Security & compliance
Security is not an appendix.
Schedules contain personal data of your entire team. This is how we protect it: technically, organisationally and contractually.
In short
Planvyo runs on our own hardware in colocation in a data centre in Ede, including the database. Your data stays within the Netherlands and the EEA. Every customer has an isolated environment with daily encrypted backups within the EU, and a data processing agreement under art. 28 GDPR is a standard part of the terms.
Technical and organisational measures
Own hardware in the Netherlands
Application and database run on our own hardware in colocation in a data centre in Ede, not at a hyperscaler outside the EU.
Isolated environment per customer
Every schedule runs in its own environment. No shared databases between customers, no risk of third-party access.
Encrypted backups in the EU
Daily backups, stored encrypted within the EU (Germany). Hourly backups available as an option.
Mandatory 2FA for administrators
Administrator access requires two-factor authentication (TOTP). Passwords are stored hashed; secrets encrypted with AES-256.
Audit logging
Security events and administrative actions are logged, so it can always be established afterwards who did what and when.
Hardening & best practices
Rate limiting, CSRF protection, strict security headers (HSTS, CSP) and a security policy based on ISO 27001/27002 standards.
Sub-processors
We keep the chain short and transparent. These are the parties that (may) process personal data:
Stripe Payments Europe, Ltd.
Payments and subscriptions
EU/US (SCCs)Hetzner Online GmbH
Backup storage
Germany (EU)Google Ireland Ltd. (Analytics)
Website statistics, only after consent
EUGDPR & data processing agreement
The data processing agreement (DPA) under art. 28 GDPR is part of our terms and available online. You remain the owner of your data: you can export at any time during your subscription, and after cancellation we keep your data for 30 days for export before everything is permanently deleted.