Data Processing Addendum
Last updated 3 September 2026
Roles
For the planning records themselves PlanningLeads is an independent controller: the data comes from public statutory registers, is held at organisation level, and every personal identifier is gated or purged as described in our privacy notice. For the account data you give us (names, emails, saved searches, API keys, usage) PlanningLeads is the controller of that account. Where you put your own contact lists or notes into the CRM fields, PlanningLeads is the processor and you are the controller; this addendum governs that processing.
What we process for you
Account identifiers, saved searches and bookmarks, CRM notes typed against a lead, webhook endpoints, API keys (hashed), and a request log holding the route template, status, timing and key id, never a path, query string or body.
Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting (application, database, backups) | Germany (EU) |
| Resend | Transactional email (magic links, alerts, digests) | EU/US, SCCs |
| Stripe | Payments (we never see card data) | EU/US, SCCs |
| Anthropic | Classification of public planning descriptions; no customer account data is sent | US, SCCs |
| Google (Maps Platform) | Geocoding and imagery of public site addresses | EU/US, SCCs |
| GitHub | Source control and deployment automation; no customer data | US |
We give 30 days' notice of a new sub-processor by email to the account owner.
Security measures
TLS on every connection, HSTS and a strict Content-Security-Policy; API keys hashed with SHA-256 and shown once; HMAC-signed webhooks; per-key rate limits and export caps; session cookies with CSRF tokens; EU hosting with nightly encrypted backups and a monthly restore drill; key-only SSH with intrusion banning; operating system and dependency patching on a monthly cadence. More at Trust & Security.
Retention and deletion
Account data is deleted within 30 days of account closure. Request logs are kept for 90 days. Backups roll off after 14 days. Individuals named in public planning records can ask for suppression at privacy@planningleads.ie and the record is hidden from every surface within 72 hours.
Breach notification
We notify affected account owners without undue delay, and within 72 hours of becoming aware, with what happened, what data was involved and what we have done.
Audit and assistance
On request we provide this addendum, the sub-processor list, the security summary and our incident history, and we assist with data-subject requests that concern data we process on your behalf.
Data location and transfers
Production data is stored in Germany. Transfers to the sub-processors above rely on the EU Standard Contractual Clauses in their terms.