Back to Legal Hub
Privacy & Data Protection

Privacy Policy

Planckchron Inc, a Delaware C-Corporation, is committed to data protection and privacy compliance. All technologies described are in research stages.

Effective: January 20, 2025
Version: 2.0
Reading time: ~15 minutes
GDPR Aligned
Practices aligned with the EU General Data Protection Regulation
CCPA/CPRA Aligned
Practices aligned with the California Consumer Privacy Act
Privacy Portal
1

Information We Collect

Transparency in data collection practices

  • Personal information you provide when contacting us, creating an account, or using our services (name, email, company details)
  • Technical data including IP addresses, browser types, device information, operating system, and unique device identifiers
  • Usage data about how you interact with our website and services, including pages visited, features used, and time spent
  • Cookies and similar tracking technologies for session management, analytics, and personalization
  • Location data (approximate) based on IP address for service optimization and fraud prevention
  • Communications data when you contact our support team or interact with our services

Detailed Data Processing Information

Account Information

NameEmail addressCompany nameJob title
Purpose

Service provision, account management, communication

Legal Basis

Contract performance, legitimate interest

Retention Period

Active account duration + 90 days after deletion request

Technical Data

IP addressBrowser typeDevice informationOperating system
Purpose

Security, fraud prevention, analytics, service optimization

Legal Basis

Legitimate interest

Retention Period

24 months from collection

Usage Data

Pages visitedTime on siteClick patternsFeature usage
Purpose

Service improvement, user experience optimization, analytics

Legal Basis

Legitimate interest

Retention Period

24 months from collection

Communications

Support emailsChat messagesFeedback submissions
Purpose

Customer service, support, issue resolution

Legal Basis

Legitimate interest, contract performance

Retention Period

3 years from last communication

Research Data

Scientific datasetsSimulation resultsResearch submissions
Purpose

Scientific research, innovation, service development

Legal Basis

Consent, legitimate interest

Retention Period

7 years (academic research standards)

Cookie Data

Session cookiesPreference cookiesAnalytics cookies
Purpose

Session management, personalization, analytics

Legal Basis

Consent (non-essential), legitimate interest (essential)

Retention Period

13 months maximum (analytics), session duration (essential)

Location Data

CountryRegion/StateCity (approximate)Timezone
Purpose

Service localization, compliance, fraud prevention

Legal Basis

Legitimate interest

Retention Period

24 months from collection

Payment Information

Last 4 digits of cardBilling addressTransaction history
Purpose

Payment processing, fraud prevention, accounting

Legal Basis

Contract performance, legal obligation

Retention Period

7 years (tax and accounting requirements)

Legal Basis Definitions

Contract Performance: Processing necessary to fulfill our service agreement with you
Legitimate Interest: Processing necessary for our legitimate business interests
Consent: You have explicitly agreed to the processing
Legal Obligation: Required by law (e.g., tax records)

Sensitive Personal Information

We do not intentionally collect sensitive personal information such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation.

2

How We Use Your Information

Legal bases and purposes for data processing

Service Provision

Deliver, maintain, and improve our services and website functionality

Legal Basis: Contract Performance

Customer Support

Respond to inquiries, provide technical support, and resolve issues

Legal Basis: Legitimate Interest

Analytics & Optimization

Analyze usage patterns, optimize user experience, and improve performance

Legal Basis: Legitimate Interest

Security & Fraud Prevention

Protect against unauthorized access, security threats, and fraudulent activities

Legal Basis: Legal Obligation

Communications

Send service updates, security alerts, and important notifications

Legal Basis: Contract Performance

Marketing (with consent)

Send promotional materials and personalized recommendations

Legal Basis: Consent
3

Cookies & Tracking Technologies

How we use cookies and similar technologies

We use cookies and similar tracking technologies to enhance your experience, analyze usage, and personalize content. You can manage your cookie preferences at any time.

Essential

Required for basic website functionality

Duration: Session

Analytics

Help us understand visitor behavior

Duration: 2 years

Functionality

Remember your preferences

Duration: 1 year

Marketing

Deliver relevant advertisements

Duration: 90 days

View Full Cookie Policy β†’
4

Information Sharing

When and how we share your data

We do not sell your personal information. We may share data in the following circumstances:

  • With service providers who assist in operating our business under strict contractual obligations
  • With business partners for joint offerings (only with your consent)
  • In response to valid legal requests from public authorities
  • To protect our rights, privacy, safety, or property, or that of our users
  • In connection with a merger, acquisition, or sale of assets
5

Third-Party Services

Our trusted service providers

Third-Party Service Providers

We work with the following trusted partners to deliver our services

Vercel Inc.

Website hosting and content delivery

Privacy Policy
Data Shared:
Technical dataUsage dataIP addresses
Location

United States (SOC 2 Type II certified)

Data Transfer Safeguards

Standard Contractual Clauses (SCCs), GDPR compliant

Sentry

Error tracking and performance monitoring

Privacy Policy
Data Shared:
Error logsTechnical dataUser IDs (hashed)
Location

United States (SOC 2 Type II certified)

Data Transfer Safeguards

Data Processing Agreement, EU-US Data Privacy Framework

Supabase Inc.

Database and authentication services

Privacy Policy
Data Shared:
Account dataUser-generated contentAuthentication data
Location

United States (SOC 2 Type II certified, ISO 27001)

Data Transfer Safeguards

Standard Contractual Clauses, encryption at rest and in transit

Google Analytics

Website analytics and usage statistics

Privacy Policy
Data Shared:
Usage dataTechnical dataAnonymized IP addresses
Location

United States (Privacy Shield replacement - Adequacy Decision)

Data Transfer Safeguards

Google Cloud Data Processing Amendment, IP anonymization

Cloudflare Inc.

CDN, DDoS protection, and security services

Privacy Policy
Data Shared:
IP addressesRequest headersTechnical data
Location

Global (primary: United States)

Data Transfer Safeguards

Standard Contractual Clauses, EU Data Localization options

Data Transfer Mechanisms

Standard Contractual Clauses (SCCs): EU-approved contracts that ensure adequate data protection when transferring data outside the EEA.

Adequacy Decisions: The European Commission has determined that certain countries provide adequate data protection (e.g., UK, Switzerland).

Data Processing Agreements: Contracts with all subprocessors ensuring GDPR-compliant data handling.

Last updated: January 20, 2025 β€’ We will notify you of material changes to our subprocessor list

6

Data Security

How we protect your information

Encryption

AES-256 encryption at rest and TLS 1.3 in transit

Access Control

Role-based access with multi-factor authentication

Monitoring

24/7 security monitoring and threat detection

Audits

Annual third-party security audits and penetration testing

Compliance

SOC 2 Type II, ISO 27001, HIPAA certified

Data Centers

Tier 4 facilities with redundant power and cooling

7

Data Breach Procedures

Our incident response protocol

In the unlikely event of a data breach affecting your personal information:

  1. 1
    We will notify affected users within 72 hours of discovery (as required by GDPR)
  2. 2
    We will notify relevant supervisory authorities within 72 hours
  3. 3
    We will provide clear information about what data was affected
  4. 4
    We will outline steps we're taking to mitigate the impact
  5. 5
    We will provide guidance on steps you can take to protect yourself
8

Your Privacy Rights

Rights you have regarding your data

Right to Access

Request a copy of your personal data

Right to Rectification

Correct inaccurate or incomplete data

Right to Erasure

Request deletion of your data

Right to Portability

Receive your data in a portable format

Right to Restriction

Limit how we process your data

Right to Objection

Object to certain processing activities

Exercise Your Rights β†’
9

Children's Privacy

Protecting minors online

Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately and we will take steps to delete such information.

10

Compliance & Standards

Our regulatory compliance

GDPR

European Union

CCPA/CPRA

California, USA

PIPEDA

Canada

UK GDPR

United Kingdom

LGPD

Brazil

APPI

Japan

11

State-Specific Rights

Additional rights by jurisdiction

California

CCPA/CPRA rights including opt-out of sale, sensitive data limits

Virginia

VCDPA rights including access, deletion, and opt-out

Colorado

CPA rights including universal opt-out mechanism

Connecticut

CTDPA rights including data portability

Utah

UCPA rights including deletion and opt-out

12

Policy Changes

How we update this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. For significant changes, we may also send you an email notification.

Contact Information

For questions or concerns, please contact the appropriate department:

Privacy Team

General privacy inquiries

Data Protection Officer

GDPR and data protection matters

Security Team

Security concerns and breach reports

Corporate Headquarters

Planckchron Inc
11601 Wilshire Boulevard, Suite 500
Los Angeles, CA 90025
United States

Registered Office

Corporation Trust Company
1209 Orange Street
Wilmington, DE 19801