GDPR Commitment

GDPR Commitment

Last updated and effective

Overview

At Planhat, we are committed to upholding the principles of the General Data Protection Regulation (GDPR), and we design our platform and our processes with the aim of supporting our customers in meeting their own GDPR obligations. Not only is the GDPR an important step in protecting the fundamental right of privacy for European citizens, it also raises the bar for data protection, security and compliance in the industry. Below is a general summary of some of the main points.

This document is an informational summary of Planhat’s general approach to data protection. It is not intended to create obligations in addition to those set out in the agreement between Planhat and the customer, including Planhat’s Terms of Service and the Data Processing Agreement (the “DPA”). In the event of any inconsistency between this document and the Terms of Service or the DPA, the Terms of Service and the DPA prevail. Planhat may update this document from time to time, provided that such updates do not result in a degradation of the overall security of the services.

Servers & Security
Servers

Planhat offers hosting of customer data on infrastructure in the EU and the US. Regional hosting means that the production environment, backups and disaster recovery are hosted on servers located in the applicable region.

Planhat engages sub-processors, including infrastructure, support and development resources, for providing its services. Some sub-processors are located outside the EU. Sub-processors are subject to a due diligence and selection process, and Planhat enters into written agreements with each sub-processor imposing data protection obligations that are in substance the same as those imposed on Planhat. Where a transfer outside the EU takes place, it is made on the basis of an adequacy decision or appropriate safeguards such as the EU standard contractual clauses, as further described in the DPA. A current list of sub-processors is available in Planhat’s List of Sub-Processors.

Security

Planhat maintains an information security programme, including technical and organisational measures appropriate to the risk. Those measures are described in Planhat’s Security Statement (https://www.planhat.com/legal/security-statement), which is the primary description of Planhat’s security measures and which Planhat updates from time to time to reflect its current practices.

Product & Data
Processing of Personal Data

Planhat processes personal data as a processor on behalf of its customers and as a controller on its own behalf.. The categories of personal data processed by Planhat as a processor, the categories of data subjects and the purposes of that processing are determined by the customer and are described in the DPA. Planhat’s processing as a controller is described in Planhat’s privacy policy (https://www.planhat.com/legal/privacy-policy).

Given the nature of Planhat’s services (SaaS B2B), the personal data that Planhat processes as a controller in relation to users of the platform relates to their professional use of, and interactions with, Planhat. The lawful bases on which Planhat relies for that processing, and the rights available to individuals, are set out in Planhat’s privacy policy. As a Planhat customer, you are responsible for ensuring that personal data you collect and process using the platform is collected and used lawfully, including for determining the applicable lawful basis and for providing any information required to your own end users

Right to Correct, Amend or Delete Personal Data

As controller, the customer can access, correct, amend and delete personal data relating to its end users directly in the Planhat application and via the API, as described in Planhat’s documentation. Where the customer requires further assistance in responding to a data subject request, Planhat will provide assistance in accordance with Clause 7 of the DPA.

If Planhat receives a request directly from a data subject in relation to personal data processed on a customer’s behalf, Planhat will notify the customer and will not respond to the request itself unless instructed to do so by the customer.

Individuals wishing to exercise rights in relation to personal data for which Planhat is the controller may contact compliance@planhat.com.

Removal of Old or Unused Data

As controller, the customer determines the retention periods applicable to the Personal Data it processes using Planhat, and can identify and remove records using the filtering and deletion functionality available in the application and via the API.

Retention and deletion of Personal Data on expiry or termination of the agreement are governed by the DPA.

Data Portability

The customer can export data from Planhat in structured, commonly used and machine-readable formats via the API, and export functionality is also available within the application. The formats and the scope of the export functionality available from time to time are described in Planhat’s documentation.

Data Access

Planhat personnel are granted access to Personal Data processed on a customer’s behalf on the basis of least privilege, and only where necessary to provide the services in accordance with the agreement. Personnel with such access are bound by confidentiality obligations. Access controls are described further in Planhat’s Security Statement.

Policies & Communication
Data Protection Officer

Planhat has appointed a Data Protection Officer whose role includes monitoring compliance with the GDPR and advising Planhat on its data protection obligations. Get in touch directly at dpo@planhat.com.

Data Processing Agreements (DPAs)

Planhat enters into written data processing agreements with sub-processors that process Personal Data on Planhat’s behalf, imposing data protection obligations that are in substance the same as those Planhat owes to its customers. Planhat’s Data Processing Agreement with its customers forms part of Planhat’s Terms of Service.

Privacy Policy

Planhat maintains a publicly available privacy policy describing its processing of personal data as a controller. As a customer, you remain responsible towards your own end users for providing the information required under applicable data protection laws and for having appropriate privacy terms in place.

Information in Case of Data Breach

In the event of a personal data breach affecting personal data processed by Planhat on the customer’s behalf, Planhat will notify the customer in accordance with the DPA. It remains the customer’s responsibility, as controller, to assess the breach and to make any notification required to a competent supervisory authority or to affected data subjects. Where Planhat is the controller of Personal Data affected by a breach, Planhat will notify affected individuals and supervisory authorities as required under applicable data protection law.

Previous Versions

GDPR Commitment, December 8, 2022