Trust
Where your data sits, who can reach it, and what happens if we stop
You are handing your whole administration to a small company. That deserves an answer before you have to ask for it, so here it is on a page instead of in a conversation.
01 – Where it sits
One database, in Western Europe
The portal runs on Cloudflare Workers and your data sits in a Cloudflare D1 database that runs in Western Europe. Documents and backups are stored separately, in storage pinned to the European Union.
The honest footnote, and it is about the database itself. Running in Western Europe is not the same as a contractual guarantee that it stays there. For documents and backups that guarantee has been in place since 7 September 2026; for the database it can only be set when it is created, and it already exists. If you need it in writing for everything, say so before you sign.
02 – Who else can reach it
Six parties, and what each one gets
Nobody else. We do not sell data, we do not rent it out, and we do not train models on it.
- Cloudflare: hosting, the database, sessions and images. Everything passes through here.
- Resend: sending mail: quotes, invoices, invitations. The message and the recipient's address.
- Stripe: payments. The name and payment details of whoever pays.
- SnelStart or Moneybird: the bookkeeping link, and only if you switch it on yourself.
- Google, Apple and Mozilla: delivering push messages to an engineer's phone. Encrypted in transit; they cannot read them.
- Anthropic: writing articles, and only if you use the article engine. Nothing is sent if you do not.
03 – How it is locked
What is actually in place
- Two-step sign-in with a code from an authenticator app, per user. The secret sits encrypted with a key that lives outside the database.
- A password from a known data breach is refused. Your password never leaves the portal to check that.
- Passwords are never stored, only a derivative. Twelve characters minimum, five sign-in attempts a minute.
- Every question to the database is bound to one company. You cannot see another customer's data, not even by typing an address.
- Every release runs the full test suite first. If one test fails, nothing ships.
- Sessions are revocable and expire. Changing your password signs out every other device.
04 – If you leave
Your data comes with you
Every screen exports as CSV and invoices come out as UBL, so any package can read them. That is not a favour we grant on the way out, it is how it was built. After the agreement ends we delete everything within thirty days, except the invoices we sent you, which the law makes us keep for seven years.
05 – One person
The question you should be asking
Ploink is one person. Your administration should not depend on whether that person stays healthy, and pretending otherwise would be worse than saying it.
- Everything is exportable at any moment, without asking us.
- What happens if we stop goes into the contract, in writing, before you sign.
- The software runs on a standard platform, not on a machine in someone's attic.
06 – What we do not have
Said plainly, because you will find out anyway
No ISO 27001 and no SOC 2. Those cost tens of thousands a year and a company this size does not carry them; anyone who tells you otherwise at this scale is either much bigger or not telling the truth. What we do have is a data processing agreement that says exactly what happens, written against the software rather than copied from a template, and everything on this page is checkable.
07 – Ask
Anything else you need on paper
The data processing agreement, the subprocessor list, or an answer to your accountant's questionnaire: ask and you get it, normally the same week.
Last checked 7 September 2026.