Trust & Security
Everything a procurement or compliance team usually asks before the product conversation begins - roles, contracts, sub-processors, hosting, retention, transfers, AI handling and breach response - in one place.
Roles and contracts
Where data lives
AI handling
Detail on our approach is set out in Responsible AI.
Channels
Retention and deletion
International transfers
Plateon is a UK company serving clients internationally. Where a transfer of UK or EEA personal data is restricted, we rely on adequacy where it exists and otherwise on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses - with a transfer risk assessment where the mechanism requires one.
Special category and payment data
The Concierge is built for data minimisation: it asks only for what a booking or request needs. Guests sometimes volunteer health-adjacent detail - an allergy, an access requirement - and that information is handled only for the purpose it was given, under your instructions.
Plateon does not request, process or store payment card details. Where a deposit is required, guests are directed to a PCI-compliant payment provider.
If something goes wrong
We maintain a documented incident response procedure. On becoming aware of a personal data breach affecting your data, we notify you without undue delay and in any event within [HOURS] hours, with the information you need for your own regulatory obligations, and support your assessment and any notification you must make.
Documents available on request
Data processing agreement · Technical and organisational measures · Sub-processor schedule (also published here) · Retention and deletion policy · Incident response summary · International transfer documentation · Records of processing activities extract relevant to your deployment.
Write to hello@plateontechnology.com and we will send them.