Back to home

Last updated: August 22, 2026

Data Processing Agreement

These are the Article 28 GDPR terms on which Planoro processes personal data on your company's behalf. They apply automatically to every customer and form part of the Terms of Service.

1. Parties and scope

This Agreement is between the customer identified by the Planoro account (the controller) and Bruno Magalhães (empresário em nome individual, Portugal; full registered details in the Privacy Policy), operating Planoro (the processor).

No signature needed. This Agreement applies automatically from the moment you accept the Terms of Service and for as long as Planoro processes personal data on your behalf. You do not have to request or sign it. If your organisation needs a separately signed copy, or requires its own form of DPA, contact support@planoro.app.

It covers only the personal data your company enters or generates in its workspace — worker, client, and contact records and the operational data attached to them. It does not cover the personal data of your own account or your billing details, for which Planoro is the controller and the Privacy Policy applies directly.

2. Subject matter, duration, nature and purpose

  • Subject matter: provision of the Planoro workforce and operations platform.
  • Duration: for as long as your account is active, plus the retention periods set out in the Privacy Policy.
  • Nature and purpose: hosting, storage, organisation, retrieval, display, transmission and deletion of the data, carried out solely to operate, secure and support the service for you.
  • Types of personal data: as listed in section 3 of the Privacy Policy — identification and contact details, employment-related attributes such as roles, skills, certifications and rates, scheduling and assignment data, communications, expenses and receipts, and technical and security data.
  • Categories of data subjects: your workers (internal and external), your client contacts, your on-site managers, and your team members.
  • Special category data: Planoro is not designed for special category data under Article 9 GDPR. Do not enter health, biometric, or similar data into free-text fields.

3. Processing on documented instructions

We process the data only on your documented instructions, which consist of these terms, the Terms of Service, the Privacy Policy, and the actions you and your users take in the application. We do not use it for our own purposes, do not sell it, and do not use it to train machine-learning models.

If we are required by EU or Member State law to process the data otherwise, we will tell you before doing so unless that law prohibits it. If we believe an instruction infringes data-protection law, we will tell you.

4. Confidentiality

Everyone we authorise to access the data is bound by an obligation of confidentiality and is granted access only where needed to operate or support the service. Access is limited to the smallest number of people necessary.

5. Security measures

We implement appropriate technical and organisational measures under Article 32 GDPR, including:

  • Row-level access controls scoping every record to a single company.
  • Encryption in transit, and encryption at rest for integration credentials.
  • Authenticated, signature-verified payment webhooks.
  • Rate limiting and abuse protection on authentication and public endpoints.
  • Security audit logging of sensitive account actions.
  • Automated enforcement of the retention periods stated in the Privacy Policy.
  • Regular backups for continuity, held under the same protections as live data.

Measures may change as the service evolves; we will not reduce the overall level of security during the term.

6. Sub-processors

You give general authorisation for us to engage sub-processors. The current list, with the purpose and data involved for each, is in section 7 of the Privacy Policy and is kept up to date there rather than duplicated here.

Each sub-processor is bound by a written contract imposing data-protection obligations equivalent to those in this Agreement, and we remain fully liable to you for their performance. Before adding or replacing a sub-processor that handles your data we will update that page and give reasonable advance notice to account owners, so you have the opportunity to object. If you object on reasonable data-protection grounds and we cannot offer an alternative, you may terminate the affected part of the service.

7. International transfers

The primary database and file storage are hosted in the European Union. Some sub-processors are established in the United States, so certain data is transferred internationally. Where that happens we rely on the European Commission's Standard Contractual Clauses or another valid transfer mechanism, together with supplementary measures where required. Details are in section 7 of the Privacy Policy.

8. Assistance with data-subject requests

The application itself is the primary means of responding to data subjects: you can search, correct, export and delete the records you control directly. Where a data subject contacts us instead, we will not respond on your behalf — we will refer them to you and tell you promptly.

Taking account of the nature of the processing, we will assist you with appropriate technical and organisational measures, so far as possible, in fulfilling your obligation to respond to requests to exercise rights under Chapter III GDPR.

9. Breach notification and impact assessments

We will notify you of any personal-data breach affecting data we process for you without undue delay after becoming aware of it, whatever its severity, and provide the information you need to meet your own obligations under Articles 33 and 34 — the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed.

We will also provide reasonable assistance with data-protection impact assessments and any prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to us.

10. Return and deletion

You can export your data at any time from the application while your account is active. On termination we delete or return the data in line with the retention periods in section 8 of the Privacy Policy, except where EU or Member State law requires us to keep it — most notably invoices and accounting records, which Portuguese tax and commercial law requires us to retain.

11. Audit and information rights

We will make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In practice we ask that you first raise the request with us in writing, so we can answer it with documentation. Audits are limited to once in any twelve-month period unless a supervisory authority requires otherwise or a breach has occurred, must be scheduled with reasonable notice, must not disrupt the service or compromise the confidentiality of other customers, and are at your cost.

12. Relationship to the Terms

This Agreement forms part of the Terms of Service. The limitation of liability in the Terms applies to this Agreement, except where a mandatory provision of the GDPR provides otherwise. Where this Agreement conflicts with the Terms on the processing of personal data, this Agreement prevails.

For questions about this Agreement, email support@planoro.app.