Legal

Data Protection

Version 1.0 · Effective date: 19 August 2026

This page sets out how data protection law applies to the Service and what roles each party holds. It supplements the Terms of Service and the Privacy Policy. A full Data Processing Agreement under Article 28 UK GDPR is available as part of an Enterprise agreement — see section 7.

1. Roles of the parties

Planning application records are public register information published by UK local planning authorities under their own statutory duties. For that data, each party acts as an independent controller: the authority publishes it, PlanWire aggregates and normalises it, and you determine independently how it is used in your own product. Neither party processes that data on the other's behalf, so no processor relationship arises from your ordinary use of the API.

PlanWire is the controller for the data we collect to operate the business and the Service: your account email, billing records, API usage metadata, and the query parameters, filters, saved alerts and webhook endpoints associated with your account. We process that data to deliver the Service, enforce rate limits, bill correctly, and prevent abuse. That processing is described in our Privacy Policy.

Where a specific arrangement does place PlanWire in a processor role — for example a bespoke ingestion or enrichment engagement carried out on your instructions — the Enterprise DPA in section 7 governs it.

2. Categories of data

Public register data: planning application records as published by the originating authority. These may contain personal data, typically applicant and agent names and, occasionally, individuals named in free-text descriptions. PlanWire does not add personal data to these records.

Account and usage data: your contact and billing details, API keys, request logs, and configuration such as webhook endpoints and alert criteria.

3. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit (TLS) for all API and webhook traffic, encryption at rest for stored data, authentication by per-account API key with tier-scoped rate limits, HMAC-SHA256 signatures on webhook payloads so you can verify origin, access control limiting production data to personnel who need it, and logging of API access.

4. Sub-processors

We use third-party providers to operate the Service. The current list, with the purpose and data region of each, is published in the Privacy Policy and kept up to date. Each operates under a data processing agreement with us.

We will give at least 30 days' notice by email before adding or replacing a sub-processor, to the address on your account. This applies to all paid subscriptions. It gives you time to complete your own review and, if you choose, to cancel before the change takes effect under the ordinary cancellation terms in section 5 of the Terms of Service.

5. Data subject requests

Requests concerning planning records themselves — for instance an applicant asking that their name be removed — should be directed to the originating local planning authority. The authority publishes the record and is the controller of it; we reproduce what they publish. Where an authority amends, redacts or withdraws a record, that change flows through to the Service.

We will also consider a direct suppression request where we are satisfied it is valid, and will act on it across the Service. For requests about your own account data, contact hello@planwire.io; your rights are set out in the Privacy Policy.

6. International transfers

Personal data is processed in the United Kingdom and the European Economic Area. Where a sub-processor transfers data outside the UK or EEA, that transfer is made under the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision, as applicable.

7. Enterprise Data Processing Agreement

For customers who require a signed Article 28 DPA — commonly because their own procurement or regulatory obligations demand one regardless of the roles analysis above — we offer a full DPA as part of an Enterprise agreement. It is negotiated and countersigned rather than applied automatically, and covers processing instructions and duration, confidentiality of personnel, defined security measures, sub-processor notice and objection rights, a contractual personal data breach notification window, assistance with data subject requests and impact assessments, deletion and return on termination, and audit rights.

These are contractual commitments with operational consequences on both sides, which is why they sit within a negotiated agreement rather than a standing public undertaking. To request one, contact hello@planwire.io.

8. Retention

Our retention periods for account data are set out in the Privacy Policy. Your obligations for data received from the Service on termination are in section 9 of the Terms of Service: derived material is yours to keep; bulk stores of raw API responses are to be deleted within 30 days.

9. Contact

Data protection contact: hello@planwire.io
Entity: Orra Designs Ltd (SC462855), Scotland, United Kingdom

Privacy Policy Terms of Service © 2026 PlanWire