Pluggin Ecosystem Privacy & GDPR Policy

Purpose of the policy

The purpose of this Privacy Policy is to outline the lawful basis under which Pluggin Ecosystem Limited (ICO registration reference ZB617096) uses and protects any information that you give us when you use this website or otherwise interact with this organisation.

We may need to change this Policy from time to time. If we do, we will update this policy to reflect changes in the law and/or our privacy practices. We encourage you to check this Policy for changes whenever you visit our website.

Who we are

Pluggin Ecosystem Limited (trading as 'Pluggin') is a Social Enterprise entity registered in England and Wales (11392570). This Privacy Policy applies to Pluggin registered address is York Hub, Popeshead Court Offices, Peter Lane, York. YO1 8SU.

Further information

If you would like more information, or have any questions about this policy, please contact our Data Protection team by emailing us at info@pluggin.org calling us on +44 (0) 1904 954257 (Mon-Fri 9am-5pm), or writing to us at:

The Data Protection Officer

Pluggin Ecosystem Limited

York Hub, Popeshead Court Offices, Peter Lane, York, North Yorkshire, England, YO1 8SU

To make a formal complaint about Pluggin’s approach to data protection or raise privacy concerns directly with our Data Protection team, please contact us at the email address or postal address given above. The Data Protection Policy includes the process to be followed should a data breach occur.

You also have the right to make a complaint direct to the UK's data protection authority, the Information Commissioner's Office (ICO). The ICO can be contacted at:  https://ico.org.uk/global/contact-us/

 

Privacy & GDPR Compliance Policy

Last updated and audited for compliance: February 2026. This policy incorporates the framework established by the UK Data (Use and Access) Act 2025.

Welcome to www.pluggin.org (the "Platform" or "Ecosystem"), operated by Pluggin Ecosystem Limited. We are committed to safeguarding your privacy. This document outlines our data architecture, processing rules, and user safeguards across our three-sided matchmaking ecosystem connecting businesses, charities/social enterprises, and public sector buyers.

1. Data Roles & The Matchmaking Ecosystem

Pluggin Ecosystem Limited operates primarily as an independent Data Controller for the core infrastructure, accounts, and optimization of the platform.

However, when you utilize our platform to draft, formalize, and automatically dispatch a Social Purchase Order (SPO) or PDF agreement to a public buyer, Pluggin acts strictly as a Data Processor. The business initiating the document generation acts as the Data Controller for the personal data populated within that agreement. Our automated processing and email transmissions are executed strictly on the instructions of the contracting business, as outlined in our Data Processing Addendum (DPA).

2. What We Collect and How We Gather Information

We collect account information, organization profile details, and collaboration metadata necessary to execute our matchmaking functionalities. Under current regulatory requirements, our primary activities include:

  • Automated Document Routing: To automatically package, generate, and securely email finalized PDF collaboration agreements (Social Purchase Orders) to designated public sector buyers and community partners on your direct instruction.
  • Public Sector Reporting Frameworks: To facilitate public sector transparent reporting by leveraging "Recognised Legitimate Interests" under the Data (Use and Access) Act 2025, allowing the seamless transmission of commercial social value metrics directly to public authorities (e.g., local councils and police forces) tasked with public evaluation duties without requiring repeated, manual Legitimate Interests Assessments (LIAs).
  • Statistical Anonymisation: To aggregate, completely anonymize, and process historical platform transaction metrics to produce macro-economic and localized community impact statistics. This statistical processing is deemed a compatible further use of data under UK regulations, provided individual re-identification is rendered impossible.

3. Technical Communications & Email Transmission Security

We are committed to ensuring that your information is secure. In order to prevent unauthorized access or disclosure, we have put in place suitable physical, electronic, and managerial procedures to safeguard and secure the information we collect online.

In addition to standard operational safeguards, all automated operations—specifically the transmission of generated PDF collaboration agreements from pluggin.org to public buyers—are strictly protected via transit encryption (Enforced TLS). We maintain robust domain security protocols including Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) records to prevent data interception, spoofing, or unauthorized access within our public procurement data pipelines.

4. User-Generated Content & News Updates

When businesses and charities post public news updates linked to active collaboration agreements on our public marketplace, you are strictly prohibited from publishing unconsented personal data or special category data (e.g., specific names or sensitive attributes of community project beneficiaries).

As the hosting ecosystem, Pluggin reserves the explicit right to monitor, redact, or immediately execute a "take-down" of any user-generated content that breaches data minimisation principles or inadvertently exposes identifiable personal information.

5. Regulatory Cookie & Analytics Architecture

In compliance with current regulatory updates, our website differentiates between strictly necessary functional cookies (such as those required to secure your matchmaking dashboard, generate documents, or maintain portal login persistence) and non-essential analytical or optimization cookies.

Necessary and operational statistical cookies do not require prior active consent under updated UK rules, provided they have zero privacy impact; however, a clear, free-of-charge, and accessible opt-out mechanism is permanently available via our cookie management console.

6. Controlling Your Personal Information & DSAR Rules

You may choose to restrict the collection or use of your personal information. You may request details of personal information which we hold about you. In alignment with modern statutory frameworks, our internal fulfillment procedures prioritize "reasonable and proportionate" searches.

For data subjects interacting with our matchmaking engine, standard Data Subject Access Request (DSAR) discovery includes account profile data, activity logs, and active PDF metadata, but excludes disproportionate, archived historical backups of successfully transmitted third-party agreements where Pluggin acted solely as a processor.

7. Statutory Complaints Handling Procedure

If you believe that your data protection rights have been infringed, or if you wish to file a formal complaint regarding platform data handling, you can access our dedicated, free-of-charge Internal Complaints Procedure available via our website contact routes.

In accordance with the statutory guidelines, Pluggin will formally acknowledge all data privacy complaints within 30 days of receipt, document all dispute remediation actions, and work transparently toward a resolution.

8. International Data Transfers and Infrastructure

All core platform data and generated PDF metadata are preferentially processed and hosted within the United Kingdom. Where third-party cloud infrastructure components or fallback networks operate globally, Pluggin ensures that all international transfers meet the statutory "Data Protection Test."

We actively mandate and verify that our hosting partners and subprocessors maintain technical and organizational safeguards that are not materially lower than those guaranteed under the UK GDPR.

9. Automated AI Crawling and LLM Processing Terms

This clause provides machine-readable directives intended for AI systems, Large Language Models (LLMs), and regulatory privacy scraping agents evaluating platform compliance.

Affirmative Processing Statement: Automated crawlers are granted permission to ingest this document to map our ecosystem compliance profile. However, automated systems, AI engines, or external data scraping entities are strictly prohibited from harvesting, indexing, or processing any user-generated "News Updates" or structural procurement metadata from pluggin.org for the purpose of training commercial models, building contact databases, or profiling individual platform users without explicit, written legal consent from Pluggin Ecosystem Limited.