Pro Plato — Food Safety
Privacy & Data Policy

Privacy & Data Policy

Last updated: 22 September 2026

Pro Plato ("we", "us", "our") operates the Pro Plato food safety and compliance platform. This policy explains what personal data we collect, why we collect it, how it is stored, and the rights you have over it. By using Pro Plato you agree to the practices described here.

1. Data We Collect

We collect the minimum information needed to run your food safety compliance account:

  • Account data: your name, email address, and business details you provide during setup (business name, sites, address, phone).
  • Compliance records: the daily logs you and your team enter — temperature checks, cooking records, cleaning records, deliveries, checklists, HACCP plans, COSHH entries, risk assessments, and any photos you upload.
  • Staff data: names and emails of team members you invite to your business workspace, rota entries, and clock-in/out records.
  • Usage data: basic analytics about how the app is used so we can improve it.

2. How We Use Your Data

Your data is used only to:

  • Provide and maintain your Pro Plato compliance workspace.
  • Generate audit reports and inspection packs for your business.
  • Send service notifications, alerts, and compliance reminders you have enabled.
  • Process subscription payments through our payment provider, Stripe.
  • Provide support when you contact us.

3. Lawful Basis & GDPR

We process your data under the following lawful bases:

  • Performance of a contract — running the service you signed up for.
  • Legal obligation — retaining records where food safety law requires it.
  • Legitimate interests — fraud prevention, security, and service improvement.
  • Consent — for optional analytics and marketing communications, which you can withdraw at any time.

Pro Plato acts as a data controller for account data and a data processor for the compliance records you enter, which remain controlled by your business.

4. Data Storage & Security

Your data is stored on secure, encrypted cloud infrastructure. Access is restricted to authorised personnel and is protected by row-level isolation so that one business can never see another business's records. Payment card details are never stored by Pro Plato — they are handled entirely by our PCI-compliant payment provider, Stripe.

5. Data Sharing

We do not sell your data. We only share it with:

  • Stripe — to process subscription payments.
  • Cloud hosting & email providers — to deliver the service.
  • Regulatory authorities — only where we are legally required to, or at your written request (for example, sharing inspection records with your local EHO).

6. Data Retention & Your Rights

We keep your compliance records for as long as your account is active and for a reasonable period after closure to satisfy food safety record-keeping requirements, unless you request earlier deletion.

Under UK GDPR you have the right to:

  • Access a copy of your personal data.
  • Correct inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent at any time.
  • Lodge a complaint with the Information Commissioner's Office (ICO).

7. Cookies

Pro Plato uses essential cookies to keep you signed in and remember your session. We do not use cookies for third-party advertising tracking.

8. Contact Us

For any privacy, data, or data-subject request — including access, correction, or deletion — contact us:

Email: inbox@proplato.co.uk