A Spanish company
PlanVortex is built and run by TALIA SOFTWORKS, S.L., tax ID B05350616, registered with the Commercial Registry of Ciudad Real, Spain. The full registration details are in the terms of use.
Where the data lives, who else touches it, what we keep from the accounts you connect and what happens when something goes down. No forms and no emailing us to ask: it is all on this page.
Last updated: 4 September 2026.
PlanVortex is built and run by TALIA SOFTWORKS, S.L., tax ID B05350616, registered with the Commercial Registry of Ciudad Real, Spain. The full registration details are in the terms of use.
Prices are in euros and the invoice is issued by a Spanish company with Spanish VAT. If you have a valid EU VAT number, the reverse charge applies. No currency conversion and no conversion fee.
The database, the identity system and the files you upload are in the European Union. No provider outside the European Economic Area stores your account's content.
We act as the processor for the data you handle with PlanVortex. The data processing agreement can be downloaded right here, already signed on our side. Our supervisory authority is the Spanish Data Protection Agency (AEPD).
PlanVortex does not run on anyone else's cloud: it runs on our own servers, which we operate ourselves. Here is what there is and where each piece sits.
The only transfer outside the European Economic Area that exists today is AI generation, and only if you use it: what you ask for travels to the model provider. It is spelled out in the table below, and on the free plan it never happens at all, because the free plan includes no AI credits.
A sub-processor is a company that processes data on our behalf so the service can work. There are five, not one more. There is no product analytics tool, no support tool, no session recording and no lead capture: we do not use them.
| Provider | What for | Where it processes | What it sees |
|---|---|---|---|
| IONOS | Server hosting | Spain (EU) | Hosts the machine everything runs on. Like any hosting provider it has physical access to the hardware; it does not access the data. |
| Cloudflare | Files and network protection | EU (R2 under European jurisdiction) | The files you upload — images and videos — and the web traffic that passes through its protection. |
| Stripe | Payments and billing | Ireland (EU) | Your billing details and payment method. Card details are collected by Stripe directly: they never pass through our servers and we do not store them. |
| OpenRouter | AI generation (optional) | United States | Only if you use AI: the instructions you write and the text or image that comes back. We do not send your connected accounts, your contacts or your statistics. |
| Analytics and anti-spam | Ireland (EU), with transfers to the US | Analytics only if you accept it, and in the dashboard with identifiers stripped from the address. reCAPTCHA protects the contact form. |
When you publish on Instagram or reply to a Google Business review, you are the one sending that content to that network, using the account you connected. The network handles it under its own policy and as an independent controller, not on our behalf. We are the road, not the destination.
We commit to giving at least 30 days' notice, by email to the account administrators, before adding or replacing a sub-processor, so that you can object. It is the same obligation we take on in the data processing agreement.
The access permission to your social accounts is the most sensitive thing you trust us with, so it is worth being precise about what we do with it.
The full detail — encryption in transit, access control, retention periods and how to exercise your rights — is in the privacy policy. Read the privacy policy
That works out to a maximum of about 43 minutes of downtime a month. It is a service target, not an agreement with penalties: we would rather publish the number we are aiming at than publish none, which is what almost everyone in this sector does.
If your procurement needs a signed service level agreement, with penalties and committed response times, write to us and we will talk it through. It is not in the small print because we would rather not promise it automatically to everyone.
The Article 28 GDPR agreement, with the list of sub-processors, the security measures and the processing instructions. It downloads with no form, without leaving your email and without waiting for anyone to reply.
Read and download the agreementIf your procurement process asks for a document, a security questionnaire or a clause that is not here, ask for it and you will get it. The person who answers is the one who writes the code.
Get in touch