Legal

Privacy policy

What data we process, what for and for how long.

Last updated: 1 September 2026.

1.1 Confirm that you have read and agree to PlanVortex's privacy policy.

This privacy policy sets out how PlanVortex uses and protects any information you give PlanVortex when you use our website or app.

PlanVortex is committed to ensuring that your privacy is protected. If we ask you to provide certain information by which you can be identified when using this website, you can be sure that it will only be used in accordance with this statement of

privacy. PlanVortex may change this policy from time to time by updating this page. You should check this page from time to time to ensure you are happy with any changes. This policy is effective as of 01/ 01/2021.

We may collect the following information:

1. name and job title

2. contact information, including email address

3. demographic information such as zip code, preferences, and interests

4. other information relevant to customer surveys and/or offers

What we do with the information we collect

We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:

1. Internal record keeping.

2. We may use the information to improve our products and services.

3. To email you when the service itself calls for it: account notices, important changes, billing and invitations. If you also agreed to receive product news, you can stop receiving it whenever you want, from the email itself or by writing to us.

4. To ask you occasionally about your experience so we can improve the service, always by email. You are free not to reply, or to ask us not to do it again.

5. To remember your preferences (language, light or dark theme and active organisation) so that the website and the dashboard behave as you left them. We do not build commercial profiles and we do not change what you see based on your interests.

6. We do not disclose your information to third parties for commercial or promotional purposes. It is only handled by providers working on our behalf and under contract (hosting, file storage, payment gateway and analytics), plus the social networks you connect yourself, which only receive what you publish through them.

7. We will never sell your information.

Cookies and analytics

We use cookies and local storage in two places: this website (planvortex.com) and the management dashboard (app.planvortex.com). There are two groups, and only the second one is asked about.

Necessary

These make the service work and cannot be turned off: keeping you signed in, supporting borrowed sessions when the dashboard is opened inside an integrator's application, and remembering your preferences (language, light or dark theme and active organisation), together with a cache in your browser that avoids asking the server again for what has already been downloaded. They are not used to track you outside our service and are not shared with anyone.

Analytics (Google Analytics 4)

These are only switched on if you accept them. Until you do, Google Analytics starts in denied mode and no analytics cookie is written; Google may only receive an anonymous signal that the page has loaded, without identifying you or recognising you between visits. We never use advertising or personalisation cookies: those categories are always denied, whatever you accept.

  • Cookies set once you accept: "_ga" and "_ga_" followed by an identifier, lasting up to two years. They are used to tell visits and sessions apart.
  • What is collected: which pages and screens are visited, from what kind of device, the approximate country and how you got here. This is aggregated data: it is not sold, and it is not used to make decisions about your account.
  • In the dashboard the address is also cleaned before being sent: client, organisation or publication identifiers are replaced with a generic marker and the address parameters are never sent. That way no data from your account ends up in the measurement.
  • Provider: Google Ireland Limited, which processes this data on our behalf and may transfer it outside the European Economic Area under the transfer framework in force.

How to change or withdraw your decision

At any time, from the "Cookies" link in the footer, both on this website and in the dashboard: reopen the notice, change the analytics setting and save. Withdrawing your consent is as easy as giving it and does not affect anything you can do in the service. You can also delete the cookies from your browser.

How we protect your data

These are the technical and organisational measures we use to protect the information you entrust to us, and in particular the access permissions for the accounts you connect, which is the most sensitive data we hold:

  • All traffic is encrypted with HTTPS/TLS: the website, the dashboard and the API. There is no unencrypted way of talking to us.
  • The access permissions for your social networks (the OAuth tokens) never leave the server. The API strips them from every response before sending it, so they cannot be read from the dashboard, from an integration or from an activity log, not even while you are signed in.
  • The secrets you deliberately hand us (your own API keys, the credentials of your Discord application) are stored encrypted with AES-256-GCM and are write-only: they can be replaced, but never read back.
  • Identity is managed by Keycloak: we do not store passwords. Every request to the API arrives with a signed token (RS256) that is verified on the server and then checked against the specific permission that operation requires within that organisation. Nobody sees the data of an organisation they have not been invited to.
  • The databases and the cache are not published on the internet: only the service itself talks to them, and staff access to production systems is limited to what is strictly needed to operate them.
  • The files you upload are neither public nor guessable by address: they are served through signed links that expire.
  • We ask each social network for the minimum permission the feature you are about to use needs, not one more, and we revoke it as soon as you disconnect the account.

If a security breach affecting your personal data were to happen anyway, we would tell you and notify the supervisory authority within the deadlines set by the GDPR.

How long we keep your data, and how it is deleted

We keep your data for as long as your account is active, because it is what makes the service work. Beyond that, any deletion you ask for really happens: we do not archive accounts "just in case".

  • When you disconnect a social network account, we revoke the permission against that network there and then (it stops being valid instantly, even if you do nothing else) and we delete its credentials from our database.
  • When you delete an organisation, its connected accounts, publications, statistics, conversations, comments, integrations and files are all removed.
  • When you close your PlanVortex account, an automated process that runs daily deletes it in full: client, organisations, connected accounts, publications, statistics, conversations, comments, files, integrations and subscription. The deletion is permanent and takes at most 24 hours.
  • On free plans, files you upload and never use in a publication are deleted automatically after one month.
  • What we bring back from the social networks (publications, counters, comments and reviews) is a working copy that is continuously refreshed against the network itself and disappears with the account it belongs to. We do not build a parallel archive that outlives the disconnection.
  • Invoices and the tax data attached to them are kept for the periods required by accounting and tax law, even if you have closed your account. That is the only exception to the above.

You can ask us at any time for access to your data, its rectification or erasure, the restriction of or objection to its processing, and its portability, by writing to contact@planvortex.com. We will reply within one month at the latest. If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD).

Google and YouTube data

If you connect a YouTube channel, PlanVortex uses YouTube API Services to do from the dashboard exactly what you would do from YouTube: upload videos and Shorts, delete them, read the channel's and each video's counters, and read, reply to, moderate or delete comments.

What we store: the channel's identifier, name and picture; the access permission you grant us; the identifiers and basic data of the videos you publish or manage with PlanVortex; their counters; and the comments that show up in your inbox. We do not download or store video content, and we do not access any part of your Google account other than YouTube.

What for: solely to provide you with the features you asked for. We do not use Google data for advertising, we do not sell it, we do not pass it to third parties for commercial purposes, and we do not use it to train artificial intelligence models. It is only processed, on our behalf and under contract, by the providers that operate our infrastructure.

How long it lasts: data obtained from the YouTube API is refreshed against YouTube continuously (and in any case within 30 days) or deleted, as required by the YouTube API Services Developer Policies.

How it is deleted: when you disconnect the channel from the dashboard we revoke the permission against Google immediately and delete the credentials; the rest of the channel's data goes with the organisation or the account, as described in the section above. You can also withdraw our access yourself, without going through us, from your Google account permissions, and you can request deletion by writing to contact@planvortex.com.

PlanVortex's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Documents and settings that apply to you if you connect a YouTube channel:

GOVERNING LAW

2.1 You and we agree that your use of the Application and this EULA shall be governed by and construed in accordance with the laws of Spain and that any disputes regarding this EULA will be heard exclusively by the courts of Spain.

CHANGES TO THIS EULA

3.1 We may amend this EULA when we deem it appropriate or necessary for legal reasons or to reflect changes to the Application. If so, we will make the revised EULA available here.

INTELLECTUAL PROPERTY

4.1 The Application, including graphics, user interface, and other content, contains proprietary information and material that is protected by copyright and other laws, including, but not limited to, intellectual property. You agree that we own o We license all of this information and proprietary material and you may not use or exploit any of it without our permission. This does not cover User Generated Content, which is discussed below.