GDPR Compliance
Last updated: 13 August 2026
1. Commitment
Planify is a personal project operated by Chereji Ionuț, based in Timișoara, Romania. We process personal data under the GDPR (EU) 2016/679, applicable Romanian data-protection law, and EU rules on privacy and electronic communications where they apply.
Until a company is registered, the individual named above is the operator and, where applicable, the data controller or processor as described below.
Privacy contact: ticket@planify.team
This page explains how Planify complies with GDPR. The Privacy Policy is the information notice for data subjects (what we collect and why). Together they form our public GDPR documentation. A signed Data Processing Agreement can be provided to a Customer on request.
2. Roles
| Account, Coordinator, website, support, and billing data | Planify is the controller (GDPR Articles 4(7), 13–14, 24). |
| Member data entered or collected by a Customer (names, WhatsApp numbers, roles, assignments, confirmations) | The Customer is the controller. Planify is the processor (GDPR Articles 4(8), 28). |
Coordinators process Member data only as users of the Customer’s Team. They are not independent controllers of Planify’s platform.
3. Processor terms (Article 28) — for Customers
When we process Member data for you, we:
- process it only to provide Planify (scheduling, WhatsApp operational messages, dashboards, support you request), unless EU or Romanian law requires otherwise;
- require persons who may access it to keep it confidential;
- apply the security measures in Section 6;
- use sub-processors listed in Section 5, and will notify Customers of intended changes where GDPR requires;
- help you respond to data-subject requests, taking into account the nature of processing;
- help you with security, breach notification, and (where relevant) DPIA/consultation obligations, taking into account the nature of processing and information available to us;
- delete or return Member data after the end of the service, subject to the retention in the Privacy Policy and to legal retention duties;
- make available information reasonably necessary to demonstrate these commitments and allow audits as agreed in writing, without endangering security or other Customers’ data.
You instruct us to process Member data as described in the product, these pages, and your configuration in the application. You must not instruct us to process data unlawfully.
You are responsible for having a legal basis to add Members and to send them WhatsApp messages, and for informing Members where Article 13/14 requires it.
4. Legal bases we use as controller
- Contract (Art. 6(1)(b)) — creating and operating your account, providing the service you requested.
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, service reliability, limited product improvement. We do not use legitimate interest to justify WhatsApp marketing.
- Consent (Art. 6(1)(a)) — non-essential cookies; any optional marketing communication (we do not send marketing WhatsApp through Planify).
- Legal obligation (Art. 6(1)(c)) — tax, accounting, or official requests where they apply.
We do not seek to process special-category data (Art. 9). Customers must not upload it.
5. Sub-processors
| Provider | Role | Region / notes |
|---|---|---|
| maghost.com | Hosting and infrastructure | Romania / EU |
| Meta Platforms Ireland Ltd. / WhatsApp | WhatsApp Business API message delivery | EEA entity with possible transfers under Meta’s SCCs / DPT |
| Paddle | Merchant of record, payments, invoices, tax | Paddle’s own buyer and data terms apply to the transaction |
We do not sell personal data. We do not use Member phone numbers for advertising.
6. Security measures
- TLS in transit.
- Hashed passwords; encrypted storage of WhatsApp phone numbers.
- Access to production systems limited to the operator on a need-to-know basis.
- Role-based access inside a Team (Customer owner vs assigned Coordinators).
- Authentication, session controls, and logging of security-relevant events.
- Multi-tenant separation: Customer data is scoped to the Customer’s Team.
No method of transmission or storage is 100% secure. We work to keep measures appropriate to the risk of a scheduling/messaging SaaS.
7. Retention and deletion
- Active account: data kept while the Team exists.
- After archive or cancellation: up to 365 days for recovery, then permanent deletion, unless you request earlier deletion where the law allows, or a longer legal archive applies (typically billing records).
- On a validated erasure request, we delete or anonymize personal data we no longer need, and we will assist Customers with Member deletion requests directed to them as controllers.
8. International transfers
Hosting is in the EU. Message delivery through Meta/WhatsApp may involve transfers outside the EU/EEA. Those transfers rely on the safeguards in Meta’s WhatsApp Business Data Processing Terms (Standard Contractual Clauses or an equivalent mechanism). Paddle publishes its own transfer documentation for payment data.
9. Data-subject rights
How to exercise access, rectification, erasure, restriction, objection, and portability is described in the Privacy Policy. Summary:
- Customers and Coordinators: email ticket@planify.team.
- Members: contact the organization that added you first; if that fails, contact us and we will help or forward.
We respond within one month (extendable by two months for complex requests, with notice). Identity may be verified before we act.
Supervisory authority in Romania: ANSPDCP — https://www.dataprotection.ro. You may also complain to the authority in your EU Member State of residence or work.
10. Personal data breaches
If a breach likely to result in a risk to people’s rights occurs, we will notify the competent authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the GDPR does not require notification. Where the law requires, we will inform affected Customers and/or individuals.
11. Children
Accounts are for persons 18+. If a Customer adds a minor as a Member, the Customer must have parental/guardian consent and a lawful basis. Planify does not knowingly create accounts for children.
12. WhatsApp-specific GDPR notes
WhatsApp messages contain operational scheduling content and the Member’s number. Meta is a sub-processor for delivery. Customers must not use Planify for marketing broadcasts, spam, or content that would make Meta a recipient of data for advertising. See the Terms and Conditions.
13. Changes
We will update this page when our processing, sub-processors, or operator status changes (including after company registration). Material changes will be communicated to Customers by email or in-app notice.
14. Contact
Related: Privacy Policy, Terms and Conditions, Refund Policy.