Privacy Policy
Last updated: April 9, 2026
This Privacy Policy explains how Open Growth Group INC, a Delaware corporation (“Open Growth Group”, “we”, “our”, or “us”), collects, uses, shares, and protects personal information when you interact with ConFYI PM at pm.con.fyi, related applications, integrations, support channels, and services (collectively, the “Service”). The Service uses Plane software, but this deployment is operated by Open Growth Group INC.
This Policy describes our practices where we determine why and how personal information is processed. Capitalised terms not defined here have the meaning in our Terms of Service.
1. Our role: controller and processor
As controller: when you visit our public pages, create or administer an account, communicate with us, or purchase access, Open Growth Group determines how account, billing, security, support, and Service-usage data is processed.
As processor: when a Customer stores and manages Customer Data in a ConFYI PM workspace, we process that data on Customer’s behalf. Customer determines the purposes of that processing and is the controller. Applicable data-processing terms, rather than this Policy alone, govern that processor relationship.
If you are an end user in another organisation’s workspace, contact that organisation for information about how it handles your personal information within the workspace.
2. Scope
This Policy applies to the hosted ConFYI PM Service, its public product and legal pages, communications with our support or business teams, and technical telemetry from the deployment.
It does not govern a Customer’s independent handling of Customer Data, third-party services integrated with the Service, or websites and services operated by Plane Software or other parties. Their own notices apply to their processing.
3. Information we collect
3.1 Information you provide
Account and profile data: name, email address, organisation, role, profile photo, password hash, authentication settings, workspace memberships, invitations, preferences, and permissions.
Billing and transaction data: plan, billing name and address, tax information, subscription status, and invoice history. Full payment-card details are handled by a payment processor; we may receive a token, card brand, expiry, and last four digits.
Support and communications: messages, tickets, feedback, survey responses, and other information you choose to provide.
Customer Data: projects, issues, documents, comments, attachments, fields, workflow configurations, workspace metadata, and other material submitted to a workspace.
3.2 Information collected automatically
We may collect IP address, browser and operating-system details, device identifiers, language, approximate location derived from IP, referring and exit URLs, pages and features used, clickstream, timestamps, session duration, application logs, error reports, diagnostic data, performance metrics, authentication events, and security events.
3.3 Cookies and similar technologies
We use cookies, local storage, and similar technologies for authentication, security, session management, preferences, and limited analytics. Essential cookies cannot be disabled without affecting Service operation. We do not sell cookie-derived personal information or use it for cross-context behavioural advertising.
3.4 Information from other sources
If you sign in through an identity provider or connect an integration, we receive the information you authorise that provider to share, such as name, email, account identifier, tokens, and integration metadata. We may also receive business contact information from partners or public professional sources.
4. How we use information
We use personal information to provide and administer accounts and workspaces; authenticate users; host and process Customer Data; operate projects, documents, collaboration, APIs, and integrations; process payments; provide support; communicate Service, security, billing, and policy notices; monitor performance; diagnose errors; prevent fraud and abuse; enforce our Terms; improve usability and features; create aggregated analytics; comply with law; and establish or defend legal claims.
Where European, UK, or Swiss law applies, we rely on performance of a contract, legitimate interests in operating and securing the Service, consent for optional activities, and legal obligations. You may withdraw consent at any time without affecting earlier lawful processing.
5. AI-assisted features
If you use an optional AI Feature, inputs you select and relevant workspace context may be sent to configured model providers acting as service providers to generate the requested output. We do not use Customer Data to train general-purpose models for other customers, and we require model providers not to use Service inputs for independent model training.
AI output is treated as Customer Data. Customer remains responsible for reviewing outputs and for decisions or automation based on them.
6. How we share information
We do not sell or rent personal information and do not share it for cross-context behavioural advertising. We may share information with:
- hosting, storage, network, database, monitoring, authentication, email, support, payment, analytics, and AI service providers that process it under contractual restrictions;
- third-party services you connect or direct us to use;
- other members of your workspace according to assigned roles and permissions;
- professional advisers subject to confidentiality;
- authorities when disclosure is legally required or reasonably necessary to protect rights, security, and people; and
- a successor in a merger, financing, reorganisation, acquisition, or asset sale, subject to appropriate notice and protection.
We may share aggregated or de-identified information that cannot reasonably identify a person and will not attempt to re-identify it.
7. Deployment-specific privacy
Open Growth Group hosts this ConFYI PM deployment and can process data necessary to operate, secure, support, and maintain it. A Customer controls its workspace content, membership, permissions, integrations, retention decisions, and lawful basis for the personal data it places in the workspace.
If a Customer exports data or connects another provider, that provider’s terms and privacy practices govern its subsequent handling. Customers should limit access using roles and permissions and promptly remove users who no longer require access.
8. International transfers
Open Growth Group is based in the United States and may use providers in the United States, European Economic Area, United Kingdom, and other jurisdictions. Personal information may therefore be processed outside your country.
Where required, we use lawful transfer safeguards such as adequacy decisions, European Commission Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, and supplementary technical and organisational controls.
9. Data retention
Account data is generally retained while an account is active and for a reasonable period after closure. Customer Data remains available during the active relationship and may be retained for up to thirty days after termination for export, then deleted or anonymised, subject to backups and legal requirements.
Billing records may be retained for approximately seven years where tax and accounting law requires it. Operational and security logs are generally retained for up to twelve months. Support data is retained while needed to resolve the matter and meet legal obligations. Backups expire on their normal rotation. We may retain data longer for fraud prevention, disputes, litigation holds, or legal compliance.
10. Data security
We use administrative, technical, and organisational safeguards designed to protect personal information, including encryption in transit, appropriate encryption at rest, password hashing, role-based access, least-privilege controls, logging, monitoring, backups, vulnerability management, and incident-response procedures.
No system is completely secure. You are responsible for protecting credentials, choosing appropriate workspace permissions, securing your devices, and promptly reporting suspected compromise to us.
11. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing; receive portable data; withdraw consent; opt out of marketing; and complain to a supervisory authority. You can update some information in account settings. For other requests, email hello@opengrowthgroup.co.
We may verify your identity before responding. We will respond within the period required by law and will not discriminate against you for exercising privacy rights. If your request concerns data controlled by your organisation inside its workspace, we may direct you to that organisation.
12. United States state privacy rights
Residents of California and other states with comprehensive privacy laws may have rights to know, access, correct, delete, and obtain a copy of personal information and to opt out of certain sale, sharing, targeted advertising, or profiling. We do not sell personal information or share it for cross-context behavioural advertising.
Categories collected may include identifiers, commercial information, internet or network activity, professional information, workspace content, and inferences necessary for security or Service improvement. Requests may be submitted to hello@opengrowthgroup.co.
13. European, UK, and Swiss rights
People in the EEA, UK, or Switzerland may exercise the rights described above, object to legitimate-interest processing, and lodge a complaint with their local data-protection authority. Open Growth Group is controller for public-site, direct account, billing, support, and security processing, and processor for Customer Data handled on a Customer’s instructions.
14. Children
The Service is intended for business use and is not directed to children under 16, or a higher minimum age required in a jurisdiction. We do not knowingly collect personal information from children. If you believe a child supplied information, contact us and we will take appropriate deletion steps.
15. Marketing and cookie choices
You may opt out of marketing using the unsubscribe link in a message or by contacting us. Transactional, account, billing, security, and Service messages remain necessary while your account is active. Browser controls can limit cookies, but disabling essential storage may break authentication and other functions.
16. Third-party services
The Service may link to or integrate with services we do not operate. Their own privacy policies govern their processing. Review those terms before connecting an integration or sending data to another platform.
17. Do Not Track and Global Privacy Control
Our public pages may not respond to browser “Do Not Track” signals. Where applicable law requires it, we honour Global Privacy Control signals as a request to opt out of sale or sharing. We do not sell personal information or use it for cross-context behavioural advertising.
18. Changes to this Policy
We may update this Policy to reflect changes in the Service, law, or our practices. Material changes will receive reasonable notice by email, in-product message, or prominent notice. The current effective date appears at the top of this page.
19. Contact
For privacy questions, rights requests, or complaints, contact:
Open Growth Group INC
Delaware, USA
hello@opengrowthgroup.co

