plek
  • How It Works
  • Why Plek
  • Features
  • Case Studies
Sign in Book a Demo
  • How It Works
  • Why Plek
  • Features
  • Case Studies
Sign in Book a Demo

[ / ] Legal

Privacy Policy

Last updated: September 6, 2026 · Terms of Service

This notice states what Plek collects, why we collect it, who else sees it, and what you can ask us to do about it.

1. Introduction

This Privacy Policy describes how Plek Inc. (“Plek”, “we”, “us”) handles personal information when you visit plek.ai, request a demonstration, sign in to a Plek account, receive a case study, or answer a survey we run for one of our customers. It covers our public website and the Plek service.

It does not cover what a customer does with data inside its own organisation, and it does not cover a third-party website once you follow a link away from ours. If you do not agree with the practices described here, please do not use the service.

2. Who we are

Plek Inc. is a corporation organised under the laws of the State of Delaware, United States. Plek maps human work and what it costs, using an employer’s own workforce records.

Our role depends on the data. For information about visitors to plek.ai, account holders and people who contact us, we are the controller: we decide why that information is processed and how. For workforce data a customer uploads, and for survey responses we collect on a customer’s behalf, the customer is the controller and we are its processor — we act on that customer’s documented instructions, and a question about such data belongs to the customer first.

A data processing agreement covering our processor role is available on request from pierre@plek.ai.

3. Information we collect

Information you give us

  • Email address. Required to sign in, to request a demonstration, to receive a case study, or to book a call.
  • Name, job title and company, where you choose to supply them.
  • Workforce data a customer uploads. Typically job titles, headcount, reporting structure, locations, working time and compensation figures drawn from the customer’s system of record.
  • Employee survey responses. Where a customer runs a Plek survey, we collect what respondents report about their tasks and the tools they use. Respondents are instructed not to put names, employee identifiers or other personal details into free-text answers.
  • Your correspondence. Support requests, emails and notes from calls.

Information we collect automatically

  • Server logs. Our own first-party logging records the IP address, user agent, referring page, the page requested, the timestamp and a pseudonymous session identifier for requests to plek.ai. That record stays with us; it is not fed to a third-party analytics product.
  • Sign-in records. When you sign in we record the IP address and device type used, so that an account holder can be told about access they did not expect.
  • Case-study activity. We record a small fixed set of actions needed to understand the reader journey, such as opening the catalogue, selecting a case study, submitting an email address, completing its one-time code, opening the requested study and selecting “Book a demo”. Catalogue, reading and demo actions are aggregate measurements with no visitor or session identifier. The email-submission and code-completion checkpoints share only a keyed, challenge-local pseudonym; the completion event may then be linked to the separate marketing contact record. We do not put an email address, access token, full URL or arbitrary click data in an event.

We do not ask for, and do not want, government identifiers, payment card numbers, health information or any other special category of personal data. Please do not send them to us.

4. How we use information

We use personal information to:

  • provide the service — create and maintain accounts, deliver one-time sign-in codes, run analyses and produce reports;
  • keep it secure — detect and investigate abuse, automated attacks and unauthorised access;
  • improve it — understand which parts of the product are used, where they fail, and fix them;
  • communicate — answer questions, confirm bookings, send service and security notices, and send the material you asked for.

Entering an email address to receive a case study or one-time code does not subscribe you to promotional email. Any marketing consent is collected separately, remains optional, and can be withdrawn at any time. Current and former workspace-associated addresses are kept out of new case-study prospect capture. A person with an active customer workspace is classified from that workspace membership, not from their email domain or marketing-contact record.

Where the GDPR or the UK GDPR applies, we rely on performance of a contract for account and service data; on our legitimate interests in operating, securing and improving the service for server logs and product analysis; on consent where you have given it, which you may withdraw at any time; and on compliance with a legal obligation where one applies.

5. How we share information

We do not sell personal information. We do not share it for cross-context behavioural advertising. We use no advertising networks and run no advertising tracking of any kind.

We do share personal information with a small set of service providers, who process it only on our instructions and only to run the service:

  • Amazon Web Services — application hosting, database, object storage, the Cognito authentication directory, and operational logs and aggregate metrics in Amazon CloudWatch.
  • Cloudflare — the Turnstile bot challenge on protected forms, when enabled. Cloudflare processes visitor IP addresses in the course of that security check.
  • Amazon Simple Email Service (SES) — delivery of transactional email, including sign-in codes and confirmations.
  • OpenAI — AI processing of customer content, described in section 6.
  • jsDelivr, unpkg, cdnjs and d3js.org — deliver a small number of open-source JavaScript libraries used on the demo and parts of the product; each sees the visitor’s IP address and browser information for that request, in the way any static-asset host does, and none of them sets a cookie for us.

We may also disclose information to our professional advisers under a duty of confidentiality; where we are required to by law, subpoena or other legal process, or where disclosure is necessary to establish or defend legal claims or to protect someone’s safety; and to a successor entity in a merger, acquisition or sale of assets, in which case this notice continues to apply until it is replaced.

6. AI processing

Parts of the service use large language models to classify, summarise and structure work content. Two rules govern that processing.

Content we send to an AI provider is not used to train that provider’s models. We use commercial API endpoints under terms that exclude our data from model training.

The structured content we choose to send carries no direct identifiers. Job titles, task descriptions and the other structural facts an analysis needs go to an AI provider without a name, email address or employee identifier from our records; where the provider needs a stable reference for a survey respondent, we send a one-way cryptographic hash of it, not the identifier itself.

Free-text answers are transmitted as written. Respondents are instructed not to put names, employee identifiers or other personal details into free-text survey answers (section 3), but we do not scan or redact that text before it reaches an AI provider. If a respondent types a personal detail into a free-text answer, it is sent as typed.

Model output is an estimate. Plek presents it as an estimate, and it is reviewed before it becomes a customer’s decision.

7. Cookies and similar technologies

plek.ai sets first-party cookies that are strictly necessary for the site to work:

  • a session cookie, which keeps you signed in;
  • a CSRF token, which protects forms against cross-site request forgery.

Cloudflare sets a cookie of its own for bot management and security. It distinguishes a person from an automated client; it does not profile you.

There are no advertising cookies, no analytics cookies, no session replay and no tracking pixels on plek.ai. We do not follow you across other websites.

Some pages — the interactive demo and parts of the product — load a small number of open-source JavaScript libraries (for charts, maps and PDF export) from public code CDNs: jsDelivr, unpkg, cdnjs and d3js.org. We treat that the same way we treat loading a font or an image from a static host: the CDN operator sees the visitor’s IP address and browser information for that request, and none of them sets a cookie for us or receives any other information about you.

Global Privacy Control and Do Not Track. Because we run no cross-site tracking and no advertising, there is no sale, share or targeted advertising for a browser signal to switch off. We treat a Global Privacy Control signal as a valid opt-out request in any event: optional first-party page measurement and case-study measurement are disabled for that browser. Strictly necessary access, security and authentication records still operate; blocking the strictly necessary cookies listed above will stop sign-in from working.

8. Security

We use TLS for data in transit, access controls that restrict production data to the people who need it, and a managed hosting platform with a security layer in front of it. Accounts sign in with one-time codes rather than stored passwords.

We make no certification claim. Plek does not currently hold SOC 2, ISO 27001 or any comparable certification, and this notice will say so until that changes. No system is completely secure. If we become aware of a breach affecting personal information, we will notify the affected parties and the relevant regulators as the law requires.

9. Retention

We keep personal information for as long as it is needed for the purpose it was collected for.

  • Account and customer data — for the life of the account and the customer relationship, and afterwards only where a legal, accounting or dispute-related obligation requires it.
  • Server logs — for a limited operational period, long enough to investigate abuse and diagnose faults.
  • Product diagnostics — for a limited operational period, long enough to investigate application errors and performance problems.
  • Case-study email/code checkpoints — for 365 days, after which those pseudonymous event rows are automatically deleted. Aggregate catalogue, reading and Book-a-demo counters contain no visitor or session identifier and are operational metrics rather than contact history.
  • Case-study marketing contacts — the marketing contact record for an unverified address whose only interaction is the case-study gate is deleted after 30 days. A verified contact, consent record, account link, or an address given through the home-page form or the sign-in page follows the retention period for that purpose. A real enquiry or completed demonstration booking is retained separately for that purpose. Receiving a one-time code is not marketing consent.
  • Unconfirmed authentication profiles — requesting a code can create a separate profile in our authentication directory before verification. Profiles still unconfirmed after seven days are flagged for controlled review. They are not automatically deleted while a code could be in use; removal happens only after active verification has been stopped and allowed to expire.
  • Enquiry and demonstration records — while we are in contact and for a reasonable period afterwards.

Retention depends on the purpose, so there is no single period across the whole service. The 365-day case-study event limit and 30-day abandoned marketing-contact limit above are enforced automatically. You can ask us to delete information about you at pierre@plek.ai, and we will do so unless we are required to keep it.

10. Your rights

Depending on where you live, you have some or all of the following rights.

EEA, United Kingdom and Switzerland. Access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, withdrawal of consent, and the right to lodge a complaint with your supervisory authority.

California and other US states with comprehensive privacy laws. The right to know what we collect and how we use it, to obtain a copy, to correct it, to delete it, to opt out of sale, sharing and targeted advertising — none of which we do — and to limit the use of sensitive personal information, which we do not collect. Where state law gives you a right to appeal a decision on your request, you may appeal by replying to that decision.

We will not discriminate against you for exercising any of these rights.

Request deletion of your data. Briefly describe what you want deleted; we’ll verify your request and explain the next steps.

To exercise them, email pierre@plek.ai. We will verify the request, normally by confirming control of the email address it concerns, and respond within the period the applicable law allows. An authorised agent may act for you on written proof of authority.

If your request concerns workforce data or survey responses we hold for a customer, we act as that customer’s processor. Tell us, and we will pass the request to the customer and support their response.

11. International transfers

Plek is based in the United States and processes personal information there. Our service providers may process it in the United States and in other countries where they operate. Where personal information moves out of the EEA, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, together with the measures described in section 8.

12. Children

The service is a business tool. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. Any account must be opened by an adult acting for an organisation. If you believe a child has given us personal information, write to pierre@plek.ai and we will delete it.

13. Changes to this notice

We will update this notice when our practices change. The date at the top records the most recent change. Where a change materially affects how we handle personal information, we will give notice by email to account holders, or by a notice on the site, before it takes effect. Continued use of the service after that date means you accept the updated notice.

14. Contact

Questions, requests and complaints go to pierre@plek.ai. We read every one.

Plek Inc.
Delaware, United States

plek

[πλέκω] [verb] • Ancient Greek

To braid, to weave together.


Plek weaves AI into the fabric of your organization to generate value.

Platform

  • How It Works
  • Why Plek
  • Features
  • Case Studies
  • FAQ

Resources

  • Privacy Policy
  • Terms of Service
  • Security
  • Help & FAQ

Company

  • Sign In
  • Contact Us
  • LinkedIn
  • Careers
plek

© 2026 Plek Inc. All rights reserved.