Privacy Policy
Your privacy is our priority. Learn how we collect, use, and protect your information.
Last updated: July 20, 2026 | Effective: August 15, 2026
Summary (plain English)
This summary is for orientation only — the binding text follows below.
- Who we are. PlanMagnet is operated by Timecampus Technologies Private Limited, a company incorporated in India and part of the Burdenoff Group. We are the controller / data fiduciary for your account, billing, waitlist and website-visitor data. For the work-management data your organisation puts into PlanMagnet — projects, work items, boards, comments, attachments, time logs, custom fields and the activity of the people in your workspace — your organisation is the controller and we are the processor.
- What PlanMagnet is. A unified product & project management platform spanning agile delivery (Kanban & Scrum boards, backlogs, sprints), product planning (roadmaps, initiatives, feedback & feature voting), portfolio & program management, milestones & releases, dependencies, custom fields & workflows, time tracking & timesheets, risk & quality gates, budgets & expenses, no-code automation, and delivery analytics. The personal data PlanMagnet handles is mostly collaboration content — who is in your workspace and what they record in their work — so privacy and tenant isolation are central to the product, not an afterthought.
- Where it lives. All Customer Data is stored in India by default, in Indian cloud regions. Some operational metadata transits Cloudflare's edge.
- What we collect. Account and profile data, what you do in the product, device / connection data, billing data, support correspondence, waitlist data, and the work-management content your organisation chooses to store in PlanMagnet (projects, work items, comments, attachments, time entries, custom-field values, automation rules).
- Why we use it. To run the Service, keep it secure, bill you, support you, comply with law, and improve the product. We do not sell your personal data. We do not train AI models on your projects, work items, comments, attachments, or other Customer Data.
- Sensitive content. PlanMagnet does not ask for special-category data, but a customer may choose to store confidential material in work items, comments or attachments — product roadmaps, security risks, budgets, customer details or other third-party data. We apply tenant isolation, RBAC and encryption at rest, and process such content only on your organisation's instructions. We do not require special-category data (health, biometrics, caste, religion, etc.) and you must not introduce it outside the scope agreed in your contract.
- AI features. AI-assisted planning suggestions (e.g. drafting and summarising work items, breaking down initiatives) are on the roadmap. Where AI is used to support a planning or delivery decision, you keep a human in the loop. We do not make automated decisions with legal or similarly significant effect on your behalf.
- Subprocessors. Listed in DPA Annex 3 and at
https://burdenoff.com/contracts/subprocessors. They include AWS, Cloudflare, Amazon SES, Razorpay, Stripe (via our US entity), Google Workspace (internal team collaboration only), GitHub, and Linear. - Your rights. Under India's DPDP Act, GDPR, UK GDPR and (where applicable) US state privacy laws you can access, correct, erase, port, restrict or object to processing. Contact
[email protected]. - Age. PlanMagnet is a workplace collaboration tool for working-age individuals (18 and over) and the organisations that use it. It is not directed to children.
- Grievance Officer (DPDP Act §8(10)). Vignesh T.V., Founder, CEO & CTO, Timecampus Technologies Private Limited —
[email protected].
1. Who we are and how to reach us
PlanMagnet (the "Service") is operated by:
Timecampus Technologies Private Limited ("Timecampus", "we", "us", "our") A company incorporated under the Companies Act, 2013 CIN: U72900TN2022PTC156974 Registered office: "VISWAM", Plot No. 43, Veeramani Nagar, 2nd Cross Street, Nanmangalam, Chennai – 600117, Tamil Nadu, India.
Timecampus is part of the Burdenoff Group. Engineering, support, security and operations personnel are employed by Burdenoff Consultancy Services Private Limited (the Group's manpower entity) and act under Timecampus's instructions and intra-group confidentiality, access-control and data-protection arrangements. International payment processing is handled by Algoshred Technologies Corp (Delaware, USA; EIN 35-2845680), with a virtual PO at 8 The Green, Ste A, Dover, DE 19901, USA.
Contacts
| Topic | |
|---|---|
| Privacy / data subject requests | [email protected] |
| Grievance Officer (DPDP Act) — Vignesh T.V., Founder, CEO & CTO | [email protected] |
| Security & responsible disclosure | [email protected] |
| Support | [email protected] |
| General | [email protected] |
| Postal (India) | the registered office address above |
| Postal (US, billing entity) | Algoshred Technologies Corp, 8 The Green, Ste A, Dover, DE 19901, USA |
For EU / UK representatives and supervisory authorities, see §14.
2. Scope of this Policy
This Policy applies to:
- the PlanMagnet website at
planmagnet.com(marketing pages, pricing pages, the waitlist sign-up, public docs, community pages); - the PlanMagnet product, including the web app at
app.planmagnet.com, the mobile applications, and any official CLI, SDKs or browser/code extensions made available; - the projects, work items, comments, attachments and other work-management content processed by the Service;
- sales, support, billing and other business interactions with Timecampus about PlanMagnet.
It does not cover:
- third-party services you integrate (e.g., your issue tracker such as Jira, your source host such as GitHub or GitLab, identity provider, accounting system). Those have their own privacy notices.
- other Burdenoff Group products, which have their own privacy notices.
- how your employer handles your data outside PlanMagnet — if you are a member, collaborator or guest using PlanMagnet through an organisation, that organisation's own privacy notice governs its decisions about your data.
3. Our role: controller vs. processor
Two things can happen at once:
3.1 Timecampus as controller / data fiduciary. For data we collect to run our business — your account, billing, support, security, waitlist, website analytics, marketing — we are the controller under GDPR / UK GDPR, the Data Fiduciary under India's DPDP Act, 2023, and the Business under California's CPRA. This Policy is the notice for that processing.
3.2 Timecampus as processor / data processor. For the work-management data an organisation puts into PlanMagnet — projects, work items, boards, sprints, roadmaps, comments and threads, attachments, time logs, custom-field values and the membership/activity records of the people in the workspace — the organisation is the controller / Data Fiduciary and Timecampus is the processor on its documented instructions under our Data Processing Addendum (DPA) (https://burdenoff.com/contracts/planmagnet/PLA-LEGAL-003). If you are a member, collaborator or guest whose data appears in an organisation's PlanMagnet tenant, please direct your data-subject requests to that organisation first; we will assist them under the DPA.
Where you sign up as an individual (e.g., a solo founder or freelancer running your own projects), you act in both capacities and we treat you accordingly.
4. Personal data we collect
We collect only what we need for the purposes in §5.
4.1 Information you give us
| Category | Examples |
|---|---|
| Waitlist (pre-launch) | Name, work email, organisation name, role, team size, country, areas of interest |
| Identity & contact | Name, work email, username, profile photo, phone (optional) |
| Account & authentication | Password hash (where local auth is used), SSO subject ID, MFA factors, recovery codes |
| Organisation & role | Tenant membership, RBAC roles, team / project membership, reporting context where you record it |
| Projects & work items | Project, epic, story, task, bug and sub-task titles, descriptions, statuses, assignees, reporters, priorities, estimates, labels and the personal data a customer chooses to place in them |
| Boards, backlogs & sprints | Board columns and WIP settings, backlog ordering, sprint goals, start/end dates, sprint membership |
| Roadmaps, portfolios & programs | Initiatives, roadmap items and dates, portfolio/program groupings, milestones, releases and their owners |
| Comments & collaboration | Comments and threads on work items, @mentions, reactions, feedback-inbox submissions and feature votes |
| Time tracking | Time entries and timesheets (who logged time, against which work item, for how long), timesheet approvals |
| Custom fields & workflows | Custom-field definitions and values, configurable workflow states and transitions a customer defines |
| Risk, quality & budget | Risk register entries and owners, quality-gate checks, budget lines, expenses and spend records a customer enters |
| Automation | No-code automation rules, triggers, conditions and actions configured by the customer |
| Attachments | Files and screenshots attached to work items, comments and projects via the shared files service |
| Billing | Billing contact, billing address, GSTIN / PAN (Indian customers), VAT / tax IDs, tokenised payment-method identifier (actual card data is held by Stripe / Razorpay, not by us) |
| Communications | Support tickets, chat transcripts, in-product messages and threads, survey responses, community posts |
4.2 Information we collect automatically
| Category | Examples |
|---|---|
| Device & connection | IP address, user agent, OS, browser, language, time zone, city-level geolocation derived from IP |
| Usage / product analytics | Pages and features used, navigation paths, feature-flag exposures — collected through our self-hosted Rybbit instance (see §4.4) |
| Telemetry & diagnostics | Error stack traces, performance metrics, request IDs, audit-log entries |
| Cookies & similar | See our Cookie Policy at https://planmagnet.com/cookies |
4.3 Information from third parties
- SSO / identity providers (Google, Microsoft, your enterprise OIDC IdP): the claims you authorise (typically email, name, subject ID).
- Issue-tracker & source integrations you connect (e.g. Jira, GitHub, GitLab): the issues, pull/merge requests and metadata you choose to sync into PlanMagnet to keep work items aligned.
- Payment processors (Stripe, Razorpay): payment-status events and tokenised card metadata.
- Referrers and partners who refer you to us.
4.4 Product analytics (Rybbit)
We use Rybbit (https://rybbit.com) as our product- and website-analytics tool. We run a managed-cloud Rybbit subscription that we operate ourselves; Rybbit is not given commercial access to your data.
- Events recorded include page views, feature usage, error counts, navigation within the product, and aggregate funnel data — all keyed by an internal account / device identifier.
- We may export analytics data out of Rybbit for our own analysis, dashboarding and product decisions. We do not sell analytics data or behavioural profiles to any third party, and we do not share user-level analytics with advertising networks.
- We do not apply behavioural analytics to a customer's work items, comments or member records to profile individuals; product analytics measure how the software is used, not how to evaluate a person.
- Where analytics processing involves cookies or similar storage on EEA/UK/Swiss visitors' devices, it requires consent (see Cookie Policy §5).
4.5 Confidential content and attachments
A customer may store confidential material in PlanMagnet — internal roadmaps, security risks, budgets, customer or partner data — inside work items, comments and attachments. PlanMagnet is designed so that:
- Attachments and files are stored using the shared files service with access governed by tenant RBAC, encrypted at rest, and visible only to roles your organisation grants.
- Tenant isolation keeps each organisation's projects, work items and comments logically separated; a member of one tenant cannot read another tenant's content.
- Special-category data (health, biometric identifiers, caste, religion, political opinion, sexual orientation, trade-union membership, criminal-record data) is not required by the Service. Do not introduce such categories into work items, comments, custom fields or attachments unless your Order Form and DPA Annex 1 expressly authorise it with appropriate additional controls, and you have the lawful basis to do so.
4.6 Information we deliberately do not collect
- Card numbers — these go to Stripe or Razorpay; we hold only a tokenised reference.
- Special-category personal data, except where your contract expressly authorises a specific, controlled use.
- Customer Data for any purpose other than providing the Service to your organisation — we do not mine your projects, work items or comments for our own commercial gain.
5. Why we use personal data, and our lawful bases
| Purpose | Description | Lawful basis (GDPR / UK GDPR) | Ground (DPDP Act) |
|---|---|---|---|
| Operate the waitlist | Register interest, send launch and onboarding communications | Consent; legitimate interests | Consent / legitimate use |
| Provide the Service | Authenticate users, manage tenants, run boards, sprints, roadmaps, portfolios, work items, automation and analytics features as your organisation configures them | Contract (Art. 6(1)(b)); processor acting on controller instructions | Performance of contract / certain legitimate uses |
| Secure the Service | Detect and prevent fraud, abuse, unauthorised access, security incidents | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) | Compliance with law; legitimate use |
| Bill, invoice, account, tax | Charge for paid plans, issue invoices, comply with tax and accounting rules | Contract; legal obligation | Performance of contract; legal compliance |
| Support and communicate | Answer tickets, send service-critical email (incident notices, breach notification, change announcements, renewal notices) | Contract; legitimate interests | Performance of contract |
| Improve the Service | Aggregated and de-identified usage and telemetry (via Rybbit) to fix bugs, prioritise features, benchmark performance | Legitimate interests | Legitimate use |
| Marketing (opt-in) | Newsletters and product updates with consent or to existing customers about similar products (soft opt-in where lawful) | Consent (Art. 6(1)(a)); legitimate interests with opt-out | Consent |
| Comply with law | Respond to lawful orders, CERT-In directives, DPDP Board notices, tax filings | Legal obligation | Legal compliance |
| Defend our rights | Establish, exercise or defend legal claims | Legitimate interests; legal claims | Legitimate use |
We do not use Customer Data — including your projects, work items, comments, attachments, custom-field values, time logs, prompts or AI session content — to train, fine-tune or evaluate any generally available machine-learning or large-language model.
6. How we share personal data
We do not sell personal data. We share personal data only with the categories below.
6.1 Service subprocessors
To run the Service we use the subprocessors listed in DPA Annex 3. The authoritative live list is published at https://burdenoff.com/contracts/subprocessors.
| Subprocessor | Role | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure — primary for the platform (compute, databases, caching, secrets management, containerised services, object storage, and static asset delivery) | ap-south-1 (Mumbai), India |
| Cloudflare, Inc. | CDN, WAF, DNS, Zero Trust | Global edge |
| Amazon Simple Email Service (SES) | Transactional email | ap-south-1 (Mumbai) |
| Stripe, Inc. | International payment processing (invoiced by Algoshred Technologies Corp); marketplace payouts where enabled | US / EU |
| Razorpay Software Pvt. Ltd. | India and other regional payment processing; marketplace payouts where enabled | India |
| Apache Answer (self-hosted by Timecampus) | Support community at community.planmagnet.com (open-source, operated by us, no third-party SaaS involved) | India |
| Timecampus-operated support tooling | In-house ticketing and customer success — no third-party SaaS support desk is used | India |
| GitHub, Inc. | Source-code hosting (Timecampus internal); also referenced where customer integrations call it | US |
| Linear (Linear Orbit, Inc.) | Internal project tracking; may receive support-ticket metadata if escalated | US |
| Google Workspace (Google LLC) | Internal team collaboration only — email, calendar, docs used by Burdenoff Group personnel for internal operations. Customer Data is not stored in Google Workspace as part of the Service. | US / EU (Google managed) |
| Burdenoff Consultancy Services Pvt. Ltd. | Manpower entity — engineering, support, security and operations personnel that deliver the Service on Timecampus's behalf | India |
| Algoshred Technologies Corp (Delaware, USA) | International invoicing entity | USA |
We give workspace privacy contacts at least 30 days' notice of additions or replacements of Subprocessors. Customers under the DPA can object on reasonable data-protection grounds within 14 days.
6.2 Other recipients
- Tenant administrators and other authorised members — within your organisation's PlanMagnet tenant, projects, work items, comments and audit entries are visible to people with the relevant roles (e.g., workspace admins, project leads, project members). Access is governed by RBAC your organisation configures.
- Collaborators and guests you invite — where you share a project, board or work item with another member or an external guest, they see the content you choose to share with them.
- Buyers or successors in a corporate transaction (merger, acquisition, sale of substantially all assets), subject to equivalent protections.
- Authorities and courts — when required by law, lawful warrant, CERT-In directive, DPDP Board order, or to protect rights, safety or property.
- Professional advisors — auditors, lawyers, insurers — under confidentiality.
We do not share personal data with advertising networks, data brokers, or third parties for their independent marketing.
7. Data residency and international transfers
All Customer Data is stored in India by default. Backend services, frontend assets, object storage and transactional email all run in Indian cloud regions.
Some operational metadata leaves India:
- Cloudflare edge sees connection metadata (IP, request headers) at globally distributed points of presence as it routes traffic.
- Stripe receives international billing and marketplace-payout data (US / EU).
- Internal tooling (Google Workspace, GitHub, Linear) — used by our personnel for internal operations and may incidentally receive support-ticket metadata if you escalate to us.
- Issue-tracker / source integrations you enable (e.g. Jira, GitHub, GitLab) receive only the work-item and reference data needed to keep the integration in sync, governed by their locations and terms.
For transfers out of the EEA, UK or Switzerland we rely on:
- the European Commission's Standard Contractual Clauses (SCCs) Module 2 (Controller-to-Processor), incorporated by reference into our DPA;
- the UK International Data Transfer Addendum to the SCCs;
- the Swiss FDPIC-approved variant of the SCCs.
For India, we comply with cross-border rules under Section 16 of the DPDP Act, 2023 and any restrictions notified from time to time by the Central Government. For data subject to the SPDI Rules under the IT Act, 2000, transfers are only to entities ensuring the "same level of data protection", and only with consent or where necessary for performance of a lawful contract. Where your organisation requires data localisation for its work-management content (e.g., to keep all project and work-item data in a specific country), that is configured on the Order Form.
You can request a copy of the safeguards in place by writing to [email protected].
8. How long we keep data
We retain personal data only as long as we need it.
| Category | Retention |
|---|---|
| Waitlist data | 12 months from launch (August 2026), or earlier on request, then deletion / suppression |
| Account profile data | While the account is active + 90 days, unless a legal hold or contractual requirement applies |
| Work-management content (projects, work items, boards, sprints, comments, time logs, custom fields) | For the Subscription Term, on the controller's instructions; then per DPA §4.7 (export within 30 days, then delete), subject to any retention your organisation directs |
| Attachments in the file store | Until deleted by the organisation or the account is closed (then per work-management-content retention) |
| Audit logs | Per plan configuration (default 30 days; longer on Enterprise) |
| Analytics / usage events (Rybbit) | Aggregated indefinitely; user-level events up to 13 months |
| Backups | Hot tier rolling 30 days; cold tier up to 90 days |
| Support tickets | 24 months after closure, unless earlier deletion is requested |
| Security & abuse investigations | Up to 7 years if needed to establish or defend legal claims |
| Billing & tax records | 8 years (Indian Income-tax Act / Companies Act / GST retention requirements) |
| Marketing contacts | Until you withdraw consent, then up to 30 days for suppression list |
Tax-record retention is set as law requires; work-management content retention is set by your organisation as the controller, and we hold such content for the period it instructs. After applicable retention, data is deleted or irreversibly anonymised. Aggregated and de-identified data may be retained indefinitely to operate, secure and improve the Service.
9. AI features and automated decisions
PlanMagnet is designed to offer AI-assisted planning features on its roadmap — for example drafting and summarising work items, breaking initiatives into stories, and suggesting estimates or labels. AI-assisted planning is a planned capability that is not yet generally available. When such features ship, the privacy-relevant points will be:
- No training on your data. We do not use your projects, work items, comments, attachments, custom-field values or AI session content to train, fine-tune or evaluate any model.
- Human in the loop. AI features are designed to suggest, not to decide. You keep a person in the loop for any planning or delivery decision; we do not make automated decisions with legal or similarly significant effect on individuals on your behalf.
- You stay responsible for outputs. AI suggestions may be inaccurate or incomplete and must be reviewed before you act on them. Where local law (for example the EU AI Act) imposes obligations on the deployer of an AI system, you are responsible for meeting them as the deployer; we will provide reasonable information about how the relevant features work.
- Minimise personal data in prompts. If you put personal data into an AI feature, it is processed under our DPA. Do not submit special-category data to AI features.
- Logging. We log AI metadata (timestamps, feature, token count, status). Content storage follows your tenant configuration; you can shorten retention or request deletion.
The full terms are in our AI Product Terms (https://burdenoff.com/contracts/planmagnet/PLA-LEGAL-012).
10. Your rights
Subject to local law, you have the following rights. To exercise any of them write to [email protected]. We verify your identity (typically by replying from the email on file or via your account) before acting on a request. We respond within the timeframe local law requires — typically 30 days under GDPR / UK GDPR / DPDP Act and 45 days under CPRA.
10.1 Under the DPDP Act, 2023 (India)
- Access to your personal data and a summary of processing.
- Correction, completion, updating, and erasure.
- Nomination of another person to exercise your rights on death or incapacity.
- Grievance redressal — first raise with the Grievance Officer (§1); if unresolved, complain to the Data Protection Board of India.
- Withdraw consent at any time (where consent is the ground).
10.2 Under the GDPR / UK GDPR
- Access (Art. 15), rectification (Art. 16), erasure / "right to be forgotten" (Art. 17), restriction (Art. 18), portability (Art. 20), object (Art. 21, including direct marketing), and not to be subject to solely-automated decisions with legal or similarly significant effect (Art. 22).
- Withdraw consent for any processing based on consent, without affecting prior lawful processing.
- Lodge a complaint with your local supervisory authority (see §14).
10.3 Under the California CPRA / state US privacy laws
- Know / access what we collect, the categories of sources, purposes and recipients.
- Delete personal information, with limited exceptions.
- Correct inaccurate personal information.
- Opt out of "sale" or "sharing" — we do not sell or share personal information for cross-context behavioural advertising; if this ever changes we will provide a "Do Not Sell or Share My Personal Information" link.
- Limit use of "sensitive personal information" — we do not use it for purposes other than those CPRA allows by default.
- Non-discrimination for exercising your rights.
- Authorised agents may submit requests with proof of authorisation.
- We honour Global Privacy Control signals as opt-out signals to the extent CPRA requires.
10.4 Under the SPDI Rules (IT Act, 2000)
- Right to access and correct sensitive personal data or information; right to withdraw consent (which we honour by ceasing the processing, even if it means we can no longer provide the Service).
10.5 Where you are a member, collaborator or guest in an organisation's tenant
Direct your requests to your organisation administrator first — they are the controller for the work-management content they manage in PlanMagnet. We will assist them under our DPA. We may forward your request to them and let you know.
11. Children
PlanMagnet is a workplace collaboration tool intended for working-age individuals aged 18 and over and the organisations that use it. It is not directed to children and we do not knowingly create accounts for individuals under 18. If your organisation lawfully gives a person under 18 (for example an apprentice or intern) access to a PlanMagnet tenant, your organisation is responsible, as controller, for obtaining any guardian consent and for complying with the applicable data-protection rules; you must not introduce such records without the lawful basis and additional controls agreed in your Order Form.
If you believe we hold a child's personal data without an appropriate lawful basis, write to [email protected] and we will investigate and act.
12. Cookies and similar technologies
We and our subprocessors use cookies, local storage, and similar technologies for authentication, security, preferences and product analytics (via our self-hosted Rybbit). See the Cookie Policy at https://planmagnet.com/cookies for the full list, purposes, and how to control them. EEA, UK and Swiss visitors see a consent banner for non-essential cookies on first visit. We honour Global Privacy Control signals from US visitors.
13. Security
We follow the technical and organisational measures in our Security Exhibit (https://burdenoff.com/contracts/planmagnet/PLA-LEGAL-004) and DPA Annex 2. Highlights:
- TLS 1.2+ in transit; AES-256 at rest for primary databases, object storage and application-layer secrets; mTLS between internal services where supported.
- Defence-in-depth: WAF, RBAC at the GraphQL gateway, default-deny network policies, MFA on cloud admin and internal SSO, centralised logging and on-call (best-effort outside business hours for non-Enterprise tiers).
- Strict tenant isolation by organisation ID enforced at the resolver layer, with RBAC-governed access to projects, work items, attachments and other Customer Data.
- Build-time CVE / SBOM / IaC scanning (Trivy); deploy-time policy enforcement; runtime threat detection.
- Backups: hot rolling 30 days; cold up to 90 days. Default RPO/RTO 24h/24h; Enterprise RPO/RTO are individually negotiated.
- We notify customer points of contact of confirmed personal data breaches without undue delay, and in any event within 72 hours of becoming aware (DPA §4.8).
No method of transmission or storage is 100% secure. Report suspected vulnerabilities to [email protected] (PGP key on request); see the AUP §8 for our responsible-disclosure expectations.
14. Contacts and supervisory authorities
- Privacy Office.
[email protected]. Postal: registered office (§1). - Grievance Officer (DPDP Act §8(10)). Vignesh T.V., Founder, CEO & CTO, Timecampus Technologies Private Limited —
[email protected]. - EU representative (GDPR Art. 27) — to be appointed before we cross the GDPR Art. 27 threshold of regular processing of EEA data subjects; in the interim, EEA visitors should contact us at
[email protected]. - UK representative (UK GDPR) — same approach.
- Supervisory authorities.
- India — Data Protection Board of India (once operational under the DPDP Act).
- EEA — your local Data Protection Authority. List:
https://edpb.europa.eu/about-edpb/about-edpb/members_en. - UK — Information Commissioner's Office (ICO) —
https://ico.org.uk. - Switzerland — FDPIC —
https://www.edoeb.admin.ch. - California — California Privacy Protection Agency —
https://cppa.ca.gov.
15. Changes to this Policy
We may update this Policy. For material changes that reduce your rights we give at least 30 days' notice by email to account holders and/or in-product notice and update the "Effective date" above. Continued use of the Service after the effective date constitutes acceptance for self-serve plans; Enterprise Customers retain the version in force at the start of their then-current Subscription Term until renewal, except where law requires earlier change. Statutory consumer protections under the Consumer Protection Act, 2019 are preserved.
We maintain a version history of this Policy. Prior versions are available on request from [email protected].
16. How this Policy relates to our contracts
If you are on an Enterprise plan under a signed Master SaaS Agreement (MSA) and Data Processing Addendum (DPA) (Document IDs PLA-LEGAL-001 and PLA-LEGAL-003), those documents prevail over this Policy in the event of conflict for the processing they govern. For self-serve plans, this Policy and the Terms of Service are the operative documents.
Questions? Contact us at [email protected]