Privacy Policy
Last updated: March 2026
1. Data Controller
The data controller for the Plannrly platform is:
Checketts Propiedad SL
Tax ID: ESB42691550
Calle Francisco Salzillo 9
Orihuela Costa, Alicante, 03189, Spain
Where a Subscriber (tenant administrator) uses the Service to manage employee data, the Subscriber acts as the data controller for that employee data and Plannrly acts as the data processor.
2. Data We Collect
We collect the following categories of personal data:
Account Information
- Name, email address, and password (encrypted)
- Company/organisation name
- Profile photo (optional)
Employment Data (entered by Subscriber)
- Job title, department, and business role
- Employment type and pay rate
- Work availability and schedule preferences
Usage Data
- Time entries (clock in/out records)
- Leave requests and approvals
- Shift assignments and swap requests
- Application logs and session data
Technical Data
- IP address and browser type
- Device information
- Cookies and similar technologies (see our Cookie Policy)
3. Legal Basis for Processing
We process personal data under the following legal bases as defined by the GDPR:
- Contract performance: Processing necessary to provide the Service to you (Article 6(1)(b))
- Legitimate interests: Improving the Service, preventing fraud, and ensuring security (Article 6(1)(f))
- Legal obligation: Complying with applicable laws and regulations (Article 6(1)(c))
- Consent: Where you have given explicit consent, such as for marketing communications (Article 6(1)(a))
4. How We Use Your Data
We use your personal data to:
- Provide, operate, and maintain the Service
- Process subscription payments and manage billing
- Send transactional communications (schedule notifications, shift reminders)
- Provide customer support
- Improve and develop the Service
- Ensure the security and integrity of the Service
- Comply with legal obligations
We do not sell your personal data to third parties. We do not use your data for automated decision-making or profiling that produces legal effects.
5. Data Sharing
We may share your data with:
- Service providers: Payment processors (Stripe), hosting providers, and email delivery services that help us operate the Service
- Within your organisation: Data you enter is visible to authorised users within your tenant (e.g., managers can see employee schedules)
- Legal requirements: Where required by law, court order, or governmental authority
All third-party service providers are bound by data processing agreements and are required to protect your data in accordance with applicable law.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. After account termination:
- You may request a data export within 30 days
- Account data is deleted within 90 days of termination
- Billing records are retained for the period required by Spanish tax law (typically 6 years)
- Anonymised, aggregated data may be retained for analytics purposes
7. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request limitation of how we process your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please contact us. We will respond within 30 days.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.
9. Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS)
- Encrypted password storage (bcrypt)
- Tenant data isolation in our multi-tenant architecture
- Regular security reviews and updates
- Access controls and audit logging
While we take security seriously, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.
10. International Transfers
Your data is primarily stored and processed within the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
11. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before the changes take effect.
13. Contact
For privacy-related inquiries, please contact us:
Checketts Propiedad SL
Calle Francisco Salzillo 9
Orihuela Costa, Alicante, 03189, Spain
Contact Form