Last Updated October 2022
What Personal Data Do We Collect?
Plannuh collects personal data when we deliver our products, conduct marketing, and run our business operations. The personal data we collect varies based upon whether the data is collected (i) through our websites or applications, including www.plannuh.com and their local variations (“Sites”) or (ii) through our products and services, including but not limited to our software and support services, including https://us.plannuh.com and http://eu.plannuh.com (“Products”).
We may collect personal data directly in the following situations:
- When you register as a Plannuh user or use our software support services, we may collect contact information such as your name, email address, telephone number, organization, and job title.
- If you engage with Plannuh for marketing purposes, such as by expressing interest in Plannuh offerings through a web form, participating in a promotion, or attending a Plannuh or other marketing event, we will collect the information you submit to us, such as your contact details (including name, email address, phone number, organization and job title) and the Plannuh offerings that interest you.
- When you submit an employment application, we collect the personal data disclosed by your application, such as your name, email address, phone number, and employment and education history.
- When you use the Products, we may capture your name, email address, organization, and job title. You can upload a profile picture if you want to.
- When you use the Products, we will collect the marketing plan, budget,
expense, and metrics data you enter into the Products or instruct Plannuh to enter on your behalf. In addition, we will collect any files that you upload into the Products, or instruct Plannuh to upload on your behalf, which may include PDF files, excel spreadsheets, images, and other file formats.
- We may also collect other electronic data derived from your use of our Products. This data may include your IP address, usage data, and data showing your registration, installation, and use of the Products. Except for IP address and unique device identifiers, we generally collect this data on an aggregate and non-identifying basis.
Plannuh may collect personal data indirectly in certain situations, in particular:
- We obtain marketing contact information, including name, email address, phone number, organization, and job title, from our resellers and distributors, from public sources, and from third-party mailing lists.
- We collect personal data, including employment and education history, from third parties to conduct background and reference checks for employment applications and for applications to establish reseller and distributor relationships with Plannuh, subject to consent where consent is required by law.
How We Use Personal Data
General Business Operations
We use contact information to market, sell, and service the Products, subject to your consent where required by law. We allow recipients of marketing messages and collateral to opt-out of receiving further communications from Plannuh at any time without detriment. We use your financial or payment information, and your contact details, to support, establish, and conduct customer relationships if you were to purchase a Product. For example, your data would be necessary for the performance of our terms of service with you (including, for example,
completing purchase transactions, the fulfillment of an order, order confirmations, responding to requests for information about Products, and the provision of purchased Products). If you fail to provide the personal data we need, we may be unable to complete your transaction.
We use personal data from employment applications where necessary to support our legitimate interest in processing your application and to contact you if future opportunities arise.
Data Processed Within Our Products
We use the personal data that is processed within our Products, for our legitimate interests and business purposes in tuning, maintaining, enhancing, and developing Products. A portion of application data, which may include personal data, may be seen by Plannuh staff who you have authorized to review your account data, for example in the provision of customer support
activities. We never use this data, referred to as “Product Personal Data,” for marketing purposes; and we never sell your data to third parties, or transfer it to third parties for the third party’s own purposes. We use aggregated, non-identifying, electronic data collected from the use of our Sites and Products to operate, analyze, improve, and develop our Sites and Products. This information is not used to inform decisions about specific individuals; rather, it is processed to understand how different categories of users interact with our Sites and Products so that we can consistently provide our Products.
When We Share Personal Data
- Plannuh does not sell your personal information. However, we may share certain personal information for a business purpose. If we share your personal data (including Product Personal Data) with affiliates, partners, or with vendors acting on our behalf, we do so under binding agreements that require the third party to use and protect the personal
- With our affiliates and subsidiaries and with vendors acting on our behalf to perform services for Plannuh for a specific business purpose, support the Sites or the delivery of Products;
- With the customer on whose behalf and at whose direction we are processing the data; and
- When we have your consent to use your personal data for a specific
Control of Your Personal Data
You can change your preferences to opt-out of marketing communications at any time by following the opt-out instructions in the relevant communication. If you opt-out, we will retain your email address to confirm that we do not send you further communications.
If you have submitted an employment application to Plannuh or if your personal data has been collected by Plannuh to review a proposed reseller or distributor relationship, you may contact us by emailing email@example.com or through the Privacy Portal. We will respond to your request within a reasonable timeframe.
If you wish to access, correct, or request the deletion of your Product Personal Data, you may contact us by emailing firstname.lastname@example.org or through the Privacy Portal. We will make reasonable efforts to delete your Product Personal Data upon your request within a reasonable timeframe unless prohibited from doing so under applicable law. If you have submitted Product Personal Data to Plannuh using your own user account which allows you to control your own data, you may delete the data you submitted by logging into your account and following the Product guidelines.
Location of Processing and CrossBorder Transfers
Personal data that is transferred outside your country of residence may be subject to lawful access by courts, law enforcement, and other governmental authorities in accordance with the laws of the foreign jurisdiction.
General Data Protection Regulation (“GDPR”)
Plannuh has a range of privacy and security controls across its organizations to ensure compliance with the General Data Protection Regulation (GDPR), including, but not limited to:
- GDPR-compliant data protection agreements with all customers for whom Plannuh processes personal data;
- A Privacy Impact Assessment (PIA) driven process to ensure that all
products and services are built with privacy by design;
- An on-going training program for its employees, with data privacy and protection education upon hiring and then again at least on an annual basis;
- State-of-the-art technical and security measures, including data
encryption at rest and in transit;
- Appropriate access right limitations;
- Company-wide systems for protecting data subject rights, ensuring that individual access/portability/right-to-be-forgotten rights are respected; Whenever Plannuh transfers personal information beyond the country of origin, we will do so in accordance with applicable laws. In the context of its European operations, Plannuh may transfer personal data abroad to other states in the European Economic Area or to third countries.
To the extent personal data processed by Plannuh would be transferred to a country outside the EEA not deemed to ensure an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data, Plannuh has in place requirements relating to such international data transfers. For example, where data is transferred to third parties, Plannuh uses standard contractual clauses designed to ensure those third parties respect the confidentiality of personal data and use it only in connection with the provision of specific services and in compliance with applicable data privacy laws. The EU Standard Contractual Clauses can be viewed on the European Commission’s website here. https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en. As per the guidance of the European Data Protection Board, Plannuh has implemented programs to review such data transfers and to employ additional safeguards when appropriate for the data processing required by law and our customer contracts.
European Union Resident Data Subject Rights Under the General Data Protection Regulation (“GDPR”)
If you are a resident of the European Union, United Kingdom, Lichtenstein, Switzerland, Iceland, or Norway, you have the data subject rights under the GDPR as described in the table below. If you have questions whether any of the following applies to you, please contact us at email@example.com or through the Privacy Portal and we will respond to your questions as soon as practicable. Please note that we process Personal Data of our customers’ end users or employees in connection with our provision of the Products, in which case we may not be able to respond to you request. As such, please contact the data controller (your employer or university) to address your rights with respect to such data.
|Personal Data Processed by Plannuh’s Products||Personal Data Collected by Plannuh|
|Right to Erasure|
|Plannuh does not have control over the customer data that is stored and processed by using the Products. As such, all requests to delete Personal Data should be addressed to your employer or university (data controller). If the data controller cannot fulfill your request and asks us to address it, we will respond to the data controller within 30 days. Even if you request that we delete your Personal Data, we may still retain data collected from you in an aggregated and anonymized form.||If you would like to delete your Personal Data, please contact us at firstname.lastname@example.org or through the Privacy Portal and we will respond to your request within 30 days. Even if you request that we delete your Personal Data, we may still retain data collected from you in an aggregated and anonymized form.|
|Right to Access and Rectification|
|Plannuh does not have control over the customer data that is stored and processed by using the Products. As such, all requests to access or rectify inaccurate or incomplete Personal Data should be addressed to your employer or university (data controller). If the data controller cannot fulfill your request and asks us to address it, we will respond to the data controller within 30 days.||If you would like to access or rectify inaccurate or incomplete Personal Data, please contact us at email@example.com and we will respond to your request within 30 days.|
|Right to Data Portability|
|Plannuh does not have control over the customer data that is stored and processed by using the Products. As such, all requests to receive a copy of your Personal Data should be addressed to your employer or university (data controller). If the data controller cannot fulfill your request and asks us to address it, we will respond to the data controller within 30 days.||If you would like to receive a copy of your Personal Data, please contact us at firstname.lastname@example.org and we will respond to your request within 30 days.|
|Right to Object to Processing|
|If you object to any processing by Plannuh, please communicate such request to your employer or university (data controller). If you communicate such request to us, we will notify the data controller as soon as possible.|
|Right to Restrict Processing|
|You have a right to restrict processing of your Personal Data by Plannuh. Please send your request to email@example.com or through the Privacy Portal.|
|Right to Withdraw Consent|
|If we are processing your Personal Data based on your consent, you have the right to withdraw your consent at any time by emailing firstname.lastname@example.org or the Privacy Portal|
|Right to File a Complaint|
|You can contact our DPO by emailing email@example.com. If we are unable to resolve your complaint, you can contract the European Data Supervisory Authority for Plannuh, Inc., which is the Office of the Data Protection Commissioner. They can be contacted here: Canal House, Station Road, Portarlington, Co. Laois, R32 AP23, Ireland. email firstname.lastname@example.org|
Personal Data Processing Grounds
When we process your Personal Data, we do so on the following grounds:
Performance under a Contract. We may process your Personal Data as part of our contractual obligations to you or your employer/university.
Consent. We may process Personal Data based on the consent you expressly grant to us at the time we collect such data. You can withdraw your consent at any time, which will not affect the lawfulness of the processing before your consent was withdrawn.
Legitimate Interest. We process Personal Data for the legitimate interests of Plannuh and that our partners, affiliates, and customers. These legitimate interests include, investigating illegal activities, detecting security issues, improving and maintaining the Site and the Products, contacting you to provide support, sending you relevant marketing information (subject to applicable laws). We will balance our interests and rights against the impact of
the processing on data subjects.
Legal Obligation & Other Grounds. We may need to process your Personal Data to comply with a legal obligation, such as a lawful subpoena, court order, law-enforcement request, or to fulfill the lawful instructions of our customers (when they are acting as the data controller). We may also need to process your Personal Data to protect vital interests and defend legal claims.
California Resident Rights
If you are a California resident, you have the following rights with regards to your Personal Data. If you have any questions about this section or whether any of the following applies to you, please email email@example.com or through the Privacy Portal.
Right to Disclosure & Access. You have the right to request certain information about our collection and use of your Personal Data over the past 12 months. We will provide you with the following information: (i) categories of Personal Data that we have collected about you; (ii) categories of sources
from which that Personal Data was collected;(iii) categories of third parties with whom we have shared your Personal Data; (iv) the purpose for collecting or selling your Personal Data; (v) the specific items of Personal Data that we collected about you; (vi) if we disclosed/sold your Personal Data over the last 12 months, we will identify the categories of Personal Data shared/sold with each category of third-party recipient.
Right to Deletion. You have the right to request that we delete the Personal Data that we have collected from you.
Right to be Free from Discrimination. You may freely exercise these rights without fear of being denied our Products. We will not charge you different prices or rates or provide you with a lower quality of services if you exercise your rights under CCPA.
Exercising Your Rights. All requests pursuant to this section must be addressed to firstname.lastname@example.org or through the Privacy Portal. In compliance with CCPA we will require certain identifying information from you to verify your request. We will make best efforts to respond to your valid request within 45 days from the receipt. In some instances, we may be required to continue to retain or share portions of your Personal Data to comply with regulatory or legal obligations.
Other State Resident Rights
Nevada. If you are a Nevada resident, you have the right to opt-out of the sale
of certain Personal Data to third parties who intend to license or sell that
Personal Data. You can exercise this right by contacting us at email@example.com and providing us with your name and the email address associated with your account. We do not currently sell your Personal Data as sales are defined in Nevada Revised Statutes Chapter 603A.
Storage and Security
We follow generally accepted standards to protect the personal data submitted to us, both during transmission and once it is received. Information you provide to us is stored on secure servers in Amazon Web Services. If Plannuh has issued you a password, you are responsible for keeping the password confidential. If you have any questions about the security of your personal data, you can contact us for more information by emailing firstname.lastname@example.org. We retain personal data to the extent necessary to provide Products to our customers, employees, and prospective employees. Generally, we retain personal data for as long as you remain an active customer or user of our Sites and Products and for 3 years afterward, or otherwise as required for our business operations or by applicable laws. We may retain non-personally identifiable aggregate information beyond this time for research purposes and to help us improve and further develop our Products. You cannot be identified from aggregate information retained or used for these purposes. Any record of a stated objection by you to receiving marketing communications will be retained by us so that we respect your wishes by not contacting you further.
The Products are not directed to children under the age of 13, and Plannuh will never knowingly collect personal or other information from anyone it knows is under the age of 13. If you are under 13, please do not attempt to register for or use the Products or send any personal information about yourself to us. If we learn that we have collected personal information from a
child under age 13, we will promptly take all reasonable steps to delete the data from our system.
Plannuh Employees and Contingent Workers
Contact Our Data Protection Officer
Any questions or concerns regarding the use or disclosure of Personal Data should be directed to Planful, Inc. at the address given below. Planful, Inc. will investigate and attempt to resolve complaints and disputes regarding use and disclosure of Personal Data in accordance with the principles contained in this Policy.
Planful, Inc. DPO
555 Twin Dolphin Drive, Suite 400
Redwood City, CA 94065
+1 (888) 914-9661
or via email at email@example.com