Always On · alwayson.plangrowdo.com · Version 1.2 · July 2026
In this Agreement, the following terms have the meanings set out below:
This DPA applies to all personal data that Plan Grow Do Ltd processes on behalf of the Tenant in connection with operating the Platform. Full details of those processing activities are set out in Schedule 1.
Plan Grow Do Ltd acts as a Data Processor in relation to all personal data entered into the Platform by or on behalf of the Tenant. The Tenant remains the Data Controller and is responsible for ensuring its use of the Platform complies with applicable data protection law.
This DPA applies only where Plan Grow Do Ltd acts as a processor on the Tenant's behalf. For certain activities Plan Grow Do Ltd acts as an independent data controller in its own right, including:
Processing carried out by Plan Grow Do Ltd in its capacity as an independent controller is governed by Plan Grow Do Ltd's own Privacy Notice, not this DPA.
The Tenant (Controller) agrees to:
Plan Grow Do Ltd agrees to:
Process personal data only on the documented instructions of the Controller, including in relation to international transfers, unless required to do so by law (in which case Plan Grow Do Ltd will inform the Controller before processing, unless prohibited by law).
Ensure that all persons authorised to access personal data within the Platform are subject to appropriate confidentiality obligations.
Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as detailed in Section 5.
Not engage sub-processors without the general authorisation of the Controller, subject to Section 6 of this DPA.
Assist the Controller, by appropriate technical and organisational measures, in fulfilling obligations to respond to data subject rights requests and to comply with UK GDPR Articles 32–36 (security, breach notification, DPIAs).
At the choice of the Controller, delete or return all personal data on termination of services, unless applicable law requires retention, as further detailed in Section 14.
Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and cooperate with audits as set out in Section 15.
Plan Grow Do Ltd implements the following technical and organisational measures to protect personal data processed within the Platform:
tenant_id controls, designed to prevent users from accessing data belonging to another tenantThe Tenant gives general authorisation to Plan Grow Do Ltd to engage the sub-processors listed below. Plan Grow Do Ltd will give the Tenant reasonable advance notice of any intended change to this list (additions or replacements) and the Tenant may object within a reasonable period.
Plan Grow Do Ltd ensures all sub-processors are bound by written data processing agreements providing at least equivalent data protection obligations to those in this DPA.
| Sub-Processor | Service | Data Location | Transfer Safeguard |
|---|---|---|---|
| Supabase Inc. | Database and file storage (PostgreSQL). Primary store for all contact records, communication history, and platform data. | EU, Ireland (eu-west-1) | EU-based; adequacy applies. Supabase DPA in place. |
| Vercel Inc. | Application hosting and edge delivery. Serves the Always On platform to users. | EU-primary edge network | Standard Contractual Clauses (SCCs). Vercel DPA in place. |
| Resend Inc. | Transactional email. Sends platform invitations, notifications, and system emails. | EU region | SCCs. Resend DPA in place. |
| Anthropic PBC (Claude API) | AI processing. Powers the Sally, Dan, and Caroline AI agents. Contact record data and communication context are sent to the Claude API to generate responses, qualifications, and recommendations. Under Anthropic's Commercial Terms of Service (which apply to API access), customer inputs and outputs are not used to train Anthropic's models by default. | United States (Anthropic infrastructure; no EU data residency option on the standard API) | SCCs (EU Standard Contractual Clauses) plus a UK International Data Transfer Addendum, incorporated into Anthropic's Commercial Terms of Service. |
| Google LLC (Gmail API) / Google Workspace | Gmail email sync. Where a Tenant user connects their Gmail account, the Gmail API is used to sync emails to and from contacts. Only emails matching existing contact records are synced. | Google infrastructure | SCCs / IDTA. Google Cloud DPA in place. Enabled only where user authorises via OAuth. |
| Microsoft Corporation | Outlook / Microsoft 365 email sync (Microsoft Graph API). Where a Tenant user connects their Outlook account, Microsoft Graph is used to sync emails to and from contacts. Only emails matching existing contact records are synced. | Microsoft infrastructure | SCCs / IDTA. Microsoft Online Services DPA in place. Enabled only where user authorises via OAuth. |
| Meta Platforms Ireland Ltd | WhatsApp Cloud API. Enables WhatsApp messages from contacts to be received, stored, and responded to within the Platform where the Tenant has enabled this feature. | Meta infrastructure (EU routing where available) | SCCs. Meta Business Terms and DPA in place. Enabled only where activated by the Tenant. |
The Platform allows individual users to connect their Gmail or Microsoft Outlook mailbox. When Email Sync is enabled, the following applies:
Once a user connects their mailbox, the Platform accesses and processes the following data:
The Platform does not process email attachments or access emails unrelated to contacts with existing records in the Platform. Historical emails are not bulk-imported; only emails sent or received after connection is established are synced, unless a specific historical sync is configured.
Mailbox connections are only established where the individual user explicitly authorises access via OAuth. Plan Grow Do Ltd does not connect mailboxes without user authorisation. Users can disconnect their mailbox at any time from their profile settings, which immediately revokes access and stops further syncing.
When a user disconnects their mailbox, the Platform immediately revokes the OAuth token and deletes it from storage. No further email syncing takes place after disconnection. Emails already synced and stored against contact records remain, unless deleted by a Tenant manager.
Users may also revoke access directly via their Google Account permissions page or Microsoft My Apps portal at any time.
The Always On platform includes three AI agents (Sally, Dan, and Caroline) powered by Anthropic's Claude models. These agents assist with inbound contact handling, sales qualification, daily pipeline management, and market intelligence. When an AI agent processes a contact interaction, relevant contact record data and communication context are sent to the Claude API to generate a response, qualification score, recommendation, or suggested action.
All outputs produced by the AI agents, including qualifications, scores, draft responses, recommendations, and suggested next actions, are advisory and assistive only. They are tools to support the Tenant's team, not decisions in themselves.
The Tenant remains responsible for reviewing, approving, and acting on any AI-generated output before it is relied upon or communicated to a contact. Plan Grow Do Ltd does not accept responsibility for decisions taken by the Tenant on the basis of AI-generated outputs without appropriate review.
The Platform does not make solely automated decisions that produce legal effects or similarly significant effects on individuals within the meaning of UK GDPR Article 22. Human review is always part of the process.
The Always On platform is designed for B2B sales management and is not intended for the processing of Special Category Data or criminal offence data.
The Tenant must not intentionally submit Special Category Data into the Platform unless it has:
Plan Grow Do Ltd recognises that Special Category Data may occasionally appear incidentally in free-text fields (for example in emails, WhatsApp messages, or form submissions) without having been intentionally submitted. In those cases, Plan Grow Do Ltd will process such data only as necessary to provide the Platform and in accordance with this DPA and the Tenant's instructions.
Plan Grow Do Ltd will assist the Controller in fulfilling its obligations to respond to data subject rights requests under UK GDPR, including requests relating to:
Where a data subject contacts Plan Grow Do Ltd directly regarding their rights, Plan Grow Do Ltd will promptly refer the request to the Controller. The Controller is responsible for determining how to respond.
Plan Grow Do Ltd provides tools within the Platform to enable the Controller to export, rectify, and delete personal data to support data subject requests.
Plan Grow Do Ltd will notify the Controller without undue delay and, where feasible, within 24 hours of becoming aware of a personal data breach affecting data processed under this DPA.
Where not all information is available within 24 hours, Plan Grow Do Ltd will provide an initial notification with the information available at that time, followed by further updates in phases as the investigation progresses. Initial notification will include, where known:
Plan Grow Do Ltd will cooperate with the Controller throughout the investigation and provide reasonable assistance where the Controller is required to notify the ICO or affected data subjects.
To report a suspected breach: info@plangrowdo.com
Where the Controller is required to conduct a Data Protection Impact Assessment (DPIA) in connection with processing on the Platform, Plan Grow Do Ltd will provide reasonable assistance, including:
All primary data storage is within the EU (Ireland). Where personal data is transferred to or processed by sub-processors outside the UK or EU, including Anthropic (Claude API), Google (Gmail API), Microsoft (Microsoft Graph), and Meta, Plan Grow Do Ltd ensures appropriate safeguards are in place:
Details of transfer mechanisms for each sub-processor are available on request from info@plangrowdo.com.
On termination of the service agreement, Plan Grow Do Ltd will, at the Controller's written election within 30 days of termination:
Where no election is made within 30 days of termination, Plan Grow Do Ltd will securely delete active production data by default.
The Platform maintains automated backups of all tenant data. Deletion from active production systems will be completed within the timeframe above, but backup copies may remain until they are overwritten or expire under Plan Grow Do Ltd's standard backup retention cycle.
Backup data is held solely for disaster recovery purposes and will not be accessed, used, or restored for any other purpose. If a backup containing deleted customer data is restored following a disaster recovery event, the previously deleted data will be re-deleted promptly following restoration.
The Controller has the right to audit Plan Grow Do Ltd's compliance with this DPA. Plan Grow Do Ltd will first respond to audit requests by providing relevant documentation (such as security policies, sub-processor agreements, and breach records) within a reasonable timeframe.
Where a physical audit or inspection is required, this will be agreed in advance, conducted at the Controller's cost, with no less than 30 days' written notice, and no more than once per calendar year, unless a personal data breach has occurred.
The Controller agrees not to request information that would compromise the security of other tenants' data or Plan Grow Do Ltd's commercially confidential information.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the main service agreement between the Tenant and Plan Grow Do Ltd.
Where Plan Grow Do Ltd has processed personal data in breach of this DPA or UK GDPR and this has caused damage to the Controller or a data subject, Plan Grow Do Ltd accepts liability to the extent it is responsible for the breach.
Where the Controller has given inaccurate or unlawful instructions that caused a breach, the Controller bears responsibility to the extent of those instructions.
This DPA comes into effect when the Tenant activates their Always On workspace and accepts the service terms. It remains in force for the duration of the service agreement between the parties.
This DPA terminates automatically on termination or expiry of the service agreement, subject to any continuing obligations under Section 14 (return and deletion of data).
This DPA is governed by and construed in accordance with the laws of England and Wales. Any disputes arising under this DPA are subject to the exclusive jurisdiction of the courts of England and Wales.
This Schedule sets out the details of the processing carried out by Plan Grow Do Ltd on behalf of the Controller, as required by UK GDPR Article 28(3).
The provision of the Always On B2B sales management platform, including AI-assisted contact qualification, pipeline management, email and WhatsApp communication sync, and sales analytics.
For the duration of the service agreement, plus any post-termination period required to fulfil obligations under Section 14.
| Nature | Purpose |
|---|---|
| Storage and retrieval | Holding contact, prospect, and communication records within the Platform |
| AI analysis and generation | Qualifying contacts, generating responses and recommendations via the Sally, Dan, and Caroline AI agents (advisory outputs only; see Section 8) |
| Email synchronisation | Syncing emails between a user's connected Gmail or Outlook mailbox and contact records where the user has authorised Email Sync |
| Form handling | Receiving and storing web form enquiries submitted by contacts via Tenant-embedded forms |
| WhatsApp messaging | Receiving, storing, and responding to WhatsApp messages from contacts where the Tenant has enabled this feature |
| Reporting and analytics | Generating pipeline reports, activity metrics, and sales dashboards for the Tenant |