Privacy Policy
Last updated: July 9, 2026
Pleno is strata council software built for British Columbia strata corporations — a tool that helps a council manage maintenance, documents, contracts, and the record of decisions in one place. This policy explains what personal information we handle, why, how we protect it, and the choices you have. We take privacy seriously because the information a strata council keeps is often sensitive, and because the people using Pleno are volunteers who trusted us with it.
1. Our two roles: controller and processor
Pleno handles two very different kinds of information, and our responsibilities differ depending on which one is involved.
- Account Data — we are the controller. This is the information we need to give a council member an account and run the service: your name, email address, role on the council, and authentication details. We decide how this information is used, and this policy governs it directly.
- Strata Corporation Data — we are the processor. This is everything a council stores inside Pleno about its building: maintenance records, resident reports, contracts, documents, meeting minutes, financial figures, the building map, and the timeline of activity. The strata corporation is the controller of this information. We process it on the corporation's instructions to provide the service, and we do not use it for our own purposes.
We do not sell personal information — not Account Data, not Strata Corporation Data, ever.
2. Information we handle
Account Data (we are the controller)
- Identity and contact: your name, email address, and (optionally) phone number.
- Account and role: the strata corporation you belong to (identified by its BC strata plan number, e.g. BCS 1234), your council or operational role, and your access level.
- Authentication: credentials, session information, and security metadata such as login events used to keep the account safe.
- Support and billing contact: information you provide when you contact support or when you administer a subscription.
Strata Corporation Data (we are the processor)
Because Pleno is a workspace for a strata council, the corporation's records that a council chooses to store may include personal information about identifiable people. Depending on what the council enters, this can include:
- Maintenance cards and quotes: issue descriptions, locations, vendor and contractor names captured as free text, quoted amounts, decisions, and target dates.
- Resident reports: submissions raised about the building, which may contain a resident's name, unit, contact details, and description of the issue.
- Contracts and documents: vendor and service agreements, bylaws, meeting minutes, correspondence, and other files uploaded to the document vault (often PDFs).
- Forwarded email content and attachments: when a council member forwards an email into Pleno or captures one through the Gmail add-on, the message body and attachments are processed into a maintenance card. This content can include residents' addresses, third-party names, and other personal information.
- Governance and financial records: AGM dates, depreciation reports, budgets, and financial figures.
- Activity timeline and logs: a record of actions taken in the account, attributed to the council member who took them.
Pleno is a council-only tool. Residents and contractors do not receive logins. Contractors are referenced only as free-text metadata on cards, not as user accounts.
Information collected automatically
- Technical data: IP address, device and browser type, and pages or features used, collected to operate and secure the service.
- Usage data: aggregate, non-identifying signals about how features are used, to help us improve the product.
3. How we use information
We use the information above only to run Pleno and to serve the council, specifically to:
- authenticate users and enforce role-based access so people see only what their role permits;
- provide the core features — maintenance tracking, resident reports, contracts, the document vault, the depreciation report, and the activity timeline;
- turn forwarded emails and captured Gmail threads into structured maintenance cards;
- run the assistive AI features described in section 5;
- send operational messages such as council-rotation and AGM reminders, invitation and sign-in reminders, billing alerts, and account-recovery links;
- keep the service secure, prevent abuse, maintain audit trails, and meet legal obligations, including record-keeping expectations under BC's Strata Property Act;
- support you when you ask for help, and administer billing.
We do not use Strata Corporation Data to build profiles, to advertise, or for any purpose other than delivering the service to the corporation that owns it.
4. Consent and legal basis
We handle personal information in accordance with British Columbia's Personal Information Protection Act (PIPA) and, where it applies, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). We collect, use, and disclose personal information for purposes a reasonable person would consider appropriate in the circumstances, and we rely on consent — express or implied — as required by those laws.
For Strata Corporation Data, the strata corporation is responsible for having the authority and any necessary consent to enter personal information about residents and other individuals into Pleno, and for handling that information in line with its own obligations under PIPA and PIPEDA. We act on the corporation's instructions as its processor.
5. Artificial intelligence features
Pleno uses AI to reduce council busywork. Two features rely on it:
- Email-to-card extraction. When an email is forwarded in or captured from Gmail, we clean the message and send the relevant text (and, where needed, attachment text) to an AI provider to draft structured card fields such as the issue, location, and quotes.
- "Ask about this strata" chat. A council member can ask questions about their own strata, and the assistant answers using only that strata's documents, returning answers with page-level citations back to the source file.
AI outputs are assistive and human-in-the-loop. Extracted cards are created as drafts for a person to review before they are relied on — nothing is auto-published. AI outputs may contain errors and are not legal, financial, accounting, or other professional advice.
How AI providers handle your text
- To power these features we send the relevant text to specialist AI providers located in the United States — currently a large-language-model provider for drafting and answering, and an embeddings provider that indexes documents so the chat can find relevant passages.
- Text is sent only to produce your result — it is not used to train the providers' models.
- Document content is treated as untrusted data, not as instructions, to guard against prompt-injection.
- The chat is scoped to a single strata: a council member can never retrieve another corporation's documents.
6. Service providers and sharing
We share information only with the service providers we need to run Pleno, and each receives only what it needs for its function. Our providers are contractually required to protect personal information to a standard comparable to PIPA and PIPEDA.
| Provider type | What they do | What they receive |
|---|---|---|
| Cloud hosting & database | Host the application, database, and authentication | Account Data and Strata Corporation Data, isolated per strata |
| AI language provider | Draft card fields and answer document questions | The relevant text sent for a given request |
| AI embeddings provider | Index documents so the chat can find relevant passages | Document text to be indexed |
| Payment processor | Handle subscription billing | Billing contact and payment details (card data is handled by the processor, not stored by us) |
| Email / SMS provider | Deliver operational notifications | Recipient name and contact address |
| Google Workspace | Power the optional Gmail add-on | Only the content of the message you choose to capture (see section 8) |
We may also disclose information when required by law, to respond to a valid legal request, to protect the rights or safety of users or the public, or in connection with a corporate transaction (in which case this policy continues to govern the information).
7. Where your data is stored and processed
Pleno stores the application database and uploaded documents with a cloud provider using a Canadian region where available, with per-strata isolation so one corporation's data cannot be reached from another's account.
Some processing necessarily occurs outside Canada. In particular, the AI features described in section 5 send the relevant text to providers in the United States. While information is outside Canada it may be accessible to that country's courts, law-enforcement, and regulatory authorities under their laws. We only work with providers that agree to protect the information to a standard comparable to PIPA and PIPEDA.
8. The Pleno Gmail add-on
The optional Gmail add-on lets a council member open an email thread in Gmail and create a maintenance card from it. To keep access as narrow as possible:
- The add-on reads only the message you have open when you use it — its sender, subject, body, attachments, and thread identifier. It does not read your wider mailbox.
- It links your Google identity to your Pleno account so the card is created under your permissions; it does not store your Google password.
- The thread identifier is stored on the card so the email and the card can stay connected.
- Our use of information received through Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
9. Communications and consent
By providing your contact details you consent to receive the operational messages Pleno needs to send — invitations, AGM and council-rotation reminders, sign-in prompts, billing alerts, and account-recovery links. These keep the account functioning and, in some cases, are required to meet the strata's governance obligations.
You can withdraw consent to non-essential email or SMS at any time through your account settings. Certain administrative and security messages (for example, billing failures or recovery links) are part of the service and cannot be switched off while the account is active. Our messages comply with Canada's Anti-Spam Legislation (CASL).
10. Cookies and analytics
We use strictly necessary cookies to keep you signed in and to secure the service; these are always on because the product cannot work without them. We use limited analytics to understand how features are used and to improve Pleno. Analytics receive aggregate, non-identifying signals — not the contents of your strata's records. Where analytics cookies are not strictly necessary, they are off by default and only enabled with your consent through the cookie banner. You can also control cookies through your browser settings.
11. Data retention
We keep information for as long as it is needed to provide the service and to meet legal and governance requirements.
- Strata records are retained to support the corporation's record-keeping, including the minimum periods set out in BC's Strata Property Act.
- Audit trails of actions taken in the account are preserved even after a council member leaves, so the history of decisions remains intact.
- We do not automatically delete or lock an account merely because it has been inactive — a building's history should not vanish during an off-season or a council transition.
- When a subscription ends, the strata's data is removed after a defined wind-down period, and residual copies in backups are purged on a rolling schedule.
- Account Data is retained while the account is active and for a reasonable period afterward to meet legal, security, and billing needs.
12. How we protect information
We use technical and organizational safeguards appropriate to the sensitivity of the information, including:
- Encryption in transit (TLS) for data moving between your device and Pleno;
- Row-level security in the database so every record is scoped to a single strata corporation and cannot be reached from another account — this same isolation applies to the AI features, which run under your permissions, never with elevated access;
- Role-based access control so council and operational roles only reach the data their role allows;
- Audit trails and activity logs that record who did what;
- Access controls and least-privilege practices for our own team, limited to a genuine business need.
No system can be guaranteed perfectly secure, but we work continuously to protect the information entrusted to us.
13. Data breaches
We maintain a process to detect, investigate, and respond to security incidents. If a breach of security safeguards creates a real risk of significant harm, we will notify affected individuals and the relevant privacy authority, and — where we act as processor — the strata corporation, as required by PIPA and PIPEDA.
14. Your privacy rights
Under PIPA and PIPEDA you have the right to:
- Access the personal information we hold about you and ask how it has been used and disclosed;
- Correct information that is inaccurate or incomplete;
- Withdraw consent to non-essential uses, subject to legal or contractual limits.
For Account Data, contact our Privacy Officer using the details below. For Strata Corporation Data — records inside a strata's workspace — the strata corporation is the controller, so we will generally direct such requests to that corporation, and we will assist it in responding.
If you are not satisfied with how we have handled your information, you may complain to the Office of the Information and Privacy Commissioner for British Columbia (OIPC) or, where PIPEDA applies, the Office of the Privacy Commissioner of Canada.
15. Children
Pleno is a tool for adult volunteers serving on strata councils. It is not directed at children, and we do not knowingly collect personal information from anyone under the age of majority through the service.
16. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "last updated" date above, and we will provide additional notice for material changes. Your continued use of Pleno after an update means you accept the revised policy.
17. Contact us
Questions, requests, or complaints about privacy can be directed to our Privacy Officer:
Pleno — Privacy Officer Email: privacy@pleno.ca
General enquiries: hello@pleno.ca
British Columbia, Canada