Data Export and Retention Policy

Make My Plan Ltd, trading as PlanProve

Version 1.0 — Last updated: 4 August 2026

1. Purpose and scope

This policy sets out how long PlanProve retains different categories of data, what happens to that data when an account is closed or a subscription ends, and how a professional or practice can export their data. It applies to all data processed through the PlanProve platform, whether entered directly by a professional, uploaded as a document, or generated by the platform (such as AI-extracted deadlines or site constraint data).

This policy is written to reflect the storage limitation principle under UK GDPR Article 5(1)(e): personal data must be kept for no longer than is necessary for the purpose it was collected for. Where PlanProve acts as a data processor on behalf of a professional or practice (the data controller), retention of client and third-party data within case files follows the controller's instructions, not a period set unilaterally by PlanProve.

2. Roles: controller and processor

For data relating to a professional's own account (login details, billing, usage of the platform), PlanProve (Make My Plan Ltd) is the data controller.

For client and case data entered by a professional (client details, project correspondence, objector or neighbour personal data included in case files, documents uploaded to a site), the professional or practice is the data controller and PlanProve acts as data processor. Retention decisions for this category rest with the controller; PlanProve's role is to retain, delete, or export this data on their instruction, consistent with the periods set out below unless the controller specifies otherwise in a signed Data Processing Agreement.

3. Retention schedule

Specific periods below, not indefinite retention.

CategoryRetention periodReason / basis
Active account data (profile, sites, projects, documents, case notes)For the lifetime of the account, while it remains activeNecessary to provide the service (UK GDPR Art. 6(1)(b), contract performance)
Third-party personal data within case files (objector/neighbour correspondence, consultee contacts)Retained for as long as the related project record is retained by the professional's accountProcessed by PlanProve as processor on the practice's instructions; retention follows the controller's (the practice's) own retention decision, not PlanProve's
Account data after a deletion request30 days from the date deletion is requested, then deletedBalances a short recovery window against storage limitation (Art. 5(1)(e))
Financial records (invoices, payment records via Stripe)6 years from the end of the relevant accounting periodHMRC statutory minimum for business records
Usage and analytics logs (PostHog)12 months, anonymised thereafterOnly useful for a limited window; indefinite retention isn't justified by purpose
BackupsUp to 7 daysSupabase's standard backup retention window; deleted data may persist in a backup for up to this long after removal from the live system
Search and system logs90 days, then anonymisedMatches existing PlanProve search log retention already in place

4. What happens when a subscription ends or an account is closed

4.1 Voluntary non-renewal (e.g. at the end of a free trial period)

If a professional or practice chooses not to continue after a trial or free period ends, their account and data are not deleted automatically. Data remains in place unless and until a deletion request is made, as described in 4.2.

4.2 Voluntary account deletion

A professional can request deletion of their account. This is currently a request-based process: the request is recorded against the account, and PlanProve then carries out the deletion. Deletion is completed within 30 days of the request being made, consistent with UK GDPR erasure expectations.

4.3 Backups

Deleted data may persist in routine backups for up to 7 days after deletion from the live system, reflecting Supabase's standard backup retention window. Backups are not separately exported or shared and fall out of scope naturally at the end of this window.

5. Data export

A professional or practice can request an export of their data at any time, whether the account is active or scheduled for deletion.

  • What an export includes: site and project records, uploaded documents, case notes, contacts, and time/invoice records associated with the account.
  • How to request one: currently a manual request to info@planprove.com. There is no self-service export tool in the product yet.
  • Format: data is provided in a structured, readable format (e.g. CSV/JSON for records, original files for documents), assembled manually on request given there is no automated export tool at present.
  • Turnaround time: within 30 days of the request, matching the deletion commitment in Section 4.2.

6. Third-party and sub-processor data

Where data is held by a sub-processor rather than directly within PlanProve's own database, that sub-processor's own retention behaviour also applies. Current sub-processors and their role:

  • Supabase — primary database and file storage (EU region, eu-west-1)
  • Vercel — application hosting
  • Stripe — payment processing and financial records
  • Resend — transactional email delivery
  • Anthropic — AI assistant processing (see note on data residency below)
  • PostHog — product analytics (EU-hosted instance)

Anthropic, Stripe, Resend and Vercel are based in or process data via the USA. Each incorporates the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses into their standard commercial terms, confirmed directly from each vendor's published Data Processing Addendum, so this applies automatically as a customer on their normal terms.

7. Review of this policy

This policy should be reviewed whenever the underlying technical implementation changes (for example, if account deletion behaviour is rebuilt, or if AI processing is moved to an EU-pinned provider), and at minimum annually. Recommend dating and versioning this document once finalised.