Privacy Policy
Plandek Website
Plandek Ltd. · Last Updated: 1 May 2026
Scope of this Notice
This Privacy Policy describes how Plandek Ltd. ("Plandek," "we," "our," or "us") collects and uses personal data in connection with our public website at plandek.com, our marketing and sales activities, and related interactions outside the Plandek application.
It applies to you if you are:
A visitor to the Plandek website
A prospective customer or sales contact
A subscriber to our newsletter, blog, or other marketing communications
A registrant or attendee at a webinar, trade event, or industry event we host or attend
A job applicant
A partner contact
If you are an end user of the Plandek application at dashboards.plandek.com, please refer to our separate Application Privacy Policy, which governs personal data processed within the service. This notice does not cover that processing.
1.0 Introduction
Plandek is a technology company providing engineering analytics and software delivery insights. Plandek Ltd. is registered in the United Kingdom and operates from offices in London, UK and North Carolina, US, with a remote-first workforce.
For more information about Plandek and our products, please see plandek.com.
2.0 Personal Data We Collect
2.1 Information You Provide to Us
We collect personal data when you:
Submit a form on our website (for example, to download a resource, request a demo, or contact sales)
Subscribe to our newsletter, blog, or marketing communications
Register for or attend a webinar or event
Take part in a referral program, survey, or marketing promotion
Apply for a job at Plandek
Communicate with us by email, phone, video conference, or live chat
The personal data we typically collect in these contexts includes your first and last name, business email address, phone number, job title, and company name. If you participate in a referral program, you may also provide a third party's name, email, and company; you confirm that you have that person's permission to share their details with us.
If you apply for a job, we may also collect your CV, cover letter, and any other information you choose to share as part of your application.
2.2 Information We Collect Automatically
When you visit our website, we and our service providers collect information automatically through cookies and similar technologies. This information may include:
Access times and the pages you view
Links you click on and search terms you enter
Actions you take in connection with the pages you visit
Device information such as IP address, approximate location, browser type, operating system, and language
The URL of the page that referred you to our website, and the URL you navigate to when you leave
Whether you open marketing emails from us and click on links within them
For details of the cookies we use and your choices, please see our Cookie Notice.
2.3 Information We Receive From Third Parties
We may combine information we collect directly from you with information we receive from third parties, including:
Analytics, advertising, and identity resolution platforms (for example, Google, LinkedIn, Meta, Microsoft, Common Room)
Customer relationship and marketing platforms (for example, HubSpot)
Lead generation providers and data enrichment services
Public sources such as professional networking sites and company websites
The personal data received from these sources typically includes name, business email address, business address, job title, company name, company size, and telephone number.
3.0 How We Use Personal Data
We use the personal data described above to:
Respond to your enquiries and provide information you have requested (such as resources, demos, or pricing)
Send marketing communications about our products, events, content, and offers, where you have consented to receive them or where we have a legitimate interest in doing so
Schedule and manage demos, free trials, and onboarding conversations
Plan, host, and follow up on events and webinars
Conduct market research and improve our marketing and sales activities
Generate and manage sales leads, including interest-based advertising on third-party platforms
Operate, maintain, and improve our website
Recruit and assess job applicants
Detect, prevent, and respond to fraud, abuse, and security incidents
Comply with legal obligations and enforce our terms
We may record video conferencing calls in which you participate, for example to support sales conversations or train our team. Where we do so, we will tell you at the start of the call and in the meeting invitation, and we will provide a link to this notice.
We do not sell your personal data.
4.0 How We Share Personal Data
Service Providers
We use third-party service providers to support our website, marketing, and sales activities. These providers process personal data only on our instructions, under written contracts that require them to protect the data, use it solely to deliver services to us, and not sell it.
Service Provider | Provider Entity | Purpose | Data Categories | Region |
|---|---|---|---|---|
HubSpot | HubSpot, Inc. | CRM, marketing automation, forms, and consent management | Name, business email, business address, job title, phone number, IP address, geographic data, page interactions | EU |
Framer | Framer B.V. | Website hosting and content delivery | IP address, request metadata, page interactions | EU |
Intercom | Intercom Inc. | Live chat and prospect engagement on the website | Name, email address, IP address, geographic data | EU/US |
Google Tag Manager | Google LLC | Tag and script management | IP address, page interactions | EU |
Google Analytics | Google LLC | Website analytics and visitor measurement | IP address, geographic data, page interactions | EU |
Google Ads | Google LLC | Advertising and conversion measurement | Hashed identifiers, page interactions | EU |
LinkedIn Insight | LinkedIn Ireland Unlimited Company | Advertising, audience targeting, and conversion measurement | Hashed identifiers, page interactions | EU |
Microsoft Clarity | Microsoft Corporation | Session replay and behavioural analytics | IP address, page interactions, mouse movement, scrolls, clicks, form interactions | US |
Microsoft Advertising (Bing UET) | Microsoft Corporation | Advertising and conversion measurement | Hashed identifiers, page interactions | US |
Meta Pixel | Meta Platforms Ireland Limited | Advertising, audience targeting, and conversion measurement | Hashed identifiers, page interactions | EU/US |
Capterra | Capterra, Inc. | Conversion tracking from Capterra and related listing sites | Hashed identifiers, page interactions | US |
Common Room | Common Room Inc. | Community intelligence and visitor identification | IP address, company-level identifiers, page interactions | US |
We may update this list from time to time. The current list reflects providers used in connection with our website and marketing activities. Sub-processors used to deliver the Plandek application are listed in our Application Privacy Policy and Sub-Processor Register.
Legal Disclosures
We may disclose personal data where required to comply with applicable law, regulation, legal process, or enforceable governmental request. Where appropriate and not prohibited, we will notify the affected individual or our customer.
Change in Control
If Plandek is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. Any successor entity will be required to handle the data in accordance with this notice or to provide notice and choice before any materially different use.
5.0 How We Secure Personal Data
We use a combination of administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, use, alteration, and disclosure. These include encryption in transit and at rest, access controls, vendor management, and ongoing monitoring. Our technical and organisational measures are aligned with internationally recognised security frameworks.
6.0 Your Rights
Subject to applicable law, you have the following rights in relation to the personal data we hold about you:
Access: request confirmation of whether we process your personal data and a copy of that data
Rectification: ask us to correct inaccurate or incomplete data
Erasure: ask us to delete your personal data
Restriction: ask us to limit how we use your personal data
Objection: object to our processing of your personal data, including for direct marketing
Portability: receive a copy of certain personal data in a structured, machine-readable format
Withdraw consent: where we rely on consent, withdraw it at any time
We do not make decisions about you using solely automated processing that produces legal or similarly significant effects.
To exercise any of these rights, please contact us at privacy@plandek.com. You also have the right to lodge a complaint with the supervisory authority in your country. In the UK, this is the Information Commissioner's Office (ICO).
7.0 How Long We Keep Personal Data
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including to provide information you have requested, manage our sales relationship with you or your organisation, comply with our legal obligations, resolve disputes, and enforce our agreements.
When personal data is no longer required, we will delete it or anonymise it. Information that has been anonymised or aggregated may be retained for analytical purposes.
8.0 International Data Transfers
Plandek operates from offices in the United Kingdom and the United States, with a remote-first workforce. Some of our service providers process personal data outside the country in which you are located.
Where we transfer personal data internationally, we rely on appropriate safeguards required under applicable law, including the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, the UK Addendum, and applicable adequacy decisions. Copies of the relevant safeguards are available on request from privacy@plandek.com.
9.0 Lawful Bases (UK/EEA)
Where UK GDPR or EU GDPR applies, we process personal data on the following lawful bases:
Consent: for marketing communications, non-essential cookies, and other processing where consent is required. You can withdraw consent at any time.
Legitimate interest: for B2B sales and marketing to professional contacts, website analytics, fraud prevention, security, and improving our marketing. Where we rely on legitimate interest, we balance our interest against your rights and interests, and you may object at any time.
Contract: to take steps prior to entering into a contract with you or your organisation (for example, processing free trial requests).
Legal obligation: to comply with applicable laws and regulatory obligations.
10.0 Your Choices
Marketing communications: you can opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@plandek.com.
Cookies and tracking: you can manage your preferences through our cookie management tool or your browser settings. See our Cookie Notice for details.
Recruitment: if you do not wish to be considered for future roles, please contact us and we will remove your details from our applicant pool, subject to any retention obligations.
Even if you opt out of marketing, we may still send you operational communications relating to your enquiries, accounts, or applications.
Plandek Application
Plandek Ltd. · Last Updated: 1 May 2026
Scope of this Notice
This Privacy Policy describes how Plandek Ltd. ("Plandek," "we," "our," or "us") handles personal data in connection with the Plandek application available at dashboards.plandek.com (the "Application") and related product services.
It applies to:
Authenticated users of the Application ("End Users")
Account administrators acting on behalf of a Plandek customer
Other individuals whose personal data is processed in the course of operating, supporting, securing, or billing for the Application
If you are visiting our public website or interacting with our marketing or sales activities, please refer to our separate Website Privacy Policy, which governs that processing.
1.0 Introduction
Plandek provides engineering analytics that ingest data from a customer's software delivery toolchain (such as version control, ticketing, and CI/CD systems) and surface insights to authorised users within the customer's organisation. Plandek Ltd. is registered in the United Kingdom and operates from offices in London, UK and North Carolina, US, with a remote-first workforce.
Our Role: Controller and Processor
Our role under data protection law depends on the data in question:
Customer Data (Plandek as Processor). Personal data ingested into the Application from a customer's connected systems, or otherwise uploaded by a customer or its End Users, is processed by Plandek as a processor on behalf of the customer (the "Controller"). This includes, for example, names and email addresses associated with code commits, issue assignees, reviewers, and similar engineering metadata. Plandek processes such data only on the documented instructions of the customer, in accordance with the Data Processing Agreement (DPA) entered into with the customer.
If your personal data appears in the Application because your employer or another organisation is a Plandek customer, please direct privacy questions and requests to that organisation. Plandek will support customers in responding to your requests as required under the DPA.
Account Data (Plandek as Controller). Plandek acts as a controller of personal data we process for our own purposes in operating the Application, such as account administration, authentication, support interactions, billing, security monitoring, fraud prevention, audit logging, and product analytics performed at an aggregated or pseudonymised level. This notice describes that controller-side processing.
For details of the technical and organisational measures we apply to all personal data processed within the Application, please see our Technical and Organisational Measures (TOM), available on request and provided as part of customer DPAs.
2.0 Personal Data We Process as Controller
2.1 Account and Administrator Data
When a customer registers for the Application, or when an administrator creates additional accounts, we collect:
Name and business email address of the administrator and other End Users
Authentication credentials and identifiers (managed via our authentication provider)
Role and permissions assigned within the customer account
Billing contact information and, where applicable, billing address (payment card data is handled by our payment processor and not stored by Plandek)
2.2 Support and Communications
When you contact Plandek for support, raise a question, or provide feedback, we may collect:
The contents of the support request and any attachments you choose to share
Contact details (name, email address, telephone number)
Records of our communications with you
2.3 Authentication, Security, and Audit Data
We collect technical and audit data to operate, secure, and monitor the Application, including:
Authentication events (sign-ins, sign-in attempts, multi-factor authentication events)
IP address, user agent, device characteristics, and approximate location
Audit logs of administrative actions and access to data within the Application
Logs and telemetry generated by the Application's infrastructure components
2.4 Product Telemetry
We collect information about how the Application is used, including pages viewed, features used, and performance characteristics. Where feasible, we minimise, aggregate, or pseudonymise this data and use it to operate, troubleshoot, and improve the Application. We do not use this telemetry to build profiles of individual End Users for advertising purposes.
3.0 How We Use Personal Data (Controller-Side)
We use the personal data described above for the following purposes:
Provide, maintain, and operate the Application
Authenticate users and manage access
Provide customer support and respond to enquiries
Bill customers and manage subscriptions
Monitor, secure, and audit the Application against unauthorised access, abuse, fraud, and other security incidents
Detect, investigate, and respond to security incidents and policy violations
Maintain audit logs as required by our security and compliance commitments
Improve the Application, troubleshoot issues, and develop new features
Communicate operational matters such as service updates, security notices, scheduled maintenance, and changes to terms or policies
Comply with legal, regulatory, and contractual obligations
Establish, exercise, or defend legal claims
We do not use Customer Data for our own commercial purposes outside the scope of providing the Application, and we do not sell personal data.
4.0 How We Share Personal Data
4.1 Sub-Processors
To deliver the Application, we engage a limited number of trusted sub-processors. Each sub-processor is bound by written terms requiring confidentiality, security, and processing of personal data only on Plandek's documented instructions.
The current sub-processors used to deliver the Application are listed in our Sub-Processor Register, available on request and as referenced in customer DPAs. Core sub-processors include:
Sub-Processor | Provider Entity | Role | Infrastructure Provider | Region |
|---|---|---|---|---|
Google Cloud Platform | Google Cloud EMEA Limited | Hosting and core infrastructure for the Application | Google Cloud Platform | EU (multi-region) |
Elastic | Elastic N.V. | Manages Elasticsearch and Kibana instances within Plandek's GCP project on Plandek's behalf | Google Cloud Platform (within Plandek's tenancy) | EU |
Auth0 | Okta, Inc. | Authentication and identity management | Amazon Web Services (Ireland and Frankfurt) | EU |
Raygun | Raygun Limited | Application performance monitoring and error tracking | Microsoft Azure | US |
Intercom | Intercom Inc. | In-product messaging and customer support | Amazon Web Services | EU/US |
Heap | Heap Inc. | Product analytics and usage telemetry | Heap infrastructure (EU project) | EU |
We provide advance notice of changes to our sub-processors in accordance with the terms of customer DPAs.
4.2 Customers and Other End Users
Within a customer's account, personal data may be visible to other End Users of that account in accordance with the access permissions configured by the customer. Plandek does not control which users a customer grants access to.
4.3 Professional Advisors
We may share personal data with auditors, legal advisors, accountants, and other professional advisors under appropriate confidentiality obligations.
4.4 Legal Disclosures
We may disclose personal data where required to comply with applicable law, regulation, legal process, or enforceable governmental request. Where we receive a request that relates to Customer Data, we will, where lawful and practicable, redirect the requester to the customer and notify the affected customer in line with our DPA commitments.
4.5 Change in Control
If Plandek is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. Any successor entity will be required to handle the data in accordance with this notice or to provide notice and choice before any materially different use.
5.0 How We Secure Personal Data
We are committed to protecting personal data processed within the Application. Our security programme includes:
Encryption of data in transit and at rest
Strong authentication, role-based access controls, and least-privilege principles
Network segmentation, monitoring, and intrusion detection
Vulnerability management and secure development practices
Vendor risk management for sub-processors and other third parties
Incident response, business continuity, and disaster recovery procedures
Regular reviews and independent assessments aligned to recognised security frameworks
Full details are set out in our Technical and Organisational Measures (TOM), provided to customers under our DPA.
6.0 Your Rights
Subject to applicable law, you have the following rights in relation to personal data we hold about you:
Access: request confirmation of whether we process your personal data and a copy of that data
Rectification: ask us to correct inaccurate or incomplete data
Erasure: ask us to delete your personal data
Restriction: ask us to limit how we use your personal data
Objection: object to our processing of your personal data
Portability: receive a copy of certain personal data in a structured, machine-readable format
Withdraw consent: where we rely on consent, withdraw it at any time
Where you are an End User of the Application and your personal data was provided to Plandek by your employer or another customer, Plandek processes that data as a processor. In that case, please direct your request to your employer or the relevant customer; we will support them in responding as required under the DPA. For account-level data we control (such as your administrator credentials or support correspondence), please contact us directly.
We do not make decisions about you using solely automated processing that produces legal or similarly significant effects.
To exercise any of these rights in relation to data we control, please contact privacy@plandek.com. You also have the right to lodge a complaint with the supervisory authority in your country. In the UK, this is the Information Commissioner's Office (ICO).
7.0 How Long We Keep Personal Data
We retain personal data for as long as necessary to deliver the Application, fulfil the purposes described in this notice, and comply with our legal, regulatory, and contractual obligations.
Account and authentication data is retained for the duration of the customer's subscription and a defined period thereafter, after which it is deleted or anonymised in accordance with our DPA commitments.
Audit logs and security telemetry are retained for the periods required to support our security and compliance obligations.
Support records are retained for as long as needed to provide effective ongoing support and meet legal obligations.
Customer Data processed as processor is retained, deleted, and returned in accordance with the customer's instructions and the DPA.
When personal data is no longer required, we delete it or anonymise it.
8.0 International Data Transfers
Plandek operates from offices in the United Kingdom and the United States, with a remote-first workforce. The Application is hosted in the European Union, and certain sub-processors process limited personal data outside the EU/UK as identified in the table in section 4.1.
Where we transfer personal data internationally, we rely on appropriate safeguards required under applicable law, including the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, the UK Addendum, and applicable adequacy decisions. Copies of the relevant safeguards are available on request from privacy@plandek.com.
9.0 Lawful Bases (UK/EEA)
Where UK GDPR or EU GDPR applies and Plandek acts as controller, we rely on the following lawful bases:
Contract: to provide the Application to our customers and the End Users they authorise.
Legitimate interest: to operate, secure, monitor, and improve the Application; to maintain audit logs; to detect and respond to security incidents and abuse; and to communicate with our customers and their administrators about the service.
Legal obligation: to comply with applicable laws and regulatory obligations, including financial record keeping and responding to lawful requests from authorities.
Consent: for any limited processing where we ask for it specifically.
For Customer Data processed as processor, the customer (as controller) is responsible for identifying the lawful basis under which they upload, process, and direct us to process such data.
10.0 Children
The Application is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe we have collected such data, please contact us so we can delete it.
11.0 Changes to this Notice
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The "Last Updated" date at the top of this notice will reflect the most recent revision. Where a change materially affects how we process personal data, we will notify customer administrators in advance through the Application or by email.
12.0 Contact
For privacy questions, requests, or complaints relating to the Application, please contact:
Plandek Ltd.
Email: privacy@plandek.com
For support questions, please contact support@plandek.com.
Appendix A — Information for Individuals in the UK, EU, EEA, and Switzerland
For personal data described in this notice that Plandek processes as controller, Plandek Ltd. is the controller. Lawful bases are described in section 9.0.
For personal data Plandek processes as processor on behalf of a customer, the customer is the controller. Please direct privacy requests relating to such data to the customer (typically your employer or the organisation that granted you access to the Application).
You have the rights set out in section 6.0. You may also lodge a complaint with your local supervisory authority. Contact details for EU data protection authorities are available at edpb.europa.eu; in the UK, complaints can be made to the Information Commissioner's Office.
International transfers are addressed in section 8.0.
Appendix B — Information for Individuals in California
This appendix supplements the notice with information required under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA").
Plandek's Role
In most cases, personal information processed within the Application on behalf of a Plandek customer is processed by Plandek as a service provider to that customer under the CCPA. Plandek does not retain, use, or disclose such information for any purpose other than the specific business purpose of providing the Application as set out in our agreements with customers.
For account-level data Plandek processes as a controller (such as administrator credentials, billing contacts, and support records), the following provisions apply.
Categories of Personal Information
In the previous twelve months, we have collected the following categories of personal information about End Users and administrators:
Identifiers (e.g., name, business email address, IP address)
California Customer Records (e.g., business contact details, job title)
Internet or other electronic network activity (e.g., authentication events, page interactions, device information)
Geolocation data (approximate, derived from IP address)
Professional and employment information (e.g., role within the customer organisation)
We do not knowingly collect sensitive personal information about California consumers within the Application beyond authentication credentials necessary to provide the service.
Sources, Purposes, and Recipients
Sources, purposes of use, and recipient categories are described in sections 2.0, 3.0, and 4.0.
California Rights
Subject to verification and applicable exceptions, California residents may:
Request to know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of recipients
Request deletion of personal information
Request correction of inaccurate personal information
Opt out of the sale or sharing of personal information for cross-context behavioural advertising
Limit the use and disclosure of sensitive personal information
Be free from discrimination for exercising these rights
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising in connection with the Application.
How to Exercise California Rights
Submit a request to privacy@plandek.com. We will need to verify your identity using information we already hold about you. You may use an authorised agent; we will require written authorisation and may contact you to confirm.
If you are an employee or former employee of a Plandek customer, please direct your request to your employer or former employer (the controller of your personal information within the Application).
See how your engineering efforts translate into measurable business impact
Measure delivery performance, AI impact, and engineering productivity with hundreds of metrics, OOTB dashboards and custom configurations.
Contact us
UK Office
Unit 313 The Print Rooms, 164-180
Union St, London SE1 0LH
US Office
Floor 4, 1515 Mockingbird Ln,
Charlotte, NC 28209, USA








