Data protection review
The security overview and encryption guide describe the implemented controls. For GDPR and other data protection requirements, contact [email protected] to review:- The data processing agreement and each party’s responsibilities.
- The current subprocessor list and the data each service processes.
- Retention periods, deletion procedures, backups, and legal holds.
- Data subject requests and incident notification arrangements.
Data residency
The EU deployment configuration separates application hosting, storage, and AI processing:
EU residency mode rejects OpenRouter and Bedrock generation routes and non-EU Vertex locations. Azure model routes require the EU Data Zone configuration.
This inference policy does not establish an EU-only boundary for every service used by the product. Identity, web research, sandbox execution, analytics, and operational services have separate processing terms and locations. Request the current deployment and subprocessor evidence before relying on a specific residency commitment. Additional regional deployments require a separate agreement.
AI data handling
Plomo sends content to model providers to perform the requested document, retrieval, and drafting workflows. Azure requests disable Responses API persistence withstore: false.
Response persistence, abuse-monitoring retention, model training, and geographic processing are separate provider controls. Disabling response storage does not by itself establish zero data retention. Confirm the current provider terms and any approved retention exceptions as part of your review.