PlannAir Logo PlannAir
  • Magyar

Privacy Policy

PlannAir application and website · Version 1.0 · Effective from: 1 August 2026

This policy describes what personal data AeroTech Services Kft. processes in the course of operating the PlannAir application and the plannair.hu website, for what purpose and for how long, to whom it is disclosed, and what rights you have in relation to all of this.

1. The controller

Name
AeroTech Services Kft. (limited liability company)
Registered seat
2621 Verőce, Tábor út 11., Hungary
Company registration number
13-09-235634 (Company Court of the Pest County Regional Court)
VAT number
32622726-2-13
Represented by
Adorján Balázs Péter, managing director
Data protection contact
privacy@plannair.hu
Customer support
support@plannair.hu

We have not appointed a data protection officer, because under Article 37 GDPR we are not required to do so: we are not a public authority, we do not carry out large-scale, regular and systematic monitoring, and we do not process special categories of data on a large scale. You can contact us with your data protection questions at the e-mail address above.

2. Our two distinct roles

PlannAir is used within organizations (companies). Because of this we process data in two different roles, and the two differ from each other legally:

  • We act as controller in respect of the data relating to the user account: registration, login, profile, error reports, customer support. We are the ones who decide that these are necessary — this policy is about that.
  • We act as processor in respect of everything that users put into the application: projects, groups, duct pieces, exports, as well as permissions within the organization. These are controlled by the given organization: it is the controller, and we store and process them on its instructions, within the framework of the data processing agreement concluded with it. If you use PlannAir as an employee, the notice provided by your employer is primarily what governs in respect of these.

3. What data we process and for what purpose

Creating an account, logging in

Data processed
e-mail address, the encrypted hash of the password or the identifier of the Google account, the name and the profile picture link received from the Google account, time of last login
Legal basis
performance of a contract (Article 6(1)(b))
Retention
until the account is deleted, plus a further 30 days

Profile and identifiability within the organization

Data processed
display name, profile picture, and personal settings visible solely to you
Legal basis
performance of a contract (Article 6(1)(b))
Retention
until the account is deleted, plus a further 30 days

Login security log

Data processed
IP address, time, type of the event
Legal basis
legitimate interests (Article 6(1)(f)): detecting abuse, account security
Retention
90 days

Providing the service, synchronization across devices

Data processed
projects, groups, duct pieces, exports, and the record of who created or modified these and when
Legal basis
the instruction of the organization as controller (we act as processor)
Retention
as decided by the organization

Troubleshooting, crash reporting

Data processed
the user’s identifier (a random identifier, without name and e-mail address), the organization’s identifier, application and system version, the screen concerned, the technical data of the error; depending on the error, the content of the affected data as well
Legal basis
legitimate interests (Article 6(1)(f)): the operability of the service
Retention
at most 90 days

Error report sent by the user

Data processed
the text of the report and the user’s identifier
Legal basis
legitimate interests (Article 6(1)(f)): investigating the report
Retention
at most 90 days

Customer support, keeping in contact

Data processed
e-mail address, name, the content of the correspondence
Legal basis
performance of a contract, and legitimate interests (Article 6(1)(b) and (f))
Retention
1 year from the closure of the matter

Serving the website and the application

Data processed
IP address, browser identifier, the address of the requested page, time
Legal basis
legitimate interests (Article 6(1)(f)): operational security
Retention
15 days

Statistical analysis, development of the service

Data processed
aggregated metrics calculated from the data above (see section 7)
Legal basis
further use for statistical purposes (Article 5(1)(b) and Article 89)
Retention
the aggregated, anonymous result for an unlimited period

We receive the data from you, or — in the case of logging in with a Google account — from Google. If you were invited to PlannAir by an organization, the permission data relating to you is provided by a member of the organization authorized to do so.

4. Who has access to the data

We do not sell the data and we do not disclose it to third parties for marketing purposes. We use the following processors to operate the service:

Supabase, Inc. (USA)

What it does
database, authentication, real-time synchronization
Where the data is stored
Frankfurt, Germany (AWS eu-central-1)

DigitalOcean, LLC (USA)

What it does
web server, internal reporting system
Where the data is stored
Frankfurt, Germany (FRA1)

Functional Software, Inc. (Sentry, USA)

What it does
receiving and storing error reports
Where the data is stored
European Union (Frankfurt)

Google Ireland Ltd. (Ireland)

What it does
logging in with a Google account, distribution of the application through the Google Play store
Where the data is stored
European Union / United States

Apple Distribution International Ltd. (Ireland)

What it does
distribution of the application through the App Store and TestFlight
Where the data is stored
European Union / United States

OpenRouter, Inc. (USA) and the model provider routed through it

What it does
operating our internal reporting system (see section 6)
Where the data is stored
receives no personal data

Leaning Technologies Ltd. (United Kingdom)

What it does
serving the runtime environment of the Excel export in the web version — sees technical data only (IP address, browser)
Where the data is stored
United Kingdom — the transfer is covered by the European Commission’s adequacy decision or, failing that, by standard contractual clauses

Transfers outside the European Union

We store your data within the European Union: the database, the servers and the error reports are all in data centres in Frankfurt. Some of the providers above belong to a US parent company, and therefore have a theoretical possibility of accessing the data in the course of technical support. This is safeguarded by the standard contractual clauses (SCC) adopted by the European Commission, and — where the provider is certified — by the EU–US Data Privacy Framework. No personal data reaches the model provider used by our internal reporting system (see section 6).

5. How long we keep the data

The retention period belonging to each purpose is set out in the table in section 3. In addition:

  • Backups: a backup of the database is made daily and stored by our provider for 7 days. In addition, we make a weekly encrypted copy which we keep for 30 days.
  • Operational logs: the platform logs of the database provider are available for 7 days.
  • Deleting the account: upon receipt of the deletion request we immediately close the account and make the data inaccessible, and then delete it permanently after 30 days. These 30 days serve to allow a deletion started by mistake to be revoked. Permanently deleted data disappears from the backups within a further 30 days at the latest. Error reports are not deleted together with the account; they expire at the end of their own retention period — after 90 days at the latest.

The content of the organization (projects, duct pieces, exports) is not your personal data but the organization's: it remains with the organization even after your account is deleted. Your name is removed from the items created by you.

6. Automated internal reporting

We use a system based on artificial intelligence to follow how the service is running and to produce internal statistics. This system has no access to personal data: it reads the database solely through a view layer that discloses no names and no contact details, and none of the organisations’ content either — no project, group or idom names, no dimensions, no comments. What it sees is identifiers, types, counts and timestamps.

The system does not read customer correspondence, nor does it have access to the error reports, and it takes no part in answering enquiries. Since no personal data reaches it, no such data reaches the model provider operating it either.

The system does not take decisions based solely on automated processing that produce legal effects concerning you within the meaning of Article 22 GDPR: every substantive decision — closing an account, modifying a permission, deciding on a request — is taken by a human.

7. Statistical use

For the development of the service, the measurement of its performance and for our business decisions we produce aggregated, averaged and calculated statistics from the data processed. The GDPR expressly permits this as use compatible with the original purpose (Article 5(1)(b) and Article 89), with the following safeguards:

  • the result is anonymous: it contains no name, e-mail address or individual identifier, and is not capable of identifying any single person;
  • we do not produce any breakdown from which the activity of a single person or of a group of fewer than five people could be reconstructed;
  • we do not use the statistics to take decisions affecting an individual user or organization.

8. Data security

  • all data transmission takes place over an encrypted channel (TLS), and passwords are stored exclusively as a one-way hash;
  • the database applies row-level access control: the database itself decides which row a user may see — not just the application;
  • nobody apart from us and you has access to the private part of the profile (personal settings), and there is technically no query path to it; the other members of the organization see only your name and profile picture;
  • internal access to the service is limited to the necessary minimum, and is restricted to support purposes.

9. Cookies and local storage

PlannAir does not use analytics, profiling or advertising cookies, and does not run any third-party tracking code. We store on your device only the data strictly necessary for operation, for which no consent is required under the electronic communications rules:

  • the identifier token that keeps you logged in;
  • a local copy of your projects, so that the application can be used without an internet connection as well;
  • the application's settings (for example theme, language).

This data remains on your device. On logout the login token is deleted; the local copy ceases to exist when the application's data is cleared or the application is uninstalled.

10. Your rights

You may at any time request from us:

  • information about and a copy of the data processed about you (Article 15);
  • rectification, if any of your data is inaccurate (Article 16);
  • erasure (Article 17), within the framework of retention obligations based on law;
  • restriction of processing (Article 18);
  • data portability: the release of your data in a machine-readable format (Article 20);
  • to object to processing based on legitimate interests (Article 21) — in which case we cease the processing, unless we can demonstrate compelling legitimate grounds.

Please send your request to privacy@plannair.hu. We reply within one month at the latest; in the case of a complex request this deadline may be extended by two months, of which we will inform you. The reply is free of charge.

If the data was put into the system by your organization (projects, duct pieces), then in that respect you must turn to the organization — we forward any such request received by us to it, and assist in fulfilling it.

Deleting your account

You can delete your account yourself from inside the app, on the Account page — the deleting your account page describes it step by step. If you cannot sign in, you can also request the deletion at privacy@plannair.hu, in a message sent from the e-mail address belonging to your account. The deletion procedure is described in section 5.

11. Remedies

If you feel that your data is not being processed properly, please contact us first at privacy@plannair.hu — most questions are resolved fastest this way. Independently of this, you may lodge a complaint with the supervisory authority at any time:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9–11., Hungary
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: naih.hu

In the event of an infringement of your rights you may also turn to the courts. The proceedings may — at your choice — also be brought before the regional court of your place of residence or place of stay.

12. Age limit

PlannAir is made for professional, business use; it is not aimed at children. We do not provide the service to users under the age of 16, and we do not knowingly process data originating from them.

13. Changes to this policy

We update this policy from time to time — for example if a new feature or a new provider is introduced. The version in force at any given time is available on this page, with the version number and date indicated at the top. We notify you of material changes in advance within the service or by e-mail.

Home Terms of Use Imprint

PlannAir

Designing and ordering HVAC duct pieces

© 2026 AeroTech Services Kft.