PlanMyGrid
Data Processing Agreement
Effective 1 September 2026. These are the Article 28 terms that apply when PlanMyGrid processes personal data on your behalf — which happens the moment you invite a client to review work, collect files from them, or store their credentials. It applies automatically, with no signature needed.
1. When this agreement applies
- This Data Processing Agreement (DPA) forms part of the PlanMyGrid Terms of Service. It applies automatically, with no signature required, whenever you use PlanMyGrid to process personal data belonging to someone else — most commonly your clients.
- In practice that means: inviting a client to review and approve content, collecting files through an upload request page, storing a client's logins in the Vault, or uploading media that contains identifiable people.
- If you only plan your own content and no third party's personal data enters your workspace, this DPA has nothing to operate on and our Privacy Policy governs instead.
- You can request a countersigned PDF copy at any time by emailing hey@planmygrid.com.
2. Roles of each party
- For personal data you put into PlanMyGrid about your own clients and their people, you are the controller and PlanMyGrid is the processor. You decide why and how that data is processed; we act on your instructions.
- For your own account data — your name, email, billing records, and how you personally use the product — PlanMyGrid is the controller, and our Privacy Policy governs that processing rather than this DPA.
- You confirm that you have a lawful basis for the personal data you place in PlanMyGrid, and that you have given the people it concerns whatever notice the law requires. We cannot verify this for you.
- PlanMyGrid is established in the United Kingdom. UK GDPR and EU GDPR are both capable of applying, and this DPA is written to satisfy Article 28 of each.
3. Subject matter, duration, nature and purpose
- Subject matter: the hosting, storage, organisation, display, transmission, and deletion of content you upload to a PlanMyGrid workspace, together with the collaboration features built around it.
- Duration: for as long as your account is open, plus the deletion windows set out in section 9.
- Nature and purpose: providing the PlanMyGrid service — social content planning, media storage and delivery, client review and approval, scheduling and publishing to connected channels, and the AI features you choose to use.
- We process this data only to provide and secure the service. We do not sell, broker, or rent it, we do not run ad networks, and we do not use your content or your clients' content to train AI models.
4. Categories of data subjects
- Your clients, and the individual staff and contacts at those clients.
- Reviewers and approvers you invite to a share link, including anyone who leaves approval feedback.
- People who send you files through an upload request page, including the email address they choose to provide.
- Individuals who appear in, or are identifiable from, the photos and videos you upload.
- Members of your own team whom you invite into a workspace.
5. Types of personal data
- Identifiers and contact details: names, email addresses, avatars, and workspace roles.
- Images and video that may depict identifiable individuals, together with captions, filenames, and any metadata embedded in the files you upload.
- Collaboration records: approval decisions, comments and feedback, activity and audit history, share-link access records, and delivery and download events.
- Credentials you or your clients place in the Vault. These are encrypted with AES-256-GCM under a separate key before storage, so our database holds only ciphertext.
- Technical data generated by use of the service: IP addresses, timestamps, device and browser metadata, and error diagnostics.
- PlanMyGrid is not designed for special category data under Article 9, or for children's data. Please do not place either in a workspace.
6. Our obligations as processor
- We process personal data only on your documented instructions. Your use of the product, together with this DPA and the Terms of Service, constitutes those instructions. If we believe an instruction breaks data protection law, we will tell you.
- Everyone with access to personal data is bound by a duty of confidentiality.
- We implement the technical and organisational measures described in section 7.
- We assist you, so far as we reasonably can, in responding to requests from data subjects exercising their rights.
- We assist you with security, breach notification, impact assessments and prior consultation, taking into account the information available to us.
- We delete or return personal data at the end of the service, as set out in section 9.
- We make available the information needed to demonstrate compliance with Article 28 and allow for audits, as set out in section 10.
7. Security measures
- Encryption in transit: TLS secures every network request to the application, the API, and stored media.
- Encryption at rest: data is encrypted at rest by our infrastructure providers. Vault credentials receive an additional layer of AES-256-GCM encryption under a separate key.
- Access control: every request carries a signed token and is authorised on a per-request basis before any workspace, grid, media library, or client file is returned.
- Network isolation: the production database is bound to the loopback interface and is not reachable from the public internet. Administrative access is over SSH with key-based authentication.
- Secret handling: credentials for the database, storage, payment and AI providers exist only in server-side environment configuration and are never exposed to the browser.
- Administrative access is limited to the operator of the service, on a least-privilege basis, with an audit log of administrative actions.
- Resilience: a full database snapshot is taken daily and stored in a dedicated, private Backblaze bucket with 30-day retention, encrypted at rest by the storage provider. Application health is monitored continuously with error reporting.
- We state these measures as they are. PlanMyGrid does not currently hold SOC 2 or ISO 27001 certification, and we would rather tell you that than imply otherwise.
8. Sub-processors
- You give general authorisation for PlanMyGrid to engage sub-processors to deliver the service.
- The complete, current list of sub-processors — what each one does, what it receives, and where it operates — is published at planmygrid.com/privacy and forms part of this DPA.
- We will update that list before engaging any new sub-processor that handles personal data, and will give at least 30 days' notice by email to workspace owners.
- If you reasonably object to a new sub-processor on data protection grounds within those 30 days, tell us and we will work with you to find an alternative. If none is workable, you may terminate the affected subscription and receive a pro-rata refund of the unused period, as an exception to the refund rule in our Terms.
- We remain fully liable to you for the performance of each sub-processor's obligations.
9. Deletion, return and retention
- You can delete your account yourself at any time from Settings → Data controls. Deletion is immediate and cascading, and cannot be undone.
- For a full export of the personal data we process on your behalf, email hey@planmygrid.com and we will provide it in a structured, machine-readable format within 30 days. Note that the Export button in Settings saves only your browser's local working copy — it is not a complete export of your server-side data.
- On account deletion we remove synced grids, media, media references, analytics, activity history, and share links from live systems immediately, unless retention is required by law.
- Backups containing deleted data expire on their own rolling 30-day cycle, so all copies are gone within 30 days of deletion.
- On termination of the service we delete personal data processed on your behalf within 30 days, or return it to you first if you ask before the account is closed.
- Billing records are retained for as long as tax and accounting law requires, and are held by us as controller rather than on your behalf.
10. Data subject requests and audits
- Many rights requests you can satisfy yourself: workspace owners can view, correct, and delete client content directly in the product.
- Where you cannot, email hey@planmygrid.com and we will assist. We aim to respond within 5 business days and to complete assistance well inside the one-month statutory deadline you are working to.
- If a data subject contacts us directly about data you control, we will not respond substantively. We will tell them to contact you, and we will forward the request to you promptly.
- On request we will provide the information reasonably necessary to demonstrate compliance with Article 28, including our security documentation and sub-processor list.
- You may audit our compliance once in any 12-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, and without disrupting the service. A supervisory authority may audit at any time the law requires.
11. International transfers
- Both primary stores sit inside the EU. The application servers and database run on Hetzner in Falkenstein, Germany, and uploaded media and backups are stored with Backblaze B2 in its EU Central region in Amsterdam.
- Some sub-processors listed on our Privacy Policy operate outside the EU and the UK, principally in the United States.
- Where personal data is transferred outside the UK or EEA, that transfer relies on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable to that provider.
- Those clauses are incorporated into this DPA by reference for any transfer we make on your behalf.
12. Breach notification
- If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and in any event within 48 hours of becoming aware.
- That notice will describe the nature of the breach, the categories and approximate volume of data and data subjects affected so far as known, the likely consequences, the measures taken or proposed, and a contact point for more information.
- Where we cannot provide all of it at once, we will provide what we have and follow up as the picture becomes clearer rather than waiting.
- Notifying your supervisory authority and, where required, the affected individuals remains your responsibility as controller. We will give you the information you need to do it.
13. Precedence, liability and changes
- Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. In all other respects the Terms of Service continue to apply.
- Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, except where data protection law does not permit that.
- We may update this DPA to reflect changes in law, in the service, or in our sub-processors. Where a change materially reduces your rights we will give at least 30 days' notice by email to workspace owners before it takes effect.
- The effective date at the top of this page is set by hand and changes only when this document changes.
Contact
- Data protection & this DPA → hey@planmygrid.com
- Security & responsible disclosure → security@planmygrid.com
- Mailing address → PlanMyGrid, 85 Great Portland Street, London, UK
Related documents
- Sub-processor list → planmygrid.com/privacy
- Terms of Service → planmygrid.com/terms
- Data request center → planmygrid.com/data-usage
Need a signed copy?
Procurement teams often want one on file. Email hey@planmygrid.com and we’ll send a countersigned PDF of this agreement, usually the same day.