Pluria Privacy Policy

Last updated August 2026

1. Introduction

Welcome to Pluria. This Privacy Policy explains how Pluria International Inc. (“Pluria,” “we,” “us,” or “our”) collects, uses, processes, and protects your Personal Data when you use our services, including our mobile app and website. We are committed to safeguarding your privacy and the security of your information.

This Policy applies to all Users of our services, including employees of our Clients, account administrators designated as company representatives by Clients, and website visitors. By using our services, you acknowledge that you have read and understood this Privacy Policy.

This Privacy Policy outlines the types of Personal Data we collect, how we use and share it, and our practices for storing, protecting, and deleting it. It covers data collected through the Pluria app, website, email, WhatsApp, text messages, and other electronic communications sent via or in connection with our services.

Please note, this Policy does not apply to information collected by third parties—including service providers, business partners, or systems embedded in our platform. We recommend reviewing the privacy policies of such third parties before sharing your Personal Data with them.

Unless otherwise defined in this Privacy Policy, the terms used in capital letters shall have the meaning assigned to them under the TERMS OF SERVICE of the Pluria Platform (“Terms of Service ”).

2. Data Controller

The legal entity responsible for the collection, use, and processing of your Personal Data is:

Company Name: Pluria International Inc.

Address: 838 Walker Rd Suite 21-2, Dover, DE 19904, United States

Privacy Contact Email: [email protected]

3. Key Definitions

Personal Data:

Any information relating to an identified or identifiable natural person.

Data Subject:

The natural person to whom the Personal Data relates.

Processing:

Any operation performed on Personal Data, such as collection, storage, use, circulation, or deletion.

Authorization:

The prior, express, and informed consent of the Data Subject to carry out the Processing of their Personal Data.

Data Controller:

The natural or legal person who decides on the database and/or the Processing of the data.

Data Processor:

The natural or legal person who processes Personal Data on behalf of the Data Controller.

4. Scope of Application

For the purposes of this Policy, Pluria acts as the Data Controller for Personal Data collected from Users and visitors in connection with the use and access of its website, application and related domains. Additionally, Pluria is responsible for processing Personal Data for all applicable purposes described in this Privacy Policy.

This Privacy Policy applies to the Personal Data of the following individuals:
 

  1. Individuals who visit or interact with our Website, without necessarily maintaining a contractual relationship with Pluria;
  2. Clients who use our Services, as well as their representatives, designated points of contact, ultimate beneficial owners, controlling persons, or any individual acting on behalf of a Client;
  3. Service providers, including their representatives, points of contact, ultimate beneficial owners, controlling persons, or individuals acting on their behalf, who access the Pluria Website or Pluria Platform;
  4. Candidates applying for employment opportunities with Pluria;
  5. Business partners, their representatives, or individuals acting on their behalf;
  6. Individuals receiving marketing communications from Pluria;
  7. Individuals who engage with us through event registration, participation in trade shows, webinars, or conferences, or through any other form of communication, whether via email, social media, WhatsApp, phone, in person, or other electronic means.
  8. All entities and individuals who, by virtue of a written agreement, are required to accept this Privacy Policy.

Please review this Privacy Policy carefully to understand how Pluria collects, uses, and protects your Personal Data. If you do not agree with our policies and practices, you should refrain from using our Website, App, Platform, and Services. By accessing, downloading, registering with, and/or using our systems or services, you expressly consent to the processing of your Personal Data as described herein.

5. Personal Data We May Collect

Pluria collects and manages data necessary to provide and improve our services. This may include, when necessary:
 

  1. Identity Data: Full name, identification information and photograph.
  2. Contact Data: Personal and corporate email address, and landline and mobile phone numbers.
  3. Professional Data: The company you work for and your job title or position.
  4. Platform Usage Data: Information about the bookings you make (workspace location, date, and time), check-in and check-out history, Flexible Points consumption, and usage preferences.
  5. Technical Data: IP address, device type, operating system, browser information, app version, and other technical information generated when you interact with our Website or Application. This may include approximate country or city-level location, obtained from your IP address for limited application functionality.
  6. Location Data: Where the User grants the relevant device permission, the Pluria User App may access precise device location for location-based functionality, including proximity recommendations, distance calculations, maps, proximity-dependent check-in, and, where background location permission is granted, automatic check-in/check-out functionality. Precise device coordinates used for these purposes are processed on the User's device and are not transmitted to or stored by Pluria's backend systems.

6. Categories of Processed Data, Legal Bases, and Recipients

Pluria processes Personal Data in accordance with GDPR standards and all extant regulations in the jurisdictions in which it operates. The processing activities below are carried out either for the performance of a contract, to comply with legal obligations, on the basis of legitimate interests, or with the data subject’s consent, where required.

Below is a summary of the categories of data processed, the corresponding legal bases, and the third parties or processors with whom such data may be shared:

A. Account Registration

Data processed: Work email address, mobile phone number, first and last name, company name (Client), and User ID, optional user profile image.

Recipients: HubSpot (CRM and onboarding pipeline management – US/Germany)

B. User Authentication (Login)

Data processed: Work email address, User ID, authentication credentials or login tokens, and related login metadata. Where the User signs in using Google Sign-In, Pluria may process the User’s Google account identifier, email address, name, profile information made available by Google, authentication tokens, and related technical data strictly as necessary to authenticate the User and maintain secure access to the Pluria Platform.

Recipients: Mailchimp (The Rocket Science Group LLC) – bound by SCCs and DPA; no sale or trading of User data. Google LLC. (Firebase Authentication), for login-related push tokens and dynamic links (Global). Where the User signs in using Google, Google LLC (Google Sign-In) may also process Personal Data in accordance with its own terms and privacy policy. See also Section 6.N.

C. Log and Device Data (automatically collected)

Data processed: Device type, IP address, access timestamp, HTTP response, request metadata, app version.

Recipients: Internal Pluria systems only, unless otherwise specified. Posthog – analytics logs (EU) Google Firebase – mobile telemetry and push delivery (Global), Sentry/ Axiom for errors/logging.

D. Customer Queries and Service Use

Data processed: Name, email, company name, details of User inquiries, reviews, space bookings or cancellations.

Recipients: Pluria internal support teams. Railway (hosting and storage provider for service-related data). HubSpot (customer support ticketing/CRM), PostHog and MoEngage ( product analytics).

E. IP-Based Approximate Geolocation for Default City Suggestions

Data processed: IP address, used transiently, with the purpose of inferring an approximate country or city-level location, and the resulting suggested default Pluria city or general location.

Recipients: Internal Pluria systems only. This functionality relies on a locally hosted IP geolocation database provided by MaxMind. Pluria does not make external API calls to MaxMind, and does not transmit the user’s IP address for this purpose.

Retention: The IP address is not stored by Pluria for this specific purpose. Any technical logs that may also contain IP addresses are handled in accordance with the retention periods and purposes described in this Privacy Policy. Users may object to this processing at any time, pursuant to the “Data Subject Rights” section of this Privacy Policy.

F. Check-in / Check-out Information

Data processed: Check-in and check-out timestamps, booking identifiers, and related transaction information. Where proximity verification is required, the Pluria User App accesses precise device location locally to determine whether the User is sufficiently close to the relevant Space. Precise device coordinates used for this determination are not transmitted to or stored by Pluria's backend systems. Where the User has granted the required background location permission, device-based geofencing may also be used to trigger automatic check-in or check-out for relevant bookings. Pluria receives the resulting check-in/check-out action and related booking information, but not the precise coordinates that caused the geofence event.
Legal basis: Performance of a contract — check-in data enables invoicing and access to booked spaces.
Purpose: To determine whether location-dependent check-in functionality is available, record check-in/check-out activity, enable access where applicable, and support service delivery and invoicing.
Recipients:

  1. The User's employer (Client), for invoicing purposes.
  2. Space Providers, for access and service delivery.
  3. Railway (hosting of transactional logs).

G. Marketing Communications

Data processed: Name, email, phone number, company, User ID.

Recipients: Processors including Whatsapp Business, Callbell and MoEngage, Inc, all bound by appropriate DPAs and privacy safeguards.

H. Legal and Regulatory Compliance

Data processed: Name, email, phone number, booking details.

Recipients: Relevant authorities as mandated by law.

I. Audits and Business Analytics

Data processed: Name, contact details, usage data.

Recipients: Authorized auditors and regulators. Tableau (business intelligence dashboards — US/Germany)

J. Legal Claims and Rights Protection

Data processed: Contact details, account activity, booking records.

Courts, arbitrators, or competent legal authorities.

K. Technical and Performance Analytics

Data processed: Device type, OS, IP, usage logs, error reports.

Recipients: Authorized third parties, such as Posthog, Google Analytics, Hubspot, Meta Pixel, Sentry, Axiom and Hosting and CDN providers listed in this Privacy Policy. MoEngage, Inc. — Analytics platform used to understand user behavior, track engagement, and optimize user journeys for marketing and product improvement.

L. Hosting & Infrastructure Providers

Data processed: Any data stored, transmitted, or processed through Pluria’s cloud systems, including registration data, technical data, logs, performance data, booking information, and metadata.

Recipients: Railway (hosting infrastructure); Cloudflare, Inc. (security & CDN services).

M. Optional Messaging Integrations (OPT-IN ONLY)

Data processed: Name, phone number, message content, and associated communication metadata — only if the Client enables the WhatsApp Business integration.
Recipients: Meta Platforms, Inc. (United States) — solely for the purpose of connecting the Client’s WhatsApp Business account to the conversation inbox.

Important: Activation of this integration is entirely optional.
If the Client does not install or activate the WhatsApp/Meta integration, no Customer Data is shared with Meta Platforms, Inc.

N. Google Calendar Integration and Google User Data

Data processed: Where a User signs in using Google, Pluria may receive basic Google account information, including the User’s Google account identifier, name, email address, and profile picture. Where a Client, Partner Space, administrator, or User connects or authorizes a Google Calendar integration, Pluria may access and process Google Calendar data necessary to provide and maintain the integration, including calendar identifiers and names, room-to-calendar mappings, free/busy availability, and booking-related event details, such as event identifiers, titles, times, attendees, and status, for the calendars the relevant account holder chooses to connect.

Purposes: Pluria uses Google user data only to authenticate Users, manage User accounts, connect Pluria rooms or spaces to Google calendars, display and synchronize availability, and create, update, delete, sync, or troubleshoot booking-related calendar events.

Recipients: Pluria shares, transfers, or discloses Google user data only as necessary to provide, operate, secure, support, and maintain the Google Sign-In and Google Calendar integrations, including: (i) with Google, to authenticate the User or to read from or write to the connected Google Calendar as authorized by the relevant account holder; (ii) with Pluria’s hosting, infrastructure, security, and support service providers identified in this Privacy Policy, acting on Pluria’s behalf and subject to appropriate confidentiality, security, and data protection obligations; (iii) with the relevant Client, Partner Space, or authorized administrators, where necessary to configure, manage, support, or use the integration; and (iv) with legal, regulatory, or law enforcement authorities where required by applicable law. Pluria does not allow third-party service providers to use Google user data for their own purposes.

Pluria does not sell Google user data or use it for advertising, retargeting, creditworthiness or lending purposes, unrelated analytics, AI model training, generative AI, automated profiling, or any AI-related feature. Pluria does not provide Google user data to any AI service provider.

Revocation and deletion: Users may disconnect Google Calendar or revoke Pluria’s access through their Pluria settings, where available, or through their Google account permissions at https://myaccount.google.com/permissions. Upon disconnection or account deletion, Pluria deletes stored Google user data unless retention is required by law, necessary for security, fraud prevention, or legal claims, or otherwise permitted under this Privacy Policy.

Pluria’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

O. Payments and Billing

Data processed: Payment card details (tokenized), billing address, transaction identifiers, purchase history, subscription details, and related metadata necessary to process payments.
Recipients: Stripe, Inc. (United States) – Payment processor used to support self-serviced payments. Stripe processes payment information securely on Pluria’s behalf and in accordance with applicable PCI-DSS standards.

For further information regarding Railway services, visit: https://railway.com/legal/dpa 

For further information regarding Cloudflare services, visit: https://www.cloudflare.com/network

For further information regarding Google services, visit: https://firebase.google.com/terms/data-processing-terms

For further information regarding Hubspot services, visit: https://legal.hubspot.com/dpa

7. How We Use Personal Data

The collection and processing of your Personal Data enables Pluria to provide services that are responsive, secure, and tailored to your needs. We may use your Personal Data for the following purposes:

Service Delivery and Business Operations

We process your Personal Data to manage our relationship with you and deliver our services. This includes, but is not limited to:
 

  1. Entering into and performing contractual agreements;
  2. Responding to your inquiries and fulfilling your requests;
  3. Sending administrative or operational information (e.g., updates regarding the services);
  4. Managing customized contracts and, where applicable, services such as international access to workspaces;
  5. Conducting quality control and User satisfaction initiatives.
  6. Legal basis: This processing is necessary for the performance of a contract or to take steps at your request before entering into a contract.

Communications and Marketing (With Consent)

If you have provided your consent, we may use your Personal Data to:

  • Communicate with you about products, services, promotions, and events;
  • Invite you to participate in User surveys, campaigns, or promotional activities;
  • Analyze your feedback to improve our services.
  • You can withdraw your consent to marketing communications at any time.
     

Security and Fraud Prevention

We process Personal Data to help ensure the security of our services, including:

  • Protecting Pluria, its Users, partners, employees, and service providers;
  • Detecting and preventing fraud or other suspicious activity;
  • Analyzing IP addresses and transaction history to assess potential risks or respond to legal inquiries.
  • Where necessary, relevant data may be shared with clients, partners, or public authorities.

Website and Platform Optimization

We use Personal Data to operate, maintain, and improve our digital platforms, including:

  • Managing the Website and App functionality;
  • Understanding how Users interact with our services;
  • Ensuring content is presented effectively across different devices.

This is done based on our legitimate interest in optimizing User experience and system performance.

Legal and Regulatory Compliance

We may process Personal Data as required to:

  • Fulfill legal obligations, including compliance with financial, tax, labor, and anti-fraud regulations;
  • Conduct background checks where necessary (e.g., KYC procedures);
  • Respond to requests from regulatory authorities or law enforcement;
  • Enforce our Terms of Service and protect our legal rights and interests.

Aggregated and Anonymized Data for Business Intelligence

We may anonymize or aggregate Personal Data so that it no longer identifies individuals. Such data may be used for:

  • Internal reporting, analytics, and research;
  • Market research and statistical analysis;
  • Sharing with existing or potential clients, business partners, affiliates, and service providers for legitimate commercial purposes.

Marketing and Event-Related Communications

Subject to applicable laws and consent requirements, we may use your Personal Data to:

  • Inform you about new services, features, or promotions;
  • Invite you to participate in events, webinars, or User engagement initiatives;
  • Improve the efficiency of our marketing strategies and communications.

This processing may rely on your consent, our legitimate interest in promoting our services, or the need to fulfill our contractual obligations.

Partnerships and Perks

Pluria may collaborate with third parties to offer value-added services or perks. In such cases, we may share relevant Personal Data—including contact details, transaction history, and other identifying information—with trusted partners to facilitate access to these offerings. Such sharing will occur only where appropriate safeguards are in place.

Other Uses Based on Your Consent

We may use your Personal Data for other purposes, but only where you have explicitly provided consent for such use. You may withdraw your consent at any time, without affecting the lawfulness of processing prior to withdrawal.

8. Account Setup and User Identification

Your account on the Pluria User App is created based on Pluria’s direct contractual relationship with your employer or contracting entity.. Under this agreement, Pluria receives your work email—and indirectly, your name and surname—via a secure, encrypted connection, enabling us to set up your User account.

After downloading the app, you will receive a verification code at your work email. Entering this code is required to activate your account; without it, access will be denied. A new code is sent each time you log in. These emails may be sent by a third-party processor under contract with Pluria and in full compliance with data protection laws.

Once your profile is completed in the "My Account" section, your Personal Data (e.g., name, phone number) remains unchanged unless you update it. Only the Client, as the holder of the email domain, may request changes to your email address. Account termination is subject to the Pluria User App Terms and Conditions.

9. Google Calendar Integration Functionality

The Pluria Platform may also include integrations with Google Calendar where enabled or authorized by a Client, Partner Space, administrator, or authorized User. These integrations are used to connect rooms or spaces to calendars, display or sync availability, and create, update, or manage booking-related calendar events. Pluria processes Google Calendar data only as described in the “Google Calendar Integration and Google User Data” section of this Privacy Policy.

10. User Reviews and Communications Submitted via the Pluria Application

Your feedback—such as reviews and ratings of workspaces—is valuable to our Partner network. If Pluria intends to share a review or rating that personally identifies you, we will do so only after obtaining your explicit consent. In all other cases, anonymized or aggregated reviews that do not allow for your identification may be shared with our Partners without requiring prior consent.

In certain instances, it may be necessary to share the content (or excerpts) of your requests with our Partners (e.g., the Spaces) in order to address or fulfill your inquiry. In such cases, the information will be anonymized in advance to prevent any possibility of personal identification. Should it become necessary to share identifiable Personal Data with a Partner, we will notify you in advance and seek your explicit consent prior to doing so.

11. Location-Based Functionalities of the Pluria User App

The Pluria User App may process location-related information for the purpose of providing certain location-based functionalities. Such processing may involve: (i) precise device location made available through the User's device, subject to the User having granted the relevant device permission; and/or (ii) approximate location inferred from the User's IP address, as further described below.

Precise Device Location

Where the User has granted the relevant location permission through the device operating system, the Pluria User App may access precise device location, including coordinates made available through the device's location services.

Precise device location may be used within the App to provide functionality including:

  • determining the nearest or most relevant Pluria city;
  • identifying, sorting, and displaying nearby Spaces and their approximate distance from the User;
  • displaying the User's current position on maps;
  • determining whether the User is sufficiently close to a Space to access proximity-dependent functionality, including manual check-in; and
  • enabling location-based automatic check-in and check-out functionality, where applicable and where the required device permissions have been granted.

For Pluria's proximity calculations, distance-based functionality, nearest-city determination, and check-in eligibility logic, the User's precise coordinates are processed on the User's device. The User's precise coordinates are not transmitted to or stored by Pluria's backend systems.

Notwithstanding that precise device coordinates are processed on the User's device, Pluria may process information resulting from such location-based functionality. For example, the App may use the User's location locally to select a relevant city or determine whether a check-in action is available. Where a User checks in or checks out, or where an automatic check-in or check-out is triggered, Pluria receives and processes the resulting booking or check-in/check-out information, but not the precise device coordinates used to make the proximity determination.

Background Location and Automatic Check-In/Check-Out

Where supported by the User's device and where the User has granted the required background location permission, the Pluria User App may use geofencing to support automatic check-in and check-out for relevant bookings.

For this functionality, the App may register geographical areas around relevant Pluria Spaces with the device's location services. The device's location services may detect entry into or exit from such geographical areas and, where the applicable conditions are satisfied, enable the Pluria User App to initiate the corresponding automatic check-in or check-out functionality.

This background functionality does not involve transmitting the User's precise coordinates to Pluria's backend. Pluria's backend receives the resulting check-in or check-out action and related booking information rather than the precise coordinates that caused the geofence event.

Pluria does not use this functionality for the purpose of creating a continuous history of the User's movements or a profile based on the User's precise location over time.

User Control and Device Permissions

Users retain control over precise device location permissions through their device operating system. Depending on the device and functionality, Users may grant different levels of location access, including access while using the App or background location access.

Users may deny or withdraw location permissions through their device settings. If location permission is denied or withdrawn, location-dependent functionality may become unavailable or less relevant. For example, the App may be unable to sort Spaces based on the User's current distance, show the User's current position, determine whether proximity-based check-in is available, or provide automatic check-in/check-out functionality.

Withdrawing precise device location permission does not prevent the User from accessing Pluria functionality that does not require precise device location.

IP-Based Approximate Location for Default City Suggestions

Separately, when a User opens the Pluria User App, Pluria may use the User's IP address to infer an approximate country or city-level location for the limited purpose of suggesting a default Pluria city within the Application.

This IP-based functionality is approximate and does not determine the User's precise device location. It is based on the User's IP address and does not use GPS, Bluetooth, Wi-Fi triangulation, or other device-based precise location technologies.

The IP address is not stored by Pluria for this specific purpose and is not used through this functionality to track the User's movements or location over time.

For this functionality, Pluria uses a locally hosted IP geolocation database provided by MaxMind. Pluria does not make external API calls to MaxMind for this purpose, and the User's IP address is not transmitted to MaxMind in connection with this functionality.

The IP-based functionality operates separately from precise device location permissions and does not replace or override those permissions.

Third-Party Technologies

Pluria is not responsible for any location data processed independently by external service providers, device operating system providers, or third-party applications, including Google, Apple, or other providers that may process location information under their own terms and privacy policies.

Where the Pluria User App relies on device operating system permissions, maps, or other third-party technologies to enable location-related functionalities, such third parties may process information independently in accordance with their own legal responsibilities and privacy policies.

12. Affiliated Entities

Pluria may share Personal Data with its affiliated companies for operational and service-related purposes. This may include:
 

  1. Supporting affiliated entities in delivering services on behalf of Pluria;
  2. Coordinating shared resources or activities;
  3. Engaging in direct marketing initiatives, where legally permitted.
     

Any such sharing is subject to applicable local laws and appropriate safeguards. For example, Personal Data related to customers, service providers, partners, representatives, prospective employees, or website visitors may be shared among affiliates as described in this Privacy Policy and relevant data protection terms.

13. Fraud Prevention and Protection of Legal Rights

We may disclose Personal Data to regulatory, judicial, or law enforcement authorities, or to our legal, financial, and cybersecurity advisors or investigators, in the following circumstances:
 

  1. When we believe it is necessary to investigate, prevent, or respond to suspected illegal activity, fraud, abuse of our Platform or Services, or security threats (e.g., unauthorized access, denial-of-service attacks, spamming);
  2. To protect the rights, property, or safety of Pluria, its affiliates, customers, service providers, employees, and partners;
  3. To enforce our Terms of Service, Privacy Policy, or comply with applicable laws;
  4. To pursue available legal remedies or mitigate potential damages;
  5. To support litigation or other legal claims and defenses.


Where appropriate, we may share relevant Personal Data with trusted partners or authorities to support these objectives.

14. Data Subject Rights

As the Data Subject, you have the following rights regarding your Personal Data:
 

  1. Right to Access, Update, and Rectify: You have the right to access your Personal Data and request the correction or update of any partial, inaccurate, incomplete, or misleading information.
  2. Right to Request Proof of Authorization: You may request proof of the consent you granted for the processing of your data.
  3. Right to Be Informed: You have the right to be informed about the use of your Personal Data.
  4. Right to Lodge a Complaint: You may file complaints with the relevant data protection authority for violations of the law.
  5. Right to Deletion (Right to be Forgotten): You may request the deletion of your Personal Data when you consider that it is not being processed in accordance with the law, or when the data is no longer necessary for the purpose for which it was collected, provided there is no legal or contractual duty to retain it.
  6. Right to Revoke Authorization: You may revoke your consent for the processing of your data at any time, as long as it is not prevented by a legal or contractual provision.
  7. Right to Free Access: You have the right to access your Personal Data that has been processed, free of charge.
  8. Right to Data Portability: In certain circumstances, you have the right to receive the Personal Data you have provided to Pluria in a structured, commonly used, and machine-readable format.
  9. Right Not to Be Subject to Automated Decision-Making: Pluria does not make decisions based solely on automated processing—including profiling—that produce legal effects or similarly significant impacts on you.
  10. Right to Lodge a Complaint with a Supervisory Authority: If you believe that the processing of your Personal Data by Pluria is not in compliance with applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority.

Right to Rectification:

If you believe that any of the Personal Data we hold about you is incorrect, incomplete, or inaccurate, you have the right to request that it be corrected. To do so, please contact us at: [email protected]

Right to Object to Direct Marketing:

You have the right to object at any time to receiving direct marketing communications from us. You may unsubscribe by adjusting your preferences through the Pluria Application.

Right to Object to Processing Based on Legitimate Interests

Whenever Pluria processes any Personal Data based on its legitimate interests, including limited processing of IP addresses when making approximate default city suggestions, you have the right to object to such processing at any time. If you object, Pluria will stop processing the required Personal Data, unless it is required to do otherwise by law or relevant authorities.

To exercise this right, please contact us at [email protected]

Right to Deletion:

You have the right to request the deletion of your Personal Data in any of the following circumstances:
 

(a) The data is no longer necessary for the purposes for which it was collected or processed;

(b) You withdraw your consent (where the processing is based on consent), and there is no other legal basis for continuing the processing;

(c) You object to the processing based on our legitimate interest, and we cannot demonstrate that our interest overrides your rights, freedoms, or interests;

(d) The data has been processed unlawfully;

(e) Deletion is required to comply with a legal obligation.

Please note that the right to erasure is not absolute. Your request may be denied if:
 

(a) We are legally required to retain the data; or

(b) The data is necessary for the establishment, exercise, or defense of legal claims.

Additionally, in certain cases, the ability to delete Personal Data may be managed by the Client, who acts as Pluria’s contractual counterpart and facilitates your access to the Pluria Platform and User App, as described in this Privacy Policy and the Pluria Terms & Conditions.

To request the deletion of your Personal Data, please contact us at: [email protected]

Right to Restrict Processing

You have the right to request the restriction of the processing of your Personal Data in the following situations:

(a) You contest the accuracy of the Personal Data, and processing is restricted while we verify its accuracy;

(b) The processing is unlawful, but you prefer restriction of use instead of deletion;

(c) We no longer need the Personal Data for processing purposes, but you require it for the establishment, exercise, or defense of legal claims;

(d) You have objected to processing based on our legitimate interests, and processing is restricted while we assess whether our grounds override your rights and interests.

To exercise this right, please contact us by email at [email protected]

Right to Data Portability

If your Personal Data is processed based on your consent or in connection with a contract, you have the right to request that your data be transferred:

(a) Directly to you; or

(b) To another data controller of your choosing.

This right applies only to Personal Data that you have provided to us directly and actively. It does not apply to data that Pluria has generated or inferred independently.

To exercise this right, please send your request to [email protected]

Right to Lodge a Complaint with a Supervisory Authority:

If you believe that Pluria’s handling of your Personal Data does not comply with applicable data protection laws, you have the right to lodge a complaint with the relevant supervisory authority.

Before doing so, we kindly invite you to contact us first at [email protected], allowing us the opportunity to address your concerns and resolve any issues promptly.

15. Procedure for Exercising Your Rights

You may exercise your rights at any time and free of charge through the email account outlined in the previous section.

All requests must contain, at a minimum, the following information:
 

  1. Full name and identification number of the Data Subject.
  2. A clear and precise description of the Personal Data and the right you wish to exercise.
  3. Contact information to receive notifications (address and/or email).
  4. Documents proving identity or representation, if applicable.

16. Data Transfers

Third-Party Service Providers

We may share your Personal Data with carefully selected third-party service providers who assist in delivering functionalities or services related to the Pluria User App and Platform. These providers act on our behalf and process Personal Data strictly for the purposes described in Sections 6 and 7 above. All such third parties are subject to rigorous due diligence and are required to adhere to robust data protection standards, including through the execution of data processing agreements in accordance with Article 28 of the GDPR and/or all other applicable regulations.

Corporate Restructuring and Legal Audits

In the event of a business reorganization, merger, acquisition, or similar corporate transaction, your Personal Data may be disclosed to relevant third parties involved in such processes (including legal, financial, and technical advisors or auditors). In these cases, we ensure that such parties are bound by confidentiality obligations and are required to implement appropriate security measures. Access to Personal Data will be strictly limited to what is necessary for the purpose of the review or transaction.

International Data Transfers

At present, Pluria aims to store and process your Personal Data within the territory of the European Union. However, in cases where it becomes necessary to transfer Personal Data to partners, service providers, or subcontractors located outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place. These safeguards may include standard contractual clauses (SCCs) approved by the European Commission or other lawful mechanisms that ensure an adequate level of protection. If the recipient is located in a jurisdiction that does not provide an equivalent level of data protection, we will require the recipient to enter into a binding agreement that reflects the principles and protections consistent with EU data protection standards.

17. Data Retention

We retain the Personal Data we collect and process only for as long as there is a legitimate business need or as necessary to fulfill the purposes described in this Privacy Policy, including compliance with legal obligations and requests from regulatory or law enforcement authorities.

Personal data may be retained to meet statutory requirements, such as those related to tax, legal, or accounting obligations.

Once we no longer have a valid reason to retain your Personal Data—such as when our interactions have concluded, internal recordkeeping policies no longer require it, and there are no outstanding legal or regulatory obligations—we will securely delete or anonymize the data, in accordance with our data retention and disposal policies and subject to reasonable operational constraints.

IP-Based Approximate Geolocation

Pluria may access a User’s IP address to infer an approximate country or city-level location for the purpose of suggesting a default Pluria city. In such cases, the IP address is not stored by Pluria for this specific purpose. This, however, does not affect the retention of technical logs that may contain IP addresses for matters of security, fraud prevention or system performance. Such technical logs are retained only for as long as required to comply with the purposes set forth in this Privacy Policy.

User-Initiated Data Deletion

As a User, you have the right to request the deletion of your Personal Data at any time.

Because your account is created as a result of a direct contractual relationship between Pluria and your employer or contracting entity (the "Client"), the deletion process is as follows:
 

  1. You may submit a deletion request by contacting us at [email protected]
  2. Upon receiving your request, Pluria will notify the Client to coordinate the request, as the deletion of your data will affect the services provided under their corporate agreement. This coordination is for administrative purposes and does not affect your fundamental right to have your Personal Data erased.
  3. Following this coordination, we will proceed with the deletion of your Personal Data, unless we are required to retain it under applicable law or for the establishment, exercise, or defense of legal claims.

Please note that the deletion of your essential Personal Data will result in the permanent and irreversible deletion of your User account and will prevent you from accessing Pluria's services. Once an account is deleted, it cannot be restored.

Deletion Initiated by the Client

The Client (your employer) may also formally request the deletion of your account in accordance with the terms of their agreement with Pluria. In such cases, your User data will be deleted or anonymized.

Automatic Deactivation Due to Inactivity

User accounts that remain inactive for a period of twelve (12) consecutive months will be automatically deactivated. The associated Personal Data will be deleted or anonymized, meaning the data can no longer be linked to an identifiable individual, unless Pluria is required to retain it under applicable law or based on legitimate interests. Users will receive advance notice prior to account deactivation.

Data Processed with Consent

Any Personal Data that is processed based on your prior consent will be used exclusively for the purposes for which consent was granted. Such data will be retained only until you withdraw your consent, unless legal, regulatory, or investigatory obligations require us to retain it for a longer period, or where it is necessary to defend Pluria’s rights.

Anonymized and Aggregated Data

Pluria may retain certain information—including check-in/check-out data, booking records, and User IDs—in anonymized or aggregated form. This data is used for internal business and analytical purposes only and does not enable the identification of individual Users.

18. Security Measures and Confidentiality

Pluria adopts the necessary technical, human, and administrative measures to guarantee the security and confidentiality of your data and to prevent its alteration, loss, and unauthorized consultation, use, or access. All Personal Data you provide to Pluria will be managed confidentially and with the appropriate constitutional and legal guarantees.

19. Our Role as Data Controller and Data Processor

Pluria as a Data Processor

For the core services we provide to you as a User of our platform, your employer or the company that gives you access to our services (our "Client") is the Data Controller.

In this scenario, your employer determines the fundamental purpose of the data processing: to provide you with access to our network of flexible workspaces as a work-related benefit. To achieve this, your employer provides us with your essential data (such as your work email address) to create and manage your User account.

In this capacity, Pluria acts as a Data Processor. We process your Personal Data only on behalf of and in accordance with the documented instructions of your employer. Our relationship and data processing obligations are governed by a formal Data Processing Agreement (DPA) established between Pluria and the Client, ensuring that your data is handled securely and in compliance with applicable laws.

Pluria as a Data Controller

Pluria acts as a Data Controller for the Personal Data it collects and processes for its own purposes. This occurs in the following situations:
 

  1. When you visit our public website (www.pluria.co), we collect your data for analytics, website functionality, or our own direct marketing purposes.
  2. When we collect and process Personal Data from representatives of our prospective or existing Clients and Partners for the purposes of managing our business relationships and for sales and marketing outreach.
  3. When we process the Personal Data of candidates applying for employment opportunities directly with Pluria.
  4. When we generate and use anonymized or aggregated data for our own business intelligence, analytics, and service improvement.
     

In all scenarios, Pluria is committed to protecting your Personal Data and ensuring your rights are respected in accordance with this Privacy Policy and all applicable regulations.

Delegation of Data Processing Tasks

In all cases, we reserve the right to delegate certain processing tasks to a third party, always requiring them to implement suitable policies and procedures for the protection and confidentiality of Personal Data in accordance with applicable regulations.

20. Cookies and Other Web Technologies

Pluria uses cookies and similar tracking technologies across its Website, Application, and Platform to enhance functionality, improve User experience, and support analytics and marketing initiatives.

What Are Cookies and What Do We Collect?

Cookies are small text files stored on your device that collect data about your interactions with our digital services. The information we collect through cookies may include, but is not limited to, your login credentials, time zone, browser settings, and browsing behavior.

Why We Use Cookies

We use cookies for a variety of purposes, including:

  1. Enhancing your browsing experience and ensuring smoother navigation;
  2. Collecting anonymized, aggregated statistics about usage of our Website, Application, and Platform;
  3. Analyzing navigation patterns and search behavior to improve our services and promotional efforts;
  4. Displaying personalized content, promotions, banners, and advertisements tailored to your interests;
  5. Ensuring the security and integrity of our systems;
  6. Customizing content and presentation based on User preferences and activity;
  7. Supporting the delivery and optimization of third-party advertisements where applicable.

Managing Your Cookie Preferences

By default, your browser may be set to accept cookies. You can change your cookie settings at any time by:
 

  1. Adjusting the preferences in your browser settings to block or delete cookies;
  2. Using the cookie banner that appears upon your first visit to our Website or Platform, where you can manage or withdraw your consent at any time by clicking the button in the bottom left corner of the page.
  3. Please note that disabling or blocking certain types of cookies may impact the functionality of our services—for example, it may prevent you from logging in or using some features of the Pluria Platform.

We use non-essential cookies (including analytics, personalization, and advertising cookies) only after obtaining your explicit consent. When you first access our Website or App, a cookie banner will appear, allowing you to accept, reject, or customize your cookie preferences. You may update these preferences at any time through the cookie banner or by adjusting your browser settings.

Use of Analytics Tools

We use analytics technologies to better understand how Users interact with our Website and Platform. These tools collect anonymous data to help us analyze usage patterns, improve functionality, and optimize User experience. The information generated by these cookies may be transmitted to and stored by third-party analytics providers.

IP-Based Approximate Geolocation and Cookies

Pluria’s IP-based approximate geolocation functionality for suggesting a default city does not rely on cookies or similar tracking technologies. Such functionality is implemented solely through the IP address automatically transmitted when the User connects to the Pluria Application and through a locally hosted geolocation database. If Pluria implements this or similar functionalities through cookies, local storage, SDK identifiers, device identifiers, tracking pixels, device fingerprinting, or similar technologies, Pluria will update this section and its consent-management tools as required by applicable law.

21. GeoLite Data Attribution

This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com

22. Contact and Updates

If you have any questions or concerns regarding the processing of your Personal Data, you may contact our Data Privacy Officer at [email protected]

We may update this Privacy Policy periodically to reflect changes in our practices or applicable legal requirements. The most current version of the Privacy Policy will always be available on our website at www.pluria.co and in the respective app stores. If material changes are made that affect the way we process your Personal Data, we will notify you accordingly. Continued use of the Website, App, or Platform after such updates constitutes acceptance of the revised terms.

You may also request a copy of the current Privacy Policy by contacting us at [email protected]