1. Overview
Planiq provides a visual project planning service. We take your privacy seriously and only collect what we need to run the service. This page explains what we collect, why, and your rights under the GDPR.
2. Data we collect
Account data
When you sign up, we store your email address, a hashed password, your display name, and any organization memberships.
Content you create
Boards, nodes, edges, comments, uploaded files, time entries, and any other content you create in Planiq. You own this data; we store and serve it on your behalf.
Usage data
Aggregated and anonymised metrics — features used, performance timings, error reports. We use this to improve the product.
Billing data
For paid plans we store invoices and the last four digits of your payment method. Full card details are handled by our payment processor and never reach our servers.
3. How we use it
- To deliver and maintain the service.
- To communicate important changes, security notices, and billing updates.
- To detect and prevent fraud, abuse, and security incidents.
- To meet legal and tax obligations.
We do not sell your data. We do not use your content to train AI models.
4. Sharing & sub-processors
We share data only with the processors necessary to run the service:
- Hetzner Online GmbH — hosting (Germany)
- Stripe Payments Europe — payment processing (Ireland)
- Transactional email provider — sign-up confirmations and security notices
- Plausible Analytics — privacy-friendly, cookie-free analytics (EU)
All processors are bound by Data Processing Agreements (DPAs) and store data in the EU/EEA.
5. Where data is stored
All customer data is stored on encrypted servers in Germany. Backups are encrypted at rest and rotated on a 30-day cycle.
6. Cookies
We use a single first-party cookie to keep you signed in. We do not use third-party advertising cookies or cross-site tracking. Our analytics provider is cookie-free.
7. Your rights (GDPR)
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten").
- Restrict or object to processing.
- Receive your data in a portable format.
- Lodge a complaint with the Austrian Data Protection Authority.
To exercise any of these rights, email privacy@planiq.app.
8. Changes
When we materially change this policy we will notify active users by email at least 30 days before the change takes effect. Older versions remain available on request.
9. Contact
Data controller
Planiq
Mariahilfer Straße 88, 1070 Vienna, Austria
privacy@planiq.app