Data protection
Privacy Policy
Last updated: 27 July 2026
This privacy policy explains what personal data we process when you use the Planer Plus web application (the "Service") and its website planer.conaprojekt.si, for what purpose and on what legal basis. We process data in accordance with the General Data Protection Regulation (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).
1. Data controller
Trstenik 74, 4204 Golnik, Slovenia
Registration number: 6311130000
VAT number: SI78923115
Email: info@conaprojekt.si
Service: planer.conaprojekt.si
We collect only the data we need to provide the Service (data minimisation).
2. Data Protection Officer (DPO)
We have not appointed a Data Protection Officer, as this is not legally required given the nature and scope of our processing. For any data-protection question, contact us at info@conaprojekt.si.
3. What data we process
- Account data: email address, password (stored in hashed form), name and optionally company name.
- Content you create: projects, tasks, phases, deadlines, notes and other data you enter into the app. This content may include third-party personal data if you enter it (see section 5).
- Payment data: subscriptions are processed by the payment provider Stripe; card details are entered directly with Stripe — we do not store card numbers. We retain a subscription identifier and plan status.
- Team data: email addresses you enter as an account owner when inviting team members, and the status of those invitations (see section 5).
- Technical data: IP address, browser and device type, and access logs — for operation, security and abuse prevention.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and managing your account and providing the Service | Contract — Art. 6(1)(b) |
| Processing subscriptions and payments (Plus/Pro) | Contract — Art. 6(1)(b) |
| Complying with legal obligations (accounting, tax) | Legal obligation — Art. 6(1)(c) |
| Security, abuse prevention and technical operation | Legitimate interest — Art. 6(1)(f) |
| Sending system emails (password reset, team invitations) | Contract — Art. 6(1)(b); account security — Art. 6(1)(f) |
| User support and service-related communication | Contract / legitimate interest — Art. 6(1)(b) and (f) |
5. Your content and projects
The content you create in the app (projects, tasks, documentation) remains yours. We process it solely to provide the Service (storage, display, export). If you enter third-party personal data (e.g. names of colleagues or clients), you act as the controller for that data and we act as processor; you are responsible for having a valid legal basis and for informing those individuals. A data processing agreement is available for business users on request (see section 9).
The same applies to team invitations: when you invite a colleague in the app, we send an invitation notice to the address you enter, on your instruction. We process that address solely to deliver the invitation and to manage membership of your team. You are responsible for having a valid legal basis for providing your colleague's address and for informing them.
6. Automated decision-making and profiling
We do not carry out automated decision-making with legal or similarly significant effects within the meaning of Article 22 GDPR. The Service does not use artificial intelligence to process your content.
7. Data retention
- Account data and content: retained while your account is active. After account deletion or cancellation we delete or anonymise the data within a reasonable period, unless the law requires otherwise.
- Accounting and payment data: up to 10 years (tax and accounting law).
- Backups: the database is backed up daily and backups are retained for 7 days. Deleted data may remain in backups for up to 7 days after deletion, after which it is irrecoverably removed.
- Password reset records: a reset code is valid for a limited time and ceases to be valid once used; we retain a record of the request as a security log.
- Technical logs: retained by our hosting providers under their own policies — 7 days at the application hosting provider, and 30–60 days at the static hosting provider, varying by server. The static host does not include access logs in its backups.
Cancelling a subscription does not automatically delete your account — deletion must be requested separately. The procedure, the scope of the deletion and the timeframe are set out on the Account & Data Deletion page.
8. Processors and international transfers
We work with the following processors, who process personal data solely on our instructions:
- Supabase Pte. Ltd (Singapore) — managed database: storing accounts and project content. Data is stored in Ireland (eu-west-1).
- Railway Corp. (USA) — application server hosting. Processing takes place in Amsterdam, the Netherlands.
- Resend (Plus Five Five, Inc.) (USA) — delivery of system emails (password reset codes, team invitations). Mail is delivered via Amazon SES infrastructure in Ireland (eu-west-1); the provider's own processing operations take place in the United States.
- Google Cloud EMEA Limited (Ireland) — business mailbox (Google Workspace) for info@conaprojekt.si: receipt of support correspondence and of data subject requests.
- AVANT.SI d.o.o. (Slovenia; trading as NEOSERV) — web hosting for the marketing site and the application's static files. Those files contain no personal data, but the web server's access logs record visitors' IP addresses, timestamps and requested URLs.
In addition to the processors above, your data is also received by:
- Stripe, Inc. (USA) — subscription and payment processing. In providing payment services Stripe acts as an independent controller, because it also processes the data to meet its own legal obligations (fraud prevention, payment services and anti-money laundering law) rather than solely on our instructions. That processing is governed by Stripe's privacy policy.
Processing for the Service takes place within the EU/EEA — database in Ireland, application server in the Netherlands, email delivery in Ireland, and website hosting in Slovenia.
Some of these providers are companies established in the USA, so access from a third country may exceptionally occur (e.g. for technical support or maintenance); the same applies to payment processing by Stripe. Such transfers take place under Articles 44–49 GDPR — on the basis of an adequacy decision (including the EU-US Data Privacy Framework, where the provider participates in it) or appropriate safeguards such as Standard Contractual Clauses (SCCs).
We update this list whenever our processors change. Business users who have concluded a data processing agreement with us (see section 9) are additionally covered by the advance notification procedure for processor changes set out in that agreement.
9. Data Processing Agreement (DPA)
For business users who process third-party personal data in the app, we conclude a data processing agreement under Article 28 GDPR on request. Request it at info@conaprojekt.si.
10. Your rights
Under Articles 15–22 GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.
Exercise your rights at info@conaprojekt.si; we respond within one month. For the right to erasure (Article 17 GDPR), the full procedure is set out on the Account & Data Deletion page.
You may also lodge a complaint with the supervisory authority — the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana (www.ip-rs.si).
11. Security
We apply appropriate technical and organisational measures: encryption in transit (HTTPS/TLS), passwords stored in hashed form, restricted access, regular system updates, and two-factor authentication (2FA) for internal systems.
12. Cookies and browser storage
We use browser storage for login and app operation. Details are in our Cookie Policy.
13. Changes and contact
We may update this policy from time to time; we will notify you of material changes. For questions, contact info@conaprojekt.si.
See also our Legal Notice and Terms of Service.