Skip to content
← Legal

Privacy Policy

Last updated: September 16, 2026

1. Introduction

This Privacy Policy explains how Prodsync AS (organization number 933 023 281), located at Torvmyrane 13, 6160 Hovdebygda, Norway ("Prodsync," "we," "us," or "our"), collects, uses, stores, and protects your personal data when you use our services.

This Privacy Policy applies to your use of our website and the following services operated by Prodsync AS:

  • Prodsync Platform — a B2B event production management platform for organizations managing live events, concerts, and festivals.
  • Plot — a free tool for artists and tour managers to create stage plots and riders.

Both products use the same sign-in: one account can be used with Plot and, if an organization has added it as a member, with the Prodsync Platform. Plot documents belong to the account that made them and are not visible to any Prodsync Platform organization unless their owner shares or sends them.

By visiting our website or using the Prodsync Platform or Plot, you acknowledge that you have read this Privacy Policy. If you do not agree with it, please refrain from using our website and services.

Our roles under GDPR

Prodsync AS acts in different roles under the General Data Protection Regulation (GDPR) depending on the personal data and the purpose of the processing.

Prodsync AS acts as data controller for personal data processed for:

  • providing, maintaining and improving our services;
  • account registration, authentication and management;
  • organization membership administration;
  • subscription and billing administration;
  • support and service communications, such as account verification, password resets, security notices, invitations and notifications about documents shared with you, and notice of significant changes to the Terms of Service or changes in sub-processors;
  • security monitoring and abuse prevention, such as detecting spam accounts, scraping and mass sending;
  • service analytics and improvement — analyzing usage patterns and improving the user experience using account data, technical data or anonymized and aggregated information;
  • product news — news about new features and tips from Plot and Prodsync sent by email — only if you have opted in (see section 4);
  • maintaining records demonstrating acceptance of applicable terms and marketing choices; and
  • compliance with legal obligations.

For personal data contained in content entered into the Prodsync Platform or created in Plot, Prodsync AS acts as a data processor. Such processing is governed by the Prodsync Platform Terms of Service or the Plot Terms of Service, as applicable.

We do not sell your personal data. We do not use your data for advertising.

2. Data We Collect — Prodsync Platform

When you use the Prodsync Platform, we may collect the following data:

Account and profile data

  • Name and email address provided during registration
  • Authentication data (managed via Firebase Authentication or Google OAuth), and which sign-in method you used
  • Email verification status and the time you registered
  • A record of your acceptance of the Terms of Service (time and version), where you accepted them at sign-up
  • Profile information you add to your account, such as phone number and job title
  • Organization membership and role within your organization
  • Language and display preferences

Usage data

  • Pages visited and features used (collected via Plausible Analytics, a privacy-focused analytics service that does not use cookies or collect personal data)
  • Device type and browser information (anonymized)

Data sharing within your organization

Data you enter into the Prodsync Platform is visible to other members of your organization, according to their role and permissions. Organization administrators control who has access to what data. Prodsync does not share your organization's data with other organizations.

3. Data We Collect — Plot

When you use Plot, we may collect the following data:

Account and profile data

  • Name and email address provided during registration
  • Authentication data (managed via Firebase Authentication or Google OAuth), and which sign-in method you used
  • Email verification status and the time you registered
  • A record of your acceptance of the Terms of Service (time and version), where you accepted them at sign-up
  • Your choice about product news: whether you opted in, when, where (sign-up form or Settings) and which wording you saw — kept as proof of consent
  • Language and display preferences

Usage and security data

  • Pages visited and features used (collected via Plausible Analytics, a privacy-focused analytics service that does not use cookies or collect personal data)
  • Device type and browser information (anonymized)
  • IP address, used to limit how many requests can be made in a short period. Repeated limit hits are recorded as an abuse signal together with the account involved.

4. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), Prodsync AS relies on the following legal bases for its controller activities:

  • Contract performance — Processing necessary to create and manage accounts, authenticate users, provide requested services, administer subscriptions, maintain records of acceptance of applicable Terms of Service, and deliver service communications.
  • Legitimate interest — Processing necessary for our legitimate business interests, such as operating and improving our services, administering customer organizations and user access, providing support, preventing abuse, ensuring security, and analyzing service usage through account data, technical data, or anonymized and aggregated information, where these interests are not overridden by your rights.
  • Consent — Product news and tips by email are sent only if you have opted in, by ticking the box at sign-up or in Settings → Account. You can withdraw at any time in Settings → Account or via the unsubscribe link in any such email; withdrawing does not affect service messages, which are part of running your account. Opting in is never a condition for using our services.
  • Legal obligation — Processing necessary to comply with applicable laws and regulations.

5. Third-Party Services

Prodsync AS uses third-party service providers to operate our services. Depending on the processing activity, a provider may act either as a processor to Prodsync AS, where Prodsync AS acts as data controller, or as a sub-processor, where Prodsync AS acts as data processor under the applicable Terms of Service.

  • Firebase Authentication (Google) — Account authentication and identity management. Processes email, name, and OAuth profile data.
  • MongoDB — Application database. It runs on servers we operate ourselves on DigitalOcean infrastructure; no database-as-a-service provider has access to it.
  • Google OAuth — Optional sign-in method. Processes your Google account profile information (name, email, profile picture).
  • Resend — Transactional email delivery (account verification, password resets). Processes email addresses.
  • Google Gemini (Google) — Reads documents and images you upload for analysis: riders, contracts, crew lists, schedules, accommodation lists and input lists in Prodsync Platform; rider PDFs, stage plot photos and input list PDFs in Plot. The file is uploaded to Google for the analysis and deleted from Google by us as soon as the analysis is done (Google also expires such files automatically within 48 hours). We use Google's paid API tier, on which Google does not use prompts, files or responses to improve its products, and keeps a log of them for a limited period solely to detect abuse. Processing takes place under Google's Data Processing Addendum for products where Google is a data processor, with EU Standard Contractual Clauses and the EU–US Data Privacy Framework covering transfers.
  • OpenAI — Handles text you type or paste: the AI assistant, text-based imports of crew lists, schedules, line lists and contacts, and riser notes in Prodsync Platform; rider text suggestions and input list import from pasted text or an image in Plot. For customers in the EEA, OpenAI's contracting entity is OpenAI Ireland Ltd., and processing takes place under OpenAI's Data Processing Addendum with EU Standard Contractual Clauses. OpenAI does not use our requests to train its models, and every data-sharing option in our account is switched off. OpenAI retains requests for up to 30 days for abuse monitoring, then deletes them.
  • Plausible Analytics — Privacy-focused website analytics. Does not use cookies, does not collect personal data, and is fully GDPR compliant.
  • DigitalOcean — Hosting for the application and for the servers running our database.

AI features run only when you start them — for example "Import from PDF", "Analyze image" or "Refine" — and each feature says so before it sends anything. Two things in Prodsync Platform run without a button press: the riser planner sends the riser notes of artists who do not yet have a riser booking to OpenAI when the planner opens, to suggest a setup; and to find out where the AI assistant fails, we may have finished conversations with it reviewed by OpenAI, which returns a quality score and a failure category, not the conversation. Nothing else is sent to an AI provider in the background. We do not use your data to train AI models, and we have not permitted either provider to.

The AI assistant in Prodsync Platform saves your conversations with it so you can return to them; they are stored with the event they belong to as part of your organization's User Content, and our staff may read individual conversations to find and fix failures. For every other AI feature we keep only who ran it, which feature, when, how long it took and how many tokens it used — not the content.

When we add or replace one of the services above, we update this page. Customer organizations on the Prodsync Platform are also notified in advance, as set out in Section 6.3 of the Prodsync Platform Terms of Service.

Each third-party service operates under its own privacy policy. We encourage you to review their policies for details on how they handle data.

6. Cookies and Local Storage

We use cookies and browser local storage for the following purposes:

  • Authentication — Firebase Authentication uses cookies and local storage to maintain your login session. These are essential for the service to function.
  • Preferences — We store your display preferences (such as theme, language, and UI settings) in cookies or local storage so they persist between visits, and — briefly — which page to return you to after signing in.
  • Cookie consent — We store your cookie consent preference in local storage.

We do not use tracking cookies or third-party advertising cookies. Our analytics provider (Plausible) does not use cookies.

7. Data Retention

Where Prodsync AS is the data controller, we retain your data for as long as your account is active or as needed to provide our services:

  • Account data — Retained for the lifetime of your account and deleted with it.
  • Abuse signals (rate-limit hits and similar, with the IP address and account involved) — Deleted 90 days after they are resolved.
  • Consent and Terms acceptance records — Retained for the lifetime of your account and deleted with it; a copy may remain in backups for up to 30 days afterwards.
  • Analytics data — Plausible retains anonymized, aggregated analytics data. No personal data is stored.
  • Content sent to AI features — Deleted from Google as soon as an analysis completes; retained by OpenAI for up to 30 days for abuse monitoring. See section 5.

When you delete your account from Settings, your account data is deleted immediately; if you ask us by email instead, we delete it within 30 days. Backup copies are overwritten within 30 days after deletion. Where law requires us to retain specific information, we keep only that.

User Content that Prodsync AS processes on behalf of a customer organization or a Plot user — including Plot documents and sharing data — is retained and deleted as set out in Section 6.7 of the Prodsync Platform Terms of Service and Section 6.7 of the Plot Terms of Service, as applicable.

8. Your Rights Under GDPR

Where Prodsync AS acts as data controller and the GDPR applies, you have the following rights regarding your personal data.

  • Right of access — You can request a copy of the personal data we hold about you.
  • Right to rectification — You can request that we correct inaccurate or incomplete data.
  • Right to erasure — You can request that we delete your personal data, subject to legal retention requirements.
  • Right to data portability — You can request your data in a structured, commonly used, machine-readable format.
  • Right to restrict processing — You can request that we limit how we process your data in certain circumstances.
  • Right to object — You can object to processing based on legitimate interests.
  • Right to withdraw consent — Where processing is based on consent, you can withdraw it at any time. For product news, use Settings → Account or the unsubscribe link in the email.
  • Complaint — You may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or another competent supervisory authority if you believe your rights have been violated.

You can delete your account yourself from Settings in either product; a member of a Prodsync Platform organization must first leave the organization. In Plot, Settings also lets you export your data. For everything else, or to exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

Individuals in jurisdictions outside the scope of the GDPR may have privacy rights under applicable local laws. Prodsync AS will comply with applicable legal requirements relating to the exercise of such rights.

For personal data contained in content entered into the Prodsync Platform or created in Plot, Prodsync AS acts as a data processor. Such processing is governed by the applicable Terms of Service. Requests relating to such personal data should be directed to the relevant organization or user responsible for the content. Prodsync AS will assist in responding to such requests as required by applicable law.

9. Data Security

We take reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of data at rest in our databases
  • Role-based access controls within the application
  • Regular security reviews of our infrastructure and code

No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

10. International Data Transfers

Some of the services in section 5 process data outside the European Economic Area (EEA), chiefly in the United States. Where that happens, transfers rest on the EU Standard Contractual Clauses (SCCs) approved by the European Commission and, where the recipient is certified, on the EU–US Data Privacy Framework. OpenAI contracts with EEA customers through OpenAI Ireland Ltd., which transfers onward under SCCs; Google's Data Processing Addendum covers its transfers with SCCs and the Data Privacy Framework.

11. Children's Privacy

Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page.

We encourage you to review this policy periodically to stay informed about how we protect your data.

13. Contact

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Prodsync AS

Organization number 933 023 281

Torvmyrane 13, 6160 Hovdebygda, Norway

Email: [email protected]