Plannii
Privacy Policy
- Version:
- 0.1 (draft)
- Last updated:
- 2026-04-28
This Privacy Policy explains what personal data we collect in the Plannii app, for what purpose, on what legal basis, and to whom we entrust it. The document is prepared in accordance with Regulation (EU) 2016/679 (GDPR).
1. Data controller
The controller of your personal data is M&W APPLICATIONS Sp. z o.o., a Polish limited-liability company with its registered office in Wejherowo, ul. Gen. Józefa Hallera 20, 84-200 Wejherowo, Poland, entered in the Polish National Court Register under KRS 0001216464, tax ID NIP 5882541886, REGON 543717223 (the “Controller”).
The Controller can be contacted at [email protected] or by phone at +48 501 399 266.
2. What data we process
| Category | Examples | Purpose |
|---|---|---|
| Account & identity | first/last name, email, profile photo, authentication provider ID (Clerk) | account creation, login, contact |
| Event & reservation data | event name, date, location, guest list, agreed terms (Agreement Card) | performance of the service contract |
| Payment data | Stripe customer/transaction IDs, last 4 digits of the card, payment status (full card numbers and CVC never reach us) | processing payments, settlements, tax/accounting obligations |
| Communication | chat message content (1:1 and group), attachments | communication between contract parties |
| Technical data | IP address, device/OS type, app install ID, error logs | security, diagnostics, quality improvements |
3. Purposes and legal bases
- performance of a contract (Art. 6(1)(b) GDPR) — account creation, reservations, support;
- legal obligations (Art. 6(1)(c) GDPR) — issuing and storing accounting documents;
- legitimate interests (Art. 6(1)(f) GDPR) — Service security, defending claims, app analytics;
- consent (Art. 6(1)(a) GDPR) — only where required by law (e.g. optional marketing notifications).
4. Recipients (processors)
- Clerk Inc. — authentication and account management,
- Stripe Payments Europe, Ltd. — payment processing and Customer Portal,
- Sentry — application error monitoring,
- cloud hosting and infrastructure providers (EU/EEA),
- email and push notification providers.
Where possible, data is processed within the EEA. For transfers outside the EEA we use the Standard Contractual Clauses adopted by the European Commission.
5. Retention
- Account and event data — for as long as the Service is used and until a deletion request is submitted.
- Financial data (invoices, accounting records) — for the period required by tax law (typically 5 years).
- System and diagnostic logs — generally up to 30 days.
- Chat messages — until the User deletes their account or until limitation periods expire.
6. Your rights
- access to data and a copy thereof,
- rectification of inaccurate or incomplete data,
- erasure (“right to be forgotten”),
- restriction of processing,
- data portability (including a JSON export of your data),
- objection to processing based on legitimate interest,
- withdrawal of consent at any time (without affecting prior processing),
- filing a complaint with the supervisory authority — in Poland: the President of the Office for Personal Data Protection (uodo.gov.pl).
To exercise your rights, please contact us at [email protected]. Account deletion results in: deletion of the Clerk account, hard deletion of personal data in our database, anonymization of transaction data we are required to retain, and deletion of chat history linked to the account.
7. Data security
- all communication uses TLS encryption,
- sensitive data (card data, passwords) is not processed on our infrastructure — Stripe and Clerk are responsible for it,
- the database is access-controlled and backed up regularly,
- logs are automatically sanitized of personally identifying data,
- only authorized administrators can access production data.
8. Cookies and analytics
The Plannii website uses only cookies strictly necessary for the operation of the Service (session cookies). Any analytics or marketing cookies introduced in the future will require prior consent via a cookie banner.
9. Children
The Plannii app is intended for adults. We do not knowingly collect data of children under 16. If we learn of such processing, we will delete the data without undue delay.
10. Changes
Material changes will be communicated at least 14 days in advance via the App or by email. The current version is always available at this URL.