Privacy Policy
Last updated: February 1, 2026
At Zelbel Ltd ("we", "us", or "our"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Planino service.
Information We Collect
Personal Information
We collect information that you provide directly to us, including:
- Name and email address when you create an account
- Profile information such as display name, bio, and avatar
- Payment information when you subscribe to paid plans
- Communications you send to us
Automatically Collected Information
When you access our service, we automatically collect:
- Device information (browser type, operating system)
- IP address and approximate location
- Usage data and interaction patterns
- Cookies and similar tracking technologies
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices and support messages
- Respond to your comments and questions
- Analyze usage patterns to enhance user experience
- Detect, prevent, and address security issues
- Comply with legal obligations
Legal Basis for Processing (GDPR)
We process your personal data based on:
- Contract: Processing necessary to provide our services
- Legitimate Interests: Improving our services and marketing
- Consent: Where you have given explicit consent
- Legal Obligation: Where required by law
Data Storage and Security
We implement appropriate technical and organizational security measures to protect your personal information, including:
- Encryption of data in transit and at rest
- Regular security assessments and audits
- Access controls and authentication measures
- Secure data centers with physical security
Data Retention
We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this policy. When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal purposes.
International Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
Third-Party Data Processing
In accordance with Article 28 of the General Data Protection Regulation (GDPR), we engage certain third-party service providers ("data processors") to process personal data on our behalf. We have entered into Data Processing Agreements (DPAs) with each processor to ensure that your personal data is handled in compliance with applicable data protection legislation.
Below is a list of the data processors we currently use, along with a description of the services they provide and a link to their respective data protection documentation.
Microsoft Azure
Microsoft Azure provides cloud infrastructure, hosting, and AI inference services (including Azure OpenAI deployments) on our behalf. Microsoft acts as a data processor under GDPR Article 28.
Microsoft Data Protection Addendum (DPA)
Supabase
Supabase provides database hosting, authentication, and backend-as-a-service infrastructure. Supabase acts as a data processor under GDPR Article 28.
Supabase Data Processing Addendum (DPA)
Lovable
Lovable provides website hosting and deployment infrastructure. Lovable acts as a data processor under GDPR Article 28.
Lovable Data Processing Agreement (DPA)
Hostinger
Hostinger provides website hosting and domain infrastructure services. Hostinger acts as a data processor under GDPR Article 28.
Hostinger Data Processing Agreement (DPA)
Resend
Resend provides transactional email delivery services on our behalf. Resend acts as a data processor under GDPR Article 28.
Resend Data Processing Agreement (DPA)
OpenAI
OpenAI provides AI inference services used as a fallback for certain AI-powered features. OpenAI acts as a data processor under GDPR Article 28.
OpenAI Data Processing Addendum (DPA)
Stripe
Stripe processes payment transactions on our behalf. When you make a payment, your payment information is handled directly by Stripe. Stripe acts as a data processor under GDPR Article 28.
Your Rights
GDPR Rights (EU/EEA Residents)
Under the General Data Protection Regulation, you have the right to:
- Access your personal data
- Rectify inaccurate personal data
- Request erasure of your personal data
- Object to processing of your personal data
- Request restriction of processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
CCPA Rights (California Residents)
Under the California Consumer Privacy Act, California residents have the right to:
- Know what personal information is being collected
- Know whether personal information is sold or disclosed
- Say no to the sale of personal information
- Access your personal information
- Request deletion of your personal information
- Equal service and price (non-discrimination)
To exercise any of these rights, please contact us using the information provided below.
Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact us:
Zelbel Ltd
Data Protection Officer
Email: support@planino.studio
Address: [Company Address]
We will respond to your request within 30 days as required by applicable law.
