Privacy Policy
Last updated: 10 May 2025
Thank you for visiting El Plan (the “Site”). We respect your privacy and are committed to protecting your personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”) and other applicable laws.
1. Who We Are (Data Controller)
Legal Entity: El Plan
Location: Utrecht, The Netherlands
Email: info@el-plan.eu
2. What Personal Data We Collect and Why
Data category | How we obtain it | Purpose | Legal basis (Art. 6 GDPR) |
---|---|---|---|
Contact data (name, email) | You provide it when subscribing or contacting us | Send newsletters, respond to enquiries | Consent §1(a) or Legitimate interest §1(f) |
Usage data (IP, browser, pages viewed) | Collected automatically via server logs & cookies | Site security, analytics | Legitimate interest §1(f) |
Email interaction data (opens, clicks) | Collected by our email service provider | Improve newsletter relevance | Consent §1(a) |
3. Email Delivery via Mailgun
We use Mailgun Technologies, Inc. (USA) to process and deliver transactional and newsletter emails.
Mailgun acts as our processor under Art. 28 GDPR. We have executed the Mailgun Data Processing Addendum, which incorporates the EU Commission Standard Contractual Clauses (SCCs) and the commitments under the EU–US Data Privacy Framework, ensuring an adequate level of protection for data transferred to the United
3. Infrastructure & Processors
3.1 Email Delivery via Mailgun (EU Region)
We send all transactional and newsletter emails through Mailgun Technologies, Inc. using their EU region endpoint (api.eu.mailgun.net
).
All message content and related metadata are processed on servers located in the European Union (currently Frankfurt, Germany).
Mailgun acts as our processor under Art. 28 GDPR. Because data remains within the EEA during normal operation, no international transfer occurs. If Mailgun personnel outside the EEA must access data for 24 / 7 support, such access is covered by Mailgun’s Standard Contractual Clauses (SCCs) and its certification under the EU–US Data Privacy Framework.
You may unsubscribe at any time by clicking the link in any email or by writing to info@el-plan.eu.
3.2 Hosting on DigitalOcean
Our Ghost application and database are hosted with DigitalOcean, LLC on servers located in Amsterdam.
DigitalOcean acts as our processor under Art. 28 GDPR. We have executed DigitalOcean’s Data Processing Addendum, which incorporates the SCCs. No personal data is transferred outside the EEA unless you access the Site from outside it.
You may unsubscribe at any time by clicking the link in any email or emailing us at info@el-plan.eu.
4. Cookies & Analytics
We use only essential cookies required to operate the Site and anonymised analytics (no cross-site tracking).
5. How Long We Keep Your Data
Data | Retention period |
---|---|
Newsletter subscriber records | Until you unsubscribe or 24 months of inactivity |
Emails sent via Mailgun | Up to 30 days for delivery diagnostics |
Server logs on DigitalOcean | 14 days, unless needed for security investigations |
6. Sharing Your Data
We never sell personal data. Data may be shared only with:
- Service providers under written contracts, such as
- DigitalOcean (hosting & CDN)
- Mailgun (email delivery)
- Public authorities when legally required (e.g. court order).
All processors are vetted for GDPR compliance.
7. International Transfers
Where data is transferred outside the EEA/UK (e.g. to Mailgun in the USA), we rely on:
- EU–US Data Privacy Framework certification, or
- Standard Contractual Clauses approved by the European Commission.
8. Your Rights (EU)
You have the right to:
- Access, rectify or erase your data
- Restrict or object to processing
- Port your data to another service
- Withdraw consent at any time (without affecting prior processing)
- Lodge a complaint with your supervisory authority
Contact us at info@el-plan.eu to exercise any rights.
9. Security
We implement technical and organisational measures, including encryption in transit (TLS), firewalls, access controls, and regular security reviews, to keep your data safe.
10. Children
This Site is not directed to children under 16. We do not knowingly collect children’s personal data.
11. Changes to This Policy
We may update this Privacy Policy occasionally. Significant changes will be announced on the Site or via email. The “Last updated” date at the top reflects the latest revision.
12. Contact
Questions? Email info@el-plan.eu or write to the address in Section 1.
This document is provided for informational purposes only and does not constitute legal advice. Consult a qualified attorney to adapt it to your specific circumstances.