Features How It Works Pricing Blog
← Back to Home

GDPR Compliance

How Planairly protects your data under the EU General Data Protection Regulation.

Our Commitment

Planairly is committed to protecting the privacy and rights of individuals in the European Union and European Economic Area (EU/EEA). We comply with the General Data Protection Regulation (GDPR) in all aspects of our data processing activities.

This page supplements our Privacy Policy with GDPR-specific information about how we process personal data, the legal bases we rely on, and how you can exercise your rights.

Data Controller

Planairly acts as the data controller for personal data we collect directly from users (account information, usage data, project content). For detailed contact information, see our Privacy Policy.

When organizations use Planairly for their teams, the organization is typically the data controller for employee data, and Planairly acts as a data processor. In these cases, we offer a Data Processing Agreement (DPA) - see below.

Legal Bases for Processing

We process personal data only where we have a valid legal basis under GDPR Article 6:

Processing Activity Legal Basis GDPR Article
Account creation and authentication Contract performance Art. 6(1)(b)
Providing core Service features (project data, collaboration) Contract performance Art. 6(1)(b)
Third-party integration data exchange (Jira, Linear, Slack) Contract performance Art. 6(1)(b)
Billing and payment processing Contract performance Art. 6(1)(b)
Service security and fraud prevention Legitimate interest Art. 6(1)(f)
Usage analytics and service improvement Legitimate interest Art. 6(1)(f)
Marketing communications Consent Art. 6(1)(a)
Tax and financial record keeping Legal obligation Art. 6(1)(c)

Your Data Subject Rights

Under GDPR, you have the following rights regarding your personal data:

Right of Access (Art. 15)

You can request a copy of all personal data we hold about you. We will provide this in a structured, commonly used, machine-readable format within 30 days.

Right to Rectification (Art. 16)

You can update your personal information directly through your account settings, or request that we correct inaccurate data.

Right to Erasure (Art. 17)

You can request deletion of your personal data. This includes account deletion, which removes your data within 30 days. Certain data may be retained where legally required (e.g., financial records).

Right to Restriction of Processing (Art. 18)

You can request that we limit how we process your data while a dispute or complaint is being resolved.

Right to Data Portability (Art. 20)

You can request your data in a portable format (JSON/CSV). This includes your project data, task content, and account information.

Right to Object (Art. 21)

You can object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.

Right to Withdraw Consent (Art. 7(3))

Where processing is based on consent (e.g., marketing emails), you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with your local Data Protection Authority (DPA). A list of EU/EEA DPAs is available on the European Data Protection Board website.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days. If we need more time due to complexity, we will inform you within the initial 30-day period.

Service Providers and Payment Provider

We use the following service providers to deliver the Service. Paddle acts as our independent Merchant of Record for subscription purchases:

Provider Purpose Data Location Safeguard
Clerk (clerk.com) Authentication and user management United States EU-US DPF, SCCs
Supabase (supabase.com) PostgreSQL database hosting, data persistence EU (Frankfurt) / US EU hosting available, SCCs
Hocuspocus / Tiptap (tiptap.dev) Real-time collaboration server (Y.js CRDT sync) EU EU hosting
Vercel (vercel.com) Application hosting, serverless functions, CDN Global (EU-primary edge) EU-US DPF, SCCs
Paddle (paddle.com) Merchant of Record for subscription billing, payments, and invoicing UK / EEA / US / Canada SCCs where required

We will notify workspace administrators at least 30 days before adding a new sub-processor, giving you the opportunity to object.

Third-Party Integration Data Flows

When you enable integrations, data flows to third-party services that act as independent data controllers:

Jira (Atlassian)

  • Data sent: Task titles, descriptions, statuses, estimated durations, due dates, assignee account IDs, and dependency relationships.
  • Data received: Issue data, assignee information, issue links, status changes.
  • Mechanism: Atlassian Forge webtriggers with HMAC signature verification.
  • Legal basis: Contract performance - you explicitly enable and configure the integration.

Linear

  • Data sent/received: Organization, team, project, issue, status, assignee, estimate, due date, and dependency data.
  • Legal basis: Contract performance.

Slack

  • Data sent: Configured project notifications and task-action context for mapped channels or users.
  • Data received: Workspace, channel, and user identity data, plus interactive task actions initiated from Slack.
  • Legal basis: Contract performance.

Each of these services maintains their own GDPR compliance programs. Planairly does not control how these services process data once received. We recommend reviewing their privacy policies.

International Data Transfers

Where personal data is transferred outside the EU/EEA, we ensure adequate protection through:

  • EU-US Data Privacy Framework: For transfers to DPF-certified US organizations.
  • Standard Contractual Clauses (SCCs): The European Commission-approved clauses for transfers to countries without an adequacy decision.
  • Supplementary measures: Encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, and regular security assessments.

Data Processing Agreement (DPA)

Organizations that use Planairly as a data processor on behalf of their employees can request a GDPR-compliant Data Processing Agreement. Our DPA covers:

  • Scope and purpose of processing.
  • Data subject categories and data types.
  • Sub-processor engagement and notification procedures.
  • Security measures and breach notification commitments.
  • Data return and deletion upon contract termination.
  • Audit rights.

To request a DPA, contact [email protected].

Data Breach Notification

In the event of a personal data breach:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
  • If the breach is likely to result in a high risk to your rights, we will notify affected individuals without undue delay (Article 34).
  • For organizations with a DPA, we will notify the designated contact as specified in the agreement.

Data Protection by Design and Default

In accordance with GDPR Article 25, we implement privacy by design principles:

  • Data minimization: We collect only the data necessary for each feature to function.
  • Purpose limitation: Data is used only for the purposes stated in our Privacy Policy.
  • Workspace isolation: Project data is strictly isolated between workspaces - no cross-workspace data access is possible.
  • Ephemeral collaboration data: Real-time presence and cursor data is not persisted beyond the active session.
  • Integration scoping: Third-party integrations sync only the data types you explicitly configure.

Contact

For GDPR-related inquiries: