Privacy Policy

Plandek Ltd. · Last Updated: 1 May 2026

Scope of this Notice

This Privacy Policy describes how Plandek Ltd. ("Plandek," "we," "our," or "us") collects and uses personal data in connection with our public website at plandek.com, our marketing and sales activities, and related interactions outside the Plandek application.

It applies to you if you are:

  • A visitor to the Plandek website

  • A prospective customer or sales contact

  • A subscriber to our newsletter, blog, or other marketing communications

  • A registrant or attendee at a webinar, trade event, or industry event we host or attend

  • A job applicant

  • A partner contact

If you are an end user of the Plandek application at dashboards.plandek.com, please refer to our separate Application Privacy Policy, which governs personal data processed within the service. This notice does not cover that processing.

1.0 Introduction

Plandek is a technology company providing engineering analytics and software delivery insights. Plandek Ltd. is registered in the United Kingdom and operates from offices in London, UK and North Carolina, US, with a remote-first workforce.

For more information about Plandek and our products, please see plandek.com.

2.0 Personal Data We Collect

2.1 Information You Provide to Us

We collect personal data when you:

  • Submit a form on our website (for example, to download a resource, request a demo, or contact sales)

  • Subscribe to our newsletter, blog, or marketing communications

  • Register for or attend a webinar or event

  • Take part in a referral program, survey, or marketing promotion

  • Apply for a job at Plandek

  • Communicate with us by email, phone, video conference, or live chat

The personal data we typically collect in these contexts includes your first and last name, business email address, phone number, job title, and company name. If you participate in a referral program, you may also provide a third party's name, email, and company; you confirm that you have that person's permission to share their details with us.

If you apply for a job, we may also collect your CV, cover letter, and any other information you choose to share as part of your application.

2.2 Information We Collect Automatically

When you visit our website, we and our service providers collect information automatically through cookies and similar technologies. This information may include:

  • Access times and the pages you view

  • Links you click on and search terms you enter

  • Actions you take in connection with the pages you visit

  • Device information such as IP address, approximate location, browser type, operating system, and language

  • The URL of the page that referred you to our website, and the URL you navigate to when you leave

  • Whether you open marketing emails from us and click on links within them

You can manage your preferences through our cookie management tool or your browser settings.

2.3 Information We Receive From Third Parties

We may combine information we collect directly from you with information we receive from third parties, including:

  • Analytics, advertising, and identity resolution platforms (for example, Google, LinkedIn, Meta, Microsoft, Common Room)

  • Customer relationship and marketing platforms (for example, HubSpot)

  • Lead generation providers and data enrichment services

  • Public sources such as professional networking sites and company websites

The personal data received from these sources typically includes name, business email address, business address, job title, company name, company size, and telephone number.

3.0 How We Use Personal Data

We use the personal data described above to:

  • Respond to your enquiries and provide information you have requested (such as resources, demos, or pricing)

  • Send marketing communications about our products, events, content, and offers, where you have consented to receive them or where we have a legitimate interest in doing so

  • Schedule and manage demos, free trials, and onboarding conversations

  • Plan, host, and follow up on events and webinars

  • Conduct market research and improve our marketing and sales activities

  • Generate and manage sales leads, including interest-based advertising on third-party platforms

  • Operate, maintain, and improve our website

  • Recruit and assess job applicants

  • Detect, prevent, and respond to fraud, abuse, and security incidents

  • Comply with legal obligations and enforce our terms

We may record video conferencing calls in which you participate, for example to support sales conversations or train our team. Where we do so, we will tell you at the start of the call and in the meeting invitation, and we will provide a link to this notice.

We do not sell your personal data.

4.0 How We Share Personal Data

Service Providers

We use third-party service providers to support our website, marketing, and sales activities. These providers process personal data only on our instructions, under written contracts that require them to protect the data, use it solely to deliver services to us, and not sell it.

Service Provider Provider Entity Purpose Data Categories Region
HubSpot HubSpot, Inc. CRM, marketing automation, forms, and consent management Name, business email, business address, job title, phone number, IP address, geographic data, page interactions EU
Framer Framer B.V. Website hosting and content delivery IP address, request metadata, page interactions EU
Intercom Intercom Inc. Live chat and prospect engagement on the website Name, email address, IP address, geographic data EU/US
Google Tag Manager Google LLC Tag and script management IP address, page interactions EU
Google Analytics Google LLC Website analytics and visitor measurement IP address, geographic data, page interactions EU
Google Ads Google LLC Advertising and conversion measurement Hashed identifiers, page interactions EU
LinkedIn Insight LinkedIn Ireland Unlimited Company Advertising, audience targeting, and conversion measurement Hashed identifiers, page interactions EU
Microsoft Clarity Microsoft Corporation Session replay and behavioural analytics IP address, page interactions, mouse movement, scrolls, clicks, form interactions US
Microsoft Advertising (Bing UET) Microsoft Corporation Advertising and conversion measurement Hashed identifiers, page interactions US
Meta Pixel Meta Platforms Ireland Limited Advertising, audience targeting, and conversion measurement Hashed identifiers, page interactions EU/US
Capterra Capterra, Inc. Conversion tracking from Capterra and related listing sites Hashed identifiers, page interactions US
Common Room Common Room Inc. Community intelligence and visitor identification IP address, company-level identifiers, page interactions US
Cookiebot Usercentrics A/S Cookie consent management and storage of user consent preferences Consent preferences, device and browser information, IP address EU
YouTube Google LLC Embedded video content and video playback functionality on the website IP address, device and browser information, video interactions US
Spotify Spotify AB Embedded podcast and audio content on the website IP address, device and browser information, playback interactions EU/US

We may update this list from time to time. The current list reflects providers used in connection with our website and marketing activities. Sub-processors used to deliver the Plandek application are listed in our Application Privacy Policy and Sub-Processor Register.

Legal Disclosures

We may disclose personal data where required to comply with applicable law, regulation, legal process, or enforceable governmental request. Where appropriate and not prohibited, we will notify the affected individual or our customer.

Change in Control

If Plandek is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. Any successor entity will be required to handle the data in accordance with this notice or to provide notice and choice before any materially different use.

5.0 How We Secure Personal Data

We use a combination of administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, use, alteration, and disclosure. These include encryption in transit and at rest, access controls, vendor management, and ongoing monitoring. Our technical and organizational measures are aligned with internationally recognized security frameworks.

6.0 Your Rights

Subject to applicable law, you have the following rights in relation to the personal data we hold about you:

  • Access: request confirmation of whether we process your personal data and a copy of that data
  • Rectification: ask us to correct inaccurate or incomplete data
  • Erasure: ask us to delete your personal data
  • Restriction: ask us to limit how we use your personal data
  • Objection: object to our processing of your personal data, including for direct marketing
  • Portability: receive a copy of certain personal data in a structured, machine-readable format
  • Withdraw consent: where we rely on consent, withdraw it at any time

We do not make decisions about you using solely automated processing that produces legal or similarly significant effects.

To exercise any of these rights, please contact us at privacy@plandek.com. You also have the right to lodge a complaint with the supervisory authority in your country. In the UK, this is the Information Commissioner's Office (ICO).

7.0 How Long We Keep Personal Data

We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including to provide information you have requested, manage our sales relationship with you or your organization, comply with our legal obligations, resolve disputes, and enforce our agreements.

When personal data is no longer required, we will delete it or anonymize it. Information that has been anonymized or aggregated may be retained for analytical purposes.

8.0 International Data Transfers

Plandek operates from offices in the United Kingdom and the United States, with a remote-first workforce. Some of our service providers process personal data outside the country in which you are located.

Where we transfer personal data internationally, we rely on appropriate safeguards required under applicable law, including the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, the UK Addendum, and applicable adequacy decisions. Copies of the relevant safeguards are available on request from privacy@plandek.com.

9.0 Lawful Bases (UK/EEA)

Where UK GDPR or EU GDPR applies, we process personal data on the following lawful bases:

  • Consent: for marketing communications, non-essential cookies, and other processing where consent is required. You can withdraw consent at any time.
  • Legitimate interest: for B2B sales and marketing to professional contacts, website analytics, fraud prevention, security, and improving our marketing. Where we rely on legitimate interest, we balance our interest against your rights and interests, and you may object at any time.
  • Contract: to take steps prior to entering into a contract with you or your organization (for example, processing free trial requests).
  • Legal obligation: to comply with applicable laws and regulatory obligations.

10.0 Your Choices

  • Marketing communications: you can opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@plandek.com.
  • Cookies and tracking: you can manage your preferences through our cookie management tool or your browser settings.
  • Recruitment: if you do not wish to be considered for future roles, please contact us and we will remove your details from our applicant pool, subject to any retention obligations.

Even if you opt out of marketing, we may still send you operational communications relating to your enquiries, accounts, or applications.

Appendix A — Information for Individuals in the UK, EU, EEA, and Switzerland

For personal data described in this notice that Plandek processes as controller, Plandek Ltd. is the controller. Lawful bases are described in section 9.0.

For personal data Plandek processes as processor on behalf of a customer, the customer is the controller. Please direct privacy requests relating to such data to the customer (typically your employer or the organization that granted you access to the Application).

You have the rights set out in section 6.0. You may also lodge a complaint with your local supervisory authority. Contact details for EU data protection authorities are available at edpb.europa.eu; in the UK, complaints can be made to the Information Commissioner's Office.

International transfers are addressed in section 8.0.

Appendix B — Information for Individuals in California

This appendix supplements the notice with information required under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA").

Plandek's Role

In most cases, personal information processed within the Application on behalf of a Plandek customer is processed by Plandek as a service provider to that customer under the CCPA. Plandek does not retain, use, or disclose such information for any purpose other than the specific business purpose of providing the Application as set out in our agreements with customers.

For account-level data Plandek processes as a controller (such as administrator credentials, billing contacts, and support records), the following provisions apply.

Categories of Personal Information

In the previous twelve months, we have collected the following categories of personal information about End Users and administrators:

  • Identifiers (e.g., name, business email address, IP address)

  • California Customer Records (e.g., business contact details, job title)

  • Internet or other electronic network activity (e.g., authentication events, page interactions, device information)

  • Geolocation data (approximate, derived from IP address)

  • Professional and employment information (e.g., role within the customer organization)

We do not knowingly collect sensitive personal information about California consumers within the Application beyond authentication credentials necessary to provide the service.

Sources, Purposes, and Recipients

Sources, purposes of use, and recipient categories are described in sections 2.0, 3.0, and 4.0.

California Rights

Subject to verification and applicable exceptions, California residents may:

  • Request to know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of recipients
  • Request deletion of personal information
  • Request correction of inaccurate personal information
  • Opt out of the sale or sharing of personal information for cross-context behavioural advertising
  • Limit the use and disclosure of sensitive personal information
  • Be free from discrimination for exercising these rights

We do not sell personal information, and we do not share personal information for cross-context behavioural advertising in connection with the Application.