Privacy Policy

Privacy Policy

Last updated: 2 May 2026  ·  Effective date: 28 May 2026

This policy explains how PlanSafe collects, uses, stores, and protects your personal data. It is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and PECR. If anything is unclear, email privacy@plan-safe.com — we are required by law to respond.

1. Who we are

The data controller for your personal data is:

Jamie Wadhams trading as PlanSafe
Registered office: 2 Charles Court, Lympstone, EX8 5EL
Contact: privacy@plan-safe.com

Until incorporation, the controller is Jamie Wadhams, sole trader.

2. Who this policy applies to

PlanSafe is for adults aged 18 and over living in the United Kingdom. Parents and carers may enter information about dependants (including children) inside their account; we treat that data with additional care as described in section 7.

3. What data we collect

Account data

Emergency plan data

Automatically collected data

What we do not collect

4. Lawful basis for processing

PurposeLawful basis
Create and run your account, deliver features, provide supportPerformance of a contract (Article 6(1)(b))
Process special category data (medical, disability, religious, child SEND)Your explicit consent (Articles 6(1)(a) and 9(2)(a)) — separate tick at point of entry
Transactional messages (billing, security, subscribed alerts)Performance of a contract (Article 6(1)(b))
Optional marketing communicationsYour consent (Article 6(1)(a) and PECR)
Security, fraud prevention, crash diagnosticsLegitimate interests (Article 6(1)(f))
Tax and accounting obligationsLegal obligation (Article 6(1)(c))
Anonymised aggregated statisticsLegitimate interests (Article 6(1)(f)) — note: genuinely anonymised data is no longer personal data

5. How we use your data

We use your data to: create your account and sign-in; build, store, and display your emergency plan; alert you to local emergencies (if you opt in); process your subscription payments; send transactional emails and push notifications; respond to support requests; investigate misuse and security incidents; fix bugs and improve the app; and comply with law.

We do not use your data to make automated decisions with legal or similarly significant effects on you.

6. Who we share your data with

Our processors

ProcessorPurposeData shared
Apple Inc.App Store, Sign in with Apple, push notifications, in-app subscriptionsApple ID identifier, push token, subscription receipt
Google LLCPlay Store, Sign in with Google, push notifications, subscriptionsGoogle account identifier, push token, subscription receipt
Stripe Payments UK LtdSubscription billing (where Apple/Google billing is not used)Name, email, billing country, payment-method token
[Cloud hosting provider]Hosting the database and backendAll app data, encrypted at rest

Anonymised aggregate statistics

We may produce statistics from app data that cannot identify any individual — for example: "62% of UK households in PlanSafe store fewer than three days of drinking water." Once genuinely anonymised, data falls outside UK GDPR. We may share or sell such statistics to insurers, councils, or research bodies. We never sell data linked to you, your household, your contacts, or your dependants.

Other disclosures

We may disclose data to law enforcement or courts where legally required; to a buyer if PlanSafe is sold (with prior notice to you); or to professional advisers under duties of confidentiality. We do not share your personal data for advertising or marketing by third parties.

7. Children's and dependants' data

We treat children's medical and SEND data as the highest-sensitivity category. It is encrypted at rest, restricted to staff who need it, never used for analytics, and deleted immediately when you remove the dependant from your plan or close your account. Anyone listed as a dependant or emergency contact may email privacy@plan-safe.com to request removal of their data.

8. Retention periods

DataRetention period
Account data, plan content, emergency contacts, dependantsWhile account is active, plus 30 days after deletion
Special category data (medical / disability / religious / SEND)Same as above; deleted in full at the end of the 30-day grace period
Subscription and billing records7 years (UK accounting law)
Support correspondence2 years from last message
Crash logs and diagnostics90 days
Marketing consents and withdrawals3 years from withdrawal

9. Your rights

Under UK GDPR you have the following rights, free of charge, exercisable by emailing privacy@plan-safe.com. We will respond within one calendar month.

AccessGet a copy of your data
RectificationCorrect inaccurate data
ErasureRequest deletion of your data
RestrictionPause processing during a dispute
PortabilityReceive your data in a machine-readable format
ObjectObject to legitimate-interest processing
Withdraw consentAs easy to withdraw as it was to give
Right to complain: If you are unhappy with our response, you have the right to complain to the Information Commissioner's Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · Helpline: 0303 123 1113 · ico.org.uk/make-a-complaint

10. International transfers

Some processors (Apple, Google, Stripe) operate servers outside the UK, including in the US. Where this happens we rely on the UK Extension to the EU–US Data Privacy Framework or Standard Contractual Clauses together with the ICO's International Data Transfer Addendum. Copies of safeguards are available on request.

11. Security

We protect your data using TLS 1.2+ in transit, AES-256 encryption at rest, role-based access control with least privilege, multi-factor authentication for production access, and regular penetration testing. We will notify the ICO within 72 hours of any breach that risks your rights or freedoms, and notify you directly if the risk to you is high.

12. Cookies, SDKs, and tracking

The mobile app does not use web cookies. It includes SDKs from Apple and Google for sign-in, push notifications, billing, and crash diagnostics. None is used for cross-app advertising. We do not use Apple's IDFA or Google's Advertising ID. The first time you open the app we ask separately for consent to crash diagnostics and marketing notifications.

13. Changes to this policy

If we make material changes we will notify you by email and require acknowledgement in-app before you continue using PlanSafe. Minor changes will be reflected here with an updated date.

14. Contact us

Data protection: privacy@plan-safe.com
Post: 2 Charles Court, Lympstone, EX8 5EL — marked "FAO Data Protection"
Support: support@plan-safe.com

This policy is a template tailored to PlanSafe's data model. It is not a substitute for review by a UK-qualified solicitor, particularly given the special category data (medical, disability, SEND) and children's data PlanSafe processes.