Platform
Products
Pricing
Resources
Company
EN
EN
ES
MX
PT
FR
Log In
Get a Demo
EN
en
es
es
pt
fr
Demo
Platform
Products
Solutions
Pricing
Resources
Company
Log In
Security & Compliance
Object Storage
File Storage
Disaster Recovery
Remote Desktop
Servers
Wolters Kluwer
SAP Business One
SAGE
PHC
EBP
Cegid
Ahora
CSP
ISV
VAR
MSSP
MSP
Developer
System Admin
Sales
CTO
CEO
Contact us
Careers
Infrastructure
About us
Events
Documentation
Case Studies
Blog
Go to market
Marketplace
Cloud
By software
By partner type
By role
Company
Resources

Security Policy

Last updated: April 2026

1. Objetivo

O objetivo da presente política é estabelecer as diretrizes gerais e o compromisso da Direção para que a empresa faça uma gestão adequada da segurança da informação que trata.

Esta política constitui o quadro de referência do Sistema de Gestão da Segurança da Informação (SGSI), baseado na norma ISO 27001, existente na PLENIT, tendo em consideração os requisitos do Esquema Nacional de Segurança (ENS), do Código da Saúde Pública Francês, bem como do Código de Conduta da CISPE (Cloud Infrastructure Services Providers in Europe).

2. Âmbito e obrigações do pessoal

Esta política aplica-se a todos os sistemas de TI da PLENIT e a todos os membros da organização, sem exceção.

Todos os membros têm a obrigação de conhecer e cumprir esta Política de Segurança da Informação e a Regulamentação de Segurança associada.

3. Who are the groups of data subjects?

The personal data collected and processed may come from the following groups of data subjects:

  • Clients or Partners and End Users of the PLENIT Platform:
    • Companies that provided their data to formalize a service contract with PLENIT.
    • Administrators and End Users of the PLENIT Platform.
  • Suppliers:
    • Companies that share with us the necessary personal data to formalize a service contract (identification, contact, address, bank account, etc.).

4. What personal data do we process?

Whether as a data controller or processor, we handle different types of personal data, including:

  • Contact information, such as name, email address, and phone number.
  • User account information, such as username and password.
  • Payment information, including details of the physical and/or virtual card provided by PLENIT.
  • Profile information.
  • Information about product requests you wish to contract.
  • Usage information, such as the frequency of application use and the services accessed.

5. For what purpose and on what legal basis do we use personal data?

At PLENIT, we process personal data to respond to information requests, address your inquiries, or provide the contracted services.

This personal data is processed for the legitimate purposes outlined below.

5.1. PLENIT as Data Controller

Função Responsável na PLENIT Responsabilidades
Direção Direção É o responsável máximo pela implementação do Esquema Nacional de Segurança (ENS).
Responsável pela Informação Comité de Segurança É responsável pela proteção da informação e determina os requisitos de segurança da informação tratada.
Responsável pelo Serviço Comité de Segurança Determina os requisitos de segurança dos serviços prestados, de acordo com os parâmetros do Anexo I do ENS. Deve incluir as especificações de segurança no ciclo de vida dos serviços e dos sistemas, acompanhadas dos respetivos procedimentos de controlo.
Responsável pela Segurança Head of Security Determina as decisões de segurança necessárias para satisfazer os requisitos estabelecidos pelos responsáveis pela informação e pelos serviços. Analisa os relatórios de autoavaliação e/ou de auditoria e apresenta as conclusões ao Responsável pelo Sistema para que este adote as medidas corretivas adequadas.
Responsável pelo Sistema Head of Operations É responsável pela operação do sistema de informação, de acordo com as medidas de segurança definidas pelo Responsável pela Segurança. Adota as medidas corretivas adequadas na sequência dos relatórios de autoavaliação ou de auditoria apresentados pelo Responsável pela Segurança, com o apoio dos responsáveis de Engenharia e Infraestruturas.

5.2. PLENIT as Data Processor

Finalité Personnes concernées Catégories de données Base légale Période de conservation
Traitement effectué pour le compte d'un responsable du traitement dans le cadre de la prestation de nos services aux clients

La prestation des services fournis par PLENIT (le sous-traitant) à nos clients (les responsables du traitement) implique le traitement de données personnelles sous la responsabilité de nos clients.

PLENIT, qui fournit une plateforme pour la souscription de différents services ou produits technologiques, traite les informations pour le compte de ses clients, qui sont les responsables du traitement, et n'a aucune relation directe avec les personnes dont les données personnelles sont traitées. Si vous êtes un utilisateur d'un de nos clients, veuillez les contacter pour obtenir plus d'informations sur leur propre politique de confidentialité.
● Clients (Partenaires)
● Utilisateurs finaux
Données personnelles partagées par le Client sur la plateforme de PLENIT, en fonction du service souscrit. Exécution du contrat Les données seront conservées conformément aux termes de notre Contrat de Sous-traitance, signé avec chacun de nos clients.

6. How do we protect personal data?

At PLENIT, we implement technical and organizational security measures to protect your personal data and prevent its loss, misuse, unauthorized access, or disclosure. Some of the measures we take include data encryption, restricted access to personal data, and regular training of our staff on data protection.

PLENIT is ISO 27001 certified. This internationally recognized standard promotes a risk-based methodology that enables organizations to better manage information security. It demonstrates that companies have implemented an Information Security Management System audited by an independent expert evaluator.

7. How do we store personal data?

We store your personal data on secure cloud servers located within the European Union. We maintain technical and organizational measures to ensure the security of personal data and to prevent its loss, misuse, unauthorized access, or disclosure.

8. Who has access to your personal data?

PLENIT will only share your personal data with third parties when necessary to provide our services, when you have requested something that requires a response from us, or when we are legally obligated to do so.

We may also share data with companies that provide services essential to the ordinary and administrative activities of the company, acting as data processors, within the scope of services such as:

  • Payment and payment processing service providers.
  • Technology service providers, such as cloud hosting providers and data analytics services.
  • Legal and financial advisors.
  • Regulatory and governmental authorities, when necessary to comply with our legal obligations or when legally required by them.

8.1. International Data Transfers

Currently, we do not share data with providers located outside the European Economic Area (EEA), meaning no international data transfers are performed. This is also communicated to our clients in the Data Processing Agreement signed with each of them.

Additionally, as data controllers, we may share personal data among the different subsidiaries of the group, based on corporate legitimate interest. In cases where such activities involve countries within the EEA and our subsidiaries located outside the EEA, international transfers are carried out under contract, incorporating the Standard Contractual Clauses approved by the European Commission: https://eur-lex.europa.eu/legal-content/ES/ALL/?uri=CELEX:32021D0914

9. How can I exercise my rights regarding my personal data?

Anyone has the right to obtain information about the data that PLENIT processes under their ownership. These are your rights:

  • Data subjects have the right to access their personal data, as well as to request the rectification of inaccurate data or, where appropriate, request its deletion when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
  • Under certain circumstances, data subjects may request the restriction of the processing of their data, in which case it will only be retained for the exercise or defense of legal claims.
  • In certain circumstances and for reasons related to their particular situation, data subjects may object to the processing of their data. PLENIT will cease processing the data, except for compelling legitimate reasons or the exercise or defense of possible legal claims.
  • Portability: The data subject has the right to receive the personal data concerning them, which they have provided to PLENIT, in a structured, commonly used, and machine-readable format, where: a) the processing is based on consent or a contract, and b) the processing is carried out by automated means.

We inform you of your right to file a complaint with the supervisory authority (www.aepd.es) if the exercise of your rights as outlined here has not been fulfilled.

To exercise these rights, you can contact dpd@plenit.com. When making your request, please provide the following information:

  • Full name
  • Contact email address
  • The right you wish to exercise
  • Details of your request

We will resolve your request within a maximum period of one month, and you will be notified via the email address provided.

10. What is the retention period for your personal data?

We will retain your personal data for as long as necessary to provide you with our services or to comply with our legal obligations. When your personal data is no longer needed, it will be securely deleted or anonymized.

For specific retention periods, please refer to the tables in Section 5 of this Privacy Policy.

11. Changes to our Privacy Policy

We reserve the right to update this Privacy Policy at any time. If we make significant changes to this Privacy Policy, we will inform you by posting a notice on our application or website, or through other appropriate means.

12. Contact

If you have any questions or concerns about this Privacy Policy or how we handle your personal data, you can contact us at our postal address: Calle Leganitos n.º 47, planta 4 — 28013 Madrid, or send us an email at dpd@plenit.com.

‍

The AI-Powered Operating Platform for TSPs

See how Plenit can simplify your operations, boost your margins, and help you deliver modern services to every SMB you support.
Request a demo
Speak to an Expert
The Operating Platform
trusted by the IT Channel
Cloud
ServersRemote DesktopFile StorageObject StorageDisaster Recovery
GO TO MARKET
MarketingSalesLegalBilling
MARKETPLACE
Microsoft 365AcronisWatchGuardVeeamFortinet
Resources
BlogDocumentationCase StudiesEvents
Company
About usCareersPricingInfrastructureSecurity & Compliance
Get in touch
Request a demoContact us
Security
Follow us
App Privacy PolicyPrivacy PolicyCookies PolicyLegal NoticeTerms and Conditions
©2026 Plenit, all rights reserved.