Privacy Policy
Last updated: June 2, 2026
1. Who we are
Plex is a customer-relationship-management and unified-messaging platform operated by Marclie Media d.o.o. (“Plex”, “we”, “us”), a company registered in Croatia. Plex helps businesses manage customer conversations across web chat, email, Facebook Messenger, Instagram, and WhatsApp, together with a sales pipeline, calendar, and automations.
2. The two roles in which we process data
As a processor for our business customers (tenants). Most personal data in Plex belongs to our business customers and the people who contact them. We process that data on each business’s behalf and under its instructions to provide the service. The business is the controller of its customers’ data; we are its processor.
As a controller of our own account data. We are the controller of the account information of the businesses and users who sign in to Plex (names, email addresses, authentication data, and usage needed to operate and secure the platform).
3. What data we process
On behalf of our business customers, Plex may process:
- Contact records (names, email addresses, phone numbers, tags, notes).
- Conversation content from connected channels: web chat, email, Facebook Messenger, Instagram Direct, and WhatsApp.
- Sales-pipeline, appointment, and automation data the business creates.
For our own account holders, we process account and authentication data and basic product-usage information needed to run and secure the service.
4. How we use data
- To deliver the unified inbox, pipeline, calendar, and automations.
- To generate optional AI-assisted replies and lead summaries (a business can disable AI per conversation).
- To send messages on a connected channel when a business user replies from Plex.
- To secure, maintain, debug, and improve the service.
We do not sell personal data, and we do not use the content of customer conversations to train our own models. Our AI sub-processors (Anthropic and OpenAI) operate under API terms that do not use customer-submitted data to train their models by default.
5. Data received from Meta (Platform Data)
When a business connects a Facebook Page, Instagram account, or WhatsApp Business account, Plex receives messages and related identifiers from Meta solely to display those conversations in the business’s inbox and to deliver the business’s replies. We use this Platform Data only to provide the messaging features, store it scoped to the connecting business, and delete it on request or when the channel is disconnected (see Data Deletion). We do not share Platform Data with third parties except the infrastructure sub-processors listed below.
6. Sub-processors and service providers
We rely on the following providers, each acting under contractual data-protection terms:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Anthropic and OpenAI — AI-assisted replies and lead extraction.
- Meta Platform — Messenger, Instagram, and WhatsApp messaging.
- Google (Gmail API) — email mailbox connections.
- Twilio — SMS delivery.
- Resend — transactional and outbound email delivery.
7. International transfers
Plex is operated from the European Union (Croatia). Several of our sub-processors are based in the United States (Supabase, Vercel, Anthropic, OpenAI, Twilio, Resend) or operate global infrastructure (Google), so personal data may be transferred from the EEA to the United States or other jurisdictions when we provide the service. For those transfers we rely on each sub-processor’s Data Processing Addendum incorporating the European Commission’s Standard Contractual Clauses (SCCs), and on the EU-US Data Privacy Framework (DPF) where the sub-processor is certified. Where the law of a recipient country imposes obligations that could conflict with these protections, we have considered supplementary measures — encryption in transit and at rest, scoped access controls, and contractual restrictions on government data requests — needed to maintain an essentially equivalent level of protection.
8. Storage, security, and isolation
Data is stored in our Supabase project (managed PostgreSQL hosted on AWS infrastructure in the EU region) and protected in transit by TLS. Application servers run on Vercel’s edge network, with serverless functions executed in the region closest to the requester. Each business’s data is isolated at the database level by row-level security so that one business can never access another’s data. Access tokens for connected channels are stored server-side and are never exposed to other tenants or to client-side code.
9. Retention and deletion
Raw inbound message payloads received from Meta (Facebook Messenger, Instagram Direct, and WhatsApp Business Cloud API) are retained for no longer than 30 days from receipt, consistent with Meta’s WhatsApp Business Platform terms. Derived business records (contact details, conversation metadata, opportunity stage, appointment data) are retained for as long as the connecting business maintains its account, because they form part of the business’s CRM. We delete or anonymize all personal data on request or when a channel or account is disconnected. Some old, unknown-sender email beyond a retention window is pruned automatically. To request deletion, see our Data Deletion instructions.
10. Your rights
Under the GDPR and Croatian data-protection law you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Because most data is held on behalf of a business customer, requests about a specific business’s data are usually best directed to that business; we will assist them as their processor. To exercise your rights or raise a concern, contact us at privacy@marclie.com. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).
11. Cookies
Plex uses only the cookies necessary to keep you signed in and to operate the application securely. The embeddable chat widget uses minimal local storage to maintain a conversation session.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
13. Contact
Questions about this policy or your data? Email privacy@marclie.com.