Who this covers
This policy explains how Plansyx, Inc. (“Plansyx”, “we”, “us”) handles personal information across plansyx.com, the Plansyx dashboard and API, and our sales and support correspondence. Together we call these the Services.
Plansyx sells risk intelligence to organisations rather than to consumers. Most of what we process is not personal information at all: satellite observation, weather reanalysis, soil moisture, fuel condition and hydrological model output describe the physical world, not people. This policy concerns the narrower set of cases where personal information is involved.
Two roles, two sets of rules
We handle personal information in two distinct capacities, and your rights differ depending on which applies.
| Capacity | When it applies | Who to contact |
|---|---|---|
| Controller (business, under CCPA) |
Information about visitors to plansyx.com, people who request a demo, and the named users at our customers who hold platform accounts. We decide why and how this is processed. | Us, using the details in Contact. |
| Processor (service provider, under CCPA) |
Data a customer loads into the platform, such as a policy portfolio, an asset register or a corridor inventory. The customer decides why and how; we act on their documented instructions. | The customer who holds the data. We will refer you to them. |
Where we act as a processor, our contract with the customer governs, including the data processing addendum we enter into with customers, a copy of which is available on request. If that addendum conflicts with this policy, the addendum wins for that customer’s data.
What we collect
Information you give us
- Contact and role details submitted through a demo request, pilot enquiry or support message: name, work email, employer, job title, and whatever you choose to write to us.
- Account details for platform users: name, work email, organisation, role and permissions, and authentication credentials.
- Billing and procurement contacts, purchase orders and payment records, for customers under contract.
Information we observe
- Server logs: IP address, user agent, timestamps, pages and API endpoints requested, and response codes. We keep these for security, abuse prevention and debugging.
- Platform telemetry: which layers, regions, date ranges and exports an account uses. This tells us what to improve, and it supports the audit trail described in Intended use.
- Cookie and analytics data, covered in Cookies.
Information customers load into the platform
Customers upload portfolios, asset registers, claims histories and site locations so we can score them. Some of this can relate to identifiable people. We process it as a processor only, for the purpose of delivering the Services, and we do not use it to train models for other customers unless that customer has separately agreed in writing.
Public and licensed environmental data
We ingest public datasets such as NASA MODIS, VIIRS, SMAP and ECOSTRESS observation, NOAA and ECMWF forecasts, USDA Cropland Data Layer and SSURGO soils, and USDM drought indices. These describe terrain, vegetation, weather and hydrology. We do not treat them as personal information, subject to the caveat in the next section.
Where geospatial data meets personal information
A location can be personal information. A parcel boundary, a building footprint or a ranch identifier can single out a household or a business owner, even when the underlying satellite pixel does not name anybody.
We therefore apply the following rules to location data:
- Gridded environmental layers are published and used at their native resolution, roughly 4 km for drought indices and 30 to 100 m for fuel layers in priority areas. At those scales a cell describes terrain, not a person.
- Where a customer supplies parcel level or address level locations, we treat that upload as potentially personal information and apply the processor terms above.
- We do not combine customer supplied locations across customers, and we do not build a cross customer register of properties, owners or claimants.
- Aggregate statistics we publish or reuse are constructed so that individual properties cannot be re-identified from them.
For individuals who buy PRF optimisation analytics or gap cover design directly from us, we act as controller and this policy applies in full to the farm or ranch details you provide.
How we use information
- To deliver the Services. Authenticating users, running scoring jobs, generating alerts, exports and Trigger Certificates.
- To support you. Answering enquiries, running pilots, investigating defects and responding to a reported model problem.
- To secure the platform. Detecting abuse, rate limiting, investigating incidents and keeping the audit trail our regulated customers rely on.
- To improve our models and products. Using our own telemetry and public environmental data, plus customer data only where that customer has agreed.
- To meet legal and contractual obligations. Accounting, tax, export controls, and responding to lawful requests.
- To market to businesses. Sending relevant material to work contacts, with an unsubscribe link in every message.
We do not sell personal information, and we do not share it for cross context behavioural advertising, as those terms are defined under California law. We do not use customer data to make automated decisions about individuals.
Legal bases
Where the UK GDPR or EU GDPR applies, we rely on the following bases:
- Contract. Providing the Services to a customer and its named users.
- Legitimate interests. Securing the platform, improving our products, and business to business marketing. We balance these against your interests and you may object at any time.
- Legal obligation. Tax, accounting, sanctions and export compliance.
- Consent. Non-essential cookies and analytics, and any optional communications. You can withdraw consent at any time.
International transfers
We operate in the United States, and our infrastructure is hosted there. If you are in the United Kingdom, the European Economic Area or Switzerland, transferring your information to us means sending it outside your home jurisdiction.
Where we do that, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and a transfer risk assessment we review periodically. A copy of the clauses is available on request.
Security
We encrypt data in transit and at rest, enforce least privilege access with multi factor authentication for staff, log administrative actions, separate production from development environments, and version datasets and model artefacts so that an output can be reconstructed later.
We do not yet hold a third party security certification such as SOC 2 or ISO 27001. If that changes we will say so here, and customers under contract may request our current security documentation at any time. If we become aware of a breach affecting personal information, we will notify affected customers without undue delay and within the timeframes their contracts and applicable law require.
No system is perfectly secure. Please report a suspected vulnerability to contact@plansyx.com rather than disclosing it publicly, and we will work with you in good faith.
How long we keep it
| Category | Retention |
|---|---|
| Demo and enquiry contacts | 24 months after last contact, unless you become a customer |
| Platform account records | For the life of the account, then 12 months |
| Customer uploaded data | Per the customer’s contract; deleted or returned on termination |
| Server and access logs | 12 months |
| Trigger Certificates and the datasets behind them | Retained for the archival period the relevant contract requires, because independent verification depends on it |
| Billing and tax records | As required by law, typically seven years |
Your rights
Subject to your jurisdiction and to verification of your identity, you may ask us to give you a copy of your personal information, correct it, delete it, restrict or object to how we use it, provide it in a portable format, or withdraw a consent you previously gave. You may also ask a human to review any decision you believe was made about you automatically.
Write to us using the details in Contact. We answer within the period the applicable law sets, normally one month. Using these rights costs nothing and we will not treat you differently for exercising them.
If we hold the data as a processor for one of our customers, we will pass your request to that customer and support their response rather than acting on it ourselves.
You may also complain to your data protection authority. In the UK that is the Information Commissioner’s Office; in the EEA it is your national supervisory authority.
California privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you the rights to know, delete, correct, and to opt out of sale or sharing, plus the right to limit use of sensitive personal information.
We do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding twelve months. We do not knowingly collect or sell the personal information of anyone under sixteen.
The categories we collect, why, and who receives them are set out in What we collect and Who we share it with. You may use an authorised agent to make a request, and we will verify their authority.
Children
The Services are built for businesses and public bodies. They are not directed at children, and we do not knowingly collect personal information from anyone under sixteen. If you believe a child has given us information, contact us and we will delete it.
Changes to this policy
We will update this page when our practices change. The effective date at the top always reflects the current version, and we keep prior versions on request. If a change materially affects how we use personal information, we will give notice by email to account holders or a notice on the site before it takes effect.
Contact
Privacy questions, rights requests and complaints:
- Email: contact@plansyx.com. Put “Privacy” in the subject line and we will route it.
- Data protection contact: we have not appointed a Data Protection Officer. Privacy questions are handled by the Plansyx team at the address above.
- UK and EU representative under Article 27: not appointed. If we begin offering the Services directly to individuals in the United Kingdom or the EEA, we will appoint one and name them here.
We answer every kind of request from the same address, so there is one place for you to write and one place for us to track it.