Legal

PlanWise — Privacy Policy

Effective date: [EFFECTIVE_DATE]
Last updated: 28 July 2026

[FOUNDER: fill before publishing] — [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS], [CITY], [STATE], India · [GRIEVANCE_EMAIL] · [SUPPORT_EMAIL]
This document has not been reviewed by a lawyer. Have it reviewed before you rely on it.

1. Who we are and what this covers

PlanWise (“PlanWise”, “we”, “us”) is a project-management platform for architecture and design practices, operated by [LEGAL_ENTITY_NAME], a company registered in India at [REGISTERED_ADDRESS]. We publish PlanWise at planwiseapp.in and at per-practice addresses of the form planwiseapp.in/yourfirm.

This Privacy Policy explains how we handle personal data across three surfaces:

SurfaceWho uses itWhat this policy governs
Marketing site (planwiseapp.in)AnyoneEnquiries you send us, and basic request logs
The application (signed-in area)Staff of a subscribing practiceData we process on that practice's instructions
Customer portal (link-based, no login)A practice's own clientsData the practice publishes to its client

Read Section 2 first. For most of the data in PlanWise we are not the party that decides why it is collected — the practice is. That distinction changes who you contact to exercise your rights, and we are explicit about it rather than blurring it.


2. Controller and processor — the most important section

PlanWise is sold to a firm, but much of the personal data inside it belongs to that firm's employees and clients, who never signed up with us directly. We therefore split our role:

2.1 Where the practice is the controller and we are the processor

When a subscribing practice (the “Practice”) uses PlanWise to run its business, the Practice determines what data is collected and why. We act only on the Practice's documented instructions. This covers substantially all data in the signed-in application, including:

  • staff records, roles, phone numbers, experience and skill ratings, and salary information;
  • attendance logs, site check-in and check-out times, worked-hours totals, and GPS coordinates captured at check-in (see Section 4.3 — this is employee monitoring data and we treat it with corresponding seriousness);
  • projects, drawings, media, material plans, expenses, payment schedules and payment records;
  • the Practice's own clients, enquiries, contact details and portal activity.

If you are an employee or client of a Practice and you want to access, correct or delete your data, contact the Practice, not us. We cannot lawfully action such a request on our own initiative, because the data is not ours to decide about. We will, however, help the Practice respond, and we will tell you to whom you should direct the request if you contact us by mistake.

Under Section 2.1 processing, the Practice warrants to us — in the Terms of Service, clause 6 — that it has a lawful basis for every individual whose data it enters, and that it has given its staff whatever monitoring notice its local law requires. We rely on that warranty. We do not independently verify it.

2.2 Where we are the controller

We act as controller — deciding purposes ourselves — for a narrow set of data:

  • account and billing data for the Practice and the individual who signs it up;
  • enquiries submitted through our marketing site, including your name, phone, email, message, referring URL and IP address;
  • security and abuse telemetry: login attempts, rate-limit events, IP addresses, device labels, and application error records;
  • our own correspondence with you.

Sections 5–12 (rights, retention, transfers, security) apply to both roles unless stated.


3. Data we collect

3.1 You give us directly

DataWhere fromRole
Name, email, phone, practice name, messageMarketing enquiry formController
Account holder name, email, password, practice detailsSign-up / onboardingController
Staff name, phone, role, experience, skill score, salaryEntered by the PracticeProcessor
Client names, contact details, project dataEntered by the PracticeProcessor
Files, drawings, images, PDFs you uploadApplicationProcessor

We never store your password. Authentication is handled by our infrastructure provider, which stores a one-way hash. Invitation tokens are stored only as SHA-256 hashes — the plaintext token exists only in the link we send you.

3.2 Generated automatically when you use PlanWise

  • Session and device data — device label, IP address, session timestamps. A Practice owner can see and revoke the active sessions of their own staff.
  • Login and security events — last login time, password-change time, multi-factor enrolment time, failed-attempt and rate-limit records tied to IP address.
  • Audit records — an append-only, hash-chained log of who changed what and when, within a Practice. Designed so that tampering is detectable.
  • Error diagnostics — error level, message, request path and technical detail when something breaks, so we can fix it.
  • Push notification subscriptions, if you grant browser notification permission.

3.3 Location data — stated plainly

PlanWise records GPS coordinates when a staff member checks in to a site, and compares that position against an office geofence (a centre point and a radius, both configured by the Practice) to validate office attendance.

  • Location is captured at the moment of a check-in or check-out action only. PlanWise does not track continuous or background location, and does not track anyone who is not performing a check-in.
  • Coordinates are automatically erased after 30 days by default, while the attendance record itself (times, duration) is retained. This retention window is configurable per Practice.
  • The Practice, as controller, is responsible for telling its staff that this is switched on.

3.4 What we do not do

We do not sell personal data. We do not share it with advertising networks or data brokers. We do not use your project data, files, or client data to train machine-learning models. We do not run third-party advertising or cross-site tracking pixels on the application.


4. Why we process data, and our lawful bases

PurposeDataBasis (GDPR/UK GDPR)Basis (DPDP Act 2023)
Provide the platformAll application dataContract (Art. 6(1)(b)); processor acting on controller instructions (Art. 28)Legitimate use for the specified purpose / consent obtained by the Practice
Respond to your enquiryEnquiry form dataLegitimate interests (Art. 6(1)(f)) — responding to a request you initiatedConsent, given by submitting the form
Billing and tax recordsAccount, billingContract; legal obligation (Art. 6(1)(c))Legal obligation
Security, abuse prevention, rate limitingIP, session, login eventsLegitimate interests (Art. 6(1)(f)) — securing the serviceLegitimate use — prevention of fraud and network security
Diagnose faultsError recordsLegitimate interests (Art. 6(1)(f))Legitimate use
Service announcementsContact detailsContractLegal/contractual
Marketing emailsContact detailsConsent (Art. 6(1)(a)) — withdrawable at any timeConsent

Where we rely on legitimate interests, we have assessed that interest against your rights and concluded it does not override them; you may object at any time (Section 6).


5. Who we share data with

We use a small number of sub-processors. Each is bound by contract to protect the data and use it only to provide their service to us.

Sub-processorFunctionDataLocation
SupabaseDatabase, authentication, file storageAll application dataAWS ap-south-1, Mumbai, India
VercelApplication hosting, deliveryRequest data, IP addresses in transitGlobal edge; primary region India
Google LLCCalendar sync — only if a Practice owner explicitly connects itCalendar event titles, times, attendees from the connected account, read-onlyGoogle infrastructure
Push services (Apple, Google, Mozilla — determined by your browser)Deliver push notificationsNotification payload and subscription endpointProvider infrastructure
cron-job.orgTriggers scheduled background jobsNo personal data — an authenticated trigger onlyEU

We will publish an updated list here before adding a sub-processor that handles personal data.

Google Calendar integration. Read-only, one-way (Google into PlanWise), and off unless a Practice owner connects it. Access tokens are stored encrypted. Imported events default to the most restrictive visibility (owner-only), and are re-evaluated on every sync so that removing a promotion keyword demotes an event again. Disconnecting revokes our access. Our use of Google data complies with the Google API Services User Data Policy, including its Limited Use requirements.

We may also disclose data where legally compelled (Section 11).


6. Your rights

6.1 Under the Digital Personal Data Protection Act, 2023 (India)

  • Access — a summary of your personal data and the processing we perform.
  • Correction and erasure — correct inaccurate or incomplete data; erase data no longer needed for its purpose, unless retention is legally required.
  • Grievance redressal — raise a grievance with us; we respond within 30 days.
  • Nomination — nominate someone to exercise your rights if you die or become incapacitated.
  • Withdraw consent — as easily as it was given, where consent is our basis.

Grievance Officer: [GRIEVANCE_OFFICER_NAME], [GRIEVANCE_EMAIL], [REGISTERED_ADDRESS].

If unsatisfied, you may complain to the Data Protection Board of India.

6.2 Under the GDPR and UK GDPR

Where they apply, you have rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects. PlanWise makes no such automated decisions: performance scores and skill ratings are decision support shown to a human, never an automatic outcome.

You may complain to your supervisory authority — in the UK, the Information Commissioner's Office.

6.3 How to exercise them, and the honest limitation

Write to [GRIEVANCE_EMAIL]. We respond within 30 days.

If your data sits inside a Practice's account, we will forward your request to that Practice rather than action it ourselves, and tell you we have done so. This is not evasion — it is the legal consequence of the processor role described in Section 2.1. The Practice decides; we execute. Our contract obliges us to give the Practice the technical means to comply.

We may ask for proof of identity, and will not action a request that would expose someone else's data.

6.4 California and other US state rights

We do not currently offer PlanWise to US-based customers, so this policy makes no CCPA/CPRA commitments. If that changes, we will update this policy before onboarding a US customer rather than claim coverage we have not built. We do not sell or share personal data as those terms are defined under US state privacy laws.


7. International transfers

Your data is stored in India (AWS ap-south-1, Mumbai). For an Indian Practice, this is domestic processing.

If you are in the UK or EEA, understand this clearly: using PlanWise means your data is transferred to and stored in India. India has not received an adequacy decision from the European Commission or the UK Government. We therefore rely on Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with the technical measures in Section 8, as the transfer safeguard. A copy of the clauses is available on request at [GRIEVANCE_EMAIL].

We flag this rather than bury it, because a transfer story that surfaces late is exactly the kind of gap that causes problems for both of us.


8. Security

  • Tenant isolation enforced in the database, not merely in application code. Every table carrying practice data has row-level security, so a query for another practice's data returns nothing even if application code were flawed. This is verified by an automated cross-tenant test that must pass before any database change can ship.
  • Capability-based access control. Permissions are explicit grants per user, checked on every API call and every UI element. Being an owner is not a shortcut past a permission check.
  • Encryption in transit (TLS) and at rest. Google tokens are encrypted with a separate key.
  • Append-only, hash-chained audit log, so tampering is detectable.
  • Authentication protections: hashed passwords, optional multi-factor authentication, per-device session revocation, and rate limiting on login and verification.
  • Continuous security checks on our codebase: dependency auditing, secret scanning and static analysis run automatically before changes ship.
  • Automatic session hygiene: cached pages from a previous session are purged at sign-in, so a shared device does not leak the previous user's screens.

No system is perfectly secure, and we will not claim otherwise. If we become aware of a personal data breach we will notify the Data Protection Board of India and affected Practices without undue delay, and where GDPR applies, the relevant supervisory authority within 72 hours of becoming aware. Where we are the processor, we notify the Practice without undue delay so it can meet its own deadlines.

Report a vulnerability to [SECURITY_EMAIL]. We will not pursue legal action against good-faith researchers who report privately and do not access data beyond what is needed to demonstrate the issue.


9. Retention

DataRetained
Account and project dataFor the life of the subscription
Deleted recordsRecoverable 60 days (configurable), then permanently purged
GPS coordinates30 days (configurable), then erased; attendance times retained
Records of removed employeesPurged 30 days after removal
Audit logMost recent 100 entries per practice
Error diagnostics30 days
EnquiriesUntil you ask us to delete them, or 24 months of inactivity
Billing and tax records8 years, as Indian tax law requires

On termination, Section 10 of the Terms of Service governs: a 30-day window to export, then deletion within 90 days, excluding backups (purged on their own cycle, maximum 180 days) and records we must keep by law.


10. Children

PlanWise is a workplace tool, not intended for anyone under 18, and we do not knowingly collect their data. The DPDP Act requires verifiable parental consent for under-18s and prohibits tracking and targeted advertising directed at children; we avoid this by not serving children. If you believe a child's data has reached us, contact [GRIEVANCE_EMAIL] and we will delete it.


11. Legal disclosure

We may disclose data where required by valid legal process, to establish or defend legal claims, or to prevent imminent harm. Where we are the processor and lawfully permitted, we will notify the affected Practice first so it can seek protective relief. We will challenge requests that are overbroad or defective.


12. Cookies and similar technologies

We use strictly necessary cookies only: session authentication, security and load balancing. No advertising cookies, no cross-site tracking, no third-party analytics profiling. Because these are strictly necessary to deliver a service you requested, they do not require consent under the ePrivacy Directive or Rule 3 of the Indian IT Rules. If we add analytics, we will ask first.

The application also uses browser storage to work offline as a Progressive Web App. This stays on your device and is cleared at sign-in.


13. Changes

We will post material changes here and update “Last updated”. For changes that significantly affect your rights, we will give 30 days' notice by email or in-app before they take effect. Continued use after that constitutes acceptance. Archived versions are available on request.


14. Contact

Entity[LEGAL_ENTITY_NAME]
Address[REGISTERED_ADDRESS], [CITY], India
Privacy / Grievance Officer[GRIEVANCE_OFFICER_NAME] — [GRIEVANCE_EMAIL]
Security[SECURITY_EMAIL]
Support[SUPPORT_EMAIL]

We acknowledge within 72 hours and resolve within 30 days.


← Back to PlanWise