itsaplan
AboutEventsFAQLogin

itsaplan

Privacy Policy

Version 1.0 · Effective 25 July 2026
Website: itsaplanofficial.com

This Privacy Policy explains how itsaplan collects, uses, shares, retains and protects personal data.

Educational prototype and data-minimisation notice. itsaplan is currently a student-developed Research Practicum prototype, not a finished commercial service. The current draft assumes that the Service does not sell personal data, show behavioural advertising, process payments, or continuously track precise device location. Exact deployed integrations, processors and retention periods must be confirmed before publication.

Please read this Policy together with the Terms and Conditions. By using the Service, you acknowledge that you have been given this information about itsaplan's data practices.

Public-facing draft prepared for Team 3, COMP47360 Research Practicum, University College Dublin.

Contents

  1. Who we are and the scope of this Policy
  2. Privacy at a glance
  3. Personal data we collect
  4. Where personal data comes from
  5. Calendar connection and availability data
  6. AI-assisted input and recommendations
  7. Group events and information shared with participants
  8. How we use personal data and our lawful bases
  9. User testing, surveys and academic assessment
  10. Cookies, local storage and similar technologies
  11. Who we share personal data with
  12. International data transfers
  13. How long we keep personal data
  14. Security
  15. Your data-protection rights
  16. Children
  17. Automated decision-making and profiling
  18. Third-party links, venues and services
  19. Changes to this Policy
  20. Contact us and complaints

1. Who we are and the scope of this Policy

This Privacy Policy applies to the itsaplan website, web application, mobile application, APIs and related prototype features (together, the "Service").

itsaplan is a student-developed social-planning prototype created by Team 3 as part of the COMP47360 Research Practicum at University College Dublin. It is not presented as an official University College Dublin service.

The person or entity responsible for deciding why and how personal data is processed (the "controller") is: The itsaplan team. Contact details appear in section 20.

This Policy applies to account holders, event organisers, invited participants, user-testing participants and anyone who contacts us or otherwise uses the Service. It does not govern the independent data practices of venues, calendar providers, map providers, AI providers or other third-party services.

2. Privacy at a glance

  • We collect only the information needed to operate and test the current social-planning flow.
  • The intended calendar design uses free/busy availability rather than sharing calendar event titles, descriptions, attendees or notes with other group members.
  • Information submitted to a group event is used to find overlapping availability, compare preferences and generate a proposed plan. Some event information is visible to other participants.
  • Natural-language availability and recommendation features may send limited text and event context to an AI provider. Users must review AI-parsed output before submitting it.
  • We do not currently sell personal data, use it for behavioural advertising, process payments, or make reservations on users' behalf.
  • The Service is intended for adults aged 18 or over.
  • Users may ask for access, correction, deletion and other rights described in section 15.

3. Personal data we collect

3.1 Account and identity information

Depending on the sign-in method available, we may collect your email address, display name, account identifier, authentication-provider identifier, password hash or session identifier, account status, and records showing acceptance of the Terms or privacy choices. We should never store a readable copy of your password.

3.2 Group-event and planning information

When you create or join an event, we may process the event title, event ID or invite code, organiser and participant roles, invitation status, proposed date range, preferred area, attendance status, availability blocks, preference selections, votes, ranked recommendations, confirmed plan and timestamps.

Preference selections may include budget range, activity type, atmosphere or "vibe", desired busyness, distance, dietary or accessibility-related venue preferences, and similar planning choices. Accessibility selections are intended to filter venue attributes, not to collect a diagnosis. Please do not enter medical details or other unnecessary sensitive information.

3.3 Calendar connection information

Where calendar integration is enabled, we may receive an account identifier from the calendar provider, permission scopes, selected calendar identifiers, access or refresh tokens, and free/busy time blocks. The current draft assumes the Service does not retain calendar event titles, descriptions, invitees or private notes. This assumption must be verified against the deployed code and permission screen.

3.4 Free-text and AI-related information

If you type availability in natural language, we may process the text you submit, the structured time blocks produced from it, your edits or confirmation, and limited context required to generate a recommendation or explanation. Do not include confidential, highly personal or sensitive information that is not needed for planning.

3.5 Technical and usage information

When you use the Service, our hosting, authentication, database and security systems may automatically record information such as IP address, date and time, device and browser type, operating system, request and response metadata, session identifiers, page or feature interactions, crash information, error logs and security events.

3.6 Communications, support and feedback

If you contact us, report a problem or participate in testing, we may collect your message, contact details, screenshots, device information, survey or interview responses, consent records and follow-up correspondence. Audio, video or screen recordings should be collected only with separate, specific consent.

3.7 Information we do not intend to collect in the current prototype

The current prototype is not intended to collect payment-card information, government identifiers, continuous or background precise location, medical records, biometric data, private calendar content, or data used for advertising profiles. If the deployed product begins collecting any of these categories, this Policy and the product design must be updated before collection begins.

4. Where personal data comes from

  • Directly from you when you register, create or join an event, submit availability or preferences, vote, contact us, or take part in testing.
  • From another participant or organiser when they enter your email address or send you an invitation. We use that information only to deliver or manage the invitation.
  • From your calendar or sign-in provider when you choose to connect it and approve the permissions shown by that provider.
  • From your device, browser and service providers through security logs, session cookies, diagnostics and similar technical records.
  • From public and licensed sources used for venue, weather, transport, map, neighbourhood, event and busyness information. These sources generally provide contextual data about places rather than personal data about users.

5. Calendar connection and availability data

Connecting a calendar is optional where manual availability entry is available. Before connecting, you should review the permission screen provided by the calendar provider.

The intended privacy design is to use only the minimum information needed to determine whether time periods are free or busy. Other group members should not see your calendar event titles, descriptions, attendees, location or notes. They may see only the availability or participation information needed to coordinate the group event.

Calendar access tokens and identifiers should be protected and used only to provide the calendar feature. You may revoke access through the connected provider and, where available, through the Service. Revoking access stops future calendar requests but may not automatically remove availability already submitted to an event; you may delete the event data or contact us.

Do not connect another person's calendar or submit their availability without permission. Free/busy data is a planning aid and does not prove that a person is willing or able to attend.

6. AI-assisted input and recommendations

The Service may use generative AI or other automated tools to:

  • interpret natural-language availability and convert it into proposed time blocks;
  • generate short recommendation explanations or summaries; and
  • help rank or present possible times, activities or venues based on group data.

Where enabled, the current design may send the text you submit and minimal event context to the Google Gemini API.

The final Policy must state what data is sent, where it is processed, how long the provider retains it, and whether it is used to improve or train provider models.

AI output may be incorrect, incomplete or based on a misunderstanding. You must be shown the parsed availability or recommendation and given a reasonable opportunity to review, edit or reject it before relying on it.

The AI feature is not used to make legal, employment, credit, medical, insurance, education-admission or similarly significant decisions. It is used only to assist social planning.

For more information about how Google handles data, please review the Google Privacy Policy and the Gemini API Additional Terms of Service.

7. Group events and information shared with participants

itsaplan is a collaborative service. Information needed to coordinate a group event may be shown to the organiser and other participants. Depending on the current interface, this may include your display name, organiser or participant role, whether you have joined, whether you have submitted availability or preferences, your availability overlap or response status, votes or selected options, and the final proposed plan.

The Service should not reveal private calendar content to group members. Individual preference choices should be shown only where the product requires participant-level transparency; otherwise, the Service should use them to calculate a group result without unnecessarily exposing each person's detailed selections.

Event organisers are responsible for inviting only people they are entitled to contact. Do not post private invite codes or links publicly. If an invitation is shared without permission, contact the organiser or us so access can be restricted where possible.

Once information has been seen or copied by another participant, deleting it from itsaplan cannot remove copies that person has made outside the Service.

8. How we use personal data and our lawful bases

Under the GDPR, we must have a lawful basis for each processing purpose. The intended bases for the current prototype are set out below. They must be checked against the final controller, deployed features and actual data flows before publication.

PurposeData usedIntended lawful basis
Create and manage accounts; authenticate users; provide event creation, joining, availability, preferences and recommendations.Account data, event data, availability, preferences, votes and plan data.Performance of a contract or steps requested before entering a contract (Article 6(1)(b)).
Provide an optional calendar or AI feature that the user actively requests.Calendar identifiers, tokens and free/busy data; free text and parsed output.Performance of a contract for the requested feature. Separate permission or consent may also be required by the platform or ePrivacy rules.
Protect accounts, prevent misuse, troubleshoot, maintain logs and improve reliability.Technical logs, IP address, device data, error and security records.Legitimate interests in security, service integrity and debugging (Article 6(1)(f)), balanced against users' rights.
Send essential service messages and respond to support, deletion or rights requests.Contact details, account and correspondence records.Performance of a contract; legitimate interests; and, where applicable, legal obligation.
Conduct optional surveys, interviews, recordings or research activities.Consent records, feedback, recordings and study responses.Consent (Article 6(1)(a)) under a separate participant notice. Withdrawal does not affect earlier lawful processing.
Use non-essential analytics or similar tracking.Cookie identifiers and usage analytics.Consent, where required. The current prototype should not enable non-essential analytics before consent.
Comply with law, handle disputes and establish or defend legal claims.Relevant account, event, communication and security records.Legal obligation (Article 6(1)(c)) or legitimate interests (Article 6(1)(f)), depending on the circumstances.

Where we rely on legitimate interests, the interest, necessity and impact on users should be documented. Where we rely on consent, consent must be specific, informed, freely given, recorded and easy to withdraw.

9. User testing, surveys and academic assessment

Using the Service and participating in research or user testing are not automatically the same activity. If Team 3 invites you to a survey, interview, recorded usability session or other research activity, you should receive a separate participant information notice and consent request explaining the purpose, data collected, recipients, retention and withdrawal process.

Declining optional research participation should not prevent ordinary use of the Service. Research consent should not be bundled into account creation or acceptance of the Terms.

Project reports, presentations and academic assessment materials should use aggregated, anonymised or pseudonymised findings wherever possible. Names, email addresses, private screenshots, calendar details and raw free-text responses should not be included unless necessary, proportionate and separately agreed.

Unless a separate notice says otherwise, operational account and event data should not be reused as research data merely because the Service is an academic prototype.

10. Cookies, local storage and similar technologies

The website or app may use strictly necessary cookies, tokens or local storage to keep you signed in, protect the session, remember security choices, maintain an event workflow and provide features you request. These technologies are necessary for the Service to function and are not used for advertising.

Any optional analytics, performance, personalisation or third-party tracking technology should be disabled until the user has received clear information and, where required, has given consent. Withdrawing consent should be as easy as giving it.

11. Who we share personal data with

We do not currently sell personal data or share it with advertisers or data brokers. We may disclose limited data to the following recipients where necessary:

  • Other participants in the same event, as described in section 7.
  • Hosting, database, authentication, email, notification, storage, monitoring and security providers that process data on our instructions.
  • Calendar and identity providers when you choose to connect or sign in through them.
  • AI providers when you use an AI-assisted feature, subject to the limitations described in section 6.
  • Map, venue, weather, transport or event-data providers when a query must be sent to provide a requested result. The current design should avoid sending direct identifiers where they are not needed.
  • UCD academic mentors or assessors where they review the prototype or project evidence. Identifying user data should be removed from assessment materials unless there is a clear need and appropriate consent or other lawful basis.
  • Professional advisers, regulators, courts, law enforcement or other parties where disclosure is required by law or reasonably necessary to protect rights, security or users.

Before publication, Team 3 must maintain an accurate list of processors and sub-processors, confirm written data-processing terms where required, and ensure each provider receives only the information necessary for its role.

12. International data transfers

Some service providers may process personal data outside Ireland or the European Economic Area. Where personal data is transferred to a country that does not benefit from an applicable European Commission adequacy decision, the controller should use an approved safeguard such as the European Commission's Standard Contractual Clauses and assess whether additional protections are needed.

The final published Policy must identify the relevant providers, processing locations and safeguards.

You may contact us to request more information about the safeguards used for a particular transfer, subject to lawful confidentiality limits.

13. How long we keep personal data

We keep personal data only for as long as needed to operate the Service. Events created by users and their basic event information are retained unless the user deletes the event.

Account information is retained while the account is active. After an event or account is deleted, related information will be removed or anonymised within a reasonable period, although limited copies may remain temporarily in protected backups or where retention is required for security or legal reasons.

14. Security

We use reasonable technical and organisational measures appropriate to a small educational prototype. Depending on the final deployment, these should include encrypted network connections, password hashing or secure third-party authentication, least-privilege access, protected secrets and tokens, environment separation, access logging, dependency updates, backups, and procedures for responding to incidents and deletion requests.

Only team members and service providers who need access for development, support, security or assessment should be able to access identifiable data. Production data should not be copied into personal devices, chat messages, screenshots or development files unless necessary and protected.

No online service can guarantee absolute security. If we become aware of a personal-data breach, we will assess the risk and notify affected individuals and the Data Protection Commission where required by law.

15. Your data-protection rights

Subject to the conditions and limits in data-protection law, you may have the right to:

  • receive clear information about how your personal data is used;
  • access a copy of personal data held about you;
  • correct inaccurate or incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive certain data in a structured, commonly used and machine-readable format and transmit it to another controller;
  • withdraw consent at any time where consent is the lawful basis; and
  • complain to the Data Protection Commission or another competent supervisory authority.

To exercise a right, contact us using section 20 and describe the account, event or data concerned. We may ask for information needed to verify your identity and prevent unauthorised disclosure. We will respond without undue delay and normally within one month, subject to lawful extensions for complex or numerous requests.

Withdrawing consent does not affect processing that was lawful before withdrawal. Some rights are not absolute, and we will explain any lawful reason for refusing or limiting a request.

16. Children

The Service is intended for people aged 18 or over and is not directed to children. We do not knowingly create accounts for, invite, or collect personal data from anyone under 18 through the current Service.

If you believe that a person under 18 has provided personal data, contact us. We will investigate and delete or restrict the information where appropriate. The age statement in this Policy, the Terms, registration flow, testing materials and marketing must remain consistent.

17. Automated decision-making and profiling

itsaplan may automatically compare availability, combine group preferences, rank venues or times, estimate area-level busyness and generate recommendation text. These processes support a social-planning suggestion and do not produce legal or similarly significant effects.

Users should be able to review the proposed availability and plan, correct inputs, reject suggestions and make the final decision themselves. We do not use the current Service to evaluate a person's creditworthiness, employability, health, insurance risk, education eligibility or access to essential services.

The busyness feature is intended to use area-level historical or proxy signals such as transport activity, time and weather. It is not intended to build an individual behavioural profile or infer where a user regularly goes.

18. Third-party links, venues and services

The Service may show links, maps, venue details, opening hours, ratings, accessibility attributes, ticketing pages or other information supplied by third parties. Visiting a third-party site, contacting a venue, using a calendar provider or enabling an external sign-in method is subject to that third party's own privacy notice and terms.

itsaplan does not control how a venue, map provider, calendar provider or external website handles data that you provide directly to it. Review the relevant privacy information before submitting personal data or granting permissions.

19. Changes to this Policy

We may update this Policy when the Service, project status, legal requirements, processors, retention periods or data flows change. The updated version will show a revised effective date.

For material changes, we will provide reasonable notice through the Service, website or account email where practical. We will request fresh consent where the law requires it rather than treating continued use as consent.

20. Contact us and complaints

Controller: The itsaplan team
Privacy/contact email: info@itsaplanofficial.com
Website: itsaplanofficial.com

Please contact us first if you have a privacy question, wish to exercise a right, or believe personal data has been handled incorrectly. We will try to resolve the concern promptly.

You also have the right to raise a concern or make a complaint to the Irish Data Protection Commission. The DPC's current postal address is Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland. The DPC recommends using its online contact form for data-protection concerns.