Data Processing Agreement (DPA)

Version: July 2026

This Data Processing Agreement (DPA) specifies the parties' obligations under Art. 28 GDPR and forms an annex to the PlanElec Terms of Service. It is concluded between the professional business using PlanElec, as controller, and the operator of PlanElec, as processor, as soon as personal data of end customers is processed in PlanElec.

AI analysis and separate training permissions

Requested AI analysis processes the selected documents and necessary information through OpenRouter and the model operator listed among the subprocessors. Operation identifiers and cost metadata are processed for the usage allowance. Voluntary permission to train PlanElec’s own models is separate and is not a blanket instruction under this DPA. It applies only to explicitly shared documents, can be withdrawn in settings and does not change the AI allowance. Training is not currently active; anonymisation, legal basis and responsibilities must be reviewed separately before its introduction.

Parties

Controller: The electrical business using PlanElec that enters and processes the personal data of its end customers in PlanElec.

Processor: Stephan Behm, Heggen 34, 4837 Baelen, Belgium, enterprise number 1043.329.030 – operator of PlanElec.be.

1. Subject matter and duration

The subject matter is the processing of personal data by the processor on behalf of the controller for the purpose of providing the PlanElec software (planning of electrical installations, creation of schematics, floor plans and documents). The agreement applies for the duration of the use of PlanElec and ends upon termination of the usage relationship.

2. Nature and purpose of the processing

The processor processes the data exclusively to provide the agreed services – storage, processing and display of the project and end-customer data entered by the controller. No processing for the processor's own purposes takes place, in particular no analysis, disclosure or sale of the data.

3. Categories of personal data

In the context of use, the following categories of data are processed in particular:

  • Contact details of end customers (name, address, and where applicable email address and phone number)
  • Building and property data (address, floor plan, room layout)
  • Installation data (circuits, distribution board configuration, single-line diagrams, bills of materials)
  • Project metadata (project name, timestamps, editing status)

4. Categories of data subjects

The following groups of persons are affected by the processing:

  • End customers of the controller (developers, owners, tenants)
  • Other natural persons named in the project

5. Obligations of the processor

Pursuant to Art. 28(3) GDPR, the processor undertakes in particular to:

  • process the data only on documented instructions from the controller;
  • ensure that persons authorised to process the data are committed to confidentiality;
  • implement appropriate technical and organisational measures pursuant to Art. 32 GDPR;
  • engage sub-processors only under the conditions of this agreement;
  • assist the controller in responding to requests from data subjects;
  • assist the controller in complying with the obligations under Art. 32 to 36 GDPR;
  • notify the controller without undue delay of any personal data breach;
  • delete or return the data at the end of the processing, at the controller's choice;
  • make available to the controller all information necessary to demonstrate compliance with these obligations.

6. Sub-processors

The processor engages the following sub-processors to provide the services. The controller hereby grants its general authorisation:

Sub-processorPurposeLocation / basis
Supabase (AWS, EU-Region)Authentication, database and file storageEU
Resend, Inc.Sending transactional emails (account and system notifications)USA – EU-US Data Privacy Framework (Art. 45 GDPR)
PostHog, Inc. (PostHog Cloud EU)Product analytics; cookieless baseline measurement, with account attribution and masked session recording only after consentEU (Frankfurt) – provider USA, DPF-certified
IONOS SE / CoolifyHosting and operation of the application infrastructureEU
PlanElec-Cockpit (MQTT Event-Bus)Internal event bus for operational monitoring (technical identifiers only)EU
OpenRouter, Inc.Routing of AI requests to the language model; forwarding to the model operator without storageUSA – standard contractual clauses (Art. 46 GDPR)
Microsoft Azure (EU-Region)Operation of the language model for analysing plan pages and documents (EU region)EU

The processor informs the controller of any intended changes to the sub-processors and provides the opportunity to object. Processing takes place within the EU, with the exception of the routing of AI requests, which passes through a provider established in the USA while the language model itself is operated in the EU region. Transfers to providers established in the USA are made on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR) or the European Commission’s standard contractual clauses (Art. 46 GDPR).

7. Technical and organisational measures (TOMs)

The processor maintains appropriate technical and organisational measures pursuant to Art. 32 GDPR, in particular:

  • encryption of data transmission (TLS/HTTPS);
  • access control through authentication and role-based permissions;
  • data storage in data centres within the European Union;
  • regular backups;
  • logging of security-relevant events;
  • protective measures against unauthorised access (rate limiting, brute-force protection).

8. Deletion and return

Upon termination of the usage relationship, the personal data will be deleted or returned at the controller's choice, unless a statutory retention obligation applies. The controller can export its project data at any time via the application.

9. Control and audit rights

The controller has the right to verify compliance with this agreement. Upon request, the processor makes available the information and evidence required for this purpose and allows for reviews to a reasonable extent.

10. Liability

Liability is governed by Art. 82 GDPR and by the Terms of Service. Each party is liable for damage caused by an attributable breach of this agreement or of the provisions of the GDPR.

11. Contact

For questions regarding this Data Processing Agreement, you can reach us at: info@planelec.be