Legal
Last updated: 3 August 2026 (draft)
DRAFT — pending legal review, not yet approved for reliance
Hyper (“Hyper”, “we”, “us”) provides an AI-assisted research and drafting platform for UK planning professionals at hyper-planning.com. For the purposes of UK GDPR and the Data Protection Act 2018, the data controller is:
[ COMPANY LEGAL NAME ]
Company number: [ COMPANY NUMBER ]
Registered office: [ REGISTERED ADDRESS ]
ICO registration number: [ ICO REGISTRATION NUMBER, OR “registration pending” ]
Contact: hello@hyper-planning.com
This policy covers two distinct groups of individuals:
| Category | Examples |
|---|---|
| Account data | Email address and password (held by Supabase, our authentication provider — we never see your password in plain text). |
| Organisation data | The organisation you belong to, your role (owner/admin/member/viewer), and which projects you can access. |
| Project content | Project names, descriptions, files you upload, drafted text, and any personal data those files or that text happen to contain. |
| Usage & security data | IP address and action logs recorded for audit and security purposes when you take actions in the product. |
| Cookies & similar technologies | See our Cookie Policy for the full list. |
| Purpose | Lawful basis |
|---|---|
| Providing the product — authentication, storing your projects, running research and drafting features | Performance of the contract between you (or your organisation) and Hyper |
| Security, fraud prevention and abuse protection (e.g. bot/CAPTCHA checks, audit logs) | Legitimate interests, and legal obligation where applicable |
| Responding to support and sales enquiries | Legitimate interests / performance of the contract |
| Improving the product (aggregated, non-identifying analysis) | Legitimate interests, or consent where analytics cookies are used — see Cookie Policy |
We use a small number of subprocessors to run Hyper. We don’t sell personal data, and we don’t use your project content to train third-party or our own AI models.
| Provider | What it does for us |
|---|---|
| Supabase | Authentication, database and file storage. |
| Railway | Hosts our backend application. |
| Vercel | Hosts our frontend web application. |
| Neo4j Aura | Hosts the graph database behind our research features. |
| Google (Gemini API) | Powers AI-assisted extraction, research and drafting features. Only the content needed to answer a given request is sent; see the open item above on confirming Google’s data-use terms. |
| Apify | Runs the automated collection of public planning data (see Section 9) — does not process your account or project data. |
| Cloudflare (Turnstile) — planned | Bot/abuse protection on login and signup. Cloudflare sees limited technical signals (e.g. browser/network signals) needed to distinguish humans from bots; it does not see your password. |
[ PLACEHOLDER — to confirm before publishing: which of the providers in Section 5 store or process data outside the UK/EEA, and on what transfer mechanism (adequacy decision, International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, etc.) we rely on for each. ]
We keep account and project data for as long as your organisation has an active account, and for a limited period afterwards to allow reactivation and to meet legal obligations. [ PLACEHOLDER — confirm specific retention periods per data category, including audit logs and the planning-records data described in Section 9, before publishing. ]
Under UK GDPR, you have the right to:
To exercise any of these rights, contact hello@hyper-planning.com. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113, though we’d welcome the chance to resolve any concern directly first.
To power its research features, Hyper ingests public planning data published by bodies such as the Planning Inspectorate, local planning authorities and central government. Some of this data — most notably appeal decision letters — names individuals (such as appellants) who are not Hyper customers and from whom we have not collected data directly.
Where practical, we redact or generalise fields that are likely to identify a private individual (for example, an appellant’s name where an appeal is not clearly made by a company or professional agent), while keeping fields that are typically organisational (such as a planning agent’s firm name) or already public in an official capacity (such as a decision-making inspector’s name).
Open point: for one data source (PINS appeal decision letters), the source document is currently retained in full, unredacted, alongside a redacted extracted-text version. Whether to continue retaining the unredacted source document is under legal review and is not yet finalised — this section will be updated once that review concludes, and should not be relied on as a final description of our practice until then.
See our Cookie Policy for the full list of cookies and similar technologies we use and how to control them.
Hyper is a B2B product intended for use by working professionals. It is not directed at, and we do not knowingly collect data from, children.
We’ll update this page when our practices change and update the “last updated” date above. Material changes will be communicated to account holders.
Questions about this policy or how we handle personal data: hello@hyper-planning.com.