Legal

Privacy policy

What personal information we hold, why we hold it, and the rights you have over it. Most of what Plansyx processes describes the physical world rather than people; this policy covers the cases where that is not true.

Effective
15 September 2026
Version
1.0
Applies to
plansyx.com, the Plansyx dashboard and API

Who this covers

This policy explains how Plansyx, Inc. (“Plansyx”, “we”, “us”) handles personal information across plansyx.com, the Plansyx dashboard and API, and our sales and support correspondence. Together we call these the Services.

Plansyx sells risk intelligence to organisations rather than to consumers. Most of what we process is not personal information at all: satellite observation, weather reanalysis, soil moisture, fuel condition and hydrological model output describe the physical world, not people. This policy concerns the narrower set of cases where personal information is involved.

Two roles, two sets of rules

We handle personal information in two distinct capacities, and your rights differ depending on which applies.

CapacityWhen it appliesWho to contact
Controller
(business, under CCPA)
Information about visitors to plansyx.com, people who request a demo, and the named users at our customers who hold platform accounts. We decide why and how this is processed. Us, using the details in Contact.
Processor
(service provider, under CCPA)
Data a customer loads into the platform, such as a policy portfolio, an asset register or a corridor inventory. The customer decides why and how; we act on their documented instructions. The customer who holds the data. We will refer you to them.

Where we act as a processor, our contract with the customer governs, including the data processing addendum we enter into with customers, a copy of which is available on request. If that addendum conflicts with this policy, the addendum wins for that customer’s data.

What we collect

Information you give us

  • Contact and role details submitted through a demo request, pilot enquiry or support message: name, work email, employer, job title, and whatever you choose to write to us.
  • Account details for platform users: name, work email, organisation, role and permissions, and authentication credentials.
  • Billing and procurement contacts, purchase orders and payment records, for customers under contract.

Information we observe

  • Server logs: IP address, user agent, timestamps, pages and API endpoints requested, and response codes. We keep these for security, abuse prevention and debugging.
  • Platform telemetry: which layers, regions, date ranges and exports an account uses. This tells us what to improve, and it supports the audit trail described in Intended use.
  • Cookie and analytics data, covered in Cookies.

Information customers load into the platform

Customers upload portfolios, asset registers, claims histories and site locations so we can score them. Some of this can relate to identifiable people. We process it as a processor only, for the purpose of delivering the Services, and we do not use it to train models for other customers unless that customer has separately agreed in writing.

Public and licensed environmental data

We ingest public datasets such as NASA MODIS, VIIRS, SMAP and ECOSTRESS observation, NOAA and ECMWF forecasts, USDA Cropland Data Layer and SSURGO soils, and USDM drought indices. These describe terrain, vegetation, weather and hydrology. We do not treat them as personal information, subject to the caveat in the next section.

Where geospatial data meets personal information

Worth stating plainly

A location can be personal information. A parcel boundary, a building footprint or a ranch identifier can single out a household or a business owner, even when the underlying satellite pixel does not name anybody.

We therefore apply the following rules to location data:

  • Gridded environmental layers are published and used at their native resolution, roughly 4 km for drought indices and 30 to 100 m for fuel layers in priority areas. At those scales a cell describes terrain, not a person.
  • Where a customer supplies parcel level or address level locations, we treat that upload as potentially personal information and apply the processor terms above.
  • We do not combine customer supplied locations across customers, and we do not build a cross customer register of properties, owners or claimants.
  • Aggregate statistics we publish or reuse are constructed so that individual properties cannot be re-identified from them.

For individuals who buy PRF optimisation analytics or gap cover design directly from us, we act as controller and this policy applies in full to the farm or ranch details you provide.

How we use information

  • To deliver the Services. Authenticating users, running scoring jobs, generating alerts, exports and Trigger Certificates.
  • To support you. Answering enquiries, running pilots, investigating defects and responding to a reported model problem.
  • To secure the platform. Detecting abuse, rate limiting, investigating incidents and keeping the audit trail our regulated customers rely on.
  • To improve our models and products. Using our own telemetry and public environmental data, plus customer data only where that customer has agreed.
  • To meet legal and contractual obligations. Accounting, tax, export controls, and responding to lawful requests.
  • To market to businesses. Sending relevant material to work contacts, with an unsubscribe link in every message.

We do not sell personal information, and we do not share it for cross context behavioural advertising, as those terms are defined under California law. We do not use customer data to make automated decisions about individuals.

Legal bases

Where the UK GDPR or EU GDPR applies, we rely on the following bases:

  • Contract. Providing the Services to a customer and its named users.
  • Legitimate interests. Securing the platform, improving our products, and business to business marketing. We balance these against your interests and you may object at any time.
  • Legal obligation. Tax, accounting, sanctions and export compliance.
  • Consent. Non-essential cookies and analytics, and any optional communications. You can withdraw consent at any time.

Who we share it with

We share personal information with:

  • Subprocessors that host, secure and operate the platform, whose current list is available on request. Each is bound by written terms no less protective than this policy.
  • Professional advisers, including auditors and legal counsel, under confidentiality.
  • Authorities, where we are legally required to. We will tell the affected customer unless we are prohibited from doing so.
  • An acquirer, if Plansyx is party to a merger, financing or sale of assets. The information stays subject to this policy until it is replaced by a notice at least as protective.

Where Plansyx supports a parametric insurance programme, the carrier or reinsurer is a separate controller of the policy and claims data it holds. We are not the insurer. See Terms, section 4.

International transfers

We operate in the United States, and our infrastructure is hosted there. If you are in the United Kingdom, the European Economic Area or Switzerland, transferring your information to us means sending it outside your home jurisdiction.

Where we do that, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and a transfer risk assessment we review periodically. A copy of the clauses is available on request.

Security

We encrypt data in transit and at rest, enforce least privilege access with multi factor authentication for staff, log administrative actions, separate production from development environments, and version datasets and model artefacts so that an output can be reconstructed later.

We do not yet hold a third party security certification such as SOC 2 or ISO 27001. If that changes we will say so here, and customers under contract may request our current security documentation at any time. If we become aware of a breach affecting personal information, we will notify affected customers without undue delay and within the timeframes their contracts and applicable law require.

No system is perfectly secure. Please report a suspected vulnerability to contact@plansyx.com rather than disclosing it publicly, and we will work with you in good faith.

How long we keep it

CategoryRetention
Demo and enquiry contacts24 months after last contact, unless you become a customer
Platform account recordsFor the life of the account, then 12 months
Customer uploaded dataPer the customer’s contract; deleted or returned on termination
Server and access logs12 months
Trigger Certificates and the datasets behind themRetained for the archival period the relevant contract requires, because independent verification depends on it
Billing and tax recordsAs required by law, typically seven years

Your rights

Subject to your jurisdiction and to verification of your identity, you may ask us to give you a copy of your personal information, correct it, delete it, restrict or object to how we use it, provide it in a portable format, or withdraw a consent you previously gave. You may also ask a human to review any decision you believe was made about you automatically.

Write to us using the details in Contact. We answer within the period the applicable law sets, normally one month. Using these rights costs nothing and we will not treat you differently for exercising them.

If we hold the data as a processor for one of our customers, we will pass your request to that customer and support their response rather than acting on it ourselves.

You may also complain to your data protection authority. In the UK that is the Information Commissioner’s Office; in the EEA it is your national supervisory authority.

California privacy rights

If you are a California resident, the CCPA as amended by the CPRA gives you the rights to know, delete, correct, and to opt out of sale or sharing, plus the right to limit use of sensitive personal information.

We do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding twelve months. We do not knowingly collect or sell the personal information of anyone under sixteen.

The categories we collect, why, and who receives them are set out in What we collect and Who we share it with. You may use an authorised agent to make a request, and we will verify their authority.

Cookies and analytics

plansyx.com is a static site. It sets no advertising cookies and runs no third party tracking pixels. The fonts on this page are served by Google Fonts, which receives your IP address in order to deliver them.

The site stores nothing in your browser beyond what your browser does automatically. If we later add product analytics or a session cookie for the signed in dashboard, we will describe it here and, where consent is required, ask for it first. We use no analytics provider today.

Children

The Services are built for businesses and public bodies. They are not directed at children, and we do not knowingly collect personal information from anyone under sixteen. If you believe a child has given us information, contact us and we will delete it.

Changes to this policy

We will update this page when our practices change. The effective date at the top always reflects the current version, and we keep prior versions on request. If a change materially affects how we use personal information, we will give notice by email to account holders or a notice on the site before it takes effect.

Contact

Privacy questions, rights requests and complaints:

  • Email: contact@plansyx.com. Put “Privacy” in the subject line and we will route it.
  • Data protection contact: we have not appointed a Data Protection Officer. Privacy questions are handled by the Plansyx team at the address above.
  • UK and EU representative under Article 27: not appointed. If we begin offering the Services directly to individuals in the United Kingdom or the EEA, we will appoint one and name them here.

We answer every kind of request from the same address, so there is one place for you to write and one place for us to track it.