GDPREU + UK data-protection posture · Last updated 19 June 2026

GDPR.

How Noplag meets EU and UK data-protection law: our role as controller or processor, your rights as a data subject, where your data is processed, and the agreements your data-protection officer will want to see.

Noplag is built to make EU and UK data-protection compliance straightforward — for the individual running a check and for the institution deploying us at scale. This page sets out our role, your rights, where your data is processed, and the agreements your data-protection officer will want to see.

01 · Our role

Controller, processor, and you

When you run a check on your own account, Noplag Labs, Inc. is the controller for your account data and the processor of the document you submit. When your institution deploys Noplag — via LMS, enterprise agreement, or self-host — the institution is the controller and Noplag is its processor, acting only on its documented instructions under a Data Processing Agreement.

This split matters for your rights: route requests about institution-initiated checks through your institution; route requests about your personal account to us.

02 · Lawful basis

Our lawful basis for processing

We process account and usage data to perform our contract with you and to pursue our legitimate interest in operating and securing the service. We process submitted documents to deliver the check you asked for. Where we rely on consent — in practice, analytics cookies — we ask for it explicitly before anything is stored, and you can withdraw it at any time from the cookie settings button in the bottom-left corner of any page.

03 · Your rights

Your rights as a data subject

Under the GDPR and UK GDPR you have the following rights. Most are self-serve in your settings; for the rest, email dpo@noplag.com and we respond within one month.

  • Access — a copy of the personal data we hold about you.
  • Erasure — delete your account and every fingerprint, document hash, and report, completed within 24 hours.
  • Rectification — correct inaccurate account data.
  • Portability — export your checks and reports in a machine-readable format.
  • Restriction & objection — limit or object to specific processing, including profiling.
  • Withdraw consent and lodge a complaint — including with your supervisory authority.
04 · Data residency

Where your data is processed

Our default infrastructure is in the EU. Paid plans can pin processing to an EU-residency endpoint so personal data stays within the EEA, and enterprise customers can self-host the engine entirely inside their own network. Where a transfer outside the EEA is necessary — for example a US sub-processor — we rely on Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

05 · Sub-processors

Sub-processors

We maintain a current, public list of sub-processors with each provider's purpose and processing region at noplag.com/sub-processors. We give notice before adding or changing a sub-processor so controllers can object, and every sub-processor is bound by data-protection terms at least as protective as ours.

06 · Retention & erasure

Retention and erasure

Document content is purged 30 days after a check on the free tier, and on a window you control (30 / 60 / 90 days, or off) on paid plans. Account data is kept while your account is active. A right-to-erasure request — or deleting your account — removes your data from our systems, the corpus index, and the fingerprint store within 30 days, and within 24 hours for the dashboard-visible records.

07 · Security

Security measures

We encrypt data in transit and at rest, scope and log access by role, and stamp every report with the engine commit and corpus snapshot that produced it so results stay reproducible and auditable. As a relaunching open-core company we don't yet hold formal attestations like SOC 2, and we don't claim to — what we offer in the meantime is an auditable Apache 2.0 engine your IT can read directly, with our security posture documented at noplag.com/security.

08 · The DPA

The Data Processing Agreement

Institutions deploying Noplag can execute our GDPR-compliant Data Processing Agreement, which covers Article 28 processor obligations, the sub-processor list, Standard Contractual Clauses for any international transfer, and breach-notification commitments. It is attached automatically to enterprise agreements and available on request for any paid plan.

For your DPOSign the DPA, or self-host and skip the transfer question entirely.

Most reviews clear faster than a closed-source vendor's because the engine is Apache 2.0 — your team can verify the data flow in the code rather than take it on trust. Request the signed DPA at dpo@noplag.com.

09 · Self-host

Self-host for full data sovereignty

For the strictest residency requirements — German Länder universities, French grandes écoles, NHS-affiliated teaching hospitals, EU research-data clauses — run the Apache 2.0 engine inside your own VPC. No submission ever leaves your network; the only outbound traffic is the corpus refresh you schedule. At that point Noplag isn't a processor of your submissions at all.

10 · DPO & authority

DPO and supervisory authority

EU and UK users can contact our Data Protection Officer at dpo@noplag.com. You also have the right to lodge a complaint with your local supervisory authority; we'd appreciate the chance to resolve a concern directly first.

11 · Breach notification

Breach notification

If a personal-data breach affects you, we notify the relevant controller without undue delay and, where we are the controller, the supervisory authority within 72 hours where the law requires, with the information needed to assess and respond.

12 · Contact

How to reach us

Data-protection questions, rights requests, or DPA requests: dpo@noplag.com. General privacy questions: privacy@noplag.com. The date at the top of this page reflects the current version.

GDPR — Noplag