https://formendi.com/data-processing-agreement
Formendi Data Processing Agreement
Version: dpa-2026-10-09. Effective date: the date an authorised person accepts this document.
1. Parties, scope and priority
This DPA forms part of the Formendi Terms of Use between the customer identified in the acceptance record (“Customer”) and Glavrio, UAB, company code 307648878, registered address as recorded in the Lithuanian Register of Legal Entities under company code 307648878, Lithuania, Lithuania, contact [email protected] (“Formendi”).
It applies to personal data processed by Formendi on the Customer's behalf in the workspace (“Customer Personal Data”). The Customer is the controller and Formendi is its processor. If the Customer is a processor, it confirms authority from the relevant controller to appoint Formendi as subprocessor and pass on lawful instructions. These terms apply to that chain accordingly.
Formendi's independent controller activities, such as account administration and its own security/legal records, are described in the Privacy Notice. Roles depend on actual processing, not merely on this label. This DPA prevails over conflicting general Terms for Customer Personal Data; applicable transfer standard contractual clauses prevail over both where required.
2. Processing instructions and customer duties
The subject matter, nature, purposes, duration, data categories and individuals are in Schedule A. The Terms, this DPA, enabled settings and authenticated actions constitute documented instructions. Additional instructions must be lawful, within the agreed service or separately agreed in writing.
Formendi will process Customer Personal Data only on those instructions, including for transfers, unless Union or Member State law requires otherwise. Where legally permitted, it will inform the Customer before processing required by that law. It will promptly inform the Customer if an instruction appears to infringe applicable data-protection law and may pause that instruction while the issue is resolved.
The Customer determines a lawful basis, supplies required notices, limits data to what is needed and manages users/recipients. It must not submit the excluded categories in Schedule A. These duties do not relieve Formendi of its own statutory obligations.
Formendi will not sell Customer Personal Data, use it for its own advertising or train general-purpose AI models with it.
3. Confidentiality and security
Formendi will allow access only to authorised people who need it and are bound by confidentiality or an appropriate statutory duty. It will implement and maintain measures appropriate to the processing risks under GDPR Article 32, including the minimum controls in Schedule B.
Measures may be improved without materially reducing the overall protection. Formendi will provide reasonably necessary information about material changes affecting the Customer's compliance.
4. Subprocessors
The Customer gives general written authorisation for the subprocessors identified in the current service-provider register for their specified purposes. Formendi will bind each subprocessor to materially equivalent data-protection obligations and remain responsible to the Customer for its performance as required by GDPR Article 28(4).
Formendi will give at least 30 days' advance written notice of an intended addition or replacement, identifying the service, location and safeguards. The Customer may object within 14 days on reasonable data-protection grounds. The parties will seek a practical solution; if unresolved, the affected processing must not start and either party may end the affected service with an export/return opportunity. Silence is not authorisation for a new independent use of the data.
The register also distinguishes providers' separate controller processing; that processing is not converted into processing on the Customer's instructions by this clause.
5. Assistance and requests
Taking account of the processing and available information, Formendi will assist with access, correction, erasure, restriction, portability and objections through appropriate technical and organisational measures. It will promptly forward a request relating to Customer Personal Data and will not answer substantively on the Customer's behalf without instructions, unless law requires it.
Formendi will also assist the Customer with security obligations, breach notifications, data-protection impact assessments and prior consultations with supervisory authorities where required. Ordinary assistance inherent in this DPA is included in the service; any exceptional charge must be reasonable and agreed beforehand and must not prevent legally required assistance.
6. Personal data breaches
Formendi will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, aiming to provide an initial notice within 24 hours. It will not wait for a completed investigation.
The notice will give available facts about the breach, affected categories/approximate numbers, likely consequences, containment and remediation, and a contact point. Missing information may follow in phases without undue delay. Formendi will investigate, preserve necessary evidence, mitigate harm and cooperate. The Customer determines its controller notifications, without limiting Formendi's own statutory notification duties.
7. International transfers
Formendi will not transfer Customer Personal Data outside the EEA without lawful instructions and a valid Chapter V GDPR mechanism. Relevant locations and safeguards are identified in the register. Where required, appropriate Commission transfer clauses, assessments and supplementary measures must be in place before the transfer.
An EU hosting location alone does not establish that all network, support or subprocessor processing stays in the EEA. Customer-directed external exports or integrations require their own lawful disclosure and clear prior information.
8. Return and deletion
During the service, the Customer can use available owner-authorised exports. At the end, the Customer may choose return in the supported export format followed by deletion, or deletion without return. Ordinary return/deletion is included.
For a requested provider switch, the transition and protected retrieval period in Terms section 12 apply before the deletion clock starts. Retrieval access is restricted to authorised export; normal access and public sharing end as specified there. Mandatory switching and erasure requirements prevail over a conflicting timetable in this DPA.
Access, public publication and active bearer links are revoked on confirmed closure. Customer Personal Data is removed from active systems within 30 days, sooner where required. Restricted backups expire within 30 further days; during that period they are isolated from ordinary processing and any recovery reapplies deletion before restored data becomes available.
Only legally required data may be retained longer, with restricted access and use limited to that requirement; Formendi will explain the basis where permitted. On request it will confirm completion of the applicable deletion steps. No export can recall copies already held by independent recipients.
9. Information, audit and compliance
Formendi will make available information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by the Customer or its mandated independent auditor. Documentation or suitable independent assurance may be used first where sufficient, but cannot replace a necessary audit right.
Routine audit logistics should use reasonable notice, confidentiality and measures protecting other customers. Frequency, scope and costs must be proportionate. These arrangements do not limit a supervisory authority, an urgent incident investigation or mandatory statutory access.
10. Responsibility and term
Each party remains responsible for obligations applying to it. The Terms' liability provisions apply only to the extent lawful and never remove mandatory data-protection liability, data-subject rights or Formendi's statutory responsibility for subprocessors. This DPA continues until Customer Personal Data is returned/deleted or any legally required restricted retention ends.
Schedule A — processing description
- Subject matter: hosted professional project-management workspace.
- Nature and operations: collection as instructed, organisation, storage, retrieval, calculations, report generation, permission-based disclosure, customer-selected publication/export and deletion.
- Purposes: deliver budgets, costs/orders, scheduling, client/supplier management, questionnaires, collaboration, messaging and customer-directed reports or publication.
- Duration: the service relationship and limited return/deletion/backup period in section 8.
- Data subjects: the Customer's staff and collaborators, clients and prospective clients, suppliers/contractors and their representatives, questionnaire respondents and message recipients.
- Data: names, business/contact details, project locations and identifiers where entered, budget/invoice/payment references and amounts linked to people, task dates, communications, professional preferences and relevant project notes.
- Excluded data: special categories under Article 9, criminal-offence data under Article 10, identity-document copies, other services' passwords and complete payment-card details. Unnecessary children's/household data must not be entered.
- Controller identification and contact: the Customer and authorised representative recorded at acceptance; updated through authenticated account administration. A Customer acting as processor must identify its relevant controller on request where needed for compliance.
- Subprocessors, processing locations and transfer arrangements: the current version of the provider register, incorporated for its listed services.
Schedule B — minimum security measures
Formendi will maintain:
- Risk-based access controls, least privilege, authenticated individual access, project/workspace authorization and prompt revocation of access.
- Confidentiality duties for staff and documented, restricted support/admin access.
- Encrypted network transport with validated TLS to the origin; secure session handling, CSRF/Origin protection and application input/output protections.
- Protected stored data and encrypted backups with controlled keys/access; no production content in public code, logs or test fixtures.
- Recoverable backups, periodic restore checks, age-based expiry and replay of erasure instructions after recovery.
- Vulnerability/patch management, logging limited to necessary data and incident detection/escalation.
- A breach-response process and assistance for rights requests, impact assessments and required authority consultations.
- A processing/subprocessor inventory, transfer controls, documented retention and periodic review of these measures.
These controls address confidentiality, integrity, availability and resilience. This schedule does not represent certification, end-to-end encryption, or a promise that an individual customer's account has MFA unless that feature is expressly offered.