Data Processing Agreement
This agreement forms part of the Terms of Service and applies whenever we process personal data on your behalf.
Last updated: August 2026
1. Roles of the Parties
This agreement is between the Subscriber ("Controller") and Checketts Propiedad SL, which operates Plannrly ("Processor"). It is entered into automatically when a subscription begins and needs no separate signature, though a signed copy is available on request.
You decide why and how your employees' personal data is processed. We process it only to provide the Service to you. For your own account and billing data we act as controller in our own right, and that processing is described in the Privacy Policy rather than here.
You are responsible for having a lawful basis for the data you put into the Service, and for telling your employees that you use it.
2. Subject Matter & Duration
The subject matter is the provision of workforce scheduling, time and attendance, leave management and employee record-keeping. The nature of the processing is storage, organisation, retrieval, alteration and erasure, carried out by automated means.
Processing lasts for as long as your subscription is active, and then through the retention period described in the Terms: the account becomes read-only, data can be exported for 90 days, and is deleted after that.
3. Data & Data Subjects
The categories of personal data we process on your behalf are those you choose to enter, and typically include:
- Identity and contact details: name, email address, telephone number
- Employment details: job role, department, location, contract hours, start and end dates
- Working time: shifts, clock-in and clock-out records, breaks, hours worked, absence and lateness
- Leave records: requests, approvals, balances and the leave type chosen by you
- Documents you upload, and their expiry dates, where you use document management
The Service is not designed to hold special categories of data under Article 9. If you choose to record such data - for example a health reason in a leave note or an uploaded document - you do so as controller and must have a lawful basis for it.
The data subjects are your employees, managers and administrators, and anyone else you invite into your account.
4. Our Instructions & Confidentiality
We process personal data only on your documented instructions. Your use of the Service, and these Terms, are those instructions. We will not use your employees' data for our own purposes, will not sell it, and will not use it to train machine-learning models.
If we are required by EU or Spanish law to process data beyond your instructions, we will tell you before doing so unless that law forbids it. If we believe an instruction breaches data protection law, we will say so.
Everyone we authorise to access personal data is bound by a duty of confidentiality, and access is limited to those who need it to operate or support the Service.
5. Security Measures
We maintain technical and organisational measures appropriate to the risk, as required by Article 32. These include:
- Encryption of data in transit using TLS
- Passwords stored only as bcrypt hashes, never in a recoverable form
- Tenant isolation, so one customer's data is not reachable from another's account
- Role-based access controls within each account, set by you
- Audit logging of significant actions, with a retention period you control
- Regular review of dependencies for published security advisories
Measures are reviewed as the Service changes. We may replace a measure with an equivalent or stronger one, but will not materially reduce the overall level of protection.
6. Sub-processors
You give general authorisation for us to use the sub-processors below. Each is bound by data protection terms no less protective than these, and we remain responsible to you for what they do.
- Hosting and infrastructure: DigitalOcean, servers located in the EU
- Transactional email delivery: Resend
- Payment processing: Stripe, which receives billing contact and payment details but no employee data
- Application monitoring and error reporting: Laravel Nightwatch
- Bot protection on the registration and contact forms: Cloudflare Turnstile
We will give at least 30 days' notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. If we cannot resolve an objection, you may terminate the affected part of the Service without penalty. Our analytics run only on the public marketing pages and never on the application, so they do not process your employees' data.
7. Assistance & Data Subject Rights
The Service gives you the tools to answer data subject requests yourself: you can view, correct, export and delete an employee's data from within your account, and export requests produce a machine-readable file.
Where a request cannot be answered with those tools, we will assist you, taking into account the nature of the processing and the information available to us. If a data subject contacts us directly about your data, we will refer them to you rather than answer for you.
We will also assist, on request and so far as we reasonably can, with data protection impact assessments and with any prior consultation of a supervisory authority.
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and give you the information you need to meet your own obligations under Articles 33 and 34, as it becomes available to us.
8. International Transfers
Your employees' data is stored and processed within the European Economic Area. Where a sub-processor operates outside the EEA, the transfer is covered by an adequacy decision or by Standard Contractual Clauses, with additional measures where required.
9. Return & Deletion
When the Service ends, you can export your data for 90 days. After that we delete it, including from the systems of our sub-processors, except where EU or Spanish law requires us to keep it. Backups are overwritten on their normal cycle.
10. Audit & Information
On request, we will provide the information needed to demonstrate that we meet the obligations in this agreement. Where that is not sufficient for your purposes, we will accommodate an audit by you or an independent auditor you appoint, on reasonable notice, no more than once a year unless a breach or a supervisory authority gives cause, and subject to confidentiality. You bear the cost of an audit you request.
11. Term & Precedence
This agreement applies for as long as we process personal data on your behalf. Where it conflicts with the Terms of Service on a data protection matter, this agreement prevails.
12. Contact
For any question about this agreement, or to request a signed copy, contact us:
Checketts Propiedad SL
Tax ID: ESB42691550
Calle Francisco Salzillo 9
Orihuela Costa, Alicante, 03189, Spain
Email: info@plannrly.com