Privacy Policy
Last updated: 2026-05-21
1. Data controller
Stephan Behm
Heggen 34, 4837 Baelen, Belgium
info@planelec.be
2. What data we collect
- Email address (upon registration)
- Name (optional, upon registration)
- Project data (schemas, installations you create)
- Usage data (anonymous statistics on app usage)
- Waitlist data (email, optional first name, locale — when signing up for Early Access)
- Feedback data (message, category, optional screenshot, PostHog session ID, current path, user agent, viewport — when submitting the feedback form)
- Server logs (IP address, user agent — held briefly in memory to rate-limit login and signup attempts)
3. Purpose of data processing
- Providing and improving the PlanElec service
- Product improvement based on anonymous usage statistics
- Communication about your account and the service
- Security and abuse prevention (rate-limiting, brute-force protection)
4. Legal basis
- Art. 6(1)(a) GDPR — Consent (analytics cookies)
- Art. 6(1)(b) GDPR — Contract performance (account data, project data)
- Art. 6(1)(f) GDPR — Legitimate interest (anonymous product improvement)
- Art. 6(1)(f) GDPR — Legitimate interest (security, abuse prevention, proof of terms acceptance)
5. Storage and security
Your data is stored on servers within the European Union (Supabase EU region). We take appropriate technical and organizational measures to protect your data.
6. Third parties
- Supabase — Authentication and database storage (EU region)
- Supabase Storage — Storage of optional feedback screenshots (Supabase Storage, EU region)
- PostHog — Product analytics — PostHog Cloud EU (data on EU servers in Frankfurt, operator: PostHog, Inc., USA, DPF-certified) — only with consent
- Resend — Transactional email delivery (waitlist confirmations, account notifications)
- PlanElec Cockpit (MQTT) — Internal event bus for operational telemetry (MQTT / PlanElec Cockpit)
When you sign up for the waitlist, your email address and optional first name are transmitted to Resend, Inc. (resend.com) for the purpose of sending confirmation emails. Resend processes this data solely on our behalf. Resend, Inc. is based in the USA and certified under the EU-US Data Privacy Framework (DPF). The data transfer is based on Art. 45 GDPR (adequacy decision). By submitting your email on the waitlist form, you consent to this data transfer.
Specific events — registration, login, acceptance of the terms of service, creation and deletion of projects, waitlist signups and feedback submissions — are additionally forwarded to an internal event bus (MQTT broker) operated by us in order to monitor the platform and steer product improvements. Only technical identifiers (user ID, aggregate type, timestamp) are transmitted, never email addresses, names or schema content. Servers and broker are located in the EU. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security and product improvement).
7. Cookies
PlanElec uses the following types of cookies:
- Essential cookies — Required for basic application functionality (e.g., sidebar state, language preference)
- Analytics cookies — PostHog cookies for anonymous usage statistics — only after your explicit consent
Detailed Cookie Overview
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
| planelec_access | Authentication (JWT Access Token) | 1h | Essential cookies |
| planelec_refresh | Authentication (Refresh Token) | 30 days | Essential cookies |
| planelec_recovery | Password-reset marker (allows a single password change) | 10 min | Essential cookies |
| planelec_locale | Language preference | 1 year | Essential cookies |
| ph_* | PostHog product analytics | Session / 1 year | Analytics cookies |
Local Storage (localStorage)
| Key | Purpose | Category |
|---|---|---|
| planelec_cookie_consent | Cookie consent status | Essential cookies |
| planelec_locale | Language preference | Essential cookies |
8. Analytics and objection
We use PostHog for anonymous product analytics. PostHog is hosted on EU servers (eu.i.posthog.com) and is only activated after you give your consent via the cookie banner.
You can withdraw your consent at any time by going to Settings (gear icon) and clicking 'Change cookie settings' under 'Cookie Settings'. The cookie banner will be shown again.
9. Your rights
Under the GDPR, you have the following rights:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure of your data
- Right to data portability
- Right to object to processing
10. Contact
For privacy inquiries, contact us at: privacy@planelec.be
Proof of consent to Terms of Service
To document your consent, we collect and store:
- Time of consent (date, time)
- Version of terms accepted
- Language in which the text was shown
- IP address at time of consent
- User agent (browser/device identifier)
Stored exclusively to document active consent and immutable (append-only log). Legal basis: GDPR Art. 6(1)(c) (legal obligation) and Art. 6(1)(f) (legitimate interest in proof).
Retention: until account deletion plus statutory retention periods. Upon request, we provide the full record of your consents.