Legal
Data Processing Addendum
Last updated: July 2026 · Effective from: July 2026
1. Roles
For account, billing, security, product analytics, and support data, Planeer acts as controller as described in the Privacy Notice. For customer project data submitted by an organisation for analysis, document generation, public engagement, or marketplace fulfilment, Planeer acts as processor unless a separate written agreement states otherwise.
2. Processing Instructions
Planeer will process customer project data only to provide, secure, maintain, improve, and support the contracted service; to comply with law; or as otherwise documented in the customer's use of the platform. The customer is responsible for ensuring that submitted data can lawfully be processed for those purposes.
3. Processing Details
- –Subject matter: planning intelligence, application pack generation, project coordination, marketplace ordering, public consultation support, and related platform operations.
- –Duration: the term of the customer account plus retention periods required for billing, security, legal, audit, or dispute purposes.
- –Data subjects: customers, client contacts, landowners, applicants, neighbours, consultants, and workspace users.
- –Data categories: names, email addresses, account identifiers, property addresses, site notes, planning records, public comments, generated documents, payment metadata, and support communications.
4. Security Measures
Planeer maintains technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, destruction, or disclosure. Current measures include provider-managed encryption in transit, database access controls, authentication controls, server-side entitlement checks, audit-minded payment metadata, and restricted operational access.
5. Subprocessors and Transfers
Planeer may use subprocessors for hosting, authentication, payments, AI processing, email, analytics, monitoring, and database services. Where personal data is transferred outside Jersey, the UK, or the EEA, Planeer will use appropriate safeguards such as standard contractual clauses or equivalent vendor terms where required.
6. Data Subject Requests
Where Planeer receives a request from a data subject about customer project data for which the customer is controller, Planeer will direct the requester to the customer where practicable and provide reasonable assistance for access, correction, deletion, restriction, objection, or portability requests.
7. Incidents
Planeer will notify affected customers without undue delay after becoming aware of a personal data breach involving customer project data and will provide information reasonably available to support assessment, notification, and remediation.
8. Return and Deletion
On account closure or written request, Planeer will delete or return customer project data where reasonably possible, subject to backup cycles and retention needed for legal, tax, security, fraud-prevention, or dispute-resolution purposes.
9. Contact
Data protection queries should be sent to privacy@planeer.ai.