Trust & Security

Last updated August 2026

Everything a procurement or compliance team usually asks before the product conversation begins - roles, contracts, sub-processors, hosting, retention, transfers, AI handling and breach response - in one place.

In one sentence. Plateon is designed around UK GDPR and EU GDPR principles, operates under written data processing agreements, maintains a documented sub-processor list and international transfer safeguards, applies defined retention and deletion controls and protects guest information with appropriate technical and organisational measures.
01

Roles and contracts

Your role
Controller. You decide why and how guest data is processed.
Our role
Processor. We act only on your documented instructions.
The contract
A data processing agreement covering instructions, confidentiality, security, sub-processors, assistance with data-subject rights, breach notification, deletion or return of data and audit rights.
Guest-facing notice
Guests are told they are speaking with a digital concierge acting for your business and can reach a person at any point.
02

Where data lives

Hosting region
Application compute runs in Frankfurt. The primary data store is in Ireland. Conversation state is cached in Frankfurt and Virginia - see International transfers below.
Encryption
TLS in transit; encryption at rest with our infrastructure providers.
Access
Least privilege, individually named accounts, multi-factor authentication, access reviewed on joining and leaving.
Secrets
Held in a managed secret store, never in source control.
Backups
Handled by our database provider under its own backup and point-in-time-recovery arrangements. We can share the current terms and retention window for your deployment on request.
Logging
Personal data is minimised in logs and phone numbers are masked before they are written. Retention follows our hosting and monitoring providers' own log policies.
03

AI handling

Model providers
OpenAI, accessed via its business API.
Training
Guest conversations are not used to train foundation models. Provider terms prohibit training on API data.
Provider retention
Up to 30 days for abuse monitoring under OpenAI's API terms, then deleted. API content is not used to train OpenAI's models.
Grounding
Answers are drawn from your knowledge base, not the open internet.
Automated decisions
No profiling and no decisions with legal or similarly significant effects (Art. 22).

Detail on our approach is set out in Responsible AI.

04

Channels

Web chat
Served from your website; conversation content processed as described above.
WhatsApp
Delivered directly through the WhatsApp Cloud API, with no reseller in between - Meta is the sub-processor. Message content and phone numbers pass through Meta's infrastructure under their terms; roles are documented in your DPA.
Telephone
Calls are transcribed so the Concierge can handle them. Plateon stores the transcript, not the audio. Where your telephony configuration retains a recording, that is disclosed and consented to before the substance of the call, in the manner local law requires.
05

Retention and deletion

Working data expires on fixed timers, without anyone having to remember to clear it.

Conversation state, web
6 hours.
Conversation state, WhatsApp and voice
24 hours.
Voice session identifier
24 hours.
Speech buffer during a call
120 seconds.
Operational metrics
7 days.
Quality and diagnostic records
14 days.
Improvement queue
30 days.

Conversation and reservation records held in the primary store are a separate matter: they are kept for the period agreed with the client business, deleted on request and deleted at the end of the agreement.

Reservation details
Passed to your reservation system; where CoverManager is connected, the booking lives there.
On termination
Data returned in a portable format and deleted from live systems within 30 days and from backups within 90 days.
On request
Deletion of a specific guest's data on your instruction, within 14 days.
06

International transfers

Plateon is a UK company serving clients internationally. Where a transfer of UK or EEA personal data is restricted, we rely on adequacy where it exists and otherwise on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses - with a transfer risk assessment where the mechanism requires one.

07

Special category and payment data

The Concierge is built for data minimisation: it asks only for what a booking or request needs. Guests sometimes volunteer health-adjacent detail - an allergy, an access requirement - and that information is handled only for the purpose it was given, under your instructions.

Plateon does not request, process or store payment card details. Where a deposit is required, guests are directed to a PCI-compliant payment provider.

08

If something goes wrong

We maintain a documented incident response procedure. On becoming aware of a personal data breach affecting your data, we notify you without undue delay and in any event within 48 hours, with the information you need for your own regulatory obligations, and support your assessment and any notification you must make.

09

Documents available on request

Data processing agreement · Technical and organisational measures · Sub-processor schedule (also published here) · Retention and deletion policy · Incident response summary · International transfer documentation · Records of processing activities extract relevant to your deployment.

Write to hello@plateontechnology.com and we will send them.