Effective date: [EFFECTIVE_DATE]
Last updated: 28 July 2026
PlanWise (“PlanWise”, “we”, “us”) is a project-management platform for architecture and design practices, operated by [LEGAL_ENTITY_NAME], a company registered in India at [REGISTERED_ADDRESS]. We publish PlanWise at planwiseapp.in and at per-practice addresses of the form planwiseapp.in/yourfirm.
This Privacy Policy explains how we handle personal data across three surfaces:
| Surface | Who uses it | What this policy governs |
|---|---|---|
| Marketing site (planwiseapp.in) | Anyone | Enquiries you send us, and basic request logs |
| The application (signed-in area) | Staff of a subscribing practice | Data we process on that practice's instructions |
| Customer portal (link-based, no login) | A practice's own clients | Data the practice publishes to its client |
Read Section 2 first. For most of the data in PlanWise we are not the party that decides why it is collected — the practice is. That distinction changes who you contact to exercise your rights, and we are explicit about it rather than blurring it.
PlanWise is sold to a firm, but much of the personal data inside it belongs to that firm's employees and clients, who never signed up with us directly. We therefore split our role:
When a subscribing practice (the “Practice”) uses PlanWise to run its business, the Practice determines what data is collected and why. We act only on the Practice's documented instructions. This covers substantially all data in the signed-in application, including:
If you are an employee or client of a Practice and you want to access, correct or delete your data, contact the Practice, not us. We cannot lawfully action such a request on our own initiative, because the data is not ours to decide about. We will, however, help the Practice respond, and we will tell you to whom you should direct the request if you contact us by mistake.
Under Section 2.1 processing, the Practice warrants to us — in the Terms of Service, clause 6 — that it has a lawful basis for every individual whose data it enters, and that it has given its staff whatever monitoring notice its local law requires. We rely on that warranty. We do not independently verify it.
We act as controller — deciding purposes ourselves — for a narrow set of data:
Sections 5–12 (rights, retention, transfers, security) apply to both roles unless stated.
| Data | Where from | Role |
|---|---|---|
| Name, email, phone, practice name, message | Marketing enquiry form | Controller |
| Account holder name, email, password, practice details | Sign-up / onboarding | Controller |
| Staff name, phone, role, experience, skill score, salary | Entered by the Practice | Processor |
| Client names, contact details, project data | Entered by the Practice | Processor |
| Files, drawings, images, PDFs you upload | Application | Processor |
We never store your password. Authentication is handled by our infrastructure provider, which stores a one-way hash. Invitation tokens are stored only as SHA-256 hashes — the plaintext token exists only in the link we send you.
PlanWise records GPS coordinates when a staff member checks in to a site, and compares that position against an office geofence (a centre point and a radius, both configured by the Practice) to validate office attendance.
We do not sell personal data. We do not share it with advertising networks or data brokers. We do not use your project data, files, or client data to train machine-learning models. We do not run third-party advertising or cross-site tracking pixels on the application.
| Purpose | Data | Basis (GDPR/UK GDPR) | Basis (DPDP Act 2023) |
|---|---|---|---|
| Provide the platform | All application data | Contract (Art. 6(1)(b)); processor acting on controller instructions (Art. 28) | Legitimate use for the specified purpose / consent obtained by the Practice |
| Respond to your enquiry | Enquiry form data | Legitimate interests (Art. 6(1)(f)) — responding to a request you initiated | Consent, given by submitting the form |
| Billing and tax records | Account, billing | Contract; legal obligation (Art. 6(1)(c)) | Legal obligation |
| Security, abuse prevention, rate limiting | IP, session, login events | Legitimate interests (Art. 6(1)(f)) — securing the service | Legitimate use — prevention of fraud and network security |
| Diagnose faults | Error records | Legitimate interests (Art. 6(1)(f)) | Legitimate use |
| Service announcements | Contact details | Contract | Legal/contractual |
| Marketing emails | Contact details | Consent (Art. 6(1)(a)) — withdrawable at any time | Consent |
Where we rely on legitimate interests, we have assessed that interest against your rights and concluded it does not override them; you may object at any time (Section 6).
We use a small number of sub-processors. Each is bound by contract to protect the data and use it only to provide their service to us.
| Sub-processor | Function | Data | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All application data | AWS ap-south-1, Mumbai, India |
| Vercel | Application hosting, delivery | Request data, IP addresses in transit | Global edge; primary region India |
| Google LLC | Calendar sync — only if a Practice owner explicitly connects it | Calendar event titles, times, attendees from the connected account, read-only | Google infrastructure |
| Push services (Apple, Google, Mozilla — determined by your browser) | Deliver push notifications | Notification payload and subscription endpoint | Provider infrastructure |
| cron-job.org | Triggers scheduled background jobs | No personal data — an authenticated trigger only | EU |
We will publish an updated list here before adding a sub-processor that handles personal data.
Google Calendar integration. Read-only, one-way (Google into PlanWise), and off unless a Practice owner connects it. Access tokens are stored encrypted. Imported events default to the most restrictive visibility (owner-only), and are re-evaluated on every sync so that removing a promotion keyword demotes an event again. Disconnecting revokes our access. Our use of Google data complies with the Google API Services User Data Policy, including its Limited Use requirements.
We may also disclose data where legally compelled (Section 11).
Grievance Officer: [GRIEVANCE_OFFICER_NAME], [GRIEVANCE_EMAIL], [REGISTERED_ADDRESS].
If unsatisfied, you may complain to the Data Protection Board of India.
Where they apply, you have rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects. PlanWise makes no such automated decisions: performance scores and skill ratings are decision support shown to a human, never an automatic outcome.
You may complain to your supervisory authority — in the UK, the Information Commissioner's Office.
Write to [GRIEVANCE_EMAIL]. We respond within 30 days.
If your data sits inside a Practice's account, we will forward your request to that Practice rather than action it ourselves, and tell you we have done so. This is not evasion — it is the legal consequence of the processor role described in Section 2.1. The Practice decides; we execute. Our contract obliges us to give the Practice the technical means to comply.
We may ask for proof of identity, and will not action a request that would expose someone else's data.
We do not currently offer PlanWise to US-based customers, so this policy makes no CCPA/CPRA commitments. If that changes, we will update this policy before onboarding a US customer rather than claim coverage we have not built. We do not sell or share personal data as those terms are defined under US state privacy laws.
Your data is stored in India (AWS ap-south-1, Mumbai). For an Indian Practice, this is domestic processing.
If you are in the UK or EEA, understand this clearly: using PlanWise means your data is transferred to and stored in India. India has not received an adequacy decision from the European Commission or the UK Government. We therefore rely on Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with the technical measures in Section 8, as the transfer safeguard. A copy of the clauses is available on request at [GRIEVANCE_EMAIL].
We flag this rather than bury it, because a transfer story that surfaces late is exactly the kind of gap that causes problems for both of us.
No system is perfectly secure, and we will not claim otherwise. If we become aware of a personal data breach we will notify the Data Protection Board of India and affected Practices without undue delay, and where GDPR applies, the relevant supervisory authority within 72 hours of becoming aware. Where we are the processor, we notify the Practice without undue delay so it can meet its own deadlines.
Report a vulnerability to [SECURITY_EMAIL]. We will not pursue legal action against good-faith researchers who report privately and do not access data beyond what is needed to demonstrate the issue.
| Data | Retained |
|---|---|
| Account and project data | For the life of the subscription |
| Deleted records | Recoverable 60 days (configurable), then permanently purged |
| GPS coordinates | 30 days (configurable), then erased; attendance times retained |
| Records of removed employees | Purged 30 days after removal |
| Audit log | Most recent 100 entries per practice |
| Error diagnostics | 30 days |
| Enquiries | Until you ask us to delete them, or 24 months of inactivity |
| Billing and tax records | 8 years, as Indian tax law requires |
On termination, Section 10 of the Terms of Service governs: a 30-day window to export, then deletion within 90 days, excluding backups (purged on their own cycle, maximum 180 days) and records we must keep by law.
PlanWise is a workplace tool, not intended for anyone under 18, and we do not knowingly collect their data. The DPDP Act requires verifiable parental consent for under-18s and prohibits tracking and targeted advertising directed at children; we avoid this by not serving children. If you believe a child's data has reached us, contact [GRIEVANCE_EMAIL] and we will delete it.
We may disclose data where required by valid legal process, to establish or defend legal claims, or to prevent imminent harm. Where we are the processor and lawfully permitted, we will notify the affected Practice first so it can seek protective relief. We will challenge requests that are overbroad or defective.
We use strictly necessary cookies only: session authentication, security and load balancing. No advertising cookies, no cross-site tracking, no third-party analytics profiling. Because these are strictly necessary to deliver a service you requested, they do not require consent under the ePrivacy Directive or Rule 3 of the Indian IT Rules. If we add analytics, we will ask first.
The application also uses browser storage to work offline as a Progressive Web App. This stays on your device and is cleared at sign-in.
We will post material changes here and update “Last updated”. For changes that significantly affect your rights, we will give 30 days' notice by email or in-app before they take effect. Continued use after that constitutes acceptance. Archived versions are available on request.
| Entity | [LEGAL_ENTITY_NAME] |
|---|---|
| Address | [REGISTERED_ADDRESS], [CITY], India |
| Privacy / Grievance Officer | [GRIEVANCE_OFFICER_NAME] — [GRIEVANCE_EMAIL] |
| Security | [SECURITY_EMAIL] |
| Support | [SUPPORT_EMAIL] |
We acknowledge within 72 hours and resolve within 30 days.