Privacy Notice
Last updated: 2026
1. Who we are
Pleanóir is operated by Caoimhe O'Driscoll, a sole trader based in Ireland, trading as Pleanóir. For the purposes of the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018, Caoimhe O'Driscoll is the data controller for personal data processed through Pleanóir. You can contact us at notify@pleanoir.ie.
2. Personal data we collect
- Account data: name, email address, hashed password (or social sign-in identifier), school/role information you provide.
- Content: the planning prompts, class details and documents you create or upload.
- Usage and device data: log data, IP address, browser and device identifiers, approximate location derived from IP, sign-in events and device fingerprints used for security.
- Support communications: messages you send us by email.
- Billing data: handled by Paddle (see "Sharing" below); we receive a limited record of your subscription status and customer ID.
3. Purposes and legal bases
- Providing the service, generating documents, managing your account — performance of our contract with you.
- Security, fraud prevention, device-limit enforcement, new-device sign-in notifications — legitimate interests in keeping the service secure.
- Customer support and service emails — performance of our contract / legitimate interests.
- Improving the service and fixing bugs — legitimate interests.
- Complying with legal, tax and accounting obligations — legal obligation.
- Optional marketing emails — your consent, which you can withdraw at any time.
4. Pupil Data and GDPR
You choose what information to enter into Pleanóir. Some documents — such as Support Plans and similar pupil-focused plans — may reference health, disability, or additional needs information. GDPR classifies this as "special category data." You are responsible for ensuring that you have an appropriate legal basis and school policy compliance before entering such information.
5. Sharing your data
We share personal data only with the following categories of recipient:
- Paddle.com Market Ltd — our Merchant of Record, which processes payments, subscriptions, tax and invoicing on our behalf.
- Hosting and infrastructure providers — Cloudflare and our managed database/auth provider (Supabase) which host the application and store account data.
- Email delivery — Resend, used to send transactional emails such as sign-in notifications and reminders from
notify@pleanoir.ie. - AI processing — large language model providers accessed via the Lovable AI gateway, used to generate planning documents from your prompts.
- Professional advisers — accountants and legal advisers where necessary.
- Authorities — where we are legally required to disclose information.
We do not sell your personal data.
6. International transfers
Some of our service providers are based outside the EEA (for example in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.
7. Retention
Account data and generated documents are retained for the duration of an active account, and for 12 months after account closure or cancellation. After that period, data is permanently deleted, unless you request a shorter deletion period sooner by emailing notify@pleanoir.ie. We may retain limited billing and tax records for legally required periods even after account deletion.
8. Your rights
Under GDPR you have the right to:
- Access a copy of your personal data.
- Have inaccurate data corrected.
- Have your data erased ("right to be forgotten").
- Restrict or object to certain processing.
- Data portability.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with the Irish Data Protection Commission (dataprotection.ie).
To exercise any of these rights, email notify@pleanoir.ie. We aim to respond within one month.
9. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS), encryption at rest, access controls, password hashing, device-limit and new-device notification controls, and row-level security on our database.
10. Cookies
We use only essential cookies and local storage required to keep you signed in and to operate the service. We do not use advertising cookies. The Paddle checkout may set its own cookies when you make a purchase; see Paddle's privacy notice for details.
11. Changes
We may update this notice from time to time. Material changes will be communicated through the service.