Everyone on the list gets a free Mini Report at launch.
This policy covers plenary.life and the Plenary application. It is written to be read, not skimmed past. If anything here is unclear, ask us.
[Legal entity name], a [Delaware corporation] doing business as Plenary (“Plenary”, “we”, “us”), operates plenary.life and the Plenary application (together, the “Service”). Plenary is grant software for nonprofits: it maps the funding an organization can reach, scores its readiness, and drafts application materials for the organization to review and submit.
For most of what this policy describes we are the controller of your personal information. When we handle information inside an organization’s workspace on that organization’s instructions, we act as its processor — section 07 explains the difference and what it means for you.
Registered address: [Street address, City, State ZIP, Country]. Privacy questions: [privacy@plenary.life]. [If Verdex or another affiliate is a separate legal entity that processes data for the Service, name it here and describe its role.]
The summary is a guide. If it and the full policy ever disagree, the full policy applies.
Where the GDPR or UK GDPR applies, we need a legal basis for each use. The table shows the basis we rely on. If you are outside the EEA, UK, and Switzerland, the purposes still apply; the legal-basis column is there for completeness.
| Purpose | What that involves | Legal basis |
|---|---|---|
| Provide the Service | Accounts, organization profiles, funding search and match, readiness scores, reports, files, and the application workspace. | Performance of a contract |
| Draft materials in your voice | The Research and Resourcing layers build prompts from your profile and Customer Content to draft narratives, answers, and checklists for your review. | Performance of a contract |
| Radar alerts and digests | Deadline, match, and recommendation alerts, and the daily digest, sent by email or in the app. | Performance of a contract; consent for optional channels |
| Billing and administration | Subscriptions, invoices, receipts, tax records, and account changes. | Performance of a contract; legal obligation |
| Support | Answering your questions, investigating problems, and telling you about changes that affect you. | Performance of a contract; legitimate interests |
| Security and abuse prevention | Authentication, logging, fraud detection, rate limiting, and enforcing our Terms. | Legitimate interests; legal obligation |
| Product improvement | Aggregated usage analytics to see what is slow, confusing, or unused. You can opt out of analytics cookies. | Legitimate interests; consent where required |
| Marketing | Product news and offers by email. Every message has an unsubscribe link. | Consent; legitimate interests for existing customers |
| Legal compliance | Responding to lawful requests and meeting our obligations under tax, accounting, and privacy law. | Legal obligation |
We do not use your information to make decisions with legal or similarly significant effects on you without a person involved. Readiness scores and match rankings are recommendations you can act on or ignore.
Plenary uses large language models to score readiness, rank matches, and draft application materials. This section says exactly what that means for your information.
We share personal information only in the ways below. We do not sell it, we have not sold it in the preceding twelve months, and we do not share it for cross-context behavioral advertising. [Confirm — an advertising pixel can count as “sharing” under CCPA.]
Most people use Plenary through an organization’s workspace. The organization decides what goes into that workspace and who can see it, so for that information the organization is the controller and we are its processor. We handle it under our agreement with the organization and on its instructions.
In practice this means your organization’s admin can access, export, and delete workspace data, including content you created. [Confirm admins have these controls.] If you want to exercise a right over that data, ask your admin first. We will help them respond.
For information we decide how to use ourselves — account security, billing, product analytics, marketing to you — we are the controller, and everything in this policy applies directly.
We use a small number of cookies and similar technologies. Essential ones keep you signed in and the Service secure. Optional ones remember preferences, measure how the Service is used, and, if you allow them, support our own marketing. Each category, and how to turn the optional ones off, is set out in our Cookies and data policy.
We honor the Global Privacy Control browser signal as an opt-out of sale, sharing, and targeted advertising. We do not respond to browser Do Not Track signals, which have no agreed meaning.
We keep personal information only as long as we need it for the purposes above, then delete or de-identify it. The periods below are our defaults; a legal hold or a dispute can extend them.
| Information | Kept for |
|---|---|
| Account and organization profile | Life of the account + [30] days |
| Customer Content | Until you delete it; removed within [30] days, from backups within [90] days |
| Usage and device data | [14 months], then aggregated |
| Billing and tax records | [7 years], as accounting law requires |
| Support communications | [3 years] after the case closes |
| Marketing preferences and opt-outs | Until you change them |
We use administrative, technical, and physical safeguards designed to protect personal information, including [keep the ones that are true: encryption in transit and at rest, role-based access, multi-factor authentication for staff, access logging, vendor review]. [State your SOC 2, ISO 27001, or other audit status here, or remove this sentence.]
No system is perfectly secure. If a breach affects your personal information, we will notify you and any regulator the law requires, without undue delay. Security concerns can be reported to [security@plenary.life].
Plenary is based in the United States and stores data there, in [hosting region]. If you use the Service from the EEA, the UK, or Switzerland, your information is transferred to the United States and to the countries where our service providers operate.
For those transfers we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent Swiss safeguards, in our agreements with each provider. [If certified under the EU–US Data Privacy Framework, say so here; otherwise delete this sentence.] You can ask us for a copy of the safeguards that apply.
Wherever you are, you can access, correct, export, and delete your personal information, unsubscribe from marketing, and manage cookies. Some of this you can do yourself in Settings [confirm which self-service controls exist]; for anything else, email [privacy@plenary.life].
We verify requests by confirming the email on the account. We respond within 30 days, or 45 where a US state law allows it, and we will tell you if we need longer. There is no charge unless a request is plainly excessive. We never treat you differently for exercising a right. An authorized agent may make a request for you with your written permission.
Under the GDPR and UK GDPR you also have the right to restrict processing, to object to processing based on legitimate interests or used for direct marketing, to withdraw consent at any time without affecting what came before, and to lodge a complaint with your supervisory authority. We would rather hear from you first, but that is your choice.
EU representative: [Name, address, and contact of your Article 27 representative, if required]. UK representative: [Name, address, and contact, if required].
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, this section is your notice of the categories of personal information we collect and the rights you have. It should be read with sections 03, 04, 06, and 09.
| Category | Examples | Collected | Sold or shared |
|---|---|---|---|
| Identifiers | Name, email address, IP address, account ID | Yes | No |
| Customer records | Billing name and address, plan | Yes | No |
| Commercial information | Subscription and payment history | Yes | No |
| Internet or network activity | Usage data, device data, cookies | Yes | No* |
| Geolocation (coarse) | City or region inferred from IP address | Yes | No |
| Professional information | Role, title, organization | Yes | No |
| Inferences | Readiness scores, match rankings | Yes | No |
| Sensitive personal information | Account credentials[; add financial account details if you collect them directly] | Limited | No |
* If you turn on marketing cookies, the provider behind them may receive identifiers, which some state laws treat as “sharing”. Turn them off in the preference center, or send a Global Privacy Control signal, and no sharing takes place.
We use sensitive personal information only to provide the Service and secure your account, never to infer characteristics about you. We do not sell personal information, we do not offer financial incentives in exchange for it, and we do not knowingly sell or share the personal information of anyone under 16.
California residents may also ask, under the Shine the Light law, about disclosures of personal information to third parties for their direct marketing. We make none. Nevada residents: we do not sell covered information as that law defines it.
The Service is for organizations and the people who work with them. It is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 13, or under 16 where the GDPR applies. If you believe we have, tell us and we will delete it.
The Service links to funder websites and grant portals, and can connect to third-party tools you choose. Those services have their own privacy policies, and what you do there is governed by them, not by this one. Read them before you connect an account or submit an application.
We will update this policy as the Service and the law change. Every version carries its effective date at the top. For a material change we will email account owners or show a notice in the Service at least [14] days before it takes effect. Continuing to use the Service after that date means the new version applies.
[privacy@plenary.life]
[security@plenary.life]
[Legal entity name], Attn: Privacy
[Street address, City, State ZIP, Country]
[Name and contact, or “not appointed”]