Skip to content

Privacy policy

This Privacy Policy describes how personal data is processed by Szymon Jędrusik Unicornity, the owner of the planplace.pl website and of the PlanPlace.pl service — including public event plans and plans shared with contractors.

1. Data controller

The controller of your personal data is:

Szymon Jędrusik Unicornity
ul. Jana Dormana 11c, 41-219 Sosnowiec
NIP: 6443557012
REGON: 387378626

For matters related to personal data protection you can contact the Controller at: unicornitydesign@gmail.com.

2. Scope of the data processed

Contact and booking a meeting

Contact and meeting scheduling take place through the meeting-booking tool embedded on planplace.pl. When you book a slot you give your first and last name and your email address, and optionally a message. The meeting time you pick and your time zone are recorded as well. Providing this data is voluntary, but necessary to arrange a meeting and present a cooperation offer.

Public event plans

PlanPlace.pl lets organisers share public event plans that can be viewed without creating an account and without signing in. Opening a public plan does not require any personal data. The Controller does not create an account, a profile or an identifier that would let it recognise the visitor on a later visit.

Access to a plan is through a unique link that contains an access token. The token sits in the part of the address that follows the “#” character, which under the web standard is not sent in the request header to the server. The plan owner may additionally protect the plan with a password.

To display the plan correctly, the user's device communicates with the infrastructure used by the Controller (application hosting, the database and file storage) and with the map provider's infrastructure. In that communication, as with any internet connection, the infrastructure providers may process standard technical data such as an IP address, device or browser information, and information about the resources being fetched.

To settle the package limits of the organisation that shares the plan, and for aggregate statistics, the Controller counts how many times plans are opened. So that a return by the same person within 24 hours is not counted more than once, each opening is tagged with a visit identifier. That identifier is an irreversible hash calculated from the IP address, the plan identifier and a secret key known only to the server. This means that:

  • the IP address itself is not stored in the Controller's datasets,
  • the IP address cannot be reconstructed from the hash,
  • the hash is different for each plan, so it cannot link visits across plans or recognise the same person outside a single plan,
  • the hash is not combined with a first name, last name, email address or any other identifying information.

If the address cannot be determined, a random identifier generated in the browser for the duration of a single page load is used instead. It is not stored on the device and is created anew on every visit.

For password-protected plans the Controller stores — linked to the plan, not to a person — the number of failed password attempts and a temporary lock that prevents automated password guessing.

Plans shared with contractors

An organisation using PlanPlace.pl may share a plan with a contractor, meaning a company it works with on a given event. That plan also opens without creating an account and without signing in, through a separate link with an access token placed in the part of the address after the “#” character. The link is created separately for each contractor and shows only the work schedule assigned to that contractor. The organisation decides whether the map shows all of the plan's objects or only the assigned ones, and whether object dimensions and notes are shown. The link can additionally be protected with a password, set separately for each contractor.

Opening such a plan does not require personal data — there is no sign-in, registration form or profile.

Within the plan the contractor can mark a schedule item as done or undo that mark. What is then stored is that the item was completed, the time of the mark, and that it came from that contractor — meaning the company named in the schedule, not the specific person who used the device.

Because the same link is usually opened by several people from several devices, a random device marker is stored in the browser. It is needed so that consent given on one phone does not open the plan on the others, and so that location reports from different devices do not overwrite one another. The marker is a random string, contains no information about a person or a device, and only its irreversible hash — calculated together with the share identifier — is stored in the database, so it cannot recognise the same device in another plan.

To protect links from abuse, the Controller stores — linked to the share, not to a person — the number of failed password attempts together with a temporary lock, and the frequency of writes made from a given connection, with the connection identified by an irreversible hash rather than a stored address.

Visits to plans shared with contractors count towards the same organisation package limit, and on the same terms, as openings of ordinary public plans described above.

Location tracking in plans shared with contractors

An organisation sharing a plan with a contractor may require live location tracking. This is a separate feature from voluntarily showing one's own position in an ordinary public plan, and it processes data more broadly — which is why we describe it separately.

The feature is off by default. If the organisation turns it on, the first time the plan is opened the contractor sees a message naming the organisation that is asking for this, and must deliberately confirm the sharing of location and grant permission in the browser or the device's operating system. Without that the plan will not open. The condition is presented before the plan is opened, so the contractor can choose not to use the link.

Once consent is given, the device supplies the current coordinates and the service stores the device's last known position. What is stored: longitude and latitude, approximate measurement accuracy, the time of the last report, whether tracking is currently active, an irreversible hash of the device marker, and the link to the plan and the contractor. Reports are sent no more often than roughly once a minute.

The Controller:

  • stores only the device's last known position, overwritten by the next report — no trail or history of movement is created,
  • makes the location available only to users of the organisation that shared the plan, and only in that plan,
  • does not pass coordinates to the map provider or to any other third party,
  • does not use location data for profiling,
  • does not use location data for advertising or marketing purposes.

The contractor can turn tracking off at any time with a button in the plan, and also by withdrawing permission in the browser or device settings. Turning it off immediately stops the location from being sent; the plan then returns to the consent screen, because sharing location is an access condition set by the organisation.

The last known position stops being visible and is permanently deleted:

  • automatically, no later than 24 hours after the last report — deletion is handled by a task that runs on a schedule,
  • immediately when the organisation turns off the tracking requirement for that contractor,
  • immediately when the organisation turns off the contractor's access to the plan.

The organisation may also set a date after which tracking turns itself off and the link stops working until it is turned on again.

User geolocation in ordinary public plans

Within a public event plan, the user may voluntarily use a feature that shows their current location on the map. The feature is off by default and starts only after a deliberate action by the user — turning it on in the location-feature window and granting permission in the browser or the device's operating system.

Once the feature is on, the browser supplies the current coordinates and the plan updates the position on the map as the user moves. The coordinates are used only locally, in the browser's memory, for as long as the feature is in use.

The Controller:

  • does not store the user's location in its own database,
  • does not send location coordinates to its own server,
  • does not pass location coordinates to the map provider or to any other third party,
  • does not keep a history of the user's movements,
  • does not use location data for profiling,
  • does not use location data for advertising or marketing purposes.

Turning the feature off in the plan immediately stops reading the location and removes the position from the map. The same happens automatically when the page is closed or refreshed — the feature does not stay on “for next time”, because the fact that it was turned on is not stored anywhere. The user may also withdraw location permission at any time in the browser or device settings. Refusing to share location does not limit use of the public plan — it only means the current position will not be shown on the map.

The Controller's role towards data contained in plans

The content of plans — objects, descriptions, notes, the work schedule and the list of contractors — comes from the organisation using PlanPlace.pl. It decides what goes into the plan, who it is shared with and whether location tracking is required, and it therefore remains the controller of that data. The service Controller processes it on the organisation's instructions, as a processor, only to the extent needed to provide the service and on the basis of the contract concluded with it. This also applies to location transmitted by contractors.

If you have received a link to a plan and want to know for what purpose and on what basis your data is processed in that plan, the right addressee of the question is the organisation that shared the plan; its name is visible in the plan. The service Controller will assist in such a matter and will pass the enquiry on to that organisation.

3. Purpose and legal basis of the processing

Data is processed for the following purposes:

  • contacting a prospective client, arranging a meeting, and preparing and presenting a cooperation offer,
  • ensuring the website, public event plans and plans shared with contractors work correctly,
  • enabling maps and event-plan elements to be displayed,
  • letting the user voluntarily show their current position on the map in an ordinary public plan,
  • letting a contractor read the work schedule assigned to them and mark items as done,
  • passing the organisation the current location of the contractor's devices, if the organisation has set that as a condition of access to the plan,
  • distinguishing devices that use the same contractor link, so that one device's consent and reports are not attributed to another,
  • counting openings of plans in order to settle the package limits of the organisation that shares the plan, and for aggregate statistics,
  • ensuring the security of plans, including protecting password-protected plans and links from automated password guessing and limiting an excessive number of requests,
  • diagnosing technical errors in the application.

For data provided in connection with contact and booking a meeting, the legal basis for the processing is Article 6(1)(b) GDPR — processing necessary to take steps at the request of the data subject prior to entering into a contract.

For the technical data needed to keep the service working correctly and securely, to count plan openings and to diagnose errors, the basis for the processing is Article 6(1)(f) GDPR, that is the Controller's legitimate interest in ensuring the operation, security and proper settlement of the services provided.

Where the voluntary geolocation feature in an ordinary public plan is used, access to location takes place on the basis of the user's decision and the permission granted in the browser or operating system. The Controller does not store that location data in its systems.

For location tracking in a plan shared with a contractor, the Controller processes the data on the instructions of the organisation that shared the plan, on the basis of Article 28 GDPR. It is the organisation that determines the purpose of such processing and its legal basis in the relationship with the contractor, and that is responsible for informing the people who use the link. On the device, access to location takes place only after confirmation by the person using it and after permission is granted in the browser or operating system.

4. Recipients of the data

Data may be passed to service providers used by the Controller, only to the extent needed to keep the service running. They are the following categories of recipients:

  • the provider of the meeting-booking tool embedded on planplace.pl,
  • the provider of hosting infrastructure for the website and the application,
  • the provider of database and file-storage infrastructure, from which the data and graphics displayed in a plan are fetched,
  • the provider of maps and resources needed to display plans,
  • the provider of the tool used to monitor technical errors in the application,
  • the provider of the transactional email service used to send messages needed for the account to work.

The Controller will provide the current list of processors together with their seats on request sent to the email address given in section 1.

Error monitoring is configured so as to limit the information passed on: user-session recording is not used, attaching identifying data to reports — including IP addresses — has been turned off, and access tokens and passwords are stripped from addresses before a report is sent.

Apart from the cases above, data is not passed to third parties except where such an obligation follows from the law.

Using some of the services above may involve processing data outside the European Economic Area. In such cases the transfer takes place on the basis of a European Commission decision finding an adequate level of data protection in the country concerned, or on the basis of other mechanisms provided for by the GDPR, in particular standard contractual clauses approved by the European Commission.

5. How long the data is stored

Data provided in connection with contact or booking a meeting will be stored for as long as needed to pursue the contact and offer purposes, but no longer than 12 months from the moment it was provided, unless cooperation is established — in that case the data will be stored in accordance with the applicable law.

The Controller does not store in its systems location data obtained through the voluntary geolocation feature in an ordinary public plan. The current location is used on the user's device only while that feature is in use.

The last known position of a device transmitted as part of location tracking in a plan shared with a contractor is stored for no longer than 24 hours from the last report, and before that time it is deleted immediately when the organisation turns off the tracking requirement or turns off the contractor's access to the plan. A history of earlier positions is not stored, because each report overwrites the previous one.

Visit identifiers used to count plan openings are stored only for as long as needed to recognise a return of the same visit, after which they are deleted; what remains are only aggregate monthly opening counts, which contain no data identifying visitors. Information about failed password attempts, about the temporary lock and about request frequency is stored only for as long as needed for the safeguard to take effect.

Technical data processed by external infrastructure providers may be stored for a period that follows from their own data-processing rules and privacy policies.

6. Your rights in connection with the processing of data

In the cases provided for by the GDPR you have the right to:

  • access your personal data,
  • rectify the data,
  • erase the data,
  • restrict the processing,
  • object to the processing,
  • data portability,
  • withdraw consent, if the processing is based on it,
  • lodge a complaint with the President of the Personal Data Protection Office.

For matters related to exercising the rights above you can contact the Controller at: unicornitydesign@gmail.com.

If the matter concerns data contained in a plan shared by an organisation — including location transmitted under a contractor link — the request is directed to that organisation as the controller of that data, and the service Controller provides it with the technical assistance needed.

7. How the data is secured

The Controller applies appropriate technical and organisational measures aimed at protecting personal data against loss, unauthorised access, disclosure, alteration or destruction. Communication with the service takes place over an encrypted connection.

Access to a public plan requires having the full link with the access token, and optionally also a password set by the plan owner. A plan shared with a contractor requires a separate link, issued only for that contractor, and — if the organisation so sets — a separate password. The plan owner may at any time turn access off or generate a new link, which immediately invalidates the previous one; they may also set a date after which location tracking turns itself off. Turning access off, or the expiry of the organisation's rights to use the service, closes all links issued by it.

Data used to recognise visits, devices and connections is stored only in the form of irreversible hashes, not as original addresses or identifiers.

8. Cookies and similar technologies

Public plans and plans shared with contractors

PlanPlace.pl does not set any cookies as part of an event plan. The service does not use analytics, advertising or tracking tools such as Google Analytics, Google Ads, Meta Pixel, TikTok Pixel, Microsoft Clarity or Hotjar, and it does not build visitor profiles.

A plan uses browser-storage mechanisms, all of them needed to deliver a service expressly requested by the user:

  • the browser's local storage (localStorage) — remembers the interface language chosen by the visitor themselves in the language switcher. If the visitor makes no such choice, we store nothing, and the interface language is determined on every visit from the current browser settings;
  • the browser's local storage (localStorage) — only in plans shared with contractors, stores the random device marker described in section 2. It is needed so that consent to share location and reports from one device are not attributed to other devices using the same link. The marker contains no data about a person, is not used for analytics or marketing, and cannot recognise the device outside that one share;
  • the map-resource cache (Cache Storage) — stores downloaded map tiles, fonts and icons in order to limit data transfer and speed up display of the plan. Only graphic map resources are stored in it; the storage keys contain no user identifiers or session identifiers.

Because the mechanisms above serve only to deliver a feature the user asks for, and are not used for analytics, marketing or tracking in the marketing sense, their use falls within the exception provided for in Article 399 of the Polish Electronic Communications Law and in Article 5(3) of Directive 2002/58/EC and does not require the user's consent. For that reason no cookie-consent window is shown in the plan.

The user may delete the contents of the browser's storage at any time in their browser settings. Deleting the device marker in a contractor plan only means that on the next visit the device will be treated as new and will again ask for confirmation of location sharing. Location features do not use cookies or browser storage to determine and keep the position.

Displaying the map involves fetching resources from the map provider's infrastructure, which — like any internet connection — includes sending that provider standard technical data such as an IP address and information about the map elements being fetched.

The planplace.pl website

The site sets one first-party cookie — NEXT_LOCALE — which is used to remember the language chosen for the service. It is functional in nature and is necessary for the site to work correctly; it is not used for analytics or marketing.

The site uses anonymous visit analytics from Vercel Web Analytics. It does not set cookies, does not identify people and does not build visitor profiles. It only counts page views in aggregate.

Opening the meeting-booking window, which happens only after an action by the user, may result in cookies being set or similar technologies being used by the booking-tool provider, to the extent needed to handle the booking and in accordance with the rules set by that provider.

9. The nature of plans and the accuracy of location

Event plans are informational and auxiliary in nature. Where a location feature is used, the accuracy of the position shown on the map depends among other things on the user's device, GPS signal quality, the availability of Wi-Fi or mobile networks, system settings, the browser and surrounding conditions. PlanPlace.pl does not guarantee full accuracy of the position indicated on the map.

The same applies to location tracking in plans shared with contractors. Reports may be delayed or fail to arrive when the device loses coverage, is locked, or the browser is put in the background. The position visible on the map is always the last known position, not a confirmation of the current whereabouts.

Location features should not be treated as a professional navigation system, an emergency system, or as the sole source of information in situations related to safety or evacuation.

10. Changes to the Privacy Policy

The Privacy Policy may be updated if the features of PlanPlace.pl, the services used, the law, or the way data is processed change. The current version of the Privacy Policy is always available on the PlanPlace.pl website.