Skip to content
DATA PROTECTION & GDPR COMPLIANT

Privacy Policy

How PLANEX collects, stores, processes, and safeguards client information.

Updated: August 24, 2026 • Effective: January 1, 2026
01

Overview & Commitment to Privacy

At PLANEX ("PLANEX", "we", "us", or "our"), we respect your privacy and are committed to protecting the personal and proprietary information you share with us. This Privacy Policy governs your use of our website (planexhq.com), client portals, and custom software engineering services.

We do not sell, rent, or monetize personal client data. Any information shared with PLANEX is processed strictly for the purposes of scoping, engineering, testing, deploying, and maintaining custom software systems.

02

Information We Collect

We collect information in the following categories when you interact with our studio:

  • Contact & Identity Data: Full name, professional email address, company name, phone number, and physical office location provided via discovery forms.
  • Project & Technical Specifications: System requirements, product requirement documents (PRDs), database schemas, Figma links, and repository configurations.
  • Technical Log Data: IP addresses, browser types, referral URLs, operating system metadata, and access timestamps captured automatically to detect unauthorized DDoS traffic.
03

How We Use Your Information

Your information is used strictly to fulfill contractual and operational obligations:

  • To prepare itemized technical proposals, sprint milestone roadmaps, and fixed-price contracts.
  • To provision password-protected private staging environments and cloud infrastructure.
  • To facilitate real-time project communication via dedicated Slack/Discord channels.
  • To issue milestone invoices and process payments via secure, PCI-DSS compliant payment gateways.
04

Confidentiality & Non-Disclosure Agreements (NDA)

We treat all client business models, proprietary source code, database architectures, and unreleased product ideas as strictly confidential.

Prior to conducting deep technical discovery workshops or inspecting existing legacy systems, PLANEX routinely executes mutual Non-Disclosure Agreements (NDAs) to legally safeguard your intellectual assets.

05

Third-Party Sub-Processors & Infrastructure

We partner with enterprise-grade cloud infrastructure providers to deliver high-availability systems. Our primary sub-processors include:

  • Amazon Web Services (AWS) – Cloud compute (EC2), asset storage (S3), and CDN delivery (CloudFront).
  • Vercel Inc. – Edge runtime hosting and CI/CD preview deployments.
  • MongoDB Atlas & Supabase / Neon – Managed cloud database clusters with encryption-at-rest.
  • Stripe & SSLCommerz – Encrypted payment processing (PLANEX never stores credit card details).
06

Your Rights (GDPR & CCPA Compliance)

Depending on your geographic jurisdiction, you hold the following rights regarding your personal data:

  • Right of Access: Request a copy of all personal data held by PLANEX.
  • Right to Rectification: Request correction of inaccurate or incomplete records.
  • Right to Erasure ("Right to be Forgotten"): Request immediate deletion of non-contractual personal data.
  • Data Portability: Request transmission of your data in a structured, machine-readable JSON format.

To exercise any of these rights, contact our Data Protection Officer at legal@planexhq.com.