Privacy Policy

Plandek Website

Plandek Ltd. · Last Updated: 1 May 2026

Scope of this Notice

This Privacy Policy describes how Plandek Ltd. ("Plandek," "we," "our," or "us") collects and uses personal data in connection with our public website at plandek.com, our marketing and sales activities, and related interactions outside the Plandek application.

It applies to you if you are:

  • A visitor to the Plandek website

  • A prospective customer or sales contact

  • A subscriber to our newsletter, blog, or other marketing communications

  • A registrant or attendee at a webinar, trade event, or industry event we host or attend

  • A job applicant

  • A partner contact

If you are an end user of the Plandek application at dashboards.plandek.com, please refer to our separate Application Privacy Policy, which governs personal data processed within the service. This notice does not cover that processing.

1.0 Introduction

Plandek is a technology company providing engineering analytics and software delivery insights. Plandek Ltd. is registered in the United Kingdom and operates from offices in London, UK and North Carolina, US, with a remote-first workforce.

For more information about Plandek and our products, please see plandek.com.

2.0 Personal Data We Collect

2.1 Information You Provide to Us

We collect personal data when you:

  • Submit a form on our website (for example, to download a resource, request a demo, or contact sales)

  • Subscribe to our newsletter, blog, or marketing communications

  • Register for or attend a webinar or event

  • Take part in a referral program, survey, or marketing promotion

  • Apply for a job at Plandek

  • Communicate with us by email, phone, video conference, or live chat

The personal data we typically collect in these contexts includes your first and last name, business email address, phone number, job title, and company name. If you participate in a referral program, you may also provide a third party's name, email, and company; you confirm that you have that person's permission to share their details with us.

If you apply for a job, we may also collect your CV, cover letter, and any other information you choose to share as part of your application.

2.2 Information We Collect Automatically

When you visit our website, we and our service providers collect information automatically through cookies and similar technologies. This information may include:

  • Access times and the pages you view

  • Links you click on and search terms you enter

  • Actions you take in connection with the pages you visit

  • Device information such as IP address, approximate location, browser type, operating system, and language

  • The URL of the page that referred you to our website, and the URL you navigate to when you leave

  • Whether you open marketing emails from us and click on links within them

For details of the cookies we use and your choices, please see our Cookie Notice.

2.3 Information We Receive From Third Parties

We may combine information we collect directly from you with information we receive from third parties, including:

  • Analytics, advertising, and identity resolution platforms (for example, Google, LinkedIn, Meta, Microsoft, Common Room)

  • Customer relationship and marketing platforms (for example, HubSpot)

  • Lead generation providers and data enrichment services

  • Public sources such as professional networking sites and company websites

The personal data received from these sources typically includes name, business email address, business address, job title, company name, company size, and telephone number.

3.0 How We Use Personal Data

We use the personal data described above to:

  • Respond to your enquiries and provide information you have requested (such as resources, demos, or pricing)

  • Send marketing communications about our products, events, content, and offers, where you have consented to receive them or where we have a legitimate interest in doing so

  • Schedule and manage demos, free trials, and onboarding conversations

  • Plan, host, and follow up on events and webinars

  • Conduct market research and improve our marketing and sales activities

  • Generate and manage sales leads, including interest-based advertising on third-party platforms

  • Operate, maintain, and improve our website

  • Recruit and assess job applicants

  • Detect, prevent, and respond to fraud, abuse, and security incidents

  • Comply with legal obligations and enforce our terms

We may record video conferencing calls in which you participate, for example to support sales conversations or train our team. Where we do so, we will tell you at the start of the call and in the meeting invitation, and we will provide a link to this notice.

We do not sell your personal data.

4.0 How We Share Personal Data

Service Providers

We use third-party service providers to support our website, marketing, and sales activities. These providers process personal data only on our instructions, under written contracts that require them to protect the data, use it solely to deliver services to us, and not sell it.


Service Provider

Provider Entity

Purpose

Data Categories

Region

HubSpot

HubSpot, Inc.

CRM, marketing automation, forms, and consent management

Name, business email, business address, job title, phone number, IP address, geographic data, page interactions

EU

Framer

Framer B.V.

Website hosting and content delivery

IP address, request metadata, page interactions

EU

Intercom

Intercom Inc.

Live chat and prospect engagement on the website

Name, email address, IP address, geographic data

EU/US

Google Tag Manager

Google LLC

Tag and script management

IP address, page interactions

EU

Google Analytics

Google LLC

Website analytics and visitor measurement

IP address, geographic data, page interactions

EU

Google Ads

Google LLC

Advertising and conversion measurement

Hashed identifiers, page interactions

EU

LinkedIn Insight

LinkedIn Ireland Unlimited Company

Advertising, audience targeting, and conversion measurement

Hashed identifiers, page interactions

EU

Microsoft Clarity

Microsoft Corporation

Session replay and behavioural analytics

IP address, page interactions, mouse movement, scrolls, clicks, form interactions

US

Microsoft Advertising (Bing UET)

Microsoft Corporation

Advertising and conversion measurement

Hashed identifiers, page interactions

US

Meta Pixel

Meta Platforms Ireland Limited

Advertising, audience targeting, and conversion measurement

Hashed identifiers, page interactions

EU/US

Capterra

Capterra, Inc.

Conversion tracking from Capterra and related listing sites

Hashed identifiers, page interactions

US

Common Room

Common Room Inc.

Community intelligence and visitor identification

IP address, company-level identifiers, page interactions

US


We may update this list from time to time. The current list reflects providers used in connection with our website and marketing activities. Sub-processors used to deliver the Plandek application are listed in our Application Privacy Policy and Sub-Processor Register.

Legal Disclosures

We may disclose personal data where required to comply with applicable law, regulation, legal process, or enforceable governmental request. Where appropriate and not prohibited, we will notify the affected individual or our customer.

Change in Control

If Plandek is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. Any successor entity will be required to handle the data in accordance with this notice or to provide notice and choice before any materially different use.

5.0 How We Secure Personal Data

We use a combination of administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, use, alteration, and disclosure. These include encryption in transit and at rest, access controls, vendor management, and ongoing monitoring. Our technical and organisational measures are aligned with internationally recognised security frameworks.

6.0 Your Rights

Subject to applicable law, you have the following rights in relation to the personal data we hold about you:

  • Access: request confirmation of whether we process your personal data and a copy of that data

  • Rectification: ask us to correct inaccurate or incomplete data

  • Erasure: ask us to delete your personal data

  • Restriction: ask us to limit how we use your personal data

  • Objection: object to our processing of your personal data, including for direct marketing

  • Portability: receive a copy of certain personal data in a structured, machine-readable format

  • Withdraw consent: where we rely on consent, withdraw it at any time

We do not make decisions about you using solely automated processing that produces legal or similarly significant effects.

To exercise any of these rights, please contact us at privacy@plandek.com. You also have the right to lodge a complaint with the supervisory authority in your country. In the UK, this is the Information Commissioner's Office (ICO).

7.0 How Long We Keep Personal Data

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including to provide information you have requested, manage our sales relationship with you or your organisation, comply with our legal obligations, resolve disputes, and enforce our agreements.

When personal data is no longer required, we will delete it or anonymise it. Information that has been anonymised or aggregated may be retained for analytical purposes.

8.0 International Data Transfers

Plandek operates from offices in the United Kingdom and the United States, with a remote-first workforce. Some of our service providers process personal data outside the country in which you are located.

Where we transfer personal data internationally, we rely on appropriate safeguards required under applicable law, including the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, the UK Addendum, and applicable adequacy decisions. Copies of the relevant safeguards are available on request from privacy@plandek.com.

9.0 Lawful Bases (UK/EEA)

Where UK GDPR or EU GDPR applies, we process personal data on the following lawful bases:

  • Consent: for marketing communications, non-essential cookies, and other processing where consent is required. You can withdraw consent at any time.

  • Legitimate interest: for B2B sales and marketing to professional contacts, website analytics, fraud prevention, security, and improving our marketing. Where we rely on legitimate interest, we balance our interest against your rights and interests, and you may object at any time.

  • Contract: to take steps prior to entering into a contract with you or your organisation (for example, processing free trial requests).

  • Legal obligation: to comply with applicable laws and regulatory obligations.

10.0 Your Choices

  • Marketing communications: you can opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@plandek.com.

  • Cookies and tracking: you can manage your preferences through our cookie management tool or your browser settings. See our Cookie Notice for details.

  • Recruitment: if you do not wish to be considered for future roles, please contact us and we will remove your details from our applicant pool, subject to any retention obligations.

Even if you opt out of marketing, we may still send you operational communications relating to your enquiries, accounts, or applications.

Plandek Application

Plandek Ltd. · Last Updated: 1 May 2026

Scope of this Notice

This Privacy Policy describes how Plandek Ltd. ("Plandek," "we," "our," or "us") handles personal data in connection with the Plandek application available at dashboards.plandek.com (the "Application") and related product services.

It applies to:

  • Authenticated users of the Application ("End Users")

  • Account administrators acting on behalf of a Plandek customer

  • Other individuals whose personal data is processed in the course of operating, supporting, securing, or billing for the Application

If you are visiting our public website or interacting with our marketing or sales activities, please refer to our separate Website Privacy Policy, which governs that processing.

1.0 Introduction

Plandek provides engineering analytics that ingest data from a customer's software delivery toolchain (such as version control, ticketing, and CI/CD systems) and surface insights to authorised users within the customer's organisation. Plandek Ltd. is registered in the United Kingdom and operates from offices in London, UK and North Carolina, US, with a remote-first workforce.

Our Role: Controller and Processor

Our role under data protection law depends on the data in question:

  • Customer Data (Plandek as Processor). Personal data ingested into the Application from a customer's connected systems, or otherwise uploaded by a customer or its End Users, is processed by Plandek as a processor on behalf of the customer (the "Controller"). This includes, for example, names and email addresses associated with code commits, issue assignees, reviewers, and similar engineering metadata. Plandek processes such data only on the documented instructions of the customer, in accordance with the Data Processing Agreement (DPA) entered into with the customer.

    If your personal data appears in the Application because your employer or another organisation is a Plandek customer, please direct privacy questions and requests to that organisation. Plandek will support customers in responding to your requests as required under the DPA.

  • Account Data (Plandek as Controller). Plandek acts as a controller of personal data we process for our own purposes in operating the Application, such as account administration, authentication, support interactions, billing, security monitoring, fraud prevention, audit logging, and product analytics performed at an aggregated or pseudonymised level. This notice describes that controller-side processing.

For details of the technical and organisational measures we apply to all personal data processed within the Application, please see our Technical and Organisational Measures (TOM), available on request and provided as part of customer DPAs.

2.0 Personal Data We Process as Controller

2.1 Account and Administrator Data

When a customer registers for the Application, or when an administrator creates additional accounts, we collect:

  • Name and business email address of the administrator and other End Users

  • Authentication credentials and identifiers (managed via our authentication provider)

  • Role and permissions assigned within the customer account

  • Billing contact information and, where applicable, billing address (payment card data is handled by our payment processor and not stored by Plandek)

2.2 Support and Communications

When you contact Plandek for support, raise a question, or provide feedback, we may collect:

  • The contents of the support request and any attachments you choose to share

  • Contact details (name, email address, telephone number)

  • Records of our communications with you

2.3 Authentication, Security, and Audit Data

We collect technical and audit data to operate, secure, and monitor the Application, including:

  • Authentication events (sign-ins, sign-in attempts, multi-factor authentication events)

  • IP address, user agent, device characteristics, and approximate location

  • Audit logs of administrative actions and access to data within the Application

  • Logs and telemetry generated by the Application's infrastructure components

2.4 Product Telemetry

We collect information about how the Application is used, including pages viewed, features used, and performance characteristics. Where feasible, we minimise, aggregate, or pseudonymise this data and use it to operate, troubleshoot, and improve the Application. We do not use this telemetry to build profiles of individual End Users for advertising purposes.

3.0 How We Use Personal Data (Controller-Side)

We use the personal data described above for the following purposes:

  • Provide, maintain, and operate the Application

  • Authenticate users and manage access

  • Provide customer support and respond to enquiries

  • Bill customers and manage subscriptions

  • Monitor, secure, and audit the Application against unauthorised access, abuse, fraud, and other security incidents

  • Detect, investigate, and respond to security incidents and policy violations

  • Maintain audit logs as required by our security and compliance commitments

  • Improve the Application, troubleshoot issues, and develop new features

  • Communicate operational matters such as service updates, security notices, scheduled maintenance, and changes to terms or policies

  • Comply with legal, regulatory, and contractual obligations

  • Establish, exercise, or defend legal claims

We do not use Customer Data for our own commercial purposes outside the scope of providing the Application, and we do not sell personal data.

4.0 How We Share Personal Data

4.1 Sub-Processors

To deliver the Application, we engage a limited number of trusted sub-processors. Each sub-processor is bound by written terms requiring confidentiality, security, and processing of personal data only on Plandek's documented instructions.

The current sub-processors used to deliver the Application are listed in our Sub-Processor Register, available on request and as referenced in customer DPAs. Core sub-processors include:


Sub-Processor

Provider Entity

Role

Infrastructure Provider

Region

Google Cloud Platform

Google Cloud EMEA Limited

Hosting and core infrastructure for the Application

Google Cloud Platform

EU (multi-region)

Elastic

Elastic N.V.

Manages Elasticsearch and Kibana instances within Plandek's GCP project on Plandek's behalf

Google Cloud Platform (within Plandek's tenancy)

EU

Auth0

Okta, Inc.

Authentication and identity management

Amazon Web Services (Ireland and Frankfurt)

EU

Raygun

Raygun Limited

Application performance monitoring and error tracking

Microsoft Azure

US

Intercom

Intercom Inc.

In-product messaging and customer support

Amazon Web Services

EU/US

Heap

Heap Inc.

Product analytics and usage telemetry

Heap infrastructure (EU project)

EU


We provide advance notice of changes to our sub-processors in accordance with the terms of customer DPAs.

4.2 Customers and Other End Users

Within a customer's account, personal data may be visible to other End Users of that account in accordance with the access permissions configured by the customer. Plandek does not control which users a customer grants access to.

4.3 Professional Advisors

We may share personal data with auditors, legal advisors, accountants, and other professional advisors under appropriate confidentiality obligations.

4.4 Legal Disclosures

We may disclose personal data where required to comply with applicable law, regulation, legal process, or enforceable governmental request. Where we receive a request that relates to Customer Data, we will, where lawful and practicable, redirect the requester to the customer and notify the affected customer in line with our DPA commitments.

4.5 Change in Control

If Plandek is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. Any successor entity will be required to handle the data in accordance with this notice or to provide notice and choice before any materially different use.

5.0 How We Secure Personal Data

We are committed to protecting personal data processed within the Application. Our security programme includes:

  • Encryption of data in transit and at rest

  • Strong authentication, role-based access controls, and least-privilege principles

  • Network segmentation, monitoring, and intrusion detection

  • Vulnerability management and secure development practices

  • Vendor risk management for sub-processors and other third parties

  • Incident response, business continuity, and disaster recovery procedures

  • Regular reviews and independent assessments aligned to recognised security frameworks

Full details are set out in our Technical and Organisational Measures (TOM), provided to customers under our DPA.

6.0 Your Rights

Subject to applicable law, you have the following rights in relation to personal data we hold about you:

  • Access: request confirmation of whether we process your personal data and a copy of that data

  • Rectification: ask us to correct inaccurate or incomplete data

  • Erasure: ask us to delete your personal data

  • Restriction: ask us to limit how we use your personal data

  • Objection: object to our processing of your personal data

  • Portability: receive a copy of certain personal data in a structured, machine-readable format

  • Withdraw consent: where we rely on consent, withdraw it at any time

Where you are an End User of the Application and your personal data was provided to Plandek by your employer or another customer, Plandek processes that data as a processor. In that case, please direct your request to your employer or the relevant customer; we will support them in responding as required under the DPA. For account-level data we control (such as your administrator credentials or support correspondence), please contact us directly.

We do not make decisions about you using solely automated processing that produces legal or similarly significant effects.

To exercise any of these rights in relation to data we control, please contact privacy@plandek.com. You also have the right to lodge a complaint with the supervisory authority in your country. In the UK, this is the Information Commissioner's Office (ICO).

7.0 How Long We Keep Personal Data

We retain personal data for as long as necessary to deliver the Application, fulfil the purposes described in this notice, and comply with our legal, regulatory, and contractual obligations.

  • Account and authentication data is retained for the duration of the customer's subscription and a defined period thereafter, after which it is deleted or anonymised in accordance with our DPA commitments.

  • Audit logs and security telemetry are retained for the periods required to support our security and compliance obligations.

  • Support records are retained for as long as needed to provide effective ongoing support and meet legal obligations.

  • Customer Data processed as processor is retained, deleted, and returned in accordance with the customer's instructions and the DPA.

When personal data is no longer required, we delete it or anonymise it.

8.0 International Data Transfers

Plandek operates from offices in the United Kingdom and the United States, with a remote-first workforce. The Application is hosted in the European Union, and certain sub-processors process limited personal data outside the EU/UK as identified in the table in section 4.1.

Where we transfer personal data internationally, we rely on appropriate safeguards required under applicable law, including the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, the UK Addendum, and applicable adequacy decisions. Copies of the relevant safeguards are available on request from privacy@plandek.com.

9.0 Lawful Bases (UK/EEA)

Where UK GDPR or EU GDPR applies and Plandek acts as controller, we rely on the following lawful bases:

  • Contract: to provide the Application to our customers and the End Users they authorise.

  • Legitimate interest: to operate, secure, monitor, and improve the Application; to maintain audit logs; to detect and respond to security incidents and abuse; and to communicate with our customers and their administrators about the service.

  • Legal obligation: to comply with applicable laws and regulatory obligations, including financial record keeping and responding to lawful requests from authorities.

  • Consent: for any limited processing where we ask for it specifically.

For Customer Data processed as processor, the customer (as controller) is responsible for identifying the lawful basis under which they upload, process, and direct us to process such data.

10.0 Children

The Application is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe we have collected such data, please contact us so we can delete it.

11.0 Changes to this Notice

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The "Last Updated" date at the top of this notice will reflect the most recent revision. Where a change materially affects how we process personal data, we will notify customer administrators in advance through the Application or by email.

12.0 Contact

For privacy questions, requests, or complaints relating to the Application, please contact:

Plandek Ltd.
Email: privacy@plandek.com

For support questions, please contact support@plandek.com.


Appendix A — Information for Individuals in the UK, EU, EEA, and Switzerland

For personal data described in this notice that Plandek processes as controller, Plandek Ltd. is the controller. Lawful bases are described in section 9.0.

For personal data Plandek processes as processor on behalf of a customer, the customer is the controller. Please direct privacy requests relating to such data to the customer (typically your employer or the organisation that granted you access to the Application).

You have the rights set out in section 6.0. You may also lodge a complaint with your local supervisory authority. Contact details for EU data protection authorities are available at edpb.europa.eu; in the UK, complaints can be made to the Information Commissioner's Office.

International transfers are addressed in section 8.0.


Appendix B — Information for Individuals in California

This appendix supplements the notice with information required under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA").

Plandek's Role

In most cases, personal information processed within the Application on behalf of a Plandek customer is processed by Plandek as a service provider to that customer under the CCPA. Plandek does not retain, use, or disclose such information for any purpose other than the specific business purpose of providing the Application as set out in our agreements with customers.

For account-level data Plandek processes as a controller (such as administrator credentials, billing contacts, and support records), the following provisions apply.

Categories of Personal Information

In the previous twelve months, we have collected the following categories of personal information about End Users and administrators:

  • Identifiers (e.g., name, business email address, IP address)

  • California Customer Records (e.g., business contact details, job title)

  • Internet or other electronic network activity (e.g., authentication events, page interactions, device information)

  • Geolocation data (approximate, derived from IP address)

  • Professional and employment information (e.g., role within the customer organisation)

We do not knowingly collect sensitive personal information about California consumers within the Application beyond authentication credentials necessary to provide the service.

Sources, Purposes, and Recipients

Sources, purposes of use, and recipient categories are described in sections 2.0, 3.0, and 4.0.

California Rights

Subject to verification and applicable exceptions, California residents may:

  • Request to know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of recipients

  • Request deletion of personal information

  • Request correction of inaccurate personal information

  • Opt out of the sale or sharing of personal information for cross-context behavioural advertising

  • Limit the use and disclosure of sensitive personal information

  • Be free from discrimination for exercising these rights

We do not sell personal information, and we do not share personal information for cross-context behavioural advertising in connection with the Application.

How to Exercise California Rights

Submit a request to privacy@plandek.com. We will need to verify your identity using information we already hold about you. You may use an authorised agent; we will require written authorisation and may contact you to confirm.

If you are an employee or former employee of a Plandek customer, please direct your request to your employer or former employer (the controller of your personal information within the Application).

See how your engineering efforts translate into measurable business impact

Measure delivery performance, AI impact, and engineering productivity with hundreds of metrics, OOTB dashboards and custom configurations.

[2:43 PM]