Privacy Policy
This Privacy Policy explains how Planaro collects, uses, shares, and protects your personal data when you use our website, applications, and services (the “Service”). We are committed to processing your data lawfully, fairly, and transparently in line with the EU General Data Protection Regulation (GDPR) and applicable Greek law.
1. Who we are
Planaro (“Planaro”, “we”, “us”) provides an all-in-one platform for appointment management, CRM, payments, and website building for independent professionals and service businesses.
For the purposes of the GDPR, the data controller for personal data collected through our website and account sign-up is:
- SMARTYAI LTD (trading as “Planaro”)
- 20 Wenlock Road, London, England, N1 7GU, United Kingdom
- Company number: 15254574
- Email: info@planaro.io
When you use Planaro to manage your own clients (for example, storing your customers’ contact details and bookings), you are the controller of that data and Planaro acts as your processor. Those responsibilities are governed by our Terms of Service and, where applicable, a Data Processing Agreement.
2. Data we collect
Data you provide
- Account data: name, email address, business name, phone number, password (stored hashed).
- Business & service data: the services, availability, pricing, and content you set up.
- Client data you upload: the contact and booking details of your own customers (processed on your behalf).
- Payment data: handled by our payment processors — we do not store full card numbers.
- Communications: messages you send us via forms, email, or chat.
Data collected automatically
- Usage & device data: IP address, browser type, pages viewed, and actions taken, used to operate and secure the Service.
- Cookies & similar technologies: see the Cookies section below.
3. How and why we use your data
We process personal data on the following legal bases:
- Performance of a contract — to create and operate your account, provide the Service, and process payments.
- Legitimate interests — to secure, maintain, and improve the Service, prevent fraud and abuse, and communicate about your account.
- Consent — for optional marketing communications and non-essential cookies; you may withdraw consent at any time.
- Legal obligation — to comply with tax, accounting, and other legal requirements.
4. Cookies
We use strictly necessary cookies to run the Service (for example, to keep you signed in) and, with your consent, analytics cookies to understand how the site is used. You can control non-essential cookies through your browser settings or any cookie banner we present. Disabling essential cookies may affect how the Service works.
5. Sharing & service providers (processors)
We do not sell your personal data. We share it only with trusted providers who process it on our behalf under contract, including categories such as:
- Cloud hosting & infrastructure (data stored within the EU where possible);
- Payment processing (e.g. Stripe, Viva Wallet);
- Email & SMS delivery for notifications and reminders;
- Analytics to measure and improve the Service.
We may also disclose data where required by law, to protect our rights, or in connection with a business transfer such as a merger or acquisition.
6. International transfers
We aim to store and process personal data within the European Economic Area (EEA). Where a provider processes data outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
7. Data retention
We keep personal data only for as long as needed to provide the Service and for legitimate business or legal purposes (for example, tax and accounting records). When you close your account, we delete or anonymise your data within a reasonable period, unless we are required to retain it by law.
8. Your rights under the GDPR
Subject to conditions, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data (“right to be forgotten”);
- Restrict or object to certain processing;
- Data portability — receive your data in a portable format;
- Withdraw consent at any time, without affecting prior processing.
To exercise any right, email info@planaro.io. As SMARTYAI LTD is established in the United Kingdom, you may lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk). If you are in the EU, you may also complain to your local supervisory authority — in Greece, the Hellenic Data Protection Authority (www.dpa.gr).
9. Security
We use technical and organisational measures — including encryption in transit (SSL/TLS), access controls, and secure hosting — to protect personal data. No method of transmission or storage is completely secure, but we work continuously to protect your information and will notify you and the authorities of any breach where required by law.
10. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from children under the age required by applicable law. If you believe a child has provided us data, please contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the latest version, and we will notify you of material changes where required.
12. Contact us
For any question about this policy or your data, contact us at info@planaro.io.