Bandplain app — Privacy notice
Version privacy-app 2026-10-11 · Prepared in line with the GDPR and Romanian law; not reviewed by a lawyer.
This notice explains how PPFTEC S.R.L. handles personal data when you use the Bandplain app at app.bandplain.ppftec.com under a paid company licence. It is given under Article 13 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
The short version
- The payroll and pay data you import stays on your device. We do not receive it, store it or have access to it. See "What we never receive" in the app's help pages.
- We process only a little personal data of our own: the technical data created when your browser loads the app's files, and what you send us when you contact support.
- How we handle the data of your order, invoices and licence code e-mails is described in the privacy notice for buyers.
1. Who is responsible
The controller of the data described in this notice is PPFTEC S.R.L., Romania · CUI RO55537142 · Trade Register no. J2026052999008 · registered office: see Company details.
Contact for privacy questions and requests: privacy@ppftec.com. For product support: support@ppftec.com. Both are aliases of PPFTEC's company mailbox, contact@ppftec.com, on Google Workspace.
We have not appointed a data protection officer. Privacy requests are handled through the contact above.
2. What we never receive
The app runs in your web browser. Payroll files are parsed on your device. Only the mapped, minimal fields needed by the app are saved in your browser workspace; unused fields, such as names and e-mail addresses, are discarded before saving. Calculations, exports, encrypted backups and the passphrases that protect them are processed only on your device. The app does not send them to us or to anyone else.
Your company decides why and how it uses that payroll data and is its controller. Under the app's current local-first design, PPFTEC does not receive or process that data on your company's behalf (terms of use §3–§4). Your company informs its employees and applicants about its own processing.
Your licence code is also stored only in your browser. The app checks it on your device against its signature, validity date and the revocation list included in the app build; it does not send it to us. Revocation updates take effect when you load a new app build, rather than through an online licence check.
Because we never receive this data, we cannot see it, restore it or delete it for you. Keep your device secure and make encrypted backups.
3. What we process, why, on what basis, and for how long
| Data | Source | Purpose | Legal basis | Kept for |
|---|---|---|---|---|
| Delivery data: IP address, date and time, requested file, browser type (user agent) and security signals, created by our hosting provider when your browser loads the app's files | your browser, via Cloudflare | delivering the app, protecting it against attacks and abuse, fixing errors | our legitimate interest in delivering the app and protecting it against attacks (Article 6(1)(f)) | we do not retain our own application request logs: Workers Logs are disabled for this app. Cloudflare separately retains network and security data for its operational and legal purposes, using the criteria in its privacy policy, rather than one fixed period |
| Support messages: your name, work e-mail address, company and your message | you | answering your question | taking the steps you ask for under your company's contract (Article 6(1)(b)); where you write as your company's employee rather than as a party to the contract, our legitimate interest in giving support to our customer (Article 6(1)(f)) | messages about an order or a licence: together with the licence record, as set out in the buyer notice (life of the licence and 3 years after it ends, or the applicable invoice retention period if longer). Other support messages: 24 months after the last message |
| Personal data sent to support by mistake, for example a payroll file or a screenshot with employee data | you | none: we do not want it | our legitimate interest in deleting it and informing you (Article 6(1)(f)) | deleted without being looked at further, as soon as we notice it; we tell you that we did so (terms of use §4.3) |
Do you have to give the data? The delivery data is created automatically when your browser loads the app; without it the app cannot be delivered. Support messages are voluntary.
Our legitimate interests are: delivering the app, protecting it against attacks and abuse, and supporting our customers. You may object to processing based on them (section 7).
Cookies and browser storage. The app sets no cookies and uses no analytics, tracking or advertising. It uses your browser's storage, including IndexedDB, to provide the local workspace and keep your licence code on your device after you choose to use these functions. We do not receive that stored data. We treat storage needed for the app functions you expressly request as strictly necessary under Directive 2002/58/EC Article 5(3) and Romanian Law 506/2004 Article 4(6)(b).
No automated decisions about you. The app checks your licence code on your device, against the code's own validity date and signature. We make no decisions based solely on automated processing of your personal data, and we do no profiling.
4. Who receives the data
| Recipient | What it does for us | Role | Where |
|---|---|---|---|
| Cloudflare (Cloudflare, Inc. and its group) | hosts and delivers app files; handles delivery and security data | processor for customer logs and content processed on our instructions under its DPA; separate controller for its own network/security processing under its privacy policy | worldwide network; see section 5 |
| Google Workspace (Google service entities and their subprocessors) | stores and processes support messages in PPFTEC's company mailbox | our processor under the Google Cloud Data Processing Addendum | countries where Google and its subprocessors maintain facilities; see section 5 |
| Public authorities, courts | only where the law requires it, or to establish or defend a legal claim | separate controllers | EU |
We do not sell personal data, and we do not share it with anyone for their own marketing.
5. Transfers outside the European Union
| Provider | Transfer | Safeguard |
|---|---|---|
| Cloudflare | delivery of the app and network/security processing can involve the USA and other countries | Cloudflare's DPA provides European Commission Standard Contractual Clauses for restricted transfers; its own processing is described in its privacy policy |
| Google Workspace | support messages may be processed wherever Google or its subprocessors maintain facilities | Google's Cloud Data Processing Addendum provides applicable Standard Contractual Clauses for restricted transfers |
You can ask for the relevant safeguards at privacy@ppftec.com. Order and licence e-mails sent using Zoho ZeptoMail are covered by the buyer notice.
When we permanently delete a message from our mailbox, Google's Addendum allows up to 180 days to complete deletion from its systems, subject to applicable law. This is provider-side deletion timing, separate from our retention periods above.
6. Security
We keep as little data as we can. The app's design means that your payroll data never reaches us. Before each release, an automated test checks that no request sent by the app contains imported data or results. We will tell you in the app before any release that changes what the app sends over the network (terms of use §3).
7. Your rights
You have the right to:
- access the personal data we hold about you and receive a copy (Article 15 GDPR);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17);
- restrict our processing, for example while we check a disputed point (Article 18);
- receive the data you gave us in a structured, machine-readable format (portability, Article 20), where the processing is based on contract and carried out by automated means;
- object at any time, for reasons relating to your situation, to processing based on our legitimate interests (Article 21). We will then stop, unless we have compelling legitimate grounds or need the data for a legal claim.
These rights cover the data in section 3. For the payroll data in the app, your company is the controller: employees and applicants should contact their employer, who can find, export or delete their data in the app on its own devices.
To use these rights, write to privacy@ppftec.com. We may ask you to confirm the request from the e-mail address we hold, so that we do not give your data to someone else. We answer within one month; if a request is complex, we may extend this by up to two more months and will tell you why (Article 12(3)). Requests are normally free. The GDPR permits a reasonable fee or refusal for manifestly unfounded or excessive requests (Article 12(5)); we must explain and justify that exception.
8. Complaints
You can complain to the Romanian data protection authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — website: dataprotection.ro; complaints page: dataprotection.ro/?page=Plangeri_pagina_principala
You can also complain to the data protection authority of the EU Member State where you live, work, or where you think the problem happened (Article 77 GDPR). We would be glad if you contacted us first, so that we can try to solve the problem.
9. Changes to this notice
If we change this notice, we publish the new version here with a new version date and keep the earlier versions available. If a change affects how the app handles your data, or what it sends over the network, we tell users in the app before it applies.