Data Export and Retention Policy

Make My Plan Ltd, trading as PlanProve

Version 1.1 — Last updated: 13 September 2026

1. Purpose and scope

This policy sets out how long PlanProve retains different categories of data, what happens to that data when an account is closed or a subscription ends, and how a professional or practice can export their data. It applies to all data processed through the PlanProve platform, whether entered directly by a professional, uploaded as a document, or generated by the platform (such as AI-extracted deadlines or site constraint data).

This policy is written to reflect the storage limitation principle under UK GDPR Article 5(1)(e): personal data must be kept for no longer than is necessary for the purpose it was collected for. Where PlanProve acts as a data processor on behalf of a professional or practice (the data controller), retention of client and third-party data within case files follows the controller's instructions, not a period set unilaterally by PlanProve.

2. Roles: controller and processor

For data relating to a professional's own account (login details, billing, usage of the platform), PlanProve (Make My Plan Ltd) is the data controller.

For client and case data entered by a professional (client details, project correspondence, objector or neighbour personal data included in case files, documents uploaded to a site), the professional or practice is the data controller and PlanProve acts as data processor. Retention decisions for this category rest with the controller; PlanProve's role is to retain, delete, or export this data on their instruction, consistent with the periods set out below unless the controller specifies otherwise in a signed Data Processing Agreement.

3. Retention schedule

Specific periods below, not indefinite retention.

CategoryRetention periodReason / basis
Active account data (profile, sites, projects, documents, case notes)For the lifetime of the account, while it remains activeNecessary to provide the service (UK GDPR Art. 6(1)(b), contract performance)
Third-party personal data within case files (objector/neighbour correspondence, consultee contacts)Retained for as long as the related project record is retained by the professional's accountProcessed by PlanProve as processor on the practice's instructions; retention follows the controller's (the practice's) own retention decision, not PlanProve's
Account data after a deletion request30 days from the date deletion is requested, then deletedBalances a short recovery window against storage limitation (Art. 5(1)(e))
Financial records (invoices, payment records via Stripe)6 years from the end of the relevant accounting periodHMRC statutory minimum for business records
Usage and analytics logs (PostHog)12 months, anonymised thereafterOnly useful for a limited window; indefinite retention isn't justified by purpose
Backups — databaseFully overwritten within 7 days of deletionSupabase's standard backup retention window; deleted records may persist in a backup for up to this long after removal from the live system
Backups — documents and file storageFully overwritten within 30 days of deletionUploaded files are backed up separately to Cloudflare R2 (EU), because Supabase's database backups do not include files held in object storage
Search and system logs90 days, then anonymisedMatches existing PlanProve search log retention already in place

4. What happens when a subscription ends or an account is closed

4.1 Voluntary non-renewal (e.g. at the end of a free trial period)

If a professional or practice chooses not to continue after a trial or free period ends, their account and data are not deleted automatically. Data remains in place unless and until a deletion request is made, as described in 4.2.

4.2 Voluntary account deletion

A Client can request deletion from their account settings; the request is recorded and the account is deleted automatically after a 30-day grace period.

A professional can also request deletion from their account settings, and the request is recorded immediately — but completion of a professional or practice deletion is currently handled manually rather than automatically. We will complete it within 30 days of the request, consistent with UK GDPR erasure expectations, and you can withdraw the request at any time before then. You can also request deletion by email at info@planprove.com.

Completion is manual because a professional's account may be linked to a practice, to invoices retained as financial records, and to case files for which the professional is the data controller — each of which has to be settled before the account itself can be removed. Records listed in the retention schedule above — in particular invoices and payment records, retained for 6 years from the end of the relevant accounting period — are kept for their stated periods and are not removed by an account deletion.

4.3 Backups

Database backups are managed by Supabase under their standard platform terms, with a 7-day rolling window; deleted database records may persist in one for up to 7 days after removal from the live system.

Uploaded documents and files are backed up separately and daily to Cloudflare R2 (EU jurisdiction), independent of the primary database infrastructure. A file removed from the live system is retained in that backup for up to 30 days, after which it is deleted automatically.

Backups are encrypted at rest, are not shared with any party outside the sub-processors listed in Section 6, and are used only for disaster recovery.

5. Data export

You can export your data at any time, whether the account is active or scheduled for deletion, using the Download My Data button in your account settings. The export is generated immediately; there is no need to request one.

  • What an export includes: your profile, the sites you own or are directly assigned to, the projects and stages on those sites, case notes you have written, your contacts, time entries, invoices, messages you have sent, enquiries, notifications, case studies, subscription records, search history, and your uploaded documents.
  • What it does not include: sites and records belonging to practice colleagues, even where you can view them in the app. An export covers your own records rather than the whole practice's. A practice-wide export is not yet available self-service — request one at info@planprove.com.
  • Format: a ZIP archive containing export.json (all records in structured JSON) and a documents/ folder holding the original uploaded files.
  • Size limits: the archive holds up to 100 MB of documents, and individual files of 25 MB or more are listed rather than included. Anything left out is named, with the reason, in _omitted-files.txt inside the archive, and can be downloaded individually from the project it belongs to or requested at info@planprove.com. An export is never silently truncated.
  • Rate limit: one export per hour per account.

6. Third-party and sub-processor data

Where data is held by a sub-processor rather than directly within PlanProve's own database, that sub-processor's own retention behaviour also applies. Current sub-processors and their role:

  • Supabase — primary database and file storage (EU region, eu-west-1)
  • Vercel — application hosting. Serverless function execution is pinned to EU regions (Dublin dub1, London lhr1, Paris cdg1). Request-routing middleware executes on Vercel's global edge network, which includes locations outside the EU, and processes authentication session data in transit but does not store it.
  • Cloudflare — backup copies of uploaded documents and files, held in Cloudflare R2 under its EU jurisdiction setting, so the backup stays within the European Union
  • Stripe — payment processing and financial records
  • Resend — transactional email delivery
  • Anthropic — AI Planning Assistant and document extraction (in-product features); and AI-assisted development, debugging, and administrative support tooling, where diagnosing a fault or responding to a support request requires access to platform records that may contain personal data (see note on data residency below)
  • PostHog — product analytics (EU-hosted instance, Frankfurt eu-central-1)

Supabase, Cloudflare and PostHog process data within the European Union, which the UK recognises as adequate, so no Article 46 transfer safeguard is required for those transfers.

Anthropic, Stripe, Resend and Vercel are based in or process data via the USA. Each incorporates the UK Addendum to the EU Standard Contractual Clauses into their standard commercial terms, confirmed directly from each vendor's published Data Processing Addendum, so this applies automatically as a customer on their normal terms. Stripe, Resend and Vercel are additionally certified under the UK Extension to the EU–US Data Privacy Framework; Anthropic relies on the UK Addendum alone.

7. Review of this policy

This policy should be reviewed whenever the underlying technical implementation changes (for example, if account deletion behaviour is rebuilt, or if AI processing is moved to an EU-pinned provider), and at minimum annually.