Skip to content
PlanogramaWMS

Legal

Terms, privacy and cookies — in plain sight.

What governs this website, what happens to the data you send through it, and the choices you control over what runs on your device. Written to be read, not skimmed past.

Last updated

October 1, 2026

Version

1.1

Applies to

planograma.com

Who we are, and what this notice covers

In short

Planograma S.R.L. in Bucharest decides what happens to the data this website collects. Data protection goes to [email protected]; everything else to [email protected].

The controller for personal data collected through planograma.com is Planograma S.R.L., 41 Mehadia Street, District 6, 060541 Bucharest, Romania, registered under tax identification number 25520068 and trade register number J2009005627409.

We have a data protection officer. Anything to do with this notice — a question, a request to see your data, a deletion request, a complaint about how we handled any of it — goes to [email protected], and that address reaches the officer.

[email protected] is the general address, the one the contact, support and careers pages use. Write there about the product, an enquiry, support or a job. Send a data request to it and nothing is lost — it is passed on — but dpo@ is the shorter route.

This notice covers this website. The Planograma WMS application is outside it: what your team enters into your own workspace is covered by your contract with us, not by this page.

What you give us

In short

What you type into one of the five forms, or write to us by email, say on the phone, or send as a CV — and the few technical details a form carries with it. What the measurement tools collect is a section of its own.

This section is about what you hand over yourself. There is no account to create here, no login, no newsletter, no file upload and no payment: five forms are the only things that ask you for anything, and each one names Planograma S.R.L. as the controller and links to this notice beside its submit button. The measurement tools are a different matter — they collect what a browser does on a page rather than what you type, they run only if you allow them, and the section after next sets them out.

FormYou have to fill inYou can add if you want
Book a demo — opens on every pageName, email address, and the tick boxCompany, phone, team size, what you would like to see
ContactSubject, picked from a list, plus name, email address and your messageCompany, phone
SupportCategory, name, email address, a description of the problemCompany, phone, and urgency — which is pre-set and sent as it stands unless you change it
IntegrationsType of integration, the platform, name, email addressCompany, phone, what you move through it
PartnersName, company, email addressPhone, notes about your clients, and the programme — which is pre-set to reseller unless you change it

The fields in the first column have to be filled in before the form will send, and on the demo form the tick box has to be ticked as well. Everything in the second column is optional; leaving it out changes nothing except how much we know when we reply. None of it is required by law or by a contract with us. You give it so that we can come back to you.

The message boxes are free text, so what goes in them is up to you. We do not need health, political, religious or other special-category data, and we ask you not to put it there.

If your message names someone else — a colleague, a customer, a client you want to refer — we use those details only to answer your request, keep them with the enquiry and delete them with it. We have no way to reach those people ourselves, so please tell them before you put their details in the box. If one of them writes to us, they have every right listed further down this page.

Email, the phone and the careers pages work the same way. Write to [email protected] and we hold whatever you chose to include, attachments and all. Call the number on the contact page and anything we note from the call is kept with the enquiry. Apply for one of the roles and you email your CV to the same address — a CV usually carries more than a form does, an address, a date of birth, sometimes a photograph, so send only what you want us to have.

Serving a page also leaves a trace at our hosting provider, as on any website: typically the IP address the request came from, the time, the page requested and the browser's user agent. Those logs are the provider's. Our own code writes none and keeps none.

Sending a form is different. Along with what you typed, it carries a few details your browser supplies rather than you: the IP address it was sent from, the browser's user agent, the page and the language it was sent in, and the date and time. They travel with your enquiry, are kept with it and are deleted with it. The next section says why.

Why we use it, and on what legal basis

In short

To answer the enquiry you sent, to deal with a job application, and — only if you allow it — to measure how the site is used. Each of those rests on a basis named below.

  • Answering your enquiry — We read what you sent, reply to it, and carry on the conversation you started — by email, or by phone if you gave us a number. The basis is our legitimate interest under art. 6(1)(f) GDPR, and the interest is plain: you wrote to us about our product, and a company that sells warehouse software has to be able to answer the people who ask about it and follow the enquiry through. You chose what to tell us, we use it for nothing but the enquiry, and you can object at any time.
  • The technical details a form carries — The IP address, browser, page, language and time that come with a form are kept with the enquiry so that we can see where it came from and recognise submissions that are automated or abusive. To stop the forms being flooded, the site also counts submissions from each address for an hour, holding a scrambled form of the address in memory rather than the address itself, and keeps nothing of it once the hour is up. The basis is our legitimate interest under art. 6(1)(f) GDPR in answering real enquiries and keeping the forms from being misused. These details are not used to follow you anywhere else and are not joined to anything.
  • When you are personally the other side of the deal — If you write as a sole trader, a freelancer, or a referral partner signing in your own name, the contract would be with you rather than with an employer. Then the basis is art. 6(1)(b) — steps taken at your request before a contract. On the ordinary business enquiry, where you are writing for your company, it is the legitimate interest above.
  • The tick box on the demo form — "I understand Planograma will contact me about this request" is how you ask us to get in touch about the demo you are requesting. It is not marketing permission, and we do not treat it as consent under art. 6(1)(a): there is no newsletter, no mailing list and no marketing programme here to join. The request is handled under the legitimate interest above, and one line to [email protected] stops us contacting you.
  • Telling you something about this site or your request — If something needs telling — this website or one of its forms changes in a way that affects what you sent, or there is a security problem touching it — we write to the address you used. These messages are not marketing, there is no list to be added to and nothing to unsubscribe from: each one exists because of something you did here. The basis is our legitimate interest under art. 6(1)(f) in keeping the people who wrote to us correctly informed.
  • Measuring how the site is used — If you allow it, a set of tools counts visits and records how the pages are used: which page was opened, what was clicked, how far down it was read, which campaign or search brought the visit here, and — with two of them — a replay of the movement across a page. The basis is your consent, art. 6(1)(a) GDPR, given through the cookie banner. Nothing of the kind loads before you give it, and taking it back in Cookie settings stops it. Withdrawing does not make what went before unlawful. The cookie policy names every tool, every cookie and how long each one lasts.
  • Measuring advertising, and recognising the company behind a visit — The same consent covers the advertising side of it: tags from Meta, LinkedIn and Google that tell those companies a page here was opened, so that a campaign can be measured, and a service that takes the IP address a visit came from, matches it against a database of business networks and tells us which company it belongs to. Neither runs before you accept, and neither is given anything you typed into a form.
  • Job applications — If you send a CV, we use it to assess you for the role you applied for. The basis is art. 6(1)(b) — steps taken at your request before an employment contract, where the contract would be with you. Asking us to keep your CV for future openings is separate, and that rests on your consent, art. 6(1)(a). You can take it back in one line to the same address, and taking it back does not affect anything we did before.
  • Keeping the site up — Our hosting provider keeps request logs so that pages can be served and attacks can be detected. Where we rely on those logs, the basis is our legitimate interest under art. 6(1)(f) in a site that stays online and is not under attack. They are not read to build a picture of you, and nothing is joined to them.
  • Accounting — If an enquiry turns into a contract, the invoices and accounting records that follow are kept because Romanian law requires it — art. 6(1)(c). Nothing on this website takes a payment, so until there is a contract this does not touch you.

That is the list. What you send us is not used to train anything and is not passed to anyone for purposes of their own. The measurement tools are the one place where another company receives something on its own account, and nothing you typed is part of it — the cookie policy says what each of them gets.

What runs only if you allow it

In short

Nothing is set on your device and nothing is fetched from another company until you answer the banner. Accept and a set of measurement and advertising tools runs. Refuse and the site works exactly as it did.

Until you answer the cookie banner, this website sets no cookies and loads nothing from anyone else. Open a page with the network panel recording and every request on it goes to planograma.com.

One thing is stored on your device: the answer you gave the cookie banner, under the key planograma.consent in your browser's local storage. It holds three true or false values, the moment you chose them, and a version number. There is no identifier in it and nothing that names you, and it never leaves your browser — local storage is not sent with requests. It is not a cookie, and storing it needs no consent: it is strictly necessary, because it exists only to carry out the choice you made. It stays until you clear site data for planograma.com, or until we change the categories and ask you again. Change it whenever you like from Cookie settings — the buttons on the cookie policy, or the small cookie button in the bottom-right corner of every page once you have answered the banner.

Answer yes and a Google Tag Manager container loads, and with it the tools it holds: Google Analytics and Google Ads, the Meta pixel, the LinkedIn Insight Tag, Microsoft Clarity, Hotjar, theMarketer and Lead Forensics. What each one does, what it puts on your device and how long it stays there is set out tool by tool and cookie by cookie in the cookie policy.

Two of them — Microsoft Clarity and Hotjar — record how a page is used and can play that back: the movement of the pointer, the clicks, how far it was scrolled. What is typed into a form is masked by those tools and is not part of the recording.

One of them — Lead Forensics — takes the IP address a visit came from and matches it against a database of business networks, so that we can see which companies read the site. It is built to name an organisation rather than a person; where in practice the two come to the same thing, everything in this notice applies to it as it does to anything else here.

Refuse, or simply leave the banner unanswered, and none of that happens. Every page, every form and every link works exactly the same.

The one measurement we look at works the other way round. Google Search Console tells us how planograma.com appeared in Google's own search results — which searches showed the site, how often people clicked. Those are Google's aggregated statistics about its search engine, reported to us as the owner of the site. It runs no code on these pages, stores nothing on your device, and collects nothing from your visit here.

There is no automated decision-making and no profiling that produces a legal effect for you: nothing here decides anything about you, scores you or sorts you. No payment is taken on this site. The two typefaces are served from our own domain, so opening a page asks Google for nothing at all until you have accepted.

Who else sees it

In short

Four providers handle your enquiry — hosting, email, a workflow service that carries it into the CRM, and the CRM itself — each under a written agreement. If you accept the banner, the measurement companies see that a page was opened, and nothing you typed.

What you type into a form comes to us by email and goes into the customer relationship system our sales team works from, so an enquiry does not sit unread in one person's inbox. Four kinds of provider are involved in that. We describe them by category rather than by brand.

  • Website hosting — serves the pages and holds the request logs described above.
  • Email — carries and stores the messages you send us, the CVs that arrive, and the replies we send back.
  • Workflow automation — carries each form from the website into the CRM, so that an enquiry arrives as a record rather than as an email someone has to copy across. It keeps a record of what it passed on for a limited time, so that a transfer that failed can be found and sent again.
  • Customer relationship management (CRM) — holds your enquiry and our notes on it, so that it can be followed up.

We have a written data processing agreement with each of them under art. 28 GDPR. They act on our instructions, for the purposes above, and may not use what you sent for anything of their own.

Accepting the cookie banner brings in a second group, there for a different reason: not to handle your enquiry but to measure the site. They see that a browser opened a page here — which page, when, where from — and nothing you wrote to us.

  • Analytics and advertising — Google Ireland Limited for Analytics and Ads, Meta Platforms Ireland Limited for the pixel, LinkedIn Ireland Unlimited Company for the Insight Tag.
  • Recording how pages are used — Microsoft Ireland Operations Limited for Clarity, and Hotjar Ltd in Malta.
  • Marketing automation — theMarketer, in Bucharest.
  • Identifying the company behind a visit — Lead Forensics, in the United Kingdom.

With the Meta pixel and the LinkedIn Insight Tag, we and those companies decide together what is collected on this site and sent to them — art. 26 GDPR calls that joint control — and what they do with it afterwards is governed by their own notices, which the cookie policy links to. The rest act on our instructions under art. 28 agreements, in the same way as the four above; where one of them also uses what it receives on its own account, its own notice says so.

We do not sell personal data, and nothing you wrote to us goes to anyone for purposes of their own. The advertising tags tell Meta, LinkedIn and Google that a page on this site was opened; they are not given your message, your CV, or anything else from a form.

Two things can take it further, and only these two. The law obliging us to — a request from a competent authority or an order of a court. And a legal claim: if one is brought, or we have to bring one, we may use and disclose what we hold to establish, exercise or defend it, which is the same situation the retention section below describes when it says a record stays while a claim is live. Beyond those two, your data goes to someone else only if you ask us to send it.

How we protect it

In short

Encrypted on the way to us, seen by the people dealing with your enquiry, and held by providers under a written agreement that requires them to keep it secure.

Art. 32 GDPR asks for measures appropriate to the risk. Here is what that means on a website with no account and no database of visitors.

Every page and every form on planograma.com is served over HTTPS, so what you type is encrypted between your browser and us.

The website itself keeps nothing. There is no account, no visitor database and no copy of your message held on the site — what you send goes to the inbox and the customer relationship system described above, and that is where it lives.

Inside the company, your enquiry is seen by the people who deal with it: the colleague who answers you, and, if it goes that far, the people handling the contract. A CV is seen by the people hiring for that role. It is not open to everyone by default.

Outside it, each of the four kinds of provider above works under the written agreement described in the last section, which obliges it to keep what it processes secure and to help us do the same.

No website is perfectly safe and we will not claim otherwise. If you think something has gone wrong with data you sent us, write to [email protected] and say so.

How long we keep it

In short

Enquiries until there is plainly nothing left to follow up. CVs until the role is filled. Accounting records for as long as Romanian law requires.

Nothing is kept longer than it is needed for. The test is whether there is still a reason to hold it — your enquiry live, a contract running, a claim still possible, or the law requiring it. Each kind of data has its own rule, and the rule is the one we act on.

  • What you sent, and our record of it — kept while we are dealing with your enquiry, and while a commercial relationship is still in prospect. Once it plainly is not — no reply, no follow-up, nothing left to discuss — the message and the CRM record are deleted.
  • If you become a customer — your contact details stay for as long as the contract runs, and afterwards for as long as a claim under it can still be brought.
  • Job applications — a CV is deleted once the role is filled and the hiring is settled — unless you asked us to keep it for future openings, in which case we keep it until you tell us to stop.
  • Invoices and accounting records — kept for the period Romanian accounting law sets for each kind of document.
  • Server logs — kept by our hosting provider under its own retention schedule, and no longer than it needs them to run and secure the service. We do not copy them, and we keep none of our own.
  • What the measurement tools collect — held by each of those companies under its own retention schedule, not by us — we keep no copy and work from the reports in each tool. The cookies they leave on your device last from a day to a little over a year, and the cookie policy gives the figure for every one of them.
  • Your cookie choice — stays in your browser until you clear site data, or until we change the categories and ask again. It is not a record we hold.

At the end of a period the record is deleted — or anonymised, so that what is left cannot be traced back to you. Once it is anonymised it is no longer personal data and this notice no longer applies to it.

Ask us to delete something sooner and we will, unless an accounting record or a live legal claim means we have to keep it.

Where it is processed

In short

Handled by the providers above. A transfer outside the EEA runs on the Commission's standard contractual clauses, or on the Data Privacy Framework where the company is certified under it. [email protected] will tell you how it stands for your data.

We are a Romanian company, and what you send us is handled by the four kinds of provider described above.

Where one of them processes data outside the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses — the safeguard set out in art. 46 GDPR — or, where the company is certified under the EU–US Data Privacy Framework, on the adequacy decision behind it.

The measurement tools, if you accept them, are contracted through European companies: Google, Microsoft, Meta and LinkedIn through their Irish entities, Hotjar in Malta, theMarketer in Romania, Lead Forensics in the United Kingdom. Where what they collect reaches the United States it travels on one of the two safeguards above.

Write to [email protected] and we will tell you how that stands for your data, which provider is involved, and send you a copy of the clauses that cover it.

Your rights

In short

Access, correction, deletion, restriction, objection, portability, withdrawal and complaint — free, and all through [email protected].

Access

Ask whether we are holding anything about you and, if we are, what it is, why we have it — and get a copy. Art. 15 GDPR.

Rectification

Have anything wrong or out of date put right, and anything incomplete completed, including by adding a statement of your own. Art. 16 GDPR.

Erasure

Ask us to delete your enquiry or your CV, and we do it without undue delay — unless an accounting record or a legal claim stands in the way. Art. 17 GDPR.

Restriction

Have us hold your data without using it while a question about it is settled. Art. 18 GDPR.

Objection

Object to anything we do on the basis of legitimate interest, on grounds relating to your situation. We stop unless we can show compelling grounds. Art. 21 GDPR.

Portability

Where we hold what you gave us on the basis of your consent or a contract with you, receive it in a structured, machine-readable file — and have it sent straight to someone else where that is technically feasible. Art. 20 GDPR.

Withdraw consent

Where we asked for your consent — the measurement tools behind the cookie banner, or keeping your CV for future openings — take it back at any time. The banner answer changes in Cookie settings, the CV in one line to us. It does not make what we did before unlawful. Art. 7(3) GDPR.

Complain

Take it to a supervisory authority: where you live, where you work, or where you think the problem happened. Art. 77 GDPR. The Romanian authority is named in the next section.

The right to object gets its own paragraph, because the law asks us to point it out separately. Most of what we do with your enquiry rests on legitimate interest, and everything optional rests on your consent, which you can take back at any time. You can object for reasons to do with your situation, and we stop unless we can show compelling grounds that override yours. If you simply do not want to hear from us about Planograma again, you need no reason at all: say so, and we stop.

To use any of these, write to [email protected] and say what you want. [email protected] reaches us too and the request is passed on, so you do not have to pick the right one. There is no form to fill in and no particular wording. We may ask you something to check you are the person the data is about before we send anything out. We answer within one month of receiving the request; if it is genuinely complex we may take up to two months more, and we will tell you inside the first month if that happens.

It costs nothing, unless a request is manifestly unfounded or excessive — repeated for the sake of it, say — which the GDPR lets us charge a reasonable fee for, or refuse. If we refuse, we tell you why, and we tell you that you can complain to the supervisory authority and go to court.

Contact and complaints

In short

[email protected] for anything to do with your data, [email protected] for everything else. ANSPDCP if we let you down.

Everything about your data goes to [email protected] — questions about this notice, requests to use the rights above, questions about where your data is processed, and complaints about how we handled any of it. Our data protection officer reads that address.

[email protected] is for everything else: the product, an enquiry, support, a job application, a contract. It is the address the contact, support and careers pages use. A data request sent there reaches the same people — the two addresses are a convenience, not a maze.

If you want to complain to us first, tell us what went wrong and what you would like done about it. We look at it ourselves and answer on the same clock as a request: within one month of receiving it, and we say what we have changed. If it is genuinely complex we may take up to two months more, and we tell you inside the first month if that happens.

You do not have to come to us first. If you are not satisfied with how we handled it — or would rather not ask us at all — you can complain to the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, dataprotection.ro. If you live or work in another EU country, the authority there will take your complaint too, as will the authority where you think the problem happened. You can also go to court.

When this notice changes, the date and version at the top of the page change with it.

Still have a question about this document?

Write to us and a person reads it.

[email protected]