Privacy Policy
Last updated: March 2026. Draft for review — replace bracketed placeholders with final company and legal details before production.
1. Controller
The controller responsible for processing personal data is [Company legal name], [Registered address], email: support@planandpan.com (replace with official contact).
2. Purposes and legal bases
We process data to provide our services, manage your account and orders, communicate with you, process payments, improve our website, and comply with legal obligations. Legal bases include performance of a contract (Art. 6(1)(b) GDPR), legitimate interests such as IT security (Art. 6(1)(f) GDPR), and consent where required (Art. 6(1)(a) GDPR).
3. Categories of data
Depending on your use of the site, we may process: account and contact data (e.g. name, email, phone), order and project details, communication content, technical data (e.g. IP address, device/browser type, timestamps), and payment-related information processed by payment providers.
4. Recipients & transfers
We use processors for hosting, email delivery, analytics (only if you consent), and payment processing. If data is transferred outside the European Economic Area, we ensure appropriate safeguards (e.g. Standard Contractual Clauses) where required.
5. Storage periods
We retain data only as long as necessary for the purposes above, including statutory retention periods (e.g. tax and commercial law). After that, data is deleted or anonymized.
6. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and objection where applicable. You may lodge a complaint with a supervisory authority. You may withdraw consent at any time without affecting lawfulness of processing before withdrawal.
7. Cookies
See our Cookie Policy for details on cookies and similar technologies.
