Privacy Policy
Planckchron Inc, a Delaware C-Corporation, is committed to data protection and privacy compliance. All technologies described are in research stages.
Information We Collect
Transparency in data collection practices
- Personal information you provide when contacting us, creating an account, or using our services (name, email, company details)
- Technical data including IP addresses, browser types, device information, operating system, and unique device identifiers
- Usage data about how you interact with our website and services, including pages visited, features used, and time spent
- Cookies and similar tracking technologies for session management, analytics, and personalization
- Location data (approximate) based on IP address for service optimization and fraud prevention
- Communications data when you contact our support team or interact with our services
Detailed Data Processing Information
Account Information
Service provision, account management, communication
Contract performance, legitimate interest
Active account duration + 90 days after deletion request
Technical Data
Security, fraud prevention, analytics, service optimization
Legitimate interest
24 months from collection
Usage Data
Service improvement, user experience optimization, analytics
Legitimate interest
24 months from collection
Communications
Customer service, support, issue resolution
Legitimate interest, contract performance
3 years from last communication
Research Data
Scientific research, innovation, service development
Consent, legitimate interest
7 years (academic research standards)
Cookie Data
Session management, personalization, analytics
Consent (non-essential), legitimate interest (essential)
13 months maximum (analytics), session duration (essential)
Location Data
Service localization, compliance, fraud prevention
Legitimate interest
24 months from collection
Payment Information
Payment processing, fraud prevention, accounting
Contract performance, legal obligation
7 years (tax and accounting requirements)
Legal Basis Definitions
Sensitive Personal Information
We do not intentionally collect sensitive personal information such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation.
How We Use Your Information
Legal bases and purposes for data processing
Service Provision
Deliver, maintain, and improve our services and website functionality
Customer Support
Respond to inquiries, provide technical support, and resolve issues
Analytics & Optimization
Analyze usage patterns, optimize user experience, and improve performance
Security & Fraud Prevention
Protect against unauthorized access, security threats, and fraudulent activities
Communications
Send service updates, security alerts, and important notifications
Marketing (with consent)
Send promotional materials and personalized recommendations
Information Sharing
When and how we share your data
We do not sell your personal information. We may share data in the following circumstances:
- With service providers who assist in operating our business under strict contractual obligations
- With business partners for joint offerings (only with your consent)
- In response to valid legal requests from public authorities
- To protect our rights, privacy, safety, or property, or that of our users
- In connection with a merger, acquisition, or sale of assets
Third-Party Services
Our trusted service providers
Third-Party Service Providers
We work with the following trusted partners to deliver our services
Vercel Inc.
Website hosting and content delivery
United States (SOC 2 Type II certified)
Standard Contractual Clauses (SCCs), GDPR compliant
Sentry
Error tracking and performance monitoring
United States (SOC 2 Type II certified)
Data Processing Agreement, EU-US Data Privacy Framework
Supabase Inc.
Database and authentication services
United States (SOC 2 Type II certified, ISO 27001)
Standard Contractual Clauses, encryption at rest and in transit
Google Analytics
Website analytics and usage statistics
United States (Privacy Shield replacement - Adequacy Decision)
Google Cloud Data Processing Amendment, IP anonymization
Cloudflare Inc.
CDN, DDoS protection, and security services
Global (primary: United States)
Standard Contractual Clauses, EU Data Localization options
Data Transfer Mechanisms
Standard Contractual Clauses (SCCs): EU-approved contracts that ensure adequate data protection when transferring data outside the EEA.
Adequacy Decisions: The European Commission has determined that certain countries provide adequate data protection (e.g., UK, Switzerland).
Data Processing Agreements: Contracts with all subprocessors ensuring GDPR-compliant data handling.
Last updated: January 20, 2025 β’ We will notify you of material changes to our subprocessor list
Data Security
How we protect your information
Encryption
AES-256 encryption at rest and TLS 1.3 in transit
Access Control
Role-based access with multi-factor authentication
Monitoring
24/7 security monitoring and threat detection
Audits
Annual third-party security audits and penetration testing
Compliance
SOC 2 Type II, ISO 27001, HIPAA certified
Data Centers
Tier 4 facilities with redundant power and cooling
Data Breach Procedures
Our incident response protocol
In the unlikely event of a data breach affecting your personal information:
- 1We will notify affected users within 72 hours of discovery (as required by GDPR)
- 2We will notify relevant supervisory authorities within 72 hours
- 3We will provide clear information about what data was affected
- 4We will outline steps we're taking to mitigate the impact
- 5We will provide guidance on steps you can take to protect yourself
Your Privacy Rights
Rights you have regarding your data
Right to Access
Request a copy of your personal data
Right to Rectification
Correct inaccurate or incomplete data
Right to Erasure
Request deletion of your data
Right to Portability
Receive your data in a portable format
Right to Restriction
Limit how we process your data
Right to Objection
Object to certain processing activities
Children's Privacy
Protecting minors online
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately and we will take steps to delete such information.
Compliance & Standards
Our regulatory compliance
GDPR
European Union
CCPA/CPRA
California, USA
PIPEDA
Canada
UK GDPR
United Kingdom
LGPD
Brazil
APPI
Japan
State-Specific Rights
Additional rights by jurisdiction
California
CCPA/CPRA rights including opt-out of sale, sensitive data limits
Virginia
VCDPA rights including access, deletion, and opt-out
Colorado
CPA rights including universal opt-out mechanism
Connecticut
CTDPA rights including data portability
Utah
UCPA rights including deletion and opt-out
Policy Changes
How we update this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. For significant changes, we may also send you an email notification.
Contact Information
For questions or concerns, please contact the appropriate department:
Privacy Team
General privacy inquiries
Data Protection Officer
GDPR and data protection matters
Security Team
Security concerns and breach reports
Corporate Headquarters
Planckchron Inc
11601 Wilshire Boulevard, Suite 500
Los Angeles, CA 90025
United States
Registered Office
Corporation Trust Company
1209 Orange Street
Wilmington, DE 19801
