Version 1.2 - effective from May 15, 2026
For website user data, the data controller is ML Devworks Michał Lipka with its registered office at Rynek Główny 34 lok. 15, 31-010 Kraków, Poland, Tax ID (NIP): 6762707876, REGON: 543372505.
For Client employees' data, the data controller is the Client (employer), and ML Devworks Michał Lipka acts as a data processor based on a data processing agreement (DPA).
Contact: biuro@planopia.pl
2.1. We process personal data for the following purposes:
- Providing services through the Planopia.pl platform (legal basis: Art. 6(1)(b) GDPR - contract performance)
- Fulfilling legal obligations (legal basis: Art. 6(1)(c) GDPR)
- Direct marketing only towards Clients (legal basis: Art. 6(1)(f) GDPR - legitimate interest). Marketing does not include Client employees' data.
2.2. For Client employees' data - the Client is the data controller, and we are the data processor (details in DPA).
3.1. Account user data:
- First and last name
- Email address
- Job position
3.2. Employee data (processed on behalf of the Client):
- First and last name
- Email address
- Job position
- Working time data
- Leave data
3.3. Technical data:
- IP address
- Browser information
- Cookies (including session login cookies)
3.4. AI Assistant and other OpenAI API features (when enabled in the Service and available on the Client’s plan):
- User questions and selected, aggregated Account data (e.g. working-time and leave summaries for a chosen period — within the User’s permissions) are sent to OpenAI (OpenAI, L.L.C., USA) solely to generate a response.
- Chat history in the AI Assistant UI is stored in the User’s browser (localStorage) on their device — we do not store it permanently in our database. Users can remove it by clearing site data in the browser.
- We store usage counters (plan limits) and technical log entries (e.g. that the feature was used), not the full chat transcript on our servers.
4.1. Data may be transferred to:
- Hosting and infrastructure providers (including Render.com — backend and database; Vercel or Netlify — planopia.pl website)
- OpenAI (OpenAI, L.L.C.) — only when using AI features described in section 3.4
- Payment operators (including Przelewy24, Stripe) — to the extent necessary for subscription billing
- Google LLC (Google Analytics, Google Tag Manager) — traffic analysis and campaign performance measurement on planopia.pl and app.planopia.pl
- Government authorities upon request under applicable law
4.2. All subcontractors are obligated to comply with data protection principles.
4a.1. Personal data may be processed outside the European Economic Area (EEA), particularly in the United States (Oregon - US West) by hosting service providers.
4a.2. Data transfer outside the EEA is based on Standard Contractual Clauses (SCC) pursuant to European Commission Decision 2021/914.
4a.3. Google LLC (Google Analytics, Google Tag Manager) and OpenAI (for AI features) also process data in the USA based on appropriate protection mechanisms compliant with GDPR (including Standard Contractual Clauses where applicable).
5.1. Data is retained for the following periods:
- Team data (Accounts): 30 days after contract termination/subscription end, then deleted (period can be extended or shortened upon Client's written request)
- Team user data: After a user is deleted from the team by an administrator, user data is retained for 30 days (retention period). After this period, data will be permanently deleted. The administrator can restore the user or permanently delete them at any time before the retention period expires. The Client (administrator) is responsible for managing their employees' data in accordance with labor law. Users cannot delete their own accounts - this requires administrator action.
- Billing data: 5 years (in accordance with tax regulations)
- Technical logs: 90 days (period can be extended or shortened upon Client's written request)
- Data until consent withdrawal (if processing is based on consent)
5.2. After subscription termination/contract end, team data will be deleted within 30 days, except for data required by law (e.g., tax regulations). User data is retained for 30 days after deletion (retention period), then permanently deleted.
5.3. The Client has the right to request extension or shortening of the data retention period within the scope permitted by law. Requests should be sent to: biuro@planopia.pl
6.1. You have the following rights:
- Right of access to data
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
6.2. Rights can be exercised by contacting: biuro@planopia.pl
6.3. You also have the right to lodge a complaint with the supervisory authority (President of the Personal Data Protection Office in Poland, or your local data protection authority).
7.1. The planopia.pl and app.planopia.pl websites use cookies for:
- Enabling basic functionality
- Analysis of traffic and website usage (Google Analytics 4) - only after consent
- Measurement of campaign performance and attribution of sign-ups to ads (Google Ads) - only after marketing consent
7.2. Before consent is given, the Google tag operates in Consent Mode with analytics and advertising storage denied. It may then send limited, cookieless technical signals to Google for aggregate measurement and modelling. Optional analytics and marketing cookies are not written or read until the relevant consent is granted.
7.3. Data from Google Analytics 4 and Google Ads is processed by Google LLC in accordance with Google’s privacy policy. Once the relevant consent is granted, these tools may use cookies and similar identifiers to analyze website usage and measure conversions.
7.4. On the first visit, users can accept all optional cookies, reject them, or choose analytics and marketing categories separately. Refusing consent does not restrict access to the website or the ability to sign up.
7.5. Consent can be changed or withdrawn at any time using the “Cookie settings” link in the planopia.pl footer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7.6. The cookie choice is stored for 180 days unless the user deletes cookies or changes the settings earlier.
8.1. We apply appropriate technical and organizational measures, including:
- Connection encryption (HTTPS/TLS)
- Password login and session control (httpOnly cookie tokens)
- In-app access control (roles and permissions within the Client’s team)
- Regular backups
- System monitoring
8.1a. Note: at the time of this version, the Service does not offer separate multi-factor authentication (2FA) in the app. The Client is responsible for password and device security for Users.
8.2. Data is stored on servers in Oregon (US West), United States. Data transfer outside the European Economic Area (EEA) is based on Standard Contractual Clauses (SCC) pursuant to European Commission Decision 2021/914.
9.1. We reserve the right to make changes to the Privacy Policy.
9.2. Users will be notified of significant changes.
Last updated: May 15, 2026