Privacy Policy
Last updated: 13 August 2026
1. Who we are
Planify (“Planify,” “we,” “us”) is a team scheduling and WhatsApp confirmation platform. It is a personal project developed and operated by Chereji Ionuț, an individual based in Timișoara, Romania. Planify is not yet a registered company. Until incorporation, the individual named above is the operator of the service and the data controller for account, website, and billing-related personal data (see Section 3 for Member data).
This service is provided in accordance with the law of the European Union and of Romania, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
Contact for privacy matters: ticket@planify.team
This policy applies to:
- the website planify.team and related Planify websites;
- the Planify application (including app.planify.team);
- organizations (“Customers”) that create a Planify account and Team;
- invited Coordinators; and
- team members, volunteers, or staff whose data a Customer adds to Planify (“Members”).
Corporate details (registered name, tax ID) will be added here after incorporation. Until then, the individual identified above remains accountable for data protection compliance.
2. Roles under GDPR
- Planify is the data controller for Customer and Coordinator account data, website visitor data, support tickets, security logs, and billing records we need to operate the service.
- The Customer is the data controller for Member data they add or collect through Planify (names, WhatsApp numbers, roles, assignments, confirmations).
- Planify is the data processor for that Member data: we process it only to provide the service, on the Customer’s instructions, as described in this policy and our GDPR Compliance page.
Customers must have a valid legal basis (for example consent, legitimate interest, or an existing organizational relationship) before adding any Member to Planify.
3. What data we collect
3.1 Account data (Customer / Coordinator)
Name, email address, phone number, password (hashed), organization/Team name, department and position structure, role (Customer owner or Coordinator), consent timestamp, account status, and support communications.
3.2 Member data (added by the Customer)
Full name, WhatsApp phone number, member type/status, department and position, how the Member joined, event assignments, confirmation or decline status, and related timestamps.
Members do not create a Planify login unless the Customer invites them as a Coordinator. Member data is processed as described in Section 2.
3.3 Message data
Template used, message category, delivery status, and sent/delivered/read/responded timestamps for WhatsApp notifications sent through Planify. Message content is limited to operational scheduling information (for example event name, date, time, role, and response buttons). Planify is not a marketing or broadcasting tool.
3.4 Billing data
Plan, entitlement dates, and transaction references. Payments are processed by Paddle as merchant of record. Planify does not store payment card numbers.
3.5 Website and technical data
Pages visited, referrer, device/browser type, approximate location derived from IP address, cookies (Section 8), and information submitted through contact or demo forms. We also keep security and login logs needed to protect accounts.
3.6 Data we do not collect
Planify does not request payment card numbers, government ID numbers, health data, or other special-category data under Article 9 GDPR. Customers must not enter such data into free-text fields. If they do, they remain responsible for that data.
4. How we use data
We use personal data to:
- deliver the service: schedules, WhatsApp confirmations, response tracking;
- operate accounts, dashboards, Coordinators, and billing;
- send service messages (onboarding, security, account, and support);
- provide customer support;
- protect the platform (security, abuse prevention, policy review when a violation is reported or reasonably suspected);
- improve reliability and performance;
- comply with legal obligations.
We do not send marketing emails or product promotions unless we have a separate, specific opt-in. Planify WhatsApp messages are operational, not marketing.
Legal bases (GDPR Article 6): performance of a contract; legitimate interests (security, service improvement, abuse prevention); consent (optional cookies and any future marketing); legal obligation (tax/accounting where applicable).
5. WhatsApp / Meta as sub-processor
Planify sends notifications through the official WhatsApp Business API, provided by Meta Platforms Ireland Ltd. / Meta Platforms, Inc. Meta processes phone numbers, message content, and delivery metadata as a sub-processor, under Meta’s Business Terms and WhatsApp Business Data Processing Terms.
We do not sell Member phone numbers. We do not share numbers with Meta for advertising. Data shared with Meta is limited to what is required to deliver the message.
More information: WhatsApp Business Data Processing Terms.
6. Data storage and security
- Hosting: EU-based infrastructure provided by maghost.com (Romania / EU).
- Data in transit is protected with TLS.
- WhatsApp phone numbers are stored encrypted. Passwords are hashed. Access to production data is restricted to the operator on a need-to-know basis.
- Inside an organization, access to Member data is limited by role (Customer owner vs Coordinator assigned to specific departments).
- We retain Customer, Member, and event data for the life of the account. If an account is archived or cancelled, data is kept for up to 365 days for recovery, then permanently deleted, unless a valid deletion request is made sooner or a longer legal retention period applies.
- Billing and accounting records may be kept for as long as Romanian or EU tax law requires (typically up to 10 years).
7. Your rights (GDPR)
If you are in the EU/EEA or another jurisdiction with equivalent rights, you may request to:
- access your personal data;
- correct inaccurate data;
- delete your data (“right to be forgotten”), subject to legal retention duties;
- restrict or object to processing;
- receive your data in a portable format;
- withdraw consent where processing is based on consent.
If you are a Member added by an organization, contact that organization first. They are the controller of your scheduling data. If you cannot reach them, email ticket@planify.media and we will assist or forward your request.
Customers and Coordinators can email the same address. We will respond within one month, as required by GDPR.
You may lodge a complaint with your data protection authority. In Romania: ANSPDCP — dataprotection.ro.
8. Cookies
Planify websites and the application may use:
- Essential cookies — required for login, session, security, and core function. These do not require consent.
- Analytics cookies — used only if enabled, and only after consent, to understand site usage. They are not used for advertising.
You can manage non-essential cookies through the consent banner (where shown) or your browser settings. Blocking essential cookies may prevent login.
9. Data sharing with third parties
We share data only with:
- Meta / WhatsApp — message delivery (Section 5);
- Paddle — payment processing and invoicing for paid plans;
- maghost.com — hosting and infrastructure;
- authorities, when legally required.
We do not sell personal data.
10. International transfers
Where a sub-processor is outside the EU/EEA (for example Meta), transfers rely on Standard Contractual Clauses or another valid GDPR transfer mechanism in that provider’s data processing terms. Paddle and Meta publish their own transfer terms.
11. Children’s data
Planify accounts are for adults (18+). We do not knowingly collect account data from children. If a Customer adds a Member under 18 (for example a youth volunteer), the Customer confirms they have parental/guardian consent and a valid legal basis.
12. Changes
We may update this policy. Material changes will be announced by email or in-app notice. The date at the top is the latest revision.
13. Contact
Questions about this policy or your data: ticket@planify.team