Privacy Policy
Last updated July 2026
This page summarizes how Plumbex handles personal data. It is a plain-language overview and will be superseded by our definitive privacy notice and any executed engagement agreement. It is not legal advice.
Information you give us
When you request access, we collect the name, firm, work email, and any details you choose to share. We use them solely to respond to your request and arrange a walkthrough. We do not sell this information or add you to a marketing list without your consent.
Data we access on an engagement
During a diligence engagement, Plumbex connects to a target’s systems on a read-only, least-privilege, time-boxed basis under the terms of the engagement agreement. Every record is isolated to a single engagement. We redact secrets and personal data from logs, and we encrypt data in transit and at rest.
We never train on client data
Data accessed during an engagement is used only to produce that engagement’s findings and report. It is never used to train models and never shared across engagements.
Retention and deletion
Engagement data is retained only as long as needed to deliver and support the report, then deleted on request. Our right-to-erasure process purges evidence and findings and records a non-personal proof that the deletion occurred.
Contact
Questions about privacy or a deletion request: privacy@plumbex.ai.