This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer", acting as data controller) and plan.It ("Processor") and applies when Customer's use of the Service involves processing personal data subject to the EU GDPR, the UK GDPR, the Swiss FADP, or other comparable laws ("Data Protection Laws").
1. Subject matter and duration
Processor processes personal data only on Customer's documented instructions and only as long as needed to provide the Service or as required by law. The Terms of Service together with Customer's use of the Service constitute Customer's documented instructions.
2. Roles and scope
Customer is the controller; Processor is the processor. Categories of data subjects include the Customer's family-plan members and end-users of the Customer's account. Categories of personal data include account credentials, content the Customer puts into the Service, billing identifiers, and usage logs as described in our Privacy Policy.
3. Subprocessors
Customer authorizes Processor to engage the subprocessors listed in our Privacy Policy. Processor will give reasonable prior notice of the addition or replacement of any subprocessor, and Customer may object on reasonable data-protection grounds.
4. Security measures
Processor implements appropriate technical and organizational measures including: TLS for data in transit; encrypted storage and backups; row-level access control so each account only reads its own data; least-privilege internal access with multi-factor authentication on administrative tools; routine dependency and platform-security monitoring; and audit logging for privileged operations.
5. Confidentiality
Personnel and subprocessors with access to personal data are bound by written confidentiality obligations.
6. International transfers
Where personal data is transferred outside the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Module 2, Controller-to-Processor) by reference, with the UK International Data Transfer Addendum and the Swiss addendum applied as needed. Processor will assist Customer with any required transfer impact assessment.
7. Subprocessor flow-down
Processor will impose data-protection obligations on its subprocessors that are no less protective than those in this DPA and remains responsible for their performance.
8. Data-subject requests
Processor will provide tooling and reasonable assistance to enable Customer to respond to data-subject requests (access, correction, deletion, portability, restriction, objection) within the timeframes required by Data Protection Laws.
9. Incident notification
Processor will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting Customer data, and will provide the information Customer reasonably needs to meet its own notification obligations.
10. Audits
On reasonable prior written request and no more than once per year (unless required more often by a supervisory authority), Processor will make available the information necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire and copies of available subprocessor reports.
11. Return or deletion
On termination of the Service, Processor will, at Customer's choice, delete or return all personal data within 30 days of termination, except where retention is required by law or for routine encrypted backups, which are purged within 90 days.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set forth in the Terms of Service.
13. Contact
To request a signed copy of this DPA or to raise data-protection questions, email hello@planit.me.
