GDPR Compliance
1. Applicable regulatory framework
Plexum applies the following data protection regulations:
- Regulation (EU) 2016/679 (GDPR) — General Data Protection Regulation.
- Organic Law 3/2018 (LOPDGDD) — Personal Data Protection and digital rights guarantee.
- Law 34/2002 (LSSICE) — Information Society Services.
- Royal Decree 933/2021 and applicable sector-specific legislation.
2. Data controller
- Company name: [Razón social completa]
- Tax ID (CIF): [CIF]
- Address: [Domicilio completo], Barcelona, Spain
- DPO/DPD email: hola@plexum.cat
3. Data protection principles applied
Plexum applies the following principles from Article 5 of the GDPR in the design and operation of its platform:
- Lawfulness, fairness and transparency: every data collection has a documented legal basis.
- Purpose limitation: data is collected for specific purposes and not processed in an incompatible manner.
- Data minimisation: only strictly necessary data is collected.
- Accuracy: mechanisms are maintained for the rectification of inaccurate data.
- Storage limitation: data is not retained longer than necessary.
- Integrity and confidentiality: appropriate technical and organisational measures are applied.
- Accountability: Plexum can demonstrate compliance with the above principles.
4. Technical security measures
- In-transit encryption using TLS 1.2 or higher for all communications.
- At-rest encryption for data stored in the database.
- Multi-tenant isolation through Row-Level Security (RLS) in PostgreSQL — no tenant can access another tenant's data.
- Robust authentication with signed session tokens (JWT) and configurable expiry.
- Audit trail for access and changes to sensitive data.
- Periodic encrypted backups.
- Minimum password policy and 2FA option for platform users.
5. International data transfers
Personal data processed by Plexum is stored on cloud infrastructure located in the European Union (Supabase EU — Frankfurt). No international transfers to third countries outside the European Economic Area are carried out, except in the cases provided for in Chapter V of the GDPR.
Any data processor contracted by Plexum located outside the EU/EEA will have adequate safeguards in accordance with the GDPR (Adequacy decision, Standard Contractual Clauses or equivalent mechanism).
6. GDPR rights of data subjects
Data subjects may at any time exercise the rights recognised in Articles 15 to 22 of the GDPR: access, rectification, erasure, restriction, portability, objection and not being subject to solely automated individual decisions.
Response times: Plexum will respond as soon as possible and always within a maximum period of 1 month from receipt of the request (extendable by 2 additional months in cases of complexity or high volume of requests, with notification to the data subject).
To exercise these rights, write to: hola@plexum.cat
7. Personal data breach notification
In the event of a personal data security breach posing a risk to the rights and freedoms of data subjects, Plexum will notify the Spanish Data Protection Agency within a maximum of 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR.
If the breach poses a high risk to data subjects, they will be informed directly without undue delay.
8. Record of processing activities
Plexum maintains a Record of Processing Activities (RPA) in accordance with Article 30 of the GDPR, accessible to the competent supervisory authority upon request.
9. Competent supervisory authority
The competent supervisory authority in Spain is the Spanish Data Protection Agency (AEPD). Data subjects have the right to lodge a complaint with the AEPD if they consider that the processing of their data does not comply with applicable regulations.
10. Privacy by design and by default
The Plexum platform applies the principle of privacy by design and by default in accordance with Article 25 of the GDPR. Technical architecture decisions take data protection into account as a design requirement, not as an afterthought.
Last updated: June 2026