Privacy Policy
Plimsoll
1. Who we are and what this policy covers
Plimsoll (“Plimsoll”, “we”, “us”) enforces a published daily send ceiling on each sending domain and uses its own AI reply classifier to decide whether a domain's ramp continues. It provisions the domains and mailboxes that ceiling applies to.
Registered at 1204 E 6th St, Unit 3, Austin, TX 78702.
This policy explains how we handle personal data in two distinct capacities, which are governed by different rules:
| Whose data | Our role | Governed by | |
|---|---|---|---|
| Part A | Website visitors, prospects, people who contact us | Controller — we decide why and how | This policy |
| Part B | Recipient data in the customer's outbound campaigns | Processor — we act only on the customer’s documented instructions | This policy and the Data Processing Agreement signed with that customer |
Where the Data Processing Agreement (“DPA”) and this policy conflict in respect of Part B, the DPA governs.
Part A — When we are the controller
This part covers personal data we collect for our own purposes: running our website, responding to access requests, and communicating with prospective and existing customers.
A.1 What we collect
Information you give us. When you submit the access request form we collect your first name, last name, work email address and company name, together with the fact that you agreed to be contacted. If you email us or talk to us during evaluation or onboarding, we hold the content of that correspondence and any business contact details in it.
Information collected automatically. Our web server records the IP address the request came from, the user agent string, the pages requested, referring URL and timestamp. These logs exist to keep the site available and secure.
We do not knowingly collect special categories of personal data under Article 9 GDPR in this part, and the form should not be used to send us any.
A.2 Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Responding to an access request and evaluating fit | Form submissions, correspondence | Art. 6(1)(b) — steps at your request prior to a contract |
| Administering a customer relationship, billing, support | Contact details, correspondence | Art. 6(1)(b) — performance of a contract |
| Site availability, security, abuse prevention | Server logs | Art. 6(1)(f) — legitimate interest in operating a secure service |
| Direct outreach to business contacts about the service | Work email, company | Art. 6(1)(f) — legitimate interest in B2B marketing, subject to your right to object at any time |
| Meeting tax, accounting and legal obligations | Billing and contract records | Art. 6(1)(c) — legal obligation |
Where we rely on legitimate interest, we have assessed that interest against your rights and are able to provide the assessment on request.
A.3 How long we keep it
- Access requests that do not become customers: 12 months from last contact, then deleted.
- Customer contact and contract records: for the term of the agreement plus 6 years, to meet limitation periods and accounting obligations.
- Server logs: 30 days.
- Records of an objection or opt-out: retained indefinitely, so that we can honour it.
A.4 Your rights
If you are in the EEA or UK you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent is the basis. You may exercise any of these by writing to [email protected]. We answer within one month.
You also have the right to complain to a supervisory authority. If you are in the EEA you may complain to the authority in your country of residence or workplace; our EU representative is identified in section 5.
Part B — When we are the processor
The customer is the controller of every recipient record. Plimsoll processes recipient addresses and reply content on the customer's instructions and does not use either for its own outbound.
B.1 What we process, and why it is personal data
What Plimsoll handles on a customer's behalf.
- Outbound message metadata — Recipient address, sending domain, mailbox, timestamp and delivery result for every message sent through a Plimsoll domain. Read in order to enforce the ceiling and to attribute a reply.
- Reply content — The body and headers of replies delivered to a Plimsoll mailbox, read in order to classify the reply and to decide whether a domain's ramp continues.
Plimsoll never uploads, stores or enriches a prospect list. Addresses are seen at send time and retained only as the metadata described above.
B.2 What we do with it
Region. Sending, the mailboxes, the reply store and the review queue run on AWS in us-west-2. Reply classification and fine-tuning of the classifier run on Microsoft Azure in West US 3. Reply bodies stay in the United States.
Model provider. Free-text replies are classified by Azure OpenAI in West US 3 under zero data retention: Microsoft does not store reply content or use it to train any model. Header-matched replies are classified by rule without a model call. Classification decides every domain's ramp and runs for every customer.
Human review. Replies below the confidence floor are read by a named Plimsoll reviewer. Each read is logged and appears in the customer's audit export.
Suppression. Any reply classified as a removal request suppresses that address across every domain the customer operates, immediately and permanently, and the suppression cannot be lifted from the interface.
B.3 Models, inference and training
Where inference runs. Header-matched replies are classified by rule without a model call. Free-text replies are classified on Microsoft Azure in West US 3 by Azure OpenAI, under zero data retention; classification decides each domain's ramp and runs for every customer. The embedding pass, the classification queue and the reply store run on AWS in us-west-2. Both regions are in the United States.
Training. No customer's replies train a general model, and reply content sent to Azure OpenAI is neither stored nor used for training. Reviewed reply classifications are retained as a labeled corpus, detached from customer and recipient identifiers, and used only to fine-tune Plimsoll's own classifier on Azure Machine Learning in West US 3 through 2026 and 2027. A customer may opt out in domain settings.
Human review. The model classifies and never raises a ceiling. Below the confidence floor the reply holds that domain's ramp and a named reviewer reads it before anything moves.
B.4 Where the data sits
Amazon Web Services, us-west-2: sending infrastructure and mailboxes, EC2 for the embedding pass and the classification and review queues, and S3 for the reply store, the published ramp schedules and the labeled corpus.
Microsoft Azure, West US 3: Azure OpenAI for classifying free-text replies under zero data retention, and Azure Machine Learning for fine-tuning Plimsoll's classifier on the labeled corpus.
The customer's own sending tool, wherever they run it, which connects over SMTP or IMAP to mailboxes we operate.
B.5 Retention, deletion, and the limits of deletion
Reply bodies are held for 180 days and then deleted; the classification and its confidence score are kept.
Send metadata is kept for two years so a deliverability question can be answered after the fact.
Suppressions are permanent and survive cancellation, because an address that asked to be removed does not become sendable when a contract ends.
B.6 Requests from individuals whose data we process
A recipient may write to us directly. We will suppress the address across every customer domain within one business day and pass the request to the customer that sent to them.
Common provisions
5. International transfers
Plimsoll is incorporated in the United States and serves customers established in the EEA. Personal data transferred outside the EEA is protected by the European Commission’s Standard Contractual Clauses, together with a transfer impact assessment and the supplementary technical measures described in our security documentation. A copy of the clauses is available on request.
EU representative (Article 27 GDPR)
6. Security
We maintain measures appropriate to the risk, including encryption in transit and at rest, credentials scoped to the minimum necessary, access control on the principle of least privilege, isolation of each customer’s data, and audit logging of access to production systems.
We notify affected customers of a personal data breach without undue delay and, in any event, within 36 hours of becoming aware of it, with the information they need to meet their own notification duties.
7. Children
The service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.
8. Changes to this policy
We may update this policy. Material changes are notified to customers by email at least 30 days before they take effect, and the version number and date at the top of this page are updated in every case.
9. Contact
Privacy enquiries and general: [email protected]
Postal: Plimsoll, 1204 E 6th St, Unit 3, Austin, TX 78702