PlanningPoker
GDPR

GDPR compliance

What we do to meet Moldova's Law No. 195/2024, the GDPR and UK GDPR, and the documents your legal team will ask for.

Where we're based

We are S.R.L. MARGOVIMER, established in the Republic of Moldova, and primarily subject to Law No. 195/2024 on the protection of personal data (in force from 23 August 2026), overseen by the National Centre for Personal Data Protection (Centrul Național pentru Protecția Datelor cu Caracter Personal, CNPDCP). Because we also offer the Service to people in the EU and UK, the sections below describe how we meet the GDPR and UK GDPR for those users under their extraterritorial scope.

Controller or processor

For account data — your name, email and organisation — we are the controller. For the story text, votes and estimates you bring into a room, your organisation is the controller and we are the processor acting on its instructions under Article 28.

What we rely on

Contract for running the Service and billing. Legitimate interests for security and product improvement, with a balancing test available on request. Consent for optional emails and non-essential cookies. Legal obligation for tax records. No automated decision-making with legal effect, and no use of your session content to train models.

Transfers out of the EEA

Where a processor sits outside the EEA or UK we rely on the Standard Contractual Clauses with the UK Addendum, backed by a transfer impact assessment. The same safeguards cover transfers between us, in Moldova, and our EEA/UK-based processors, since Law No. 195/2024 on the protection of personal data requires equivalent protection for data leaving Moldova. Copies are available on request.

Data subject requests

Access, rectification, erasure, restriction, portability and objection. Export and account deletion are self-service in Settings; written requests are answered within one month. Requests about content your employer brought into a room go to them first, and we help them respond.

Records and governance

We keep an Article 30 record of processing, a sub-processor register with 30 days' notice of changes, and staff training on handling personal data. For UK users our UK GDPR representative is [name, address]. Our privacy contact is Andrei Barbier, reachable at privacy@planningpoker.cloud.

Where data lives

Application and database: hosted within the EU by default. Email delivery and monitoring: EU-based providers, or safeguarded by Standard Contractual Clauses where they are not. Canadian hosting is available on Enterprise.

Beyond the EU and UK

The same rights machinery serves requests under Law No. 195/2024 on the protection of personal data (access, rectification, erasure, restriction, portability, objection — complaints go to the National Centre for Personal Data Protection (Centrul Național pentru Protecția Datelor cu Caracter Personal, CNPDCP)), CCPA/CPRA requests from California, the equivalent state laws elsewhere in the US, and PIPEDA and Quebec Law 25 in Canada. One request form, one 45-day worst case.