Legal

Data Processing Addendum

Last updated: July 2026 · Effective from: July 2026

This Data Processing Addendum (“DPA”) applies where an organisation uses Planeer to process personal data in project, application, document, marketplace, or collaboration workflows. It supplements the Planeer Terms of Service and Privacy Notice.

1. Roles

For account, billing, security, product analytics, and support data, Planeer acts as controller as described in the Privacy Notice. For customer project data submitted by an organisation for analysis, document generation, public engagement, or marketplace fulfilment, Planeer acts as processor unless a separate written agreement states otherwise.

2. Processing Instructions

Planeer will process customer project data only to provide, secure, maintain, improve, and support the contracted service; to comply with law; or as otherwise documented in the customer's use of the platform. The customer is responsible for ensuring that submitted data can lawfully be processed for those purposes.

3. Processing Details

  • Subject matter: planning intelligence, application pack generation, project coordination, marketplace ordering, public consultation support, and related platform operations.
  • Duration: the term of the customer account plus retention periods required for billing, security, legal, audit, or dispute purposes.
  • Data subjects: customers, client contacts, landowners, applicants, neighbours, consultants, and workspace users.
  • Data categories: names, email addresses, account identifiers, property addresses, site notes, planning records, public comments, generated documents, payment metadata, and support communications.

4. Security Measures

Planeer maintains technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, destruction, or disclosure. Current measures include provider-managed encryption in transit, database access controls, authentication controls, server-side entitlement checks, audit-minded payment metadata, and restricted operational access.

5. Subprocessors and Transfers

Planeer may use subprocessors for hosting, authentication, payments, AI processing, email, analytics, monitoring, and database services. Where personal data is transferred outside Jersey, the UK, or the EEA, Planeer will use appropriate safeguards such as standard contractual clauses or equivalent vendor terms where required.

6. Data Subject Requests

Where Planeer receives a request from a data subject about customer project data for which the customer is controller, Planeer will direct the requester to the customer where practicable and provide reasonable assistance for access, correction, deletion, restriction, objection, or portability requests.

7. Incidents

Planeer will notify affected customers without undue delay after becoming aware of a personal data breach involving customer project data and will provide information reasonably available to support assessment, notification, and remediation.

8. Return and Deletion

On account closure or written request, Planeer will delete or return customer project data where reasonably possible, subject to backup cycles and retention needed for legal, tax, security, fraud-prevention, or dispute-resolution purposes.

9. Contact

Data protection queries should be sent to privacy@planeer.ai.