This policy explains what we do with personal data we decide about: the data of the people who run a business on Planimal, and of anyone who contacts us. Our registration and contact details are at the foot of this page.
1. When this policy applies, and when it doesn’t
Planimal is software that businesses use to keep their own client and booking records. So there are two separate piles of data with two different people answerable for them, and this policy covers only one.
The data we answer for — this policy applies. If you run a business on Planimal, work for one, or have written to us: your account, our billing records, our logs and error reports, and your messages to us. In the GDPR’s words we are the controller of it, meaning we decide why it is held.
The data a business answers for — this policy does not apply. The clients, animals and bookings that a business records in Planimal are that business’s own. It decides what to collect and why; we only hold it for them and act on their instructions. In the GDPR’s words we are their processor, under the Data Processing Agreement in Annex A of our terms.
Booked something with a business that uses Planimal? Then that business answers for your data, not us. Ask them for their privacy policy and send any request about your data to them. If you contact us instead, we pass your request on to them without undue delay and tell you we have done so.
2. What we process, why, and for how long
Your account
Email address, name, role, interface preferences, a hash of your password, session and sign-in-link tokens, and the times you confirmed your address and last signed in.
An email address is the one thing you must provide: the account is created for it and operated through it — sign-in links, confirmations and notices under our terms — and we cannot provide an account without one.
Why: to give you an account, sign you in and keep the account secure. Legal basis: performance of the contract with your organisation (article 6(1)(b) GDPR), and our legitimate interest in a secure service (article 6(1)(f)). Retention: for as long as the account exists, then as set out in clause 9 of our terms.
Subscription billing
The subscribing organisation’s name, address, contact details, VAT identification number and Chamber of Commerce number, and the invoices, amounts and payment records that go with the subscription. This is data about the business, but where the business is a sole trader — or the contact details name a person — it is personal data too, which is why it appears here.
Why: to invoice you and to keep the records tax law requires. Legal basis: performance of the contract (article 6(1)(b)) and a legal obligation (article 6(1)(c)). Retention: 7 years from the end of the financial year concerned, as Dutch tax law requires. This period runs regardless of account deletion.
Server and application logs
Request metadata, including IP address, timestamp, the address requested, response status and browser user-agent.
Why: to keep the service running, to diagnose faults and to detect and investigate abuse. Legal basis: legitimate interest in a working, secure service (article 6(1)(f)). Retention: a limited period, and no longer than needed for the purpose above.
Error monitoring
When something goes wrong, an error report is recorded by monitoring software we run on our own servers. Personal data is stripped from it first: the address being visited is reduced to its route, and the parameters of the request, the cookies, the request headers and your IP address are dropped. What is left is the fault itself and where in our code it happened.
Why: to find and fix faults. Legal basis: legitimate interest (article 6(1)(f)). Retention: at most 90 days.
Contacting us
Your email address, your message, and anything you choose to put in it.
Why: to answer you and to keep a record of what was asked and answered. Legal basis: legitimate interest in handling correspondence (article 6(1)(f)), or performance of the contract where you are a customer. Retention: for as long as needed to deal with the matter and, for support history, normally no longer than two years afterwards.
What we don’t do
We do not sell personal data, share it with anyone for their own purposes, use it for advertising, profile you, or take any decision about you by automated means. We do not use your data — or your customers’ data — to train machine-learning models. We send only the service email the account depends on; there is no marketing email and no mailing list.
3. Who else processes it
We use the sub-processors listed in Annex B of our terms. That table is the complete list, with the purpose and location of each. We give notice before we add or replace one.
Beyond them, we do not volunteer personal data to anyone. If a competent authority demands it, we disclose only what a legally binding demand compels and nothing more, and we tell you it happened unless the law forbids us to. The only other case is where disclosure is necessary to establish, exercise or defend a legal claim.
4. Where it is processed
Personal data is processed and stored in the European Economic Area. Where a sub-processor processes personal data outside the EEA, we rely on an adequacy decision of the European Commission or on its Standard Contractual Clauses. Annex B of our terms records where each one processes.
5. How it is protected
The technical and organisational measures we take are set out in Annex B of our terms, in concrete terms rather than as adjectives: transport encryption, encryption at rest for backups and file storage, tenant isolation enforced in the data layer, hashed passwords, limited production access, backups, and an audit trail.
6. Your rights
You may ask us to give you a copy of your personal data, correct it, delete it, restrict what we do with it, or provide it in a portable form. You may object to processing based on our legitimate interest. Where processing rests on consent, you may withdraw it at any time, which does not affect what we did before you withdrew it.
Write to the email address in the footer of this page.
Some data we cannot delete on request: records tax law requires us to keep for 7 years, and data we hold for one of our business customers as processor — for that, see section 1.
You have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the supervisory authority of the EU country where you live or work.
7. Cookies and local storage
Planimal sets no tracking cookies, and therefore has no cookie banner. Everything below is strictly necessary to deliver a service you asked for, so article 11.7a of the Dutch Telecommunications Act requires us to tell you about it — not to ask your permission.
Cookies
| Cookie | What it is for | Lifetime |
|---|---|---|
_planimal_key |
The signed session. Keeps you signed in from one request to the next, carries the token that protects forms against cross-site request forgery, and — on a public booking page — holds the identifier that keeps a slot reserved for your browser while you complete the booking. | Deleted when you close your browser |
_planimal_web_user_remember_me |
Set only if you ask to stay signed in: by ticking “Remember me” when signing in with a password, or by choosing “Keep me logged in on this device” rather than “Log me in only this time” when signing in with an emailed link. It holds the same session token as above, so closing the browser does not sign you out. Signing out deletes it. | 14 days, renewed for another 14 whenever you return after a week or more |
Both are signed, so their contents cannot be altered, and both are SameSite=Lax.
Local storage
Your browser also stores two preferences on your own device, which never reach us: your light/dark theme choice, and whether you collapsed the sidebar. Clearing your browser storage resets them.
We have deliberately added none of the technologies that would need your consent first — analytics, heat-mapping, embedded video, social widgets, advertising pixels. If that ever changes, this section will say so and you will be asked before they load.
8. Changes to this policy
We may update this policy. Every version stays available at its own permanent address; the version in force is always the one at /privacy. Where a change matters to you, we tell the administrative contact on the account by email before it takes effect.
9. Contact
Email the address in the footer of this page. It reaches us for any question about this policy, for exercising a right under section 6, and for reporting a suspected data breach.