Plannify documents
Data processing agreement
Last updated 29 September 2026
This English translation is provided for your convenience. The Italian version is the legally binding text and prevails in case of any discrepancy.
When you use Plannify for your business, you enter personal data about other people: customers, suppliers, employees, contacts. For that data you are the controller and Outline Digital is your processor. This agreement, required by Article 28 of the GDPR, sets out what we may and may not do with it.
It forms part of the terms of service and applies from the moment you create your account, with no need to sign it. If your organisation wants a signed copy or has its own template, write to info@outlinedigital.it.
1.Parties and subject matter
Controller: the customer who uses Plannify (“you”). Processor: Outline Digital, Via Dalmazia 36, Trani (BT), Italy, VAT no. IT08978680729 (“we”). Subject matter: the processing of personal data we carry out on your behalf to provide Plannify, for the whole life of the account.
2.What we process for you
| Nature and purpose | storing, organising, consulting, processing with AI agents, sending emails on your behalf and deleting the data, solely to run the Plannify features you use |
| Categories of data subjects | your customers and prospects, suppliers, employees and contractors, contacts, recipients of your messages, users of your websites and apps, people who sign in to your business software |
| Types of data | personal and contact details, emails the business software sends on your behalf, bookings, documents and invoices, accounting and banking data, documents and materials you upload, the data you write in your business software or project and the conversations you use to change it |
| Special categories of data | not intended: don’t enter them unless strictly necessary. If you do, they are still covered by this agreement |
| Duration | as long as the account is active, plus the deletion period set out under “Return and deletion” |
3.We process the data only on your instructions
Your instructions are this agreement, the terms and what you do in the service: the features you turn on, the approval rules, the requests you make to the team, the services you order from us. We don’t use your data for other purposes, we don’t sell it and we don’t use it to train AI models. If an instruction seemed to us to infringe the law, we will tell you.
4.Confidentiality
Only the people at Outline Digital who need it (support you ask for, security, maintenance) access the data; they are bound by confidentiality and trained in data processing.
5.Security
We apply the technical and organisational measures of Article 32 GDPR described on the Security and NIS2 page: encryption in transit, encryption of credentials, separation of data by company and by business software (each business software, at plannify.it/gestionali/ followed by its name, is closed off and separate from the others and from Plannify: data, sign-ins and files), administrative access by key, updates, backups, event logging, incident management. We update them over time without lowering the level of protection.
6.Sub-processors
You give us general authorisation to use these sub-processors, bound by contract to the same data protection obligations:
| Sub-processor | Service | Place of processing |
|---|---|---|
| IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany | cloud infrastructure: servers, databases, backups | European Union |
| Browser and phone notification services (Apple, Google, Mozilla) | delivering the push notifications you turn on | the content travels encrypted (Web Push): the service sees only the technical address of the device |
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | only for projects you order online: the dedicated server they run on, with their data | European Union |
Stripe processes the payment data for orders of Plannify services as an independent controller or on our behalf, not the data of your business software and projects. If we add or change a sub-processor, we update this page and tell you at least 30 days in advance in the HQ or by email: if you have a reasonable ground to object, you can do so during that period and, if we can’t find a solution, terminate without penalty.
7.Providers you choose are not our sub-processors
The AI provider of your key (for example Anthropic, OpenAI, OpenRouter) and the external services your project uses are chosen and activated by you, with your own account. Plannify sends them the necessary data only when the features you have chosen require it. The relationship with those providers, and the related privacy safeguards, are between you and them. If you choose a brain on your computer, the text never leaves your computer.
8.Transfers outside the European Union
We and our sub-processors process the data in the European Union. A transfer outside the EU happens only if you choose a provider or service based outside the EU, on your instructions and with that provider’s safeguards (adequacy decision, EU-US Data Privacy Framework or standard contractual clauses).
9.Data subject requests and impact assessments
Many requests you can handle yourself: viewing, correcting, exporting and deleting data from your business software or project. If a data subject contacts us, we forward the request to you without delay and don’t answer in your place. We help you, as far as is reasonable, with data protection impact assessments and consultations with the supervisory authority (the Italian Garante), giving you the information about the service that you need.
10.Personal data breaches
If we discover a breach affecting your data, we notify you without undue delay and in any case within 48 hours of becoming aware of it, at the account email address, with what we know: what happened, which data and how many data subjects are involved, the likely consequences and the measures taken. We keep you updated as things develop, so that you can notify the supervisory authority (the Italian Garante) within 72 hours and inform the data subjects if necessary.
11.Return and deletion of data
You can download all your data at any time with “Download your data” (JSON file), including the records, people and file list of the online business software. When you delete a business software, a project or your account, the data is deleted from the service immediately and disappears from backups within 14 days, except for data the law requires us to keep (for example invoices for services you ordered). The files on your computer stay on your computer, encrypted: Plannify gives the key to reopen them only to your account, so after deletion they can no longer be opened.
12.Information and audits
We give you the information needed to demonstrate compliance with this agreement: a description of the security measures, the list of sub-processors, answers to reasonable security questionnaires. On-site audits, if needed, are agreed with at least 30 days’ notice, during working hours and without access to other customers’ data; costs are borne by the party requesting them, unless breaches on our part come to light.
13.Your commitments as controller
You have a legal basis for the data you enter, you inform data subjects (including about your use of AI tools, where the law requires it), you collect the necessary consents (for example for promotional messages) and you set the approval rules appropriately for the data you process.