Legal

Planndora Privacy Policy

Apptriangle Pty Ltd

Effective September 20, 2026Updated September 20, 2026
1

Introduction

This Privacy Policy explains how Apptriangle Pty Ltd (ABN 78 651 767 949, ACN 651 767 949) of 10 Mount Street, North Sydney, 2060, NSW, Australia ("Apptriangle", "Planndora", "we", "us", or "our") collects, uses, discloses, and protects personal information in connection with Planndora, our multi-tenant project and product management platform (the "Service"), our website, and related support and billing functions.

This Policy applies wherever you access the Service from, including from Australia, the European Economic Area ("EEA"), the United Kingdom ("UK"), the United States, and the Asia-Pacific region. Section 15 sets out disclosures required specifically for those regions; where a region-specific disclosure is more protective than the general terms of this Policy, the region-specific disclosure applies to individuals in that region.

This Policy is incorporated into, and forms part of, our Terms of Service. By creating an account or using the Service, you agree to this Policy as part of that binding agreement. If you use Planndora on behalf of an organization, that organization (your "workspace" or "tenant") controls your account and the content within it, subject to Section 2 below.

2

Who We Are, and Who Controls What

Apptriangle Pty Ltd is the company that operates Planndora and is the entity legally responsible for the matters in this Policy.

For account, billing, and platform-security data — your name, login credentials, organization membership, subscription and payment metadata, and security/audit logs — Apptriangle is the data controller (or, under the Australian Privacy Act, the APP entity responsible for that information).

For workspace content — the projects, issues, sprints, comments, attachments, documents, and similar material your organization and its members create or upload — your organization (the customer that administers your workspace) is generally the data controller, and Apptriangle acts as its data processor / service provider, processing that content only as instructed by the organization and as needed to operate the Service. If you have questions about workspace content specifically, your organization's administrator is usually the right first point of contact; Apptriangle remains available for privacy and security requests at the contact in Section 21.

Business customers can request a Data Processing Addendum ("DPA") from Apptriangle that formalizes this processor relationship, including sub-processor terms, international transfer mechanisms, and audit rights — see Section 19.

3

Information We Collect

Account and organization data

  • Name, email address, password (stored as a salted cryptographic hash, never in plain text), phone number, and profile fields (bio, job title, department, avatar) you provide.
  • Organization profile details: name, slug, industry, website, employee count, and address fields entered by an administrator.
  • Member invitations, email-verification tokens, and password-reset / one-time-passcode (OTP) flows.

Workspace content

  • Projects, issues, sprints, comments, attachments, documents, wiki content, ideas, assignees, watchers, and activity history created or uploaded by you or your organization.
  • Configuration for integrations your organization connects (for example Slack, WhatsApp, or Google Calendar), limited to the credentials and settings needed to operate that connection.

AI and MCP (Model Context Protocol) data

  • Connection and configuration metadata needed to link a Planndora workspace to an MCP server endpoint (for example, endpoint address, authentication tokens, enabled tool/feature flags).
  • We do not, by default, receive or retain the workspace content that an MCP server processes when that server is deployed on infrastructure your organization controls. See Section 5.

Billing and payment data

  • Plan selection, seat counts, subscription status, billing period dates, invoices, receipts, and payment history.
  • Payment method details are processed by our payment processors (primarily Stripe; PayPal where enabled). We do not store full card numbers on Apptriangle's servers.
  • Customer and subscription identifiers returned by Stripe (or PayPal) needed to manage billing and proration.

Security, device, and usage data

  • IP address, user agent, approximate location signals when available, timestamps, and action type for security audit events (login success/failure, logout, password changes, invites, role changes, project create/delete, billing changes, IP block/unblock).
  • IP blocklist entries maintained by platform administrators (IP address, reason, creator, active status, optional expiry).
  • Transactional email usage metadata (recipient, purpose, subject, status, actor, organization) for deliverability and abuse monitoring.
  • Product usage events needed to operate features, diagnose errors, and improve performance.
4

Our AI and MCP Deployment Model

Planndora's AI features are built on the Model Context Protocol (MCP). How that server is deployed determines who processes the underlying data, and this is a deliberate design choice intended to keep customer content inside environments the customer controls wherever possible:

  • Customer-hosted MCP (default): Where your organization has its own infrastructure, the MCP server is deployed on that infrastructure, under your organization's control. In this configuration, Apptriangle does not access, store, transmit, or process the workspace content handled by that MCP instance, and we do not use it to train or fine-tune any AI or machine-learning model, whether ours or a third party's. Apptriangle's role is limited to the core Planndora application and the connection metadata described in Section 3.
  • Jointly agreed hosting (fallback): Where an organization does not have suitable infrastructure of its own, we will discuss deployment options with that organization during onboarding, and the MCP server will be deployed only in an environment the customer has reviewed and approved — which may be infrastructure operated by Apptriangle or by a mutually agreed third-party provider. In that configuration, Apptriangle (or the agreed provider) acts as a data processor for the data handled by that MCP instance, subject to the same purpose-limitation and no-training commitment above, and subject to the customer's Data Processing Addendum.
  • Because the location and operator of the MCP server are set per customer, the countries in which MCP-processed data is handled will vary and are agreed with each customer individually rather than fixed by this Policy. If you have questions about where your organization's MCP deployment is hosted, ask your workspace administrator or contact us at the address in Section 21.
5

How We Use Information

  • Provide, operate, maintain, and improve Planndora's features (projects, issues, watchers, documents, notifications, and API/MCP access where enabled).
  • Authenticate users, enforce roles and permissions, and manage organization membership.
  • Process subscriptions, per-seat charges, prorations, renewals, receipts, and failed-payment retries via Stripe (and PayPal where offered).
  • Send transactional email such as invites, verification, password reset, billing receipts, and important service notices.
  • Detect, prevent, and investigate fraud, abuse, unauthorized access, and security incidents — including IP blocking when warranted.
  • Respond to support requests and communicate product updates you opt into.
  • Comply with legal obligations and enforce our Terms of Service.

Note: AI training

We do not use workspace content to train AI or machine-learning models, and we do not sell personal information.

7

How We Share Information

  • We do not sell personal information.
  • Payment processors: Stripe (primary) and PayPal process payments, proration, invoices, and receipts under their own privacy policies.
  • Infrastructure and service providers that help us host, store files, send email, monitor uptime, or analyze reliability — bound by contractual confidentiality and security obligations. A current list of sub-processors is available at [SUB-PROCESSOR LIST URL] and we will provide advance notice before adding a sub-processor that will handle personal information.
  • Organization administrators and authorized members may access workspace content and member activity according to role permissions.
  • Platform administrators may access security logs, mail-usage logs, and IP blocklist controls needed to operate and secure the platform, on a least-privilege, need-to-know basis, and that access is itself logged.
  • We may disclose information when required by law, legal process, or to protect the rights, safety, and integrity of users and the Service.
  • In connection with a merger, acquisition, or asset transfer, information may transfer subject to appropriate confidentiality protections and, where required, notice to affected individuals.
8

International and Cross-Border Data Transfers

Apptriangle is based in Australia, and our core infrastructure and payment processors may operate in other countries, including Australia / Singapore / United States / Ireland and the United States (for Stripe/PayPal). Where we transfer personal information out of a jurisdiction that regulates such transfers, we use one or more of the following safeguards depending on the origin of the data:

  • EEA/UK-origin data: Standard Contractual Clauses (SCCs) adopted by the European Commission, and, for UK-origin data, the UK's International Data Transfer Addendum, or reliance on an applicable adequacy decision.
  • Australia-origin data: compliance with Australian Privacy Principle 8, including satisfying ourselves that the overseas recipient is subject to a comparable privacy law or contractual safeguards, or obtaining consent where required.
  • Data subject to Asia-Pacific frameworks (for example Singapore's PDPA or Japan's APPI): contractual and, where the destination is not a recognized adequate jurisdiction, comparable safeguards, together with the disclosures in Section 15.4.

Note: MCP deployment

As described in Section 4, the MCP/AI processing layer is deployed per customer and, by default, stays within infrastructure the customer controls — which for many customers reduces or eliminates cross-border transfer of workspace content for that layer entirely.

9

Cookies and Tracking Technologies

We use cookies and local/session storage for three purposes: (a) strictly necessary cookies to keep you signed in and support core functionality; (b) analytics cookies to understand product usage and reliability; and (c) marketing cookies, where used, to measure the effectiveness of our own communications.

  • For visitors in the EEA and UK, we request opt-in consent through a cookie banner before setting non-essential (analytics or marketing) cookies, consistent with the ePrivacy Directive/PECR. For visitors elsewhere, you can control cookies through your browser settings and, where offered, an in-product preference center; disabling certain cookies may limit signed-in features. See our Cookie Policy for the current list of cookies and providers.
10

Payments and Billing Privacy

Planndora uses a per-seat, prorated billing model powered primarily by Stripe. When seats are added mid-cycle, Stripe calculates prorated amounts; renewals charge for all active seats. Payment receipts and invoices are generated through the payment provider and may be emailed to the customer.

  • Card and wallet details are entered on Stripe (or PayPal) hosted checkout / customer portal surfaces whenever possible.
  • We store subscription and payment metadata needed for entitlements (plan, seats, status, period end, provider references).
  • Failed payments may trigger provider retry logic and temporary restriction of paid features until resolved.
11

Cookies and Tracking Technologies

We use cookies and local/session storage for three purposes: (a) strictly necessary cookies to keep you signed in and support core functionality; (b) analytics cookies to understand product usage and reliability; and (c) marketing cookies, where used, to measure the effectiveness of our own communications.

  • For visitors in the EEA and UK, we request opt-in consent through a cookie banner before setting non-essential (analytics or marketing) cookies, consistent with the ePrivacy Directive/PECR. For visitors elsewhere, you can control cookies through your browser settings and, where offered, an in-product preference center; disabling certain cookies may limit signed-in features. A separate Cookie Policy with the current list of cookies and providers is available at www.planndora.com/cookie_policy.
12

Data Retention

  • Account and workspace data are retained while your organization remains active or as needed to provide the Service.
  • Security logs, email-usage logs, and IP blocklist records are retained for security, audit, and abuse-prevention purposes for a period appropriate to those purposes, then deleted or aggregated where feasible.
  • Billing and payment records may be retained as required for accounting, tax, dispute resolution, and legal compliance.
  • After account deletion or organization offboarding, we delete or anonymize personal data within a reasonable period, except where longer retention is required by law or legitimate business records.
13

Security Measures

  • HTTPS/TLS for data in transit; passwords stored as salted cryptographic hashes; role-based access control (platform administrator, organization administrator, member) and project-level membership.
  • Issue-edit permissions are scoped so members can view project issues but edit only when assigned or when they hold an administrator role, limiting unnecessary write access.
  • Security audit logging of sensitive actions, and an optional IP blocklist enforced on API requests.

Security: If something goes wrong

If we become aware of a data breach that is likely to result in serious harm, we will assess it and, where required, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals in line with the Notifiable Data Breaches scheme, and notify the relevant supervisory authority within 72 hours where the GDPR/UK GDPR applies. We will also notify affected business customers directly so they can meet their own regulatory obligations. No method of transmission or storage is perfectly secure; we encourage strong, unique passwords and prompt reporting of any suspected compromise.

14

Your Rights and Choices

Subject to the exceptions and processes of the law that applies to you, you may have rights to access, correct, export, restrict, or delete your personal information, or to object to certain processing. Region-specific rights are set out in Section 15; the baseline process is:

  • Update most profile information directly in-app. For workspace content controlled by your organization, ask your workspace administrator, who can action most requests directly.
  • Send a request to support@planndora.com. We will take reasonable steps to verify your identity before acting on a request that goes beyond your own account settings.
  • We aim to acknowledge requests within 5 business days and to resolve them within 30 days, or to explain any extension needed for complex requests.
  • You may request logout-related audit recording through the product logout flow; discard tokens client-side after sign-out.
  • Marketing communications can be opted out of at any time; transactional and security messages remain necessary for the Service.

Note: Complaints

If you're unhappy with how we've handled your personal information, contact us at support@planndora.com and we will investigate and respond within 30 days. If you're not satisfied with our response, you may escalate to the regulator for your region: Australia (OAIC — oaic.gov.au), United Kingdom (ICO — ico.org.uk), European Economic Area (your member state authority), United States (state Attorney-General or FTC), Singapore (PDPC), or the equivalent data protection authority in your country.

15

Automated Decision-Making

We do not currently make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. If that changes — for example, if a feature were to automatically restrict account access based solely on an automated risk score — we will update this Policy and provide the disclosures required by applicable law, including Australia's automated-decision-making transparency requirement taking effect 10 December 2026 and Article 22 of the GDPR/UK GDPR where applicable.

16

Region-Specific Disclosures

These disclosures supplement, and where more specific control, the general terms of this Policy for individuals in the listed regions.

15.1 Australia

  • We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
  • You may complain to us directly (Section 13) or to the OAIC if you're not satisfied with our response.
  • We are subject to the Notifiable Data Breaches scheme (Section 12) and acknowledge that Australia's statutory tort for serious invasions of privacy (in force since 10 June 2025) gives individuals a direct right of action for serious, intentional or reckless invasions of privacy; nothing in this Policy limits that right.
  • If our turnover or activities bring us within scope of the Privacy Act regardless of the small-business threshold — including through the removal of exemptions expected in later reform tranches — we will comply as an APP entity.

15.2 European Economic Area and United Kingdom

  • Where the GDPR or UK GDPR applies, we process personal information on the legal bases in Section 6, and you have the rights to access, rectify, erase, restrict, port, and object to processing of your personal information, as well as the right to withdraw consent at any time where processing is based on consent.
  • International transfers are protected as described in Section 8.
  • EU/UK representative: [Apptriangle will assess whether Article 27 GDPR / UK GDPR requires appointing an EU and/or UK representative, based on the scale and nature of EEA/UK processing at the time of publishing this Policy. If required, the representative's name and contact details will be listed here.]
  • Data Protection Officer (if appointed): [name/contact, or a statement that Apptriangle has assessed that a DPO is not currently required under Article 37 and will reassess as the business grows].

15.3 United States

  • If you're a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to delete it, to correct it, to opt out of the sale or sharing of personal information (we do not sell or share personal information as those terms are defined by the CCPA), to limit use of sensitive personal information, and to be free from discrimination for exercising these rights. We do not knowingly sell or share the personal information of consumers under 16 without opt-in consent.
  • You can submit a request by emailing support@planndora.com or through the in-app request form; an authorized agent may submit a request on your behalf with appropriate proof of authorization. Residents of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, and Utah, among others) have similar rights of access, deletion, correction, and opt-out, which we honor on request even where this Policy does not name every applicable state law individually.

15.4 Asia-Pacific

  • Singapore: we comply with the Personal Data Protection Act (PDPA). We have designated [DPO NAME / "our Data Protection Officer, contactable at support@planndora.com"] as our Data Protection Officer. Where a data breach is assessed as notifiable, we will notify the Personal Data Protection Commission (PDPC) as soon as practicable and, in any event, within 3 calendar days of completing that assessment, and will notify affected individuals where required.
  • Japan: where the Act on the Protection of Personal Information (APPI) applies, we collect and use personal information only for the purposes disclosed in this Policy, and we will inform you of the destination and safeguards before transferring personal information to a country that is not recognized as providing an equivalent level of protection, or will obtain your consent where required.
  • India: where the Digital Personal Data Protection Act, 2023 (DPDPA) applies, we process personal information (of "Data Principals") on the basis of consent or another permitted ground, provide a clear notice of purpose at or before collection, and support your rights to access, correct, and erase your personal information, and to withdraw consent and lodge a complaint with the Data Protection Board of India. As India's consent-manager framework and remaining rules continue to phase in, we will update our processes and this Policy to remain aligned with them.
  • Other Asia-Pacific jurisdictions: where a customer or user is located in a jurisdiction with its own data protection law not named above (for example South Korea's PIPA or China's PIPL, which has its own data-localization and cross-border transfer assessment requirements), we will work with that customer, as part of onboarding and the deployment approach described in Section 4, to meet the requirements that apply — including, where needed, keeping data within that jurisdiction by deploying the MCP server and, where feasible, other components on locally hosted infrastructure the customer controls.
17

Children's Privacy

Planndora is built for professional and organizational use and is not directed to, or intended for use by, anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at support@planndora.com and we will take appropriate steps to remove it.

18

Marketing Communications

Marketing emails we send are sent consistently with the Australian Spam Act 2003 (consent, clear sender identification, and a functional unsubscribe mechanism in every message) and, for recipients in the EEA/UK, on a consent basis consistent with the ePrivacy Directive/PECR. You can unsubscribe at any time; this does not affect transactional or security messages necessary for the Service.

19

Data Processing Agreements for Business Customers

Business customers who need a formal processor agreement — for example to meet their own GDPR Article 28, UK GDPR, or equivalent obligations — can request a Data Processing Addendum from support@planndora.com. The DPA covers processing instructions, confidentiality, sub-processor authorization and notice, international transfer mechanisms (including SCCs/IDTA where relevant), breach notification timing, deletion or return of data on termination, and audit rights, and will reflect the deployment model your organization has chosen under Section 4.

20

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date, and where a change materially reduces your rights we will take reasonable steps to notify affected customers directly (for example by email) in advance of the change taking effect. Continued use of the Service after changes become effective constitutes acknowledgment of the updated Policy.

21

Contact Us

Apptriangle Pty Ltd (ABN 78 651 767 949, ACN 651 767 949)

10 Mount Street, North Sydney, 2060, NSW

Privacy requests, data requests, and security concerns: support@planndora.com

We will respond within a reasonable time consistent with applicable law, and in line with the timeframes set out in Section 13.