Data Processing Terms
Draft pending counsel review. This page is a skeleton, not an agreement. Highlighted items are open decisions, not final terms.
1.Roles of the parties
The Terms of Service say that, for records a customer stores about their own customers, patients or staff, PlugMySite processes them as the customer’s processor or service provider. This page is the draft of the terms that would govern that processing.
[PLACEHOLDER-FOR-COUNSEL: definitions of controller/business, processor/service provider and personal data under the laws counsel selects (for example GDPR, UK GDPR, CCPA/CPRA); which party is which for each service; the legal entity that signs]
2.Subject matter, duration, nature and purpose
[PLACEHOLDER-FOR-COUNSEL: subject matter of the processing, its duration (the term of the Terms of Service plus any return or deletion period), and its nature and purpose (providing the services the customer ordered)]
3.Types of personal data and data subjects
Depending on the services a customer uses, the product stores or handles: contact details (name, email, phone) of the customer’s own customers and leads; booking, order and invoice details; point-of-sale customer and loyalty records; text-message and email consent records; staff records for payroll and time-clock features; and health-related records in the dental and other healthcare dashboards.
[PLACEHOLDER-FOR-COUNSEL: final list of categories of personal data and data subjects, and whether any special-category or sensitive data is in scope; the dental and healthcare dashboards in particular, given that no business associate agreement exists]
4.Processing on instructions
[PLACEHOLDER-FOR-COUNSEL: PlugMySite processes personal data only on the customer’s documented instructions (the Terms, the customer’s use of the features, and written requests), and tells the customer if an instruction appears unlawful]
5.Confidentiality of personnel
[PLACEHOLDER-FOR-COUNSEL: obligation that people with access to personal data are bound by confidentiality]
6.Security measures
[PLACEHOLDER-FOR-COUNSEL: description of technical and organizational measures (Annex), written from a verified inventory and not from this draft]
See “Engineering facts for counsel” below for what the code does today.
7.Sub-processors
The current list of service providers is at /legal/subprocessors.
[PLACEHOLDER-FOR-COUNSEL: authorization model (general or specific), flow-down of obligations, advance notice of changes and the customer’s right to object]
8.Assistance with requests from individuals
The product has a privacy-request form that verifies the requester by email, records the request with a 30-day due date, applies a marketing opt-out immediately, and queues export and deletion requests for an administrator.
[PLACEHOLDER-FOR-COUNSEL: how PlugMySite assists the customer with access, deletion, portability and opt-out requests it receives about the customer’s data, and within what time]
9.Personal data breach
[PLACEHOLDER-FOR-COUNSEL: notification trigger, timeframe, contents and cooperation after a confirmed personal data breach]
10.Return and deletion
The product has tools to export and to erase a workspace’s data.
[PLACEHOLDER-FOR-COUNSEL: return or deletion on termination, the period after termination, and any legal-retention exceptions (consent and acceptance records are kept for the life of the account plus a counsel-approved limitations period)]
11.Audits and information
[PLACEHOLDER-FOR-COUNSEL: how PlugMySite shows compliance and what audit or questionnaire rights the customer has]
12.International transfers
[PLACEHOLDER-FOR-COUNSEL: processing locations, transfer mechanism (for example standard contractual clauses) and any supplementary measures; none is asserted here]
13.Liability and order of precedence
[PLACEHOLDER-FOR-COUNSEL: how this document relates to the Terms of Service, which prevails on a conflict, and how liability is allocated]
14.How this is accepted
[PLACEHOLDER-FOR-COUNSEL: whether this is incorporated by reference in the Terms of Service or signed separately, and how acceptance is recorded]
Engineering facts for counsel
These statements describe what the code does on 2026-10-09. They are inputs for counsel, not promises, and they are not a description of security measures.
- Stored payment-provider keys, Instagram and other access tokens, and SSN/EIN values are encrypted in the application before they are written to the database. Other columns, including the tenant API key and other personal data, are not field-encrypted, and the database as a whole is not separately encrypted by PlugMySite.
- AI providers are split by policy: only providers marked as allowed receive a customer’s business data (OpenRouter paid models with data collection denied, or an operator-run model); the free-tier providers receive public information only. The retention and training terms of the upstream AI providers have not been verified.
- No business associate agreement exists with any AI, email or SMS provider.
- Error reports sent to Sentry are scrubbed of known sensitive fields; objects passed to server logs and third-party log lines are not scrubbed, only log strings.
- Consent and acceptance records are append-only, hash-chained and kept when a workspace is erased.