This policy describes how we collect, use, store, and share personal data when you use the Planista websites, web application, our mobile application where we offer it, related APIs, and integrations (the “Service”). It is written for visitors and users worldwide, including the European Economic Area, the United Kingdom, the United States, and Russia. We update this policy when our practices, data categories, or subprocessors change materially.
The controller identified above (“we”, “us”) is the controller of personal data processed for the Service, unless we act solely as a processor for your organisation (e.g. in a business subscription). In the latter case, your employer or project owner’s terms apply in addition.
Depending on how you use the Service, we may process:
Where GDPR/UK GDPR applies, we rely on:
We do not make decisions that produce legal or similarly significant effects concerning you based solely on automated processing, including profiling, without human involvement, within the meaning of applicable law (AI features suggest options; you remain responsible for choices).
We describe categories of personal information consistent with California and similar state laws. We do not sell personal information for money. Certain sharing for cross-context behavioural advertising may be treated as “sharing” in some states: our use of analytics after consent should be disclosed in the Cookie policy. California residents may have rights to know, delete, correct, and opt out of certain sharing; contact us at privacy@planista.pro. We do not knowingly sell or share personal information of minors under 16 without affirmative authorisation as required by law.
Primary processing of account data, your content, files, backups, transactional email, and technical logs for the Service is carried out using infrastructure located in the Russian Federation (Yandex Cloud). Optional AI features send the text you choose to DeepSeek; that step may involve processing outside Russia and is subject to the requirements of Federal Law No. 152-FZ on cross-border transfer and other rules where they apply. We maintain technical and organisational measures, processing records, and notices as required for our actual processing activities.
We use the following categories of processors (non-exhaustive for ancillary tools of the same class):
Where GDPR/UK GDPR applies and a transfer outside the UK/EEA/adequacy decisions occurs, we use appropriate safeguards (e.g. Standard Contractual Clauses or equivalent) when required. If we add or replace a material subprocessor, we will update this policy or provide notice as required by law.
We keep data as long as your account exists and as needed for the purposes above, then delete or anonymise it unless a longer period is required by law or dispute resolution. Backup copies may persist for a limited technical window.
We implement technical and organisational measures appropriate to the risk (encryption in transit where standard, access controls, etc.). No method of transmission or storage is 100% secure.
Where applicable law requires us to notify you or a regulator of a personal data breach, we will do so in accordance with those requirements.
Depending on your location, you may have the right to access, rectify, erase, restrict, port, or object to certain processing, and to withdraw consent where processing is consent-based. You may lodge a complaint with a supervisory authority (EEA/UK). Contact us at privacy@planista.pro. We may need to verify your identity before responding.
The Service is not directed at children under the age where parental consent is required in your jurisdiction. We do not knowingly collect personal information from such children.
We may update this policy from time to time. We will post the new version and adjust the “Last updated” date. Material changes may require additional notice under local law.