Privacy policy
What personal data Plandura processes, why we do it, how long we keep it, and the rights you can exercise at any time.
Data controller
When you visit our public pages and create an account, CXminds is the data controller. You can always reach us at sales@cxminds.dk.
When your company uses Plandura for strategy work, your company is the controller of that content and Plandura is the processor, as set out in the data processing agreement.
CXminds, Drastrup Skovvej 30, 9200 Aalborg SV, Danmark. CVR: 26875862. E-mail: sales@cxminds.dk.
What we process
- Account data: name, email, role and the company you belong to.
- Company data from the Danish business register: name, address, industry and number of employees.
- Content you write: strategy, goals, KPIs, projects, tasks, reviews and notes.
- Usage data: sign-ins and actions performed in the workspace (for security and troubleshooting).
- Billing data: subscription, invoices and payment status. Card details are handled only by our payment provider.
- Statistics about the public pages — only if you consented to statistics cookies.
Why we process it (legal basis)
- To perform the agreement with your company (GDPR art. 6(1)(b)).
- To comply with accounting obligations (GDPR art. 6(1)(c)).
- For legitimate interests in operation, security and abuse prevention (GDPR art. 6(1)(f)).
- Based on your consent for statistics, marketing and newsletters (GDPR art. 6(1)(a)). Consent can be withdrawn at any time.
How long we keep data
- Account data is kept while the account is active.
- Company content is kept while the subscription is active and deleted no later than 90 days after it ends, unless you ask for deletion earlier.
- Accounting records are kept for 5 years after the financial year, as Danish law requires.
- Security logs are kept for up to 12 months.
Who has access
Access to content is limited to users in the company that owns it, and this is enforced in the database — not only in the interface.
A consultant only gets access to a client workspace when the client has invited or accepted them, and access can be removed at any time.
Our staff access data only when needed for support or operations, and such access is logged.
Where data is processed
Database, sign-in and files are hosted in the EU. A few sub-processors may process data outside the EU/EEA under the European Commission's standard contractual clauses; they are listed on the data processing agreement page.
Where the data comes from
- From you, when you create an account and work in the platform.
- From your company or your consultant, if you were invited into a workspace.
- From the public Danish business register, when we look up official company details from your CVR number.
- From our payment provider, for subscription and payment status (never card details).
Disclosure and sub-processors
We never sell personal data and never use it for purposes other than running Plandura.
We use a small number of suppliers for hosting, site delivery, payment and AI features. They process data only on our instructions and under a data processing agreement. The full list is on the data processing agreement page.
Otherwise data is disclosed only where the law requires it.
AI features
- When you use an AI feature, the text you chose to get help with is sent to our AI provider to generate a suggestion.
- That content is not used to train models and never becomes part of anyone else's answer.
- AI only suggests. Nothing is saved or acted on until a person approves it.
- Do not enter sensitive personal data into AI fields — they are meant for strategy content.
No automated decisions
Plandura makes no automated decisions about individuals and performs no profiling with legal effect. Decisions about employees, hiring and the like are always made by you.
Security incidents
If we detect a personal data breach we follow a defined procedure and notify the controlling company without undue delay — and the Danish Data Protection Agency within 72 hours where the rules require it.
Your rights
You can export or delete your data yourself under Settings → Profile, or write to us and we will respond within one month.
If you are unhappy with how we handle your data, you can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, dt@datatilsynet.dk.
- Access: get a copy of the data we hold about you.
- Rectification: correct inaccurate data such as name and role.
- Erasure: have your account and personal data deleted.
- Portability: export your data in a machine-readable format.
- Objection and restriction: object to processing based on legitimate interests.
- Withdraw consent: change your cookie choice or unsubscribe from emails at any time.
Security
- Data is encrypted in transit and at rest.
- Sign-in requires a verified email, and platform administration requires two-factor authentication.
- Access rules are enforced per company in the database (row level security).
- Backups are taken regularly and restores are tested.
Changes
We update this policy when the platform or the law changes. Material changes are announced in the product or by email.