Release details
Current published document
- Version
- 1
- Published
- August 23, 2026
- Effective
- August 23, 2026
Privacy, Misuse and Dispute Procedure
Effective date: 21 August 2026
This is Planique's public email-first procedure for privacy requests, misuse concerns and related disputes. It supplements the Privacy Notice and does not replace a right or remedy provided by applicable law.
Planique is operated by Cropol Labs d.o.o., Ulica sv. Ane 30A, 31000 Osijek, Croatia, company number 030322161.
1. When to use this procedure
Use it to raise:
- a privacy inquiry, complaint or data-rights request;
- a claim that a Planique profile or record may concern you;
- suspected stalking, harassment, surveillance, coercion or abusive use;
- suspected professional, employer, insurer, credit, institutional, research or commercial use of a private vault;
- an account-age concern;
- a dispute about restriction, correction, deletion, suspension or account action;
- a Washington or Nevada consumer-health appeal; or
- a question or request from a regulator, court or competent authority.
Planique does not provide an in-app evidence uploader or store complaint text, identity documents or source evidence in the ordinary Planique application database.
2. How to contact Planique safely
Use Contact Planique or write to planique.planner@gmail.com.
Initially provide only:
- a safe way to contact you;
- the general nature of the issue;
- the outcome or right you want considered;
- an account or case reference already known to you, if relevant; and
- whether there is an urgent risk to a person.
Do not initially send Health records, financial information, private-vault exports, passwords, authentication tokens, verification codes, identity documents or authority documents. The contact form accepts no attachments and is not intended for sensitive information. If additional material is genuinely necessary, Planique will explain why and arrange a controlled follow-up route.
This route is not an emergency service. Contact the appropriate local emergency or law-enforcement service if there is an immediate threat to safety.
3. Intake and neutral response
The Privacy Officer opens a restricted case reference and acknowledges the message. The case records only the minimum necessary classification, dates, identity or authority result, deadline, scope, decision and safe correspondence. Private-vault content is not copied into an ordinary ticket.
If you claim to be represented in another person's vault, Planique's response is neutral. We do not confirm or deny that a matching account, profile or record exists until identity, entitlement, confidentiality, safety and the rights of everyone involved have been assessed.
4. Identity and authority
For an account holder, Planique prefers an existing authenticated session and recent or step-up authentication. If account access is unavailable, we may use control of the registered email and limited account information where the risk permits.
If additional verification is reasonably necessary, Planique requests the least intrusive proportionate evidence and explains why. Health, Budget, Journal or other vault information is never used as an authentication question.
For an authorized agent, guardian or represented-person concern, Planique separately assesses identity, authority, scope, the right or safety interest invoked, the account holder's confidentiality, other people's rights and whether legal advice or a competent-authority decision is required. We do not give an agent access beyond the authority demonstrated.
Identity and source-evidence copies are kept in a restricted process only as long as necessary and normally no later than 30 days after verification or case closure, unless a documented legal hold applies.
5. Risk assessment and temporary measures
Planique assesses urgency, credibility, sensitivity, possible harm and whether continued processing could make the situation worse. A proportionate temporary measure may:
- restrict an affected profile, module or account;
- stop new entries, changes, reminders, exports or derived processing;
- preserve only necessary evidence under a documented legal hold;
- seek an explanation from the account holder where safe and appropriate;
- prevent disclosure while competing rights are assessed; or
- escalate to the Privacy Officer, Security Incident Owner, qualified counsel or a competent authority.
Planique does not automatically contact an account holder if doing so could create risk, compromise an investigation or disclose protected information.
6. Assessment and possible outcomes
The decision-maker considers Planique's current Terms and legal notices, the account holder's declarations, applicable privacy, consumer, health and safety law, the evidence, necessity and everyone's rights. An outcome may include:
- no action where the concern is not substantiated;
- correction or an invitation to the account holder to correct information;
- continued restriction while a lawful process is completed;
- minimization or deletion of specific information;
- Planique deletion where authorized and necessary;
- module or account suspension or termination for misuse;
- a limited disclosure where law authorizes it;
- a reasoned refusal or partial response with a review, appeal or complaint route; or
- referral to a regulator, court or other competent authority.
Planique will not disclose an account holder's entire vault merely because a requester may be mentioned in it.
7. Account-holder review and appeals
Where practicable and lawful, an account holder affected by a restriction is told the general reason, whether the measure is temporary or permanent, and how to request review. Information may be withheld where necessary to protect a claimant, security, an investigation, legal privilege or another person's rights.
To challenge a decision, reply using the case reference and state the outcome you want reviewed. For a Washington consumer-health appeal, include Washington consumer health appeal. For a Nevada consumer-health appeal, include Nevada consumer health appeal. Planique conducts a fresh review and provides the applicable regulator or Attorney General route if an appeal is denied.
8. Response times
Planique records deadlines from receipt and responds under the shortest applicable compatible rule:
- GDPR requests are handled without undue delay and normally within one month. A lawful extension of up to two further months may apply for complexity or volume, with notice and reasons within the first month.
- Washington consumer-health requests are handled within 45 days from receipt, subject to one permitted 45-day extension with timely notice and reasons.
- Nevada consumer-health requests are handled within 45 days after authentication, subject to one permitted extension; authenticated deletion is scheduled within the applicable 30-day period.
- Other jurisdictions may apply a different period.
Urgent safety and active-security matters are triaged sooner. An acknowledgement is not a promise that every dispute will be finally resolved within a fixed period.
9. Secure fulfilment
Planique provides an account holder's data copy through the authenticated, reviewed export process—not as an email attachment or permanent email link. A prepared archive remains protected and available for up to 48 hours; each generated download URL lasts about 60 seconds.
Record, profile, Health and account deletion use the relevant authenticated control or reviewed operator procedure. Deletion includes related Planique-created information, reminders, Calendar items, known files and applicable provider follow-up within the selected scope. A narrow legal record may remain only where a binding duty or documented hold requires it.
10. Case records and retention
Planique ordinarily keeps privacy-request records and minimized privacy or misuse case records for three years after closure. A genuine dispute or claim subset may be kept for five years after final closure, subject to applicable limitation rules and annual review. Source identity or authority evidence is deleted under the 30-day rule described above.
The minimized case record does not contain a copy of the vault. It records only the necessary allegation, scope, identity or authority result, decision, communication, restriction and evidence-deletion outcome.
11. Regulatory and legal routes
Using this procedure does not stop you from contacting a regulator, court, law-enforcement body, app-store remedy or another competent authority and does not pause a statutory deadline.
For GDPR matters, you may contact the supervisory authority where you live or work or where you believe an infringement occurred. Planique's Croatian authority is the Croatian Personal Data Protection Agency (AZOP). Canadian and US residents may use the privacy, consumer-protection or Attorney General route applicable to their location.
12. Contact
Privacy Officer: Chief Executive Officer, Cropol Labs d.o.o.
Email: planique.planner@gmail.com
Address: Ulica sv. Ane 30A, 31000 Osijek, Croatia