Data Processing Agreement
Planbrand.com Ltd Version 1.0 — effective 7 September 2026
This Agreement forms part of the Terms of Service between Planbrand.com Ltd ("Planbrand", "we") and the customer ("you"). You do not need to sign it separately — it applies automatically from the moment you put personal data into the platform. If your procurement process requires a countersigned copy on your own paper, email info@planbrand.com and we will sign it.
It exists because UK GDPR Article 28 requires a written contract between a controller and its processor. Without one, you are in breach — not only us. That is why it is free, automatic, and published rather than hidden behind a sales conversation.
You are the controller. You decide which personal data goes into Planbrand, why, and on what lawful basis. Your contacts, your form respondents, your portal customers — your decisions about them.
We are the processor. We hold and handle that data on your behalf, and only as you instruct.
Where we process data about you — your account, your billing, your use of the product — we are a controller in our own right, and the Privacy Policy governs that instead. The two roles are separate and neither absorbs the other.
Subject matter and duration: providing the Planbrand platform, for as long as your subscription runs, plus the deletion window in section 9.
Nature and purpose: storing, organising, displaying, transmitting and deleting personal data so that you can run marketing, sales and customer operations for your brands.
Categories of data subject: your contacts and leads; people who submit your forms; customers who hold accounts on your Planbrand-hosted portals; your own staff whom you invite into your workspace.
Categories of personal data: name; email address; telephone number; company name and job title; postal address; profile image; form responses you design and therefore choose the contents of; files you attach to a contact; records of email you send them through the platform; portal login credentials.
Special category data: Planbrand is not designed for health, biometric, genetic, racial or ethnic origin, political, religious, trade-union or sexual-orientation data, and we ask you not to put it in. If you do so anyway, you carry the additional obligations that come with it — including the Article 9 condition and, where relevant, a Data Protection Impact Assessment. We will not have carried out either on your behalf.
We will:
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 48 hours of becoming aware.
The notification will describe what happened, which categories and roughly how many people and records are affected, the likely consequences, and what we are doing about it. Where we do not yet know something, we will say so and follow up rather than delay the first notification until the picture is complete.
You decide whether the ICO and the affected people need to be told. It is your call because you are the controller — but we will give you what you need to make it inside your own 72-hour deadline, which is why ours is 48.
You give us general authorisation to engage subprocessors. The current list is published at Subprocessors.
Before adding or replacing one, we will give you 30 days' notice by email to your account address. If you have a reasonable data-protection objection, tell us within those 30 days and we will work with you to resolve it; if we cannot, you may terminate the affected part of the service and receive a pro-rata refund of anything you have paid for a period you no longer get to use. Silence is acceptance.
Each subprocessor is bound by written terms no less protective than these, and we remain fully liable to you for what they do. You do not have to chase them; you chase us.
Your data is stored in the European Union (Germany). Some subprocessors are outside the UK and EEA — the Subprocessors page names each one, its country, and the transfer safeguard relied on, which will be the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision.
Where we rely on the Addendum or the Clauses, they are incorporated into this Agreement by reference and take precedence over anything here that conflicts with them.
Set out in full in the Security Overview. The measures specifically relied on in this Agreement:
We will make available the information you reasonably need to demonstrate compliance with Article 28, and will answer security questionnaires without charge.
You may audit us, or appoint an independent auditor to, no more than once in any 12 months unless a breach or a regulator's instruction makes another necessary. Give us 30 days' notice, do it in business hours, do not disrupt the service, and treat what you learn as confidential. We may satisfy an audit request by providing an up-to-date third party report if we hold one at the time — currently we do not, and we do not pretend otherwise.
When your subscription ends:
Liability under this Agreement is subject to the limits in the Terms of Service. Nothing in either document limits liability that cannot lawfully be limited, and nothing limits a data subject's own rights against either of us.
If this Agreement conflicts with the Terms of Service on a data protection question, this Agreement wins. If either conflicts with the Standard Contractual Clauses or the UK Addendum, those win.
Questions, or a countersigned copy: info@planbrand.com Planbrand.com Ltd, 8 Clock House Parade, North Circular Road, London, N13 6BG · ICO registration ZB442643
Most advanced brand template you can customise.