Trust

The answers your procurement team asks for

Where the data lives, who else touches it, what we keep from the accounts you connect and what happens when something goes down. No forms and no emailing us to ask: it is all on this page.

Last updated: 4 September 2026.

A Spanish company

PlanVortex is built and run by TALIA SOFTWORKS, S.L., tax ID B05350616, registered with the Commercial Registry of Ciudad Real, Spain. The full registration details are in the terms of use.

Invoiced in euros, with VAT

Prices are in euros and the invoice is issued by a Spanish company with Spanish VAT. If you have a valid EU VAT number, the reverse charge applies. No currency conversion and no conversion fee.

The data stays in the EU

The database, the identity system and the files you upload are in the European Union. No provider outside the European Economic Area stores your account's content.

GDPR and the Spanish DPA

We act as the processor for the data you handle with PlanVortex. The data processing agreement can be downloaded right here, already signed on our side. Our supervisory authority is the Spanish Data Protection Agency (AEPD).

Where the data lives

PlanVortex does not run on anyone else's cloud: it runs on our own servers, which we operate ourselves. Here is what there is and where each piece sits.

  • The service — the API, the dashboard and the background job scheduler — runs on dedicated servers hosted with IONOS, a European provider, in its Spanish data centre.
  • The database and the cache are ours and live on that same machine. They are not exposed to the internet: only the service itself talks to them. There is no third-party managed database anywhere.
  • Identity is handled by a Keycloak instance that is also ours and also lives there. We do not store passwords, and there is no external login provider that gets to see who signs in to your account.
  • The files you upload are stored in Cloudflare R2 under European Union jurisdiction, a storage option that guarantees objects never leave the EU. The bucket is private: it has no public or guessable address, and everything is served through signed links that expire.
  • The email we send you — account notices, billing and invitations — goes out from our own mail server. We use no bulk-sending platform, so your address never ends up on anyone's list.

The only transfer outside the European Economic Area that exists today is AI generation, and only if you use it: what you ask for travels to the model provider. It is spelled out in the table below, and on the free plan it never happens at all, because the free plan includes no AI credits.

Who else touches the data: the five sub-processors

A sub-processor is a company that processes data on our behalf so the service can work. There are five, not one more. There is no product analytics tool, no support tool, no session recording and no lead capture: we do not use them.

ProviderWhat forWhere it processesWhat it sees
IONOSServer hostingSpain (EU)Hosts the machine everything runs on. Like any hosting provider it has physical access to the hardware; it does not access the data.
CloudflareFiles and network protectionEU (R2 under European jurisdiction)The files you upload — images and videos — and the web traffic that passes through its protection.
StripePayments and billingIreland (EU)Your billing details and payment method. Card details are collected by Stripe directly: they never pass through our servers and we do not store them.
OpenRouterAI generation (optional)United StatesOnly if you use AI: the instructions you write and the text or image that comes back. We do not send your connected accounts, your contacts or your statistics.
GoogleAnalytics and anti-spamIreland (EU), with transfers to the USAnalytics only if you accept it, and in the dashboard with identifiers stripped from the address. reCAPTCHA protects the contact form.

The social networks are not our sub-processors

When you publish on Instagram or reply to a Google Business review, you are the one sending that content to that network, using the account you connected. The network handles it under its own policy and as an independent controller, not on our behalf. We are the road, not the destination.

If this list changes, you hear about it first

We commit to giving at least 30 days' notice, by email to the account administrators, before adding or replacing a sub-processor, so that you can object. It is the same obligation we take on in the data processing agreement.

What we store from the accounts you connect

The access permission to your social accounts is the most sensitive thing you trust us with, so it is worth being precise about what we do with it.

  • The access permission (the OAuth token) never leaves the server. The API strips it from every response before sending it, so it cannot be read from the dashboard, from an integration or from an activity log — not even with your own session signed in.
  • From each network we request the minimum permission the feature you are about to use needs, and not one more.
  • The secrets you hand us on purpose — your own API keys, your Discord application credentials — are stored encrypted with AES-256-GCM and are write-only: they can be replaced, but never read back.
  • What we pull from the networks — posts, counters, comments and reviews — is a working copy that is continuously refreshed against the network itself. We do not build a parallel archive that outlives disconnection.
  • When you disconnect an account we revoke the permission against that network at that very moment — it stops being valid instantly — and delete its credentials from our database.
  • When you close your account, an automated process that runs daily deletes it completely in under 24 hours. The only exception is invoices, which tax law requires us to keep.

The full detail — encryption in transit, access control, retention periods and how to exercise your rights — is in the privacy policy. Read the privacy policy

Availability commitment

99.9%monthly uptime target

That works out to a maximum of about 43 minutes of downtime a month. It is a service target, not an agreement with penalties: we would rather publish the number we are aiming at than publish none, which is what almost everyone in this sector does.

  • Planned maintenance is announced at least 48 hours in advance and carried out outside Spanish business hours. It does not count as downtime.
  • When an incident affects the service we notify the administrators of the affected accounts by email, and afterwards we publish what happened and what we did about it.
  • Scheduled posts are not lost if the service goes down: they stay pending and go out when it comes back. An outage delays a post, it does not cancel it.
  • What we cannot guarantee is the availability of the social networks themselves. If Instagram stops accepting posts, PlanVortex keeps running and keeps retrying, but the outcome is up to them.

If your procurement needs a signed service level agreement, with penalties and committed response times, write to us and we will talk it through. It is not in the small print because we would rather not promise it automatically to everyone.

Data processing agreement

The Article 28 GDPR agreement, with the list of sub-processors, the security measures and the processing instructions. It downloads with no form, without leaving your email and without waiting for anyone to reply.

Read and download the agreement

Missing something you need in order to buy?

If your procurement process asks for a document, a security questionnaire or a clause that is not here, ask for it and you will get it. The person who answers is the one who writes the code.

Get in touch