Make My Plan Ltd, trading as PlanProve
Version 1.0 — Last updated: 4 August 2026
This policy sets out how long PlanProve retains different categories of data, what happens to that data when an account is closed or a subscription ends, and how a professional or practice can export their data. It applies to all data processed through the PlanProve platform, whether entered directly by a professional, uploaded as a document, or generated by the platform (such as AI-extracted deadlines or site constraint data).
This policy is written to reflect the storage limitation principle under UK GDPR Article 5(1)(e): personal data must be kept for no longer than is necessary for the purpose it was collected for. Where PlanProve acts as a data processor on behalf of a professional or practice (the data controller), retention of client and third-party data within case files follows the controller's instructions, not a period set unilaterally by PlanProve.
For data relating to a professional's own account (login details, billing, usage of the platform), PlanProve (Make My Plan Ltd) is the data controller.
For client and case data entered by a professional (client details, project correspondence, objector or neighbour personal data included in case files, documents uploaded to a site), the professional or practice is the data controller and PlanProve acts as data processor. Retention decisions for this category rest with the controller; PlanProve's role is to retain, delete, or export this data on their instruction, consistent with the periods set out below unless the controller specifies otherwise in a signed Data Processing Agreement.
Specific periods below, not indefinite retention.
| Category | Retention period | Reason / basis |
|---|---|---|
| Active account data (profile, sites, projects, documents, case notes) | For the lifetime of the account, while it remains active | Necessary to provide the service (UK GDPR Art. 6(1)(b), contract performance) |
| Third-party personal data within case files (objector/neighbour correspondence, consultee contacts) | Retained for as long as the related project record is retained by the professional's account | Processed by PlanProve as processor on the practice's instructions; retention follows the controller's (the practice's) own retention decision, not PlanProve's |
| Account data after a deletion request | 30 days from the date deletion is requested, then deleted | Balances a short recovery window against storage limitation (Art. 5(1)(e)) |
| Financial records (invoices, payment records via Stripe) | 6 years from the end of the relevant accounting period | HMRC statutory minimum for business records |
| Usage and analytics logs (PostHog) | 12 months, anonymised thereafter | Only useful for a limited window; indefinite retention isn't justified by purpose |
| Backups | Up to 7 days | Supabase's standard backup retention window; deleted data may persist in a backup for up to this long after removal from the live system |
| Search and system logs | 90 days, then anonymised | Matches existing PlanProve search log retention already in place |
If a professional or practice chooses not to continue after a trial or free period ends, their account and data are not deleted automatically. Data remains in place unless and until a deletion request is made, as described in 4.2.
A professional can request deletion of their account. This is currently a request-based process: the request is recorded against the account, and PlanProve then carries out the deletion. Deletion is completed within 30 days of the request being made, consistent with UK GDPR erasure expectations.
Deleted data may persist in routine backups for up to 7 days after deletion from the live system, reflecting Supabase's standard backup retention window. Backups are not separately exported or shared and fall out of scope naturally at the end of this window.
A professional or practice can request an export of their data at any time, whether the account is active or scheduled for deletion.
Where data is held by a sub-processor rather than directly within PlanProve's own database, that sub-processor's own retention behaviour also applies. Current sub-processors and their role:
Anthropic, Stripe, Resend and Vercel are based in or process data via the USA. Each incorporates the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses into their standard commercial terms, confirmed directly from each vendor's published Data Processing Addendum, so this applies automatically as a customer on their normal terms.
This policy should be reviewed whenever the underlying technical implementation changes (for example, if account deletion behaviour is rebuilt, or if AI processing is moved to an EU-pinned provider), and at minimum annually. Recommend dating and versioning this document once finalised.