02 · LEGAL DOCUMENTATION

Privacy policy

Pending publication: the fields shown in square brackets must be completed before this document takes effect.

On this page
Pending publication: the fields shown in square brackets must be completed before this document takes effect.

The Spanish version is the reference text. This translation is provided for information and awaits review by a native legal professional.

Version: 0.1 Date of last update: July 13, 2026 Effective date: pending completion

Data pending completion

Before publishing these documents, at least the following fields must be replaced:

  • [TITULAR]: full company name or name of the businessman.
  • [NIF]: NIF or CIF.
  • [DOMICILIO]: social or professional address.
  • [REGISTRO MERCANTIL]: registration data, when applicable.
  • support@plan-g.co: general contact.
  • support@plan-g.co: user support.
  • privacy@actually-better.com: exercise of data protection rights.
  • legal@actually-better.com: communication of illegal content or violations of rights.
  • [URL PROVEEDORES]: updated list of suppliers and subprocessors.
  • [URL PRECIOS]: plans and pricing page.
  • [URL CONFIGURACIÓN COOKIES]: consent panel.
  • [DELEGADO DE PROTECCIÓN DE DATOS]: only if designated or mandatory.
  • [DOMINIO]: definitive web domain of Plan/G.

Data controller

Data controller: [TITULAR] NIF: [NIF] Address: [DOMICILIO] Privacy Email: privacy@actually-better.com Data Protection Officer: [DELEGADO DE PROTECCIÓN DE DATOS], where applicable.

This policy explains how Plan/G processes personal data of registered users, organizers, co-hosts, guests, attendees, visitors and people who contact the service.

Principles

Plan/G will process the data in accordance with the principles of:

  • Legality, loyalty and transparency.
  • Limitation of purpose.
  • Minimization.
  • Accuracy.
  • Limitation of the conservation period.
  • Integrity and confidentiality.
  • Proactive responsibility.

Plan/G will not sell personal data.

Plan/G will not use guest data to send them non-event advertising without an independent legal basis.

Processed data

3.1. Account and profile

We can treat:

  • Name and surname.
  • Visible name.
  • Email address.
  • Verification status.
  • Avatar or profile photo.
  • Language.
  • Country or region.
  • Time zone.
  • Internal identifier.
  • Identifiers provided by Google, Microsoft or other providers.
  • Registration date and last access.
  • Communications preferences.
  • Data related to account security.

3.2. Invitations and attendees

We can treat:

  • Name of the guest.
  • Email address or contact method.
  • Invitation status.
  • Support response.
  • Number of companions.
  • Family group or unit.
  • Indicative categories such as adult, adolescent, minor or baby.
  • Messages addressed to the organizer.
  • Token or invitation link.
  • Relationship between the invitation, the attendee and a registered account.
  • Authorization requests when the account does not match the invitation.

These data may have been provided by the interested party themselves or by the organizer.

3.3. Event details

We can treat:

  • Title and description.
  • Date and time.
  • Time zone.
  • Location and access instructions.
  • Agenda or itinerary.
  • Preferences and settings.
  • Roles and permissions.
  • History of publication, cancellation or changes.
  • Limits or capacity applied.
  • Internal event identifiers.

3.4. Participation and coordination

We can treat:

  • Confirmations and changes of attendance.
  • Contributions of objects, food or drinks.
  • Assumed tasks.
  • Items claimed or released.
  • Comments, messages and mentions.
  • Surveys or responses.
  • Administrative activity within the event.
  • Action history necessary for security or conflict resolution.

3.5. Expenses and distributions

When these functions are used we can treat:

  • Amount and description of the expense.
  • Person who paid.
  • Participants included.
  • Percentages, weights or units.
  • Balances and calculations.
  • Adjustments and exclusions.
  • Status indicated by users as paid or pending.
  • Transaction references, if payments are enabled.

Unless expressly indicated, Plan/G does not access the complete card number or custody funds between participants.

3.6. Photos, videos and files

We can treat:

  • Original file.
  • Thumbnails or optimized versions.
  • Upload date.
  • Author or account that published it.
  • Event to which it belongs.
  • Required technical metadata.
  • Comments or reactions.
  • Download logs when necessary for security.

Images may reveal personal data of the people who appear in them. Plan/G will not treat them as biometric data unless a specific facial recognition or identification function is implemented, which would require additional information and legal basis.

3.7. Location, maps and weather

We can treat:

  • Address entered.
  • Selected location or establishment.
  • Coordinates derived from the direction.
  • Inferred time zone.
  • Inquiries made to map or meteorology providers.

We do not collect continuous device location unless a feature expressly requests it and the user authorizes it.

3.8. Calendar and integrations

When the user connects or uses an integration we can process:

  • Calendar identifiers.
  • Data necessary to create or update an event.
  • Authorization tokens.
  • Connected provider account.
  • Sync status.
  • Integration errors.

Plan/G will request only the permissions necessary for the chosen functionality.

3.9. Purchasing and billing

We can treat:

  • Contracted plan.
  • Price, taxes and currency.
  • Payment status.
  • Date of purchase or renewal.
  • Supplier customer and transaction identifier.
  • Billing information.
  • Invoices and refunds.
  • Subscription history.

The complete payment method data will normally be processed by the payment provider.

3.10. Technical and safety data

We can treat:

  • IP address.
  • Device type.
  • Operating system and browser.
  • Session identifiers.
  • Date and time of access.
  • Pages or functions used.
  • Error logs.
  • Access attempts.
  • Indicators of fraud or abuse.
  • Cookie preferences.
  • Information necessary to prevent attacks and maintain service.

3.11. Support and communications

We can treat:

  • Inquiries and requests.
  • Messages sent to support.
  • Attached files.
  • Incident history.
  • Voluntary assessments.
  • Legal and administrative communications.

Especially sensitive data

Plan/G is not designed to store medical records, health documentation, sexual orientation, political opinions, religion, ethnicity or other special categories.

Certain voluntary fields, such as allergies, accessibility needs, or dietary preferences, could reveal sensitive information.

When Plan/G enables fields of this nature:

  • Completion will be voluntary.
  • It will be explained who can see the information.
  • It will be limited to the coordination of the event.
  • Explicit consent will be requested when necessary.
  • The user may delete it or withdraw their consent.
  • It will not be used for advertising or profiling.

The organizer must not introduce sensitive information from third parties without sufficient authorization.

5.1. Create and manage your account

Purpose: registration, authentication, profile, security and access to the service. Basis: execution of the contract or application of pre-contractual measures.

5.2. Manage events and invitations

Purpose: create events, send invitations, manage attendance and allow coordination. Basis: execution of the contract with registered users and legitimate interest in delivering an invitation requested by the organizer to unregistered people.

5.3. Manage roles and authorizations

Purpose: control who can access, manage events and resolve access requests. Basis: execution of the contract and legitimate interest in protecting the privacy and security of the event.

5.4. Process contributions, expenses and content

Purpose: provide the functions used by the participants. Basis: execution of the contract.

5.5. Process voluntary sensitive information

Purpose: communicate allergies, accessibility or other needs to the organizer. Basis: explicit consent, when required.

5.6. Process payments and billing

Questions about payments, plans, invoices and subscriptions should be sent to billing@actually-better.com.

Purpose: collect plans, issue invoices, manage renewals and refunds. Basis: execution of the contract and compliance with legal accounting and tax obligations.

5.7. Security and fraud prevention

Purpose: detect improper access, attacks, fraudulent accounts, abuse and circumvention of limits. Basis: legitimate interest of Plan/G and its users in maintaining a secure service; compliance with legal obligations when applicable.

5.8. Support

Purpose: respond to queries, investigate incidents and resolve complaints. Basis: execution of the contract, legitimate interest and compliance with legal obligations.

5.9. Operational communications

Purpose: send verifications, invitations, reminders, changes, receipts and security notices. Basis: execution of the contract and legitimate interest.

5.10. Commercial communications

Purpose: inform about products, news or offers. Basis: consent or prior contractual relationship when permitted by law.

The user may object or unsubscribe at any time.

5.11. Analytics and improvement

Purpose: understand the use, correct errors and improve the product. Basis: consent when cookies or non-necessary technologies are used; legitimate interest for strictly necessary aggregate metrics, security and analysis.

5.12. Legal obligations and claims

Purpose: assist authorities, defend rights and preserve evidence. Basis: legal obligation and legitimate interest in formulating, exercising or defending claims.

Information shared within an event

The information visible will depend on the role and configuration.

Owners and co-hosts

They will be able to access the information necessary to manage the event, such as identity, response, companions, contributions, expenses and relevant activity.

Participants

They will be able to access the information that the organizer or Plan/G configures as shared, such as a list of attendees, contributions, messages, photographs or common expenses.

Private information

Messages addressed exclusively to the organizer, certain contact details or sensitive fields must be limited to authorized people.

The organizer and co-hosts may download or copy information. Once exported outside of Plan/G, the processing carried out by them is outside the technical control of the platform.

Origin of data

The data may come from:

  • The user himself.
  • The organizer or co-host who creates an invitation.
  • Other participants who register an expense or content.
  • Google, Microsoft or other identity provider.
  • Stripe or other payment provider.
  • Services voluntarily connected.
  • Device, browser and security systems.
  • Map, weather or calendar providers.

When you receive an invitation without having registered, you can contact privacy@actually-better.com to find out what data is kept, correct it or request its deletion where appropriate.

Recipients and suppliers

They may access data, as necessary:

  • Owners and co-hosts of the event.
  • Authorized participants.
  • Hosting, database and content distribution providers.
  • Mail and notification providers.
  • Authentication providers, such as Google or Microsoft.
  • Payment providers, such as Stripe.
  • Map, geocoding and meteorology providers.
  • Calendar providers and integrations.
  • Support, monitoring, fraud prevention and security services.
  • Analytical services, only in accordance with applicable preferences.
  • Legal advisors, accountants or auditors.
  • Administrations, courts and competent authorities.

The updated list of suppliers will be available at [URL PROVEEDORES].

Suppliers will act in accordance with contracts and obligations of confidentiality and data protection.

International transfers

Some providers may process data outside the European Economic Area.

When international transfers occur, Plan/G will use the legally available guarantees, such as:

  • Adequacy decisions.
  • Standard contractual clauses.
  • Additional technical and organizational measures.
  • Other mechanisms recognized by regulations.

Information on the mechanism applicable to each provider can be consulted at [URL PROVEEDORES] or requested from privacy@actually-better.com.

Conservation

The data will be kept for the time necessary for the corresponding purpose.

As a general criterion:

  • The account will be kept as long as it remains active.
  • Events will be retained until they are deleted or the applicable retention period expires.
  • Invitations may be maintained as long as they are necessary to manage the event.
  • The content will be retained until it is deleted by an authorized person or the event closes.
  • Billing data will be kept for the legal periods.
  • Security records will be kept for a limited period proportional to the risk.
  • Support requests will be kept for as long as liabilities may arise.
  • Marketing preferences will be retained until withdrawn.
  • Certain data may be blocked to address claims or legal obligations.

Backups will be deleted through their regular rotation cycles and will not be used for active purposes other than incident recovery.

Automated decisions

Plan/G can use automatic rules to:

  • Check plan limits.
  • Reserve or consume capacity.
  • Detect anomalous activity.
  • Block access attempts.
  • Link an invitation with an account.
  • Prioritize security incidents.

These rules will not, in general, produce decisions with significant legal effects based exclusively on automated processing.

When an automatic decision improperly restricts an account, the user may request human review from support@plan-g.co.

Rights

The interested party can exercise the rights of:

  • Access.
  • Rectification.
  • Deletion.
  • Opposition.
  • Limitation.
  • Portability.
  • Withdrawal of consent.
  • Not be subject to certain automated decisions.

The request must be sent to privacy@actually-better.com and sufficiently identify the person and the right requested.

Plan/G may request additional information when there is reasonable doubt about identity.

Withdrawing consent does not affect the legality of the previous processing.

When the data has been entered by an organizer, Plan/G may coordinate the response with them, without prejudice to the platform's own obligations.

Claims

The interested party can file a claim with the Spanish Data Protection Agency or the control authority corresponding to their residence.

Plan/G recommends contacting privacy@actually-better.com first to try to resolve the issue.

Security

Security vulnerabilities and incidents should be reported to security@actually-better.com.

Plan/G will apply reasonable technical and organizational measures, such as:

  • Communications encryption.
  • Access control.
  • Email verification.
  • Separation of permissions.
  • Token protection.
  • Security event log.
  • Backups.
  • Vulnerability management.
  • Limitation of access by providers.
  • Incident response procedures.

No system is completely foolproof. The user must protect their account and immediately report any incident.

Minors

Persons under fourteen years of age will not be able to create a separate account.

Your data may appear as part of a family unit or list of attendees under the responsibility of an adult and must be limited to what is strictly necessary.

Persons between the ages of fourteen and seventeen will use Plan/G in accordance with the age rules described in the Terms.

Plan/G will not use minors' data for behavioral advertising.

Changes to this policy

Plan/G may update this policy due to legal, technical or functional changes.

Relevant changes will be communicated through the platform or by email where appropriate.

The update date will appear at the beginning.

Other legal documentsPending publication: the fields shown in square brackets must be completed before this document takes effect.
privacy@actually-better.com