Legal
Privacy Policy
How we handle personal data across the Planom website, the virtual tours we build, and the admin studio.
Last updated: 14 June 2026
This policy explains what personal data Planom (“we”, “us”) collects, why, and what rights you have. It covers planom.io, the interactive tours and embeds we host for our clients, and the Planom studio used by client teams. We are based in Tallinn, Estonia, and process data in line with the EU General Data Protection Regulation (GDPR).
Questions or requests: hello@planom.io.
Who is responsible for your data
For this website and our own communications, Planom (operated by marnei OÜ, Estonian registry code 16656984) is the data controller. When a real-estate developer or agency runs a tour built with Planom, that company is the controller for the buyer enquiries and visit data collected through their tour; Planom acts as their processor and only handles that data on their instructions.
What we collect
1. When you contact us or request a demo
Through the contact / “Book a demo” forms we collect what you submit:
- Your name, work email and (optionally) phone number and company.
- Your message and the project type you select.
- A pseudonymous session identifier and a short snapshot of what you were viewing, so we can give your enquiry context.
We use this to reply, prepare your demo, and follow up. Legal basis: steps taken at your request prior to a contract, and our legitimate interest in responding to enquiries.
2. When you explore a tour or embed
On the interactive tours and embeds we measure usage with privacy-friendly analytics. This is pseudonymous - tied to a random session id, not your name - and includes:
- Which buildings, apartments and scenes were viewed, and time engaged.
- Referrer and campaign parameters (e.g. UTM tags), and the embedding domain.
- Approximate country (derived from request headers), preferred language, device type and screen size.
We do not collect your name, email or precise location here unless you choose to submit a form. Legal basis: the legitimate interest of the developer (and Planom) in understanding and improving the sales experience.
3. When you use the studio (client team members)
- Account details: your name and email (accounts are invite-only).
- Sign-in sessions, including the IP address and browser used at login, kept for account security.
- The content you create - buildings, units, prices, tours, leads and offers.
4. Email engagement
When a client sends a campaign to their own contacts through Planom, a tracking pixel records whether the email was opened. Open tracking is a lower bound - clients that block images are invisible to it.
Cookies
We keep cookies to a minimum. We do not use third-party advertising cookies.
| Cookie | Purpose | Type |
|---|---|---|
| planom_session | Keeps studio members signed in (set only after you log in). | Essential - ~7 days - httpOnly |
| planom_lang | Remembers your language choice for the website. | Functional - ~1 year |
| planom_cookie_consent | Remembers that you dismissed the cookie notice. | Essential - ~1 year |
| Analytics session id | A random id that groups one visit to a tour; no personal data. | Analytics - session |
Who we share data with
We share data only with the service providers that make Planom work, under contracts that limit them to our instructions:
- Cloud hosting and database providers.
- Object storage for images (e.g. AWS S3 / Cloudflare R2).
- Email delivery (SMTP provider or Resend) for sign-in codes and notifications.
We never sell your personal data. Where a provider processes data outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
How long we keep it
- Enquiries and leads: for as long as needed to follow up, then as the client requires.
- Sign-in sessions: about 7 days, then they expire.
- Tour analytics: retained in aggregate; pseudonymous and not linked to you.
Your rights
Under the GDPR you can request access to your data, correction, erasure, restriction or portability, and you can object to processing based on legitimate interest. To exercise any of these, email hello@planom.io. If your data was collected through a specific developer’s tour, we may direct your request to that company as the controller. You also have the right to complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
Children
Planom is a business tool and is not directed at children under 16.
Changes
We may update this policy as the product evolves; the “last updated” date above always reflects the current version.
This policy describes how the platform currently works. It is provided in good faith and should be reviewed by your own legal counsel before you rely on it for a specific deployment. See also our Terms of Service.