Skip to main content
EirePlan

Eireplan Data Processing Terms

The Article 28 terms that apply when you upload personal data about other people into Eireplan. Incorporated into the Terms of Service, so no separate agreement is needed.

This Terms of Service was published on 31 August 2026

Cover image for Eireplan Data Processing Terms

Version: dpa-2026-08-31 Last updated: 31 August 2026 Contact: privacy@eireplan.ie

These Data Processing Terms form part of the Terms of Service and satisfy Article 28(3) of the General Data Protection Regulation. They apply automatically, with no separate signature, whenever you upload or enter personal data about other people into EirePlan.

You do not need to negotiate a separate data processing agreement with us. If your organisation requires one on its own paper, contact privacy@eireplan.ie.

1. When these terms apply, and who is who

Planning work involves other people's personal data. An application names an applicant. A submission names an objector. A report names a neighbour, a landowner, a consultant. When you put that material into EirePlan, two roles arise:

  • You are the controller. You decide why the data is there and what happens to it. You are responsible for having a lawful basis, for telling those people what you are doing through your own privacy notice, and for the accuracy of what you upload.
  • We are the processor. We hold and process it on your behalf, and only as you instruct.

Where we process personal data about you as our customer, for example your account, your billing and your use of the platform, we are the controller and the Privacy Policy applies instead. These terms do not cover that.

Where we process the public planning register for our own purposes, we are the controller of that processing, on the basis set out in section 15 of the Privacy Policy. These terms do not cover that either, and nothing here makes you responsible for it.

2. Our instructions

We will process personal data only on your documented instructions, which are:

  • The Terms of Service and these terms.
  • Your use of the platform's features, which is itself an instruction to carry out the processing that feature performs.
  • Any further written instruction you give us that we agree to.

This includes transfers to a third country, which are covered by section 7.

If we are required by European Union or Irish law to process personal data other than on your instructions, we will tell you before doing so, unless that law prohibits us from telling you.

We will tell you if, in our opinion, an instruction infringes data protection law. We may suspend the instruction until it is resolved. We are not obliged to give you legal advice, and telling you is not a warranty that your other instructions comply.

3. Confidentiality

We will keep personal data confidential. Everyone we authorise to process it is bound by a duty of confidentiality that survives the end of their engagement, and is given access only to what their role requires.

4. Security

We implement the technical and organisational measures set out in Annex 2, which are appropriate to the risk under Article 32. We may change them, provided the level of protection is not reduced.

You are responsible for the security decisions within your control, including who you invite into your organisation, what role you give them, the strength of your own credentials, and the security of the devices you use.

5. Sub-processors

You give general authorisation for us to engage sub-processors. The current list is in Annex 3, and it is the same list published in the Privacy Policy.

We will give at least 30 days notice in the Privacy Policy before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period by writing to privacy@eireplan.ie. If we cannot resolve your objection, you may terminate the affected part of the service and receive a pro rata refund of fees paid in advance. Continuing to use the service after the notice period is acceptance.

We impose data protection obligations on each sub-processor that are no less protective than these terms, and we remain fully liable to you for their performance.

6. Helping you meet your obligations

Data subject requests. If a person contacts us directly about data you control, we will not respond substantively. We will tell you promptly and leave the response to you. Taking into account the nature of the processing, we will help you respond, by providing the tools in the platform to search, export, correct and delete, and by reasonable further assistance where the tools are not enough.

Breach notification. If we become aware of a personal data breach affecting data we process for you, we will tell you without undue delay, and in any event within 48 hours of becoming aware. We will give you the information you need to meet your own obligation under Article 33, including the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures taken. We will not notify your supervisory authority or your data subjects on your behalf unless you ask us to in writing.

Impact assessments. We will give you reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, as they relate to our processing.

7. International transfers

Personal data you upload is stored in Ireland and processed by applications running in Belgium.

Some sub-processors in Annex 3 operate from outside the European Economic Area. For each of those, transfers are made under the European Commission's Standard Contractual Clauses, incorporated by reference into our agreement with that sub-processor and into these terms, and where applicable under the EU to US Data Privacy Framework. We have carried out transfer impact assessments and apply supplementary measures including encryption in transit and minimisation of what is sent.

Where the Standard Contractual Clauses apply between you and us, Module Two, controller to processor, applies, the governing law is Irish law, the forum is the courts of Ireland, and the annexes to those clauses are the annexes below.

8. Deletion and return

You can export your data from the platform at any time.

On termination, we will make your data available for export for 30 days. After that period we will delete it, including from our systems and those of our sub-processors, within a further 30 days, except to the extent that European Union or Irish law requires us to keep it, in which case we will keep it only for as long as required and will continue to protect it under these terms.

Encrypted backups are overwritten on a rolling cycle of up to 30 days. Data in a backup is not restored to live systems after deletion.

We will confirm deletion in writing on request.

9. Audit

We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will contribute to audits.

In practice, we will first provide written responses to a reasonable security questionnaire, and any current certifications or reports we hold. If that is genuinely insufficient for you to meet a regulatory obligation, you may audit us, on 30 days written notice, no more than once a year unless a regulator requires otherwise or a breach has occurred, during business hours, subject to confidentiality, without access to other customers' data, and at your cost.

10. Liability

Liability under these terms is subject to the limitations in clause 20 of the Terms of Service, except where that is not permitted by Article 82 or by the Standard Contractual Clauses, which give data subjects rights that no contract between us can limit.

Nothing in these terms limits a data subject's right to compensation, or a supervisory authority's powers.

11. Order of precedence

Where these terms conflict with the Terms of Service on the subject of processing personal data on your behalf, these terms prevail. Where they conflict with the Standard Contractual Clauses, those clauses prevail.


Annex 1: Details of the processing

Subject matter. Provision of the EirePlan planning platform.

Duration. For as long as your account is open, plus the deletion periods in section 8.

Nature and purpose. Hosting, storage, organisation, retrieval, indexing, search, structuring, analysis, text extraction from documents, AI assisted summarisation and drafting, report generation, backup, and support, all in order to provide the platform to you.

Types of personal data. Determined by what you upload. Typically: names, postal addresses, eircodes, email addresses, telephone numbers, professional roles and affiliations, signatures, correspondence, and any personal data contained within planning documents, drawings, reports, submissions and decisions.

Categories of data subject. Applicants, agents, architects, engineers, consultants, objectors and observers, neighbours and third parties named in submissions, landowners, your own staff, and your clients.

Special category data. Not expected. The platform is not designed for it and you should not upload it. If you do, you remain responsible for the additional conditions in Articles 9 and 10.

Annex 2: Technical and organisational measures

Encryption. TLS for all data in transit. Encryption at rest for the database, file storage and backups.

Access control. Multi-factor authentication on production systems. Role based access within the platform at organisation and project level. Administrative access limited to those who require it and logged. Credentials and secrets held in a managed secret store, never in source control.

Separation. Customer data is separated by organisation and project, enforced in the application layer, which is the only path to the database. The database denies direct access by default and is not reachable from the public internet by client applications.

Resilience and recovery. Managed database with point in time recovery. Automated backups retained on a rolling cycle. Infrastructure defined in code so that services can be rebuilt.

Monitoring. Application and access logging, error reporting, and automated dependency vulnerability alerts.

Development. Code review before merge, automated testing and build checks, and separated preproduction and production deployments.

People. Access limited to the smallest number of people necessary, each bound by confidentiality.

Vulnerability reporting. A published contact at security@eireplan.ie and a commitment not to pursue good faith researchers.

Annex 3: Sub-processors

Sub-processorPurposeLocation
Supabase, on Amazon Web ServicesDatabase and file storageIreland
Google Cloud PlatformApplication hostingBelgium
Google Firebase AuthenticationIdentity and sign-inEuropean Union and United States
CloudflareWebsite delivery, DNS, network protectionGlobal edge network
OpenRouterRouting to large language model providersUnited States
OpenAIText embeddings for searchUnited States
ResendTransactional emailUnited States
StripePayment processingIreland and United States
Google Maps PlatformGeocoding of addresses you searchUnited States

Product usage is measured on our own servers rather than by a third party analytics provider, so no analytics processor appears in this list.