Privacy Policy
Privacy Policy
Last updated: see publication date below.
Formo (the "Service"), available at formo.website, respects your privacy. This Policy explains what data we collect, why, on what legal basis, and how you can manage it.
This Policy is drafted in accordance with EU Regulation 2016/679 (GDPR) and the Russian Federal Law No. 152-FZ "On Personal Data".
1. Who is the controller
The data controller is the owner of the formo.website domain (the "Operator"). Full details are listed under "Operator details".
2. What data we process
- Account data: email address, name (if provided), interface language.
- Identity data: user id, roles, registration date.
- Form data: content of the forms you create and the responses you receive (you are the controller for the respondents' data).
- Technical data: IP address, browser, OS, visit time, referrer, cookie identifiers.
- Analytics: aggregated usage statistics (via Umami — no cross-site cookies, no resale).
- Payment data (if applicable): processed by the payment provider; we do not store card numbers.
3. Legal basis
- Contract — to provide the Service (Art. 6(1)(b) GDPR).
- Consent — for analytics, marketing cookies, mailings (Art. 6(1)(a) GDPR). Withdrawable at any time.
- Legitimate interest — security, fraud prevention, diagnostics (Art. 6(1)(f) GDPR).
- Legal obligation — tax reporting, lawful requests from authorities.
4. Purposes
- Account registration and authentication.
- Providing the form-builder and response-collection functionality.
- Service communication (magic links, recovery, service updates).
- Improving and securing the Service.
- Complying with applicable law.
5. Retention
- Account data — while the account is active; up to 30 days after deletion.
- Security and consent logs — up to 3 years.
- Technical logs and backups — up to 90 days.
- Accounting records — 5 years where required by law.
6. Sharing with third parties
We do not sell your data. We share data only with the processors below, acting under our instructions:
| Recipient | Purpose | Jurisdiction |
|---|---|---|
| Supabase (Lovable Cloud) | Account and form storage, auth | EU/US |
| Cloudflare | Hosting, DDoS protection | EU/US |
| OpenRouter | AI processing for form generation | EU/US |
| Umami | Privacy-friendly web analytics | EU |
| Timeweb Cloud | Media files (S3) | RU |
| Resend (or other SMTP) | Transactional email | EU/US |
The list may evolve; the current version is published on this page.
7. International transfers
Some processors are located outside the EU/EEA. Transfers rely on Standard Contractual Clauses and equivalent safeguards.
8. Your rights
You may at any time:
- access a copy of your data,
- request correction of inaccuracies,
- delete your account and related data,
- withdraw consent,
- restrict processing,
- lodge a complaint with a supervisory authority (in the EU — your local DPA; in Russia — Roskomnadzor).
Requests go to the contact in "Operator details". We respond within 30 days.
9. Security
We use TLS for all connections, server-side encryption of secrets, access logging, least-privilege roles, and regular backups. No system is perfectly secure; we notify you within 72 hours of any incident likely to affect your rights.
10. Children
The Service is not intended for users under 16. If you become aware that a child has provided us data without parental consent, contact us and we will delete it.
11. Changes
We may update this Policy. Material changes are posted here at least 14 days before they take effect. The current version is shown below.
12. Operator details
To be completed by the Service owner.
- Legal name: ______
- Tax ID: ______
- Registration number: ______
- Address: ______
- Contact email: post@formo.website
- Website: https://formo.website