Privacy Policy
This Privacy Policy describes how PLCs.ai, Inc. ("PLCs.ai," "we," "us," or "our") collects, uses, shares, and protects information in connection with the PLCs.ai platform, including the cloud-based web application known as plcsai-cloud, the desktop companion application known as plcsai-rva, and our website at plcs.ai (collectively, the "Service").
PLCs.ai is a business-to-business (B2B) platform. Most of the data we process on behalf of our business customers is provided by them and is subject to the agreement between PLCs.ai and the business customer (the "Customer Agreement," which includes our Terms of Service and, where applicable, a Data Processing Addendum). This Privacy Policy describes our general data practices and our commitments to data subjects. Where the Customer Agreement addresses a topic differently, the Customer Agreement controls for that customer.
We do not train any machine-learning model on Customer Content, including PLC files or AI outputs.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
We support data-subject rights under the GDPR, CCPA and TDPSA and will honor reasonable requests.
Scope
This Privacy Policy applies to information we process when:
- you visit our website;
- you create an account, sign in, or use the Service;
- you communicate with us by email or through a support channel;
- you attend a webinar, event, or demo hosted by us.
This Privacy Policy does not apply to third-party websites or services that link to or from the Service; those are governed by their own privacy policies.
Our Roles
Information We Collect
We collect the categories of information described below. Not every category applies to every individual or every customer.
- name, work email address, employer, profile picture and job title – directly from you or from third parties such as Google, Microsoft and Github;
- authentication credentials (hashed passwords, SSO identifiers, MFA tokens);
- account role and permissions.
- billing contact, billing address, purchase-order details;
- payment method details (processed by our payment processor — Stripe, Inc.).
- log and event data, such as API calls, feature events, session duration, error codes, and stack traces;
- device and environment data, such as operating system, browser or application version, IP address, device identifiers, and language;
- performance telemetry from plcsai-cloud and plcsai-rva (latency, throughput, error rates) that does not include the contents of PLC files or AI outputs.
- the contents of support tickets, chat messages, emails to support@, security@, privacy@, and sales@ (where lawful and disclosed), and voluntary feedback;
- marketing preferences and engagement (e.g., whether an email was opened or a link clicked).
How We Use Information
We use information for the following purposes. For personal information of EU/UK/Swiss data subjects, we have identified the GDPR legal basis in brackets.
- provide, operate, maintain, and secure the Service;
- authenticate Authorized Users, administer subscriptions, and provide customer support;
- respond to inquiries, send service announcements, and provide product updates;
- generate AI outputs requested by the business customer or Authorized User;
- use of strictly necessary cookies on the Service.
performance of a contract and our legitimate interests in providing you with the Service, contacting you regarding administrative issues related to the Service, this Privacy Policy, our Terms, support and maintenance.
- detect, investigate, and respond to security, fraud, or abuse events;
- maintain logs sufficient to support investigations.
legitimate interests in defending and enforcing against violations and breaches that are harmful to our business; legitimate interest in complying with mandatory legal requirements imposed on us.
No training on Customer Content. We do not use Customer Content — including PLC files, prompts, or AI outputs — to train, fine-tune, or otherwise improve any machine-learning model, whether general-purpose or customer-specific. This commitment applies to all customers on every pricing tier.
We may use aggregated and de-identified Usage Data (technical and operational data from the Service that does not identify Customer or any individual — e.g., performance metrics, error logs, feature-usage counts) to analyze trends, diagnose performance, and develop new features. We may also use support communications and voluntarily-provided feedback (which is not Customer Content) to improve the Service.
legitimate interests in developing and enhancing our business and the Service, responding to your support communications and voluntarily-provided feedback.
- send marketing communications to prospects and customers, subject to applicable opt-out rights and consent obligations where required;
- use of non-essential cookies on the Service.
explicit consent where required or consent via soft-opt in, where allowed.
- comply with applicable law, regulation, court orders, and lawful requests from public authorities;
- enforce the Customer Agreement and protect the rights, property, and safety of PLCs.ai, our customers, and others;
- enabling a structural change in the operation of the Service and our business.
legitimate interest in complying with mandatory legal requirements imposed on us; legitimate interests in defending and enforcing against violations and breaches that are harmful to our business; legitimate interests in our business continuity.
Legal Bases (GDPR)
Where the GDPR or UK GDPR applies, our legal bases for processing personal information are: (a) performance of the contract with you or your employer; (b) our legitimate interests (including operating and improving the Service, securing the Service, and marketing), balanced against your rights; (c) your consent (which you may withdraw at any time); and (d) compliance with a legal obligation. Where we rely on legitimate interests, we are happy to explain the balancing test on request, as described in Section 4.
How We Share Information
We share information only as described below. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
International Transfers
PLCs.ai is based in the United States, and information we process is typically hosted on cloud infrastructure located in the United States. If you are located outside the United States, your information will be transferred to and processed in the United States or in other countries where our Subprocessors operate.
For transfers of personal information out of the European Economic Area, the United Kingdom, or Switzerland to countries not recognized as providing an adequate level of protection, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Our Data Processing Addendum (which includes the Standard Contractual Clauses) is already in effect and applies automatically; customers that require a signed copy may request one at privacy@plcs.ai.
Data Retention
We keep personal information only for as long as needed for the purposes described in this Privacy Policy, or as required by law. Retention periods are aligned to SOC 2 Type II audit requirements and applicable legal obligations:
| Category | Typical Retention | Notes |
|---|---|---|
| Account and identity information | Term of subscription + 60 days | Held in archive for retrieval; purged from active systems after 60 days. Retained longer if required by law. |
| Billing records and invoices | 7 years | Required by U.S. tax and accounting rules. |
| Customer Content (PLC files and AI outputs) | 60 days | On contract termination: retained in archive for 60 days, then purged from active systems and backups (normal rotation). On an explicit deletion request: deleted without undue delay, within 30 days; not archived. Retained longer if required by law. |
| Prompts and AI outputs (conversation history) | Until you delete them or your account | Stored as part of your conversation history to provide the service. Deleted when you delete them, on request, or on account/contract termination, as described for Customer Content above. |
| Usage Data and product telemetry | 12 months (identified) / indefinitely (aggregated) | Aggregated data is genuinely non-reversible and cannot re-identify a customer or individual. |
| Support and other inbound communications | 3 years | Includes support tickets and emails to support@, security@, privacy@, and sales@. Used for ongoing support, security disclosure tracking, and quality improvement. Extended where needed for active investigations or legal hold. |
| Marketing records | Until unsubscribe; suppression list maintained indefinitely | Suppression list maintained indefinitely so unsubscribes are honored permanently. |
| Security/audit event records and incident-response records | 24 months | Security/audit events held in a dedicated store with a 24-month TTL, plus incident-response records; aligned to SOC 2 Type II audit needs. Extended where needed for active investigations or legal hold. |
| Operational and security logs | 365 days | Uniform retention across all logs; logs contain no direct identifiers, only internal pseudonymous identifiers. Extended where needed for active investigations or legal hold. |
If a legal hold, pending dispute, or regulatory obligation requires longer retention, we will keep the relevant records for the required period.
Your Rights
You have the right to review the personal information we collect and use about you and the right to request correction of your personal information. Depending on where you live and how we process your information, you may have some or all of the following rights:
Receive a copy of your personal information that we process.
Correct inaccurate personal information we have concerning you and have incomplete personal information completed.
Easily and at any time withdraw your consent to marketing communications or non-essential cookies. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
Receive the personal information you provided to us in a structured, commonly used, and machine-readable format, and transmit it to another person or entity.
Object to our processing of your personal information based on our legitimate interest. We may override the objection if we demonstrate compelling legitimate grounds or need to process for the establishment, exercise, or defense of legal claims.
Restrict us from processing your personal information in certain circumstances, including where you contest accuracy, where processing is unlawful, or where we no longer need the data.
Under certain circumstances, ask us to erase your personal information. We may still process it if necessary to comply with legal obligations or for the establishment, exercise, or defense of legal claims.
Subject to applicable law, you have the right to lodge a complaint with your local data protection authority. EU residents may lodge a complaint with the supervisory authority in their Member State of residence. UK residents may contact the Information Commissioner's Office (ICO).
To exercise any of these rights, contact us at privacy@plcs.ai. We may need to verify your identity before responding. If your personal information is held by PLCs.ai on behalf of a business customer, we will forward your request to the customer and cooperate with the customer's response.
In the prior 12 months, PLCs.ai has collected the categories described in Section 3 for the purposes described in Section 4 and shared them only with the categories of recipients described in Section 6. We have not sold personal information, and we have not shared personal information for cross-context behavioral advertising.
The source of information is the consumer themselves, their device or an acquaintance of the consumer (where a user provides content about another consumer).
The business purposes for which the information is used are: (i) helping to ensure security and integrity to the extent the use of the consumer's personal information is reasonably necessary and proportionate for these purposes; (ii) debugging to identify and repair errors that impair existing intended functionality; (iii) maintaining or servicing accounts, providing the service and customer service, processing or fulfilling transactions, verifying customer information, processing payments, providing analytic services, providing storage, or providing similar services on behalf of the business; and (iv) undertaking internal research for technological development and demonstration.
California and Texas residents have the following rights:
Knowing the personal information we collect about you and to obtain the personal data in a readable format
You have the right to know:
- The categories of personal information we have collected about you.
- The categories of sources from which the personal information is collected.
- Our business or commercial purpose for collecting personal information.
- The categories of third parties with whom we share personal information, if any.
- The specific pieces of personal information we have collected about you.
Right to delete personal data provided by or obtained about you
Subject to certain exceptions, on receipt of a verifiable request from you, we will delete your personal information from our records and direct any service providers to delete your personal information from their records.
Please note that we may not delete your personal information if it is necessary to:
- Complete the transaction for which the personal information was collected, fulfill the terms of a written warranty or product recall, provide a good or service requested by you, or otherwise perform a contract between you and us.
- Help to ensure security and integrity to the extent the use of the consumer's personal information is reasonably necessary and proportionate for those purposes.
- Debug to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their right of free speech, or exercise another right provided for by law.
- Comply with the applicable privacy act.
- Engage in public or peer-reviewed scientific, historical, or statistical research that conforms to all other applicable ethics and privacy laws, when deletion is likely to render impossible or seriously impair the ability to complete such research, provided we have obtained your informed consent.
- Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us.
- Comply with an existing legal obligation.
We also will deny your request to delete if it proves impossible or involves disproportionate effort, or if another exception to state privacy laws applies.
Right to correct inaccurate personal information
If we receive a verifiable request from you to correct your information and we determine the accuracy of the corrected information you provide, we will correct inaccurate personal information that we maintain about you. We may deny your request to correct in the following cases:
- We have a good-faith, reasonable, and documented belief that your request to correct is fraudulent or abusive.
- We determine that the contested personal information is more likely than not accurate based on the totality of the circumstances.
- Conflict with federal or state law.
- Other exception to state privacy laws.
- Inadequacy in the required documentation.
- Compliance proves impossible or involves disproportionate effort.
Protection against discrimination for exercising these rights
You have the right not to be discriminated against by us because you exercised any of your rights under state privacy laws.
Exercising your rights by yourself or through an authorized agent
To exercise any of your rights, contact us at privacy@plcs.ai. We will ask you for additional information to confirm your identity before disclosing the personal data requested, using a two or three point data verification process depending on the type of information you require.
You may also designate an authorized agent to make a request on your behalf by providing the agent with written permission to do so. The agent will need to submit proof to us that they have been authorized by you, and we will also require that you verify your own identity.
Cookies and Similar Technologies
We use cookies and similar technologies (such as local storage and pixels) to operate the Service, remember your preferences, analyze traffic, and measure campaign performance.
Required to deliver the Service (e.g., authentication, CSRF protection). Cannot be disabled.
Help us understand how the Service is used so we can improve it.
Used on our marketing website only, not inside the Service.
You may opt out from the use of non-essential cookies or consent to their use (dependent on your region) via our cookie banner.
Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including:
- role-based access controls, MFA for administrative access, and audit logging;
- secure software development practices, including code review, dependency scanning, and static analysis;
- background checks for personnel with access to production systems, subject to local law;
- incident-response procedures, including notification to customers in accordance with the Customer Agreement and applicable law.
No security program is perfect; if you believe a security vulnerability exists in the Service, please report it at security@plcs.ai.
Children
The Service is not directed to individuals under the age of eighteen (18), and we do not knowingly collect personal information from children under thirteen (13). If you believe we have collected such information, contact us at privacy@plcs.ai and we will delete it.
Automated Decision-Making
The Service uses artificial intelligence and machine-learning models to generate AI Outputs. These are productivity suggestions for review by our customer's engineers and do not produce decisions that have legal or similarly significant effects on individual data subjects. We do not use personal information to make solely-automated decisions of that kind.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make a material change, we will notify affected users by email or through the Service at least 30 days in advance. The version number above reflects the current version.
How to Contact Us
For privacy questions, rights requests, or a Data Processing Addendum, please contact: