Make My Plan Ltd, trading as PlanProve
Version 1.1 — Last updated: 13 September 2026
This policy sets out how long PlanProve retains different categories of data, what happens to that data when an account is closed or a subscription ends, and how a professional or practice can export their data. It applies to all data processed through the PlanProve platform, whether entered directly by a professional, uploaded as a document, or generated by the platform (such as AI-extracted deadlines or site constraint data).
This policy is written to reflect the storage limitation principle under UK GDPR Article 5(1)(e): personal data must be kept for no longer than is necessary for the purpose it was collected for. Where PlanProve acts as a data processor on behalf of a professional or practice (the data controller), retention of client and third-party data within case files follows the controller's instructions, not a period set unilaterally by PlanProve.
For data relating to a professional's own account (login details, billing, usage of the platform), PlanProve (Make My Plan Ltd) is the data controller.
For client and case data entered by a professional (client details, project correspondence, objector or neighbour personal data included in case files, documents uploaded to a site), the professional or practice is the data controller and PlanProve acts as data processor. Retention decisions for this category rest with the controller; PlanProve's role is to retain, delete, or export this data on their instruction, consistent with the periods set out below unless the controller specifies otherwise in a signed Data Processing Agreement.
Specific periods below, not indefinite retention.
| Category | Retention period | Reason / basis |
|---|---|---|
| Active account data (profile, sites, projects, documents, case notes) | For the lifetime of the account, while it remains active | Necessary to provide the service (UK GDPR Art. 6(1)(b), contract performance) |
| Third-party personal data within case files (objector/neighbour correspondence, consultee contacts) | Retained for as long as the related project record is retained by the professional's account | Processed by PlanProve as processor on the practice's instructions; retention follows the controller's (the practice's) own retention decision, not PlanProve's |
| Account data after a deletion request | 30 days from the date deletion is requested, then deleted | Balances a short recovery window against storage limitation (Art. 5(1)(e)) |
| Financial records (invoices, payment records via Stripe) | 6 years from the end of the relevant accounting period | HMRC statutory minimum for business records |
| Usage and analytics logs (PostHog) | 12 months, anonymised thereafter | Only useful for a limited window; indefinite retention isn't justified by purpose |
| Backups — database | Fully overwritten within 7 days of deletion | Supabase's standard backup retention window; deleted records may persist in a backup for up to this long after removal from the live system |
| Backups — documents and file storage | Fully overwritten within 30 days of deletion | Uploaded files are backed up separately to Cloudflare R2 (EU), because Supabase's database backups do not include files held in object storage |
| Search and system logs | 90 days, then anonymised | Matches existing PlanProve search log retention already in place |
If a professional or practice chooses not to continue after a trial or free period ends, their account and data are not deleted automatically. Data remains in place unless and until a deletion request is made, as described in 4.2.
A Client can request deletion from their account settings; the request is recorded and the account is deleted automatically after a 30-day grace period.
A professional can also request deletion from their account settings, and the request is recorded immediately — but completion of a professional or practice deletion is currently handled manually rather than automatically. We will complete it within 30 days of the request, consistent with UK GDPR erasure expectations, and you can withdraw the request at any time before then. You can also request deletion by email at info@planprove.com.
Completion is manual because a professional's account may be linked to a practice, to invoices retained as financial records, and to case files for which the professional is the data controller — each of which has to be settled before the account itself can be removed. Records listed in the retention schedule above — in particular invoices and payment records, retained for 6 years from the end of the relevant accounting period — are kept for their stated periods and are not removed by an account deletion.
Database backups are managed by Supabase under their standard platform terms, with a 7-day rolling window; deleted database records may persist in one for up to 7 days after removal from the live system.
Uploaded documents and files are backed up separately and daily to Cloudflare R2 (EU jurisdiction), independent of the primary database infrastructure. A file removed from the live system is retained in that backup for up to 30 days, after which it is deleted automatically.
Backups are encrypted at rest, are not shared with any party outside the sub-processors listed in Section 6, and are used only for disaster recovery.
You can export your data at any time, whether the account is active or scheduled for deletion, using the Download My Data button in your account settings. The export is generated immediately; there is no need to request one.
export.json (all records in structured JSON) and a documents/ folder holding the original uploaded files._omitted-files.txt inside the archive, and can be downloaded individually from the project it belongs to or requested at info@planprove.com. An export is never silently truncated.Where data is held by a sub-processor rather than directly within PlanProve's own database, that sub-processor's own retention behaviour also applies. Current sub-processors and their role:
Supabase, Cloudflare and PostHog process data within the European Union, which the UK recognises as adequate, so no Article 46 transfer safeguard is required for those transfers.
Anthropic, Stripe, Resend and Vercel are based in or process data via the USA. Each incorporates the UK Addendum to the EU Standard Contractual Clauses into their standard commercial terms, confirmed directly from each vendor's published Data Processing Addendum, so this applies automatically as a customer on their normal terms. Stripe, Resend and Vercel are additionally certified under the UK Extension to the EU–US Data Privacy Framework; Anthropic relies on the UK Addendum alone.
This policy should be reviewed whenever the underlying technical implementation changes (for example, if account deletion behaviour is rebuilt, or if AI processing is moved to an EU-pinned provider), and at minimum annually.