PRIVACY

Privacy Statement

How DLB Ventures collects, uses and protects personal data in connection with Planr.

Contents

This Privacy Statement explains how DLB Ventures processes personal data in connection with Planr.

1. Who We Are

Planr is operated by:

DLB VenturesVeerstraat 286701 DW WageningenThe NetherlandsChamber of Commerce: 42122973planr.eventscontact@planr.events

DLB Ventures is committed to protecting personal data and handling it in accordance with applicable privacy legislation, including the General Data Protection Regulation.

2. Scope

This Privacy Statement applies to personal data processed by DLB Ventures in connection with:

  • planr.events
  • Planr Accounts
  • Planr Customers
  • demo requests
  • sales enquiries
  • subscriptions
  • billing
  • support
  • platform security
  • product communications
  • use of Planr

Different rules apply where DLB Ventures processes personal data inside Planr solely on behalf of a Customer.

3. Our Role Under the GDPR

DLB Ventures may have different roles depending on the processing activity.

DLB Ventures as Controller

DLB Ventures generally acts as data controller when it determines why and how personal data is processed.

Examples include:

  • management of Customer Accounts
  • business administration
  • subscription administration
  • billing
  • sales enquiries
  • demo requests
  • support administration
  • product security
  • fraud prevention
  • Planr's own business communications

DLB Ventures as Processor

Customers may store personal data concerning their own:

  • employees
  • crew
  • artists
  • artist management
  • suppliers
  • promoters
  • guests
  • visitors
  • ticket buyers
  • contacts
  • freelancers
  • contractors
  • business partners

Where the Customer determines why this information is processed, the Customer will generally be the data controller and DLB Ventures will generally act as data processor.

In those circumstances, DLB Ventures processes the information on behalf of and according to the instructions of the Customer, subject to applicable law.

4. Account Information

When an Account is created or used, we may process:

  • name
  • business email address
  • organisation
  • job title
  • role
  • permissions
  • user identifier
  • Account status
  • authentication information
  • login history
  • relevant security information

We use this information to provide and secure access to Planr.

5. Customer and Business Information

We may process:

  • company name
  • contact person
  • business address
  • business contact information
  • Subscription details
  • contract information
  • correspondence
  • support history
  • account ownership information

This is used to manage our relationship with the Customer and provide the Service.

6. Billing and Payment Information

We may process information including:

  • billing details
  • Subscription
  • amount
  • payment status
  • invoice information
  • payment date
  • due date
  • transaction identifiers
  • payment history

Where payments are processed using Stripe or another payment provider, the payment provider may process payment credentials directly.

Planr does not need to store complete payment card details where those details are processed directly by the payment provider.

7. Data Stored by Customers in Planr

Depending on the functionality used by a Customer, Planr may process Customer-controlled information relating to:

  • events
  • contacts
  • companies
  • suppliers
  • artists
  • artist profiles
  • artist management
  • riders
  • crew
  • schedules
  • timetables
  • travel
  • accommodation
  • accreditation
  • access requests
  • backstage access
  • zone access
  • guest lists
  • orders
  • ticket information
  • merchandise
  • stock
  • finance
  • costs
  • income
  • budgets
  • settlements
  • leads
  • operational notes
  • documents
  • files
  • communications
  • other event operations

The Customer largely determines which information is entered into Planr.

DLB Ventures does not independently determine the Customer's purpose for this Customer-controlled information.

8. Special Categories of Personal Data

Planr is not primarily designed for the processing of special categories of personal data.

Customers should only enter sensitive or special-category information when:

  • it is genuinely necessary
  • there is a valid legal basis
  • the Customer has implemented appropriate safeguards

For example, a Customer might choose to record information relating to accessibility, dietary requirements or similar operational needs.

The Customer remains responsible for determining whether that processing is lawful.

9. Technical Information

When Planr or planr.events is accessed, technical information may be processed, such as:

  • IP address
  • timestamp
  • browser information
  • device information
  • operating system
  • session information
  • login attempts
  • error information
  • system logs
  • audit information
  • security events
  • use of product functionality

We may use this information to:

  • operate Planr
  • maintain security
  • diagnose errors
  • prevent misuse
  • investigate incidents
  • improve reliability

10. Support Information

When someone contacts Planr support, we may process:

  • name
  • organisation
  • contact details
  • support request
  • correspondence
  • screenshots
  • attachments
  • relevant technical information
  • previous support interactions

Users should avoid including unnecessary personal information in support requests.

11. Demo and Sales Information

When an organisation requests a demo, quotation or product information, we may process:

  • name
  • company
  • business email
  • telephone number where provided
  • position
  • organisation type
  • requirements
  • correspondence
  • requested Planr configuration

We use this information to respond to the request and potentially establish a business relationship.

12. Product and Service Communications

We may send operational communications relating to:

  • Account activity
  • security
  • payments
  • invoices
  • Subscription changes
  • important platform updates
  • changes to the Service
  • support

These communications may be necessary to provide the Service and cannot always be opted out of while an Account remains active.

Where permitted by law, we may also send relevant commercial product information.

Where consent is required, such communications will only be sent with appropriate consent.

Users can unsubscribe from optional marketing communication.

13. Purposes of Processing

Depending on the circumstances, we may process personal data in order to:

  • provide Planr
  • create and manage Accounts
  • authenticate Users
  • provide Customer workspaces
  • manage Subscriptions
  • administer billing
  • process payment status
  • provide support
  • respond to enquiries
  • provide requested integrations
  • maintain security
  • detect fraud
  • prevent misuse
  • monitor technical performance
  • resolve errors
  • maintain logs
  • improve Planr
  • comply with legal obligations
  • establish, exercise or defend legal claims
  • communicate with Customers

14. Legal Bases

Where DLB Ventures acts as controller, processing may rely on one or more of the following legal bases.

Performance of a Contract

We may process information where necessary to enter into or perform an agreement, such as:

  • Account management
  • Subscription management
  • Service delivery
  • billing
  • Customer support

Legal Obligation

We may process information where required to meet legal obligations, including applicable financial, accounting and regulatory requirements.

Legitimate Interests

We may process personal data where necessary for legitimate business interests, provided those interests are not overridden by the rights and interests of the individual.

These interests may include:

  • operating Planr
  • securing the platform
  • preventing fraud
  • improving reliability
  • managing business relationships
  • defending legal claims

Consent

Where applicable law requires consent, we will request it.

Consent may be withdrawn at any time, without affecting processing that was lawful before withdrawal.

15. Payment Providers

DLB Ventures may use specialised payment providers to process Subscription payments.

Where Stripe is used, payment information may be transmitted directly to and processed by Stripe.

Stripe acts under its own applicable privacy and contractual documentation for the relevant payment processing activities.

16. Planr Integrations

Customers may choose to connect Planr with external platforms.

Current Planr functionality may include integrations such as:

  • Weeztix
  • Shopify
  • APIs
  • webhooks
  • other operational systems

When a Customer activates an Integration, information may be exchanged between Planr and the external service.

The Customer is responsible for ensuring that its use of the Integration is lawful.

The external provider's own privacy terms may also apply.

17. Service Providers and Subprocessors

DLB Ventures may use service providers to operate Planr, including providers of:

  • hosting
  • cloud infrastructure
  • databases
  • payments
  • transactional email
  • security
  • monitoring
  • error detection
  • support systems
  • technical infrastructure

Where required, DLB Ventures enters into appropriate contractual arrangements with processors.

Service providers should only receive access to personal data to the extent reasonably necessary for their function.

18. Sale of Personal Data

DLB Ventures does not sell personal data to advertisers.

DLB Ventures does not provide Customer Data to third parties for their own unrelated advertising purposes.

19. International Data Transfers

Some service providers may process personal data outside the Netherlands or outside the European Economic Area.

Where the GDPR requires safeguards for an international transfer, DLB Ventures will use an appropriate transfer mechanism.

Depending on the relevant country and provider, this may include:

  • an adequacy decision
  • Standard Contractual Clauses
  • another mechanism permitted by applicable law

20. Security

DLB Ventures takes appropriate technical and organisational measures designed to protect personal data.

Depending on the relevant system, such measures may include:

  • encrypted connections
  • authentication
  • authorisation
  • role-based access
  • user permissions
  • Tenant separation
  • logging
  • monitoring
  • backups
  • restricted infrastructure access
  • software updates
  • patch management
  • incident response

No online service can guarantee absolute security.

Customers are also responsible for securing their own Accounts, Users and connected services.

21. Data Retention

DLB Ventures does not retain personal data for longer than reasonably necessary for the purposes for which it is processed, unless longer retention is required or permitted by law.

Retention depends on the category and purpose of the information.

Customer and Account Data

Customer and Account information may be retained while the Customer relationship or Account is active and afterwards where reasonably necessary for:

  • administration
  • support
  • security
  • dispute resolution
  • legal claims
  • compliance obligations

Financial Records

Information subject to statutory financial or administrative retention obligations is retained for the applicable statutory period.

Security and Technical Logs

Technical and security logs are retained for a period proportionate to their purpose, taking into account:

  • security requirements
  • incident detection
  • troubleshooting
  • fraud prevention
  • legal obligations

Support Information

Support correspondence may be retained where reasonably necessary to provide support, understand previous issues, improve service quality or manage disputes.

Customer Data in a Tenant

Customer Data is normally retained for the duration of the relevant Customer Agreement.

After the Agreement ends, Customer Data may be retained for a limited period where reasonably necessary for:

  • data export
  • backup rotation
  • security
  • dispute resolution
  • legal compliance

Customer Data may subsequently be permanently deleted.

Enterprise Customers may have separately agreed data-retention arrangements.

22. Backups

Personal data may remain temporarily present in technical backups after it has been removed from active production systems.

Backup copies are removed or overwritten as part of the applicable backup lifecycle.

Backup data is not normally restored for ordinary Customer access once the active data has been deleted, except where technically or legally necessary.

23. Customer Responsibility

Where a Customer acts as controller, that Customer is responsible for:

  • having a lawful basis
  • providing required privacy information
  • determining necessity
  • determining retention
  • keeping information accurate where required
  • responding to data subject requests
  • managing access rights
  • deleting information when appropriate

Planr provides the software infrastructure but does not independently determine why a Customer places a particular individual in an artist profile, guest list, crew list, contact database or similar Customer-controlled record.

24. Data Subject Rights

Where the GDPR applies, individuals may have rights including:

  • the right of access
  • the right to rectification
  • the right to erasure
  • the right to restriction of processing
  • the right to data portability
  • the right to object
  • the right to withdraw consent where processing is based on consent

These rights are subject to the conditions and exceptions contained in applicable law.

25. Requests Relating to Customer Data

If personal data was entered into Planr by one of our Customers, that Customer will usually be the data controller.

Individuals should therefore normally direct their request to the relevant Customer.

Where appropriate and legally required, DLB Ventures will reasonably assist Customers in responding to data subject requests.

26. Identity Verification

Before fulfilling a privacy request, DLB Ventures may request information reasonably necessary to verify the identity of the person making the request.

We will not request more information than reasonably necessary for that verification.

27. Response Period

Privacy requests will be handled within the periods required by applicable data protection law.

Where legally permitted, the response period may be extended for complex or numerous requests.

28. Cookies and Similar Technologies

Planr and planr.events may use cookies, browser storage and similar technology.

These may include technology required for:

  • authentication
  • sessions
  • security
  • preferences
  • basic platform functionality

Where non-essential analytics, advertising or tracking technologies are used and consent is legally required, the appropriate consent mechanism must be used.

The website must not describe optional analytics or advertising cookies as strictly necessary.

29. Automated Processing

Planr may provide:

  • calculations
  • dashboards
  • forecasts
  • alerts
  • ticket projections
  • automated workflows
  • operational recommendations

DLB Ventures does not intend these tools, by themselves, to make solely automated decisions about individuals that produce legal or similarly significant effects, unless expressly disclosed and legally supported.

30. Children

Planr is a professional B2B service and is not specifically directed at children.

DLB Ventures does not intentionally operate Planr as a consumer service for children.

Where a Customer chooses to process data concerning minors, that Customer remains responsible for ensuring an appropriate legal basis and safeguards.

31. Data Breaches

DLB Ventures maintains procedures for assessing and responding to security incidents.

Where DLB Ventures acts as processor and becomes aware of a personal data breach affecting Customer-controlled personal data, DLB Ventures will notify the relevant Customer without undue delay where required by applicable law.

Where DLB Ventures acts as controller, DLB Ventures will assess any applicable notification obligations to supervisory authorities and affected individuals.

32. Complaints

Individuals may contact DLB Ventures regarding concerns about the processing of their personal data.

Individuals also have the right to lodge a complaint with the competent data protection supervisory authority.

In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens.

33. Changes to This Privacy Statement

DLB Ventures may update this Privacy Statement when:

  • Planr changes
  • processing activities change
  • new functionality is introduced
  • service providers change
  • legal requirements change

The latest version will be published on planr.events.

Where appropriate, material changes may also be communicated through Planr or directly to Customers.

34. Contact

Questions about privacy or this Privacy Statement may be directed to:

DLB VenturesVeerstraat 286701 DW WageningenThe NetherlandsChamber of Commerce: 42122973planr.eventscontact@planr.events