Plandisc
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Danish circular annual-planner (Visma Plandisc A/S, Højbjerg, 2012), Visma-owned, hosted on Microsoft Azure in Sweden, ISAE 3000.
Plandisc offers EU hosting in Sweden, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Project management.
Assessment notes
Visma Plandisc A/S (Højbjerg, Denmark, Axel Kiers Vej 5A, 8270; CVR 37204854; founded 2012) is the world's first digital circular annual-planner, used widely in Danish and Nordic education, marketing, and public-sector teams; owned by Visma Group (Norway), with Grant Thornton ISAE 3000-II and GDPR attestations. The published DPA (Appendix B, re-read 2026-08-26) names Microsoft Azure as the hosting and infrastructure platform, storing and processing customer data in Microsoft's Swedish data centres, and Amazon AWS as the S3 store for customer data under the EU-U.S. Data Privacy Framework, so two US-controlled hyperscalers sit directly in the customer-data path. The EU-owned Visma Private Cloud in Sweden is now offered only as an alternative for customers with special data-storage requirements, not as the standard. The data stays in Sweden, but the processors holding it are US-controlled, so CLOUD Act exposure is material rather than the ownership-layer-only exposure recorded in May 2026; Visma's PE consortium including US TPG remains a separate signal at the group layer.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 5 · 2 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Plandisc
Plandisc is a Danish-originated circular annual planner (the world's first digital take on the cyclical/rolling planner format) founded in 2012 and headquartered at Axel Kiers Vej 5A, 8270 Højbjerg (the Aarhus suburb), Denmark. Co-founder Torben Stigaard serves as Managing Director. The product visualises annual planning as a disc divided into colour-coded rings representing departments, responsibilities, teams, or target groups, and is widely adopted in Danish and broader Nordic education, marketing, finance, and public-sector teams. Originally a school planning tool, Plandisc expanded across industries and was acquired by Visma Group (Norway), the same Nordic software conglomerate that owns Teamleader (Belgium, audited earlier in this directory).
For an EU-sovereignty audit Plandisc inherits the Visma ownership pattern, and the hosting picture is not the one recorded in May. The operating entity is Danish and the data region is Swedish, but the vendor's own GDPR page states that Microsoft Azure is the standard hosting provider for Plandisc, with Visma Private Cloud offered only as an alternative for customers with special data-storage requirements. Appendix B of the published DPA puts customer data in Microsoft's Swedish data centres and adds Amazon AWS as the S3 store for customer data under the EU-U.S. Data Privacy Framework, so two US-controlled hyperscalers sit directly in the customer-data path. The company carries Grant Thornton ISAE 3000 and GDPR 2024 attestation badges, and Denmark and Sweden are both EU members with no SCC requirement for transfers inside the EEA, but CLOUD Act exposure is recorded as Material on the processor chain rather than on geography alone. There is a second layer above that: Visma's group cap table includes Hg, Cinven, TPG (US), GIC, and Intermediate Capital Group, so beneath the Norwegian-owned Visma wrapper there is meaningful US-PE exposure too. Neither the ownership chain nor the processor chain meets a zero-US threshold.
Pricing is published per user and billed annually: Pro €27/user/month for up to 20 plandiscs, Enterprise €34/user/month for unlimited plandiscs, and Enterprise Plus €39/user/month adding SCIM and SAML/AzureAD. A free trial needs no credit card; there is no free tier. Best fit: Danish and Nordic schools, associations, marketing teams, and finance departments that want a unique visual planning tool with Swedish data residency and ISAE 3000 attestation, and accept Visma Group as the corporate counter-party alongside Azure and AWS in the processing chain. Procurement-grade EU-only buyers who need both the ownership chain and the processor chain free of US parties should look at Stackfield or MeisterTask in the same category.
Sub-processor map · 5
-
Amazon AWS USLuxembourg
Storage of customer data via S3 Cloud Storage; transfer basis EU-U.S. Data Privacy Framework
-
Microsoft Azure USIreland
Hosting and infrastructure platform; storage, processing and operation of customer data in Microsoft's Swedish data centres
-
Ipregistry EUFrance
IP geolocation used to block access from sanctioned countries
-
Orca Security Ltd. non-USUnited Kingdom
Cloud infrastructure security analysis, malware scanning and privilege management; processing within EU/EEA
-
WebHosting A/S EUDenmark
SMTP service for sending and receiving email
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon AWS | Luxembourg | Storage of customer data via S3 Cloud Storage; transfer basis EU-U.S. Data Privacy Framework | US |
| Microsoft Azure | Ireland | Hosting and infrastructure platform; storage, processing and operation of customer data in Microsoft's Swedish data centres | US |
| Ipregistry | France | IP geolocation used to block access from sanctioned countries | EU |
| Orca Security Ltd. | United Kingdom | Cloud infrastructure security analysis, malware scanning and privilege management; processing within EU/EEA | non-US |
| WebHosting A/S | Denmark | SMTP service for sending and receiving email | EU |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications · none listed
Capability matrix
Table 2Capabilities of Plandisc
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Netherlands · $10/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: Yes -
-
Germany · €19.99/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: No Open source: No -
-
Germany · €99/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: Yes
|
$10/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: No
Open source: No
|
€19.99/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: No
|
€99/mo |