers process IP addresses and request metadata to route traffic, apply rate limits, and keep the service secure.
How we use information
Uploaded and linked content is used to build the workspace's searchable knowledge base. Visitor messages and relevant conversation history are used to generate answers, short internal summaries, and analytics for the workspace administrator.
We use billing data to operate subscriptions and account data to secure access, provide support, and send service and invite emails. We do not sell your personal data and we do not use conversation content to train our own models.
Please do not upload, link to, or submit information you are not authorised to share, and website visitors should avoid sending sensitive personal information through the chat widget.
Service providers and where data goes
We rely on the following processors to run the service: our authentication and database provider (account, workspace, and conversation storage); OpenAI (to create search embeddings from uploaded text, and to screen widget messages for abuse); DeepSeek (to generate assistant answers and summaries from the relevant knowledge-base context and conversation content); Jina AI (to fetch a web page as text when an administrator adds it by URL, and to re-rank search results); Stripe (to process subscription and top-up payments - we never see or store your full card details); and our hosting and edge providers, which operate the servers and content-delivery/edge network that carry requests.
Some of these providers process data outside the European Economic Area. Where that happens, transfers are covered by the safeguards those providers offer (such as the European Commission's Standard Contractual Clauses).
Our marketing website uses Google Analytics to measure site usage, and only after you consent through the cookie banner - see the Cookie Policy.
How long we keep data
Administrators can delete individual documents and conversations from the admin workspace at any time; we then remove the corresponding active records and knowledge chunks.
When a subscription ends - whether it is cancelled or a free trial expires without an upgrade - the account is locked and its data is retained for 30 days so you can reactivate without losing your workspace. After those 30 days we permanently delete the workspace's data from our active systems. Routine encrypted backups are cycled out shortly afterwards.
We keep the minimum billing and transaction records that tax and accounting law requires us to retain, even after deletion of the workspace.
Your rights
Under the GDPR you can request access to your personal data, correction of inaccurate data, erasure, restriction of or objection to processing, and a copy of your data in a portable format. To exercise any of these rights, email contact@plugandplay.gr. We will respond within the time limits the GDPR sets.
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with the Hellenic Data Protection Authority (Hellenic DPA) or your local supervisory authority.