Data Processing Agreement
Version 1.0 · 16 July 2026
This Data Processing Agreement ("DPA") applies where Planacta processes personal data on behalf of an agency ("Customer") in providing the Planacta platform ("Service"). It forms part of the agreement between Planacta and the Customer. Where this DPA conflicts with that agreement on the subject of data protection, this DPA governs.
1. Roles
The Customer is the controller of the personal data it puts into the Service. Planacta is the processor and acts only on the Customer's documented instructions. The Customer's use of the Service, together with this DPA, is the Customer's documented instruction. Planacta will tell the Customer if an instruction appears to breach applicable data protection law.
2. What is processed
- Subject matter: providing media planning, actualization, approval and billing software.
- Duration: for as long as the Customer's account is active, plus the deletion window in section 9.
- Nature and purpose: hosting, storing, transmitting, displaying and computing on Customer data so the Customer can plan, reconcile and bill media.
- Categories of data subject: the Customer's own personnel; contacts at the Customer's advertising clients who receive or approve plans and invoices.
- Categories of personal data: names, business email addresses, job titles, roles, hashed authentication credentials, activity and audit records, email delivery records, and the business data the Customer enters.
- Special categories: none. The Service is not designed for special category data and the Customer must not submit it.
3. Confidentiality
Planacta treats all Customer data as confidential. Planacta will not access, use, disclose or copy Customer data except to provide, secure, maintain or support the Service, or where the Customer instructs it, or where law compels it. Personnel with access are bound by confidentiality obligations. Planacta will not sell Customer data, use it for advertising, or use it to train machine learning models.
4. Separation from other customers
Each Customer's workspace is logically isolated. No other customer of the Service can read, modify or export the Customer's data. Planacta does not operate a cross-customer administrator view: no account can browse another agency's workspace through the application. Isolation is enforced centrally and covered by automated tests that run before each release.
Planacta hosts the Service and therefore retains infrastructure-level access to the underlying database. That access is limited to the personnel who need it, exercised only for the purposes in section 3, and does not extend to routine review of Customer data.
5. Security
Planacta maintains the technical and organisational measures set out in Annex A, and will not materially reduce them during the term.
6. Sub-processors
The Customer authorises the sub-processors in Annex B. Planacta imposes data protection obligations on each sub-processor no less protective than this DPA, and remains liable for their performance. Planacta will give the Customer at least 30 days' notice before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service without penalty.
7. Data subject requests
Taking account of the nature of the processing, Planacta will assist the Customer with requests from data subjects exercising their rights. If a request reaches Planacta directly, Planacta will not respond to it substantively and will refer the individual to the Customer. The Service also lets the Customer access, correct, export and delete data itself.
8. Personal data breach
Planacta will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting the Customer's data. The notice will describe what is known about the nature of the breach, the data and individuals affected, the likely consequences, and the steps taken. Planacta will not delay a notice because its investigation is incomplete, and will assist the Customer with its own regulatory reporting.
9. Deletion and return
At any time during the term, the Customer may export its data from the Service. On termination, Planacta will delete the Customer's data within 30 days, or return it first if the Customer asks within that window. Backups are deleted on their normal cycle, within 90 days, and remain protected by this DPA until they are. Planacta may retain data where law requires, for as long as the law requires and for no other purpose.
10. Audit
Planacta will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable security questionnaires. Where that is not sufficient, the Customer may audit no more than once a year on 30 days' notice, during business hours, without disrupting the Service and without accessing another customer's data or Planacta's confidential systems.
11. International transfers
Customer data may be processed outside the Customer's country, including in the United States. Where the transfer is from the EEA, the UK or Switzerland and no adequacy decision applies, the parties agree that the European Commission's Standard Contractual Clauses (module two, controller to processor), and the UK Addendum where relevant, are incorporated into this DPA by reference and completed with the details in Annexes A and B, with Planacta as data importer.
12. Assistance
Planacta will provide reasonable assistance with data protection impact assessments and prior consultations with regulators, to the extent they relate to the Service and the Customer lacks the information itself.
13. Term
This DPA takes effect when the Customer starts using the Service and continues until Planacta stops processing the Customer's data. Sections 3, 8, 9 and 11 survive termination for as long as any Customer data remains.
Annex A · Technical and organisational measures
- Encryption in transit: HTTPS/TLS across the whole Service.
- Credentials: user passwords stored only as salted scrypt hashes; plaintext passwords are never stored or logged.
- Secrets at rest: advertising platform OAuth tokens encrypted with AES-256-GCM.
- Tenant isolation: every data read is bound to the caller's agency in a single central authorisation layer, verified by automated tests before release.
- Access control: role-based permissions within each workspace; administrators control who joins and what they can see.
- Accountability: an append-only audit log of changes, and a delivery log of emails the Service sent.
- Client approval links: single-purpose, expiring tokens that grant no account access.
- Production access: restricted to personnel who require it to operate the Service.
- Availability: data held on persistent, backed-up storage at our hosting provider.
- Change management: version-controlled code with type checking and automated isolation tests in the release path.
Annex B · Approved sub-processors
| Sub-processor | Purpose | Data |
|---|---|---|
| Railway Corp. | Application hosting and database storage | All Customer data |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Recipient name and email, message content |
| ImprovMX | Forwarding inbound email to Planacta addresses | Sender address and message content |
Google's advertising tag runs on Planacta's public marketing pages only. It is not part of the Service and processes no Customer data. Where the Customer connects Google Ads, Meta or Amazon, those are the Customer's own accounts and are not Planacta sub-processors.
Signing
A countersigned copy of this DPA is available on request. Email hello@planacta.com with your legal entity name and registered address and we will return an executed version.