Skip to content
CapabilitiesPlansBlogTry sample
CapabilitiesPlansBlogTry sampleRequest access
Request access Sign in
Home/Formendi Privacy Notice
Terms of Use Privacy Notice Data Processing Agreement Service providers Data export

privacy-2026-10-09 · [email protected]

https://formendi.com/privacy

  1. 1. Who is responsible
  2. 2. Our role and your professional's role
  3. 3. Information processed and its sources
  4. 4. Purposes and lawful bases
  5. 5. Who may receive information
  6. 6. Locations and international transfers
  7. 7. How long information is kept
  8. 8. Cookies and similar storage
  9. 9. Your rights and choices
  10. 10. Security and automated decisions
  11. 11. Children
  12. 12. Changes

Formendi Privacy Notice

Version: privacy-2026-10-09. Effective date: the date an authorised person accepts this document.

1. Who is responsible

Glavrio, UAB, company code 307648878, registered address as recorded in the Lithuanian Register of Legal Entities under company code 307648878, Lithuania, Lithuania, operates Formendi. Contact us about privacy, data rights or security at [email protected].

This notice covers Formendi's website, professional beta, waitlist, support and related features. The four public calculator websites have separate notices. Following a link between sites does not automatically transfer your private workspace records.

2. Our role and your professional's role

We are a data controller for our own account administration, website security, support, service communications and other purposes described below.

When a professional customer enters personal data about clients, suppliers or project participants, that customer normally decides why the data is used and is the controller. We process those workspace data on its instructions under our Data Processing Agreement (DPA). If the customer itself acts for another controller, the authorised processor/subprocessor chain applies.

If your designer, architect or contractor sends you a questionnaire or includes you in a project, ask that professional about their purposes, legal basis and retention. We will help them handle your rights and will also address requests concerning data for which we are the controller. Our notice does not replace their own privacy information.

3. Information processed and its sources

Depending on your use, we process:

  • Account and business details: email, name, profession, business identity, country, language, preferences and authority/contract acceptance records.
  • Login and security information: session identifiers, authentication records, password hashes if you choose a password, IP/network and browser/device signals needed for access and abuse prevention. We do not store passwords in readable form.
  • Workspace content: project names and locations where entered, budgets, invoice references, payment records, schedules, choices, client/supplier contacts, notes, invitations, questionnaires and generated reports.
  • Communications: support requests, feedback, in-app messages, recipients, timestamps and related notifications.
  • Optional publication and matching data: fields you choose for a public profile, professional visibility and a price request, including name, email, phone, area and source website where supplied.
  • Website operation and preferences: requested pages, security events, language, cookie choices and temporary schedule display state.

Information comes from you, your organisation, people who invite you or enter project data, questionnaire respondents and, where that separate feature is enabled lawfully, public-calculator price requesters. Our hosting/security providers process technical information when you connect. You can use the sample without an account; use fictional details only.

4. Purposes and lawful bases

For our controller activities:

PurposeLawful basis
Respond to a requested beta invitation, create an account and provide the service to an individual business customerSteps requested before a contract and performance of that contract: GDPR Article 6(1)(b).
Administer an organisation's users and business relationshipLegitimate interests in providing and managing the organisation's service: Article 6(1)(f).
Authenticate, prevent abuse, investigate incidents and maintain service reliabilityLegitimate interests in protecting users, information and the service: Article 6(1)(f); specific legal obligations where applicable: Article 6(1)(c).
Handle support and operational noticesContract performance for the contracting individual; otherwise legitimate interests in resolving requests and managing business communications.
Retain necessary contract evidence, handle disputes and comply with lawful obligationsLegitimate interests in establishing, exercising or defending claims; Article 6(1)(c) where a specific legal duty applies.
Send optional promotional email or use optional analytics requiring consentYour separate consent: Article 6(1)(a), plus applicable electronic-communications rules.
Arrange a price-request introduction specifically requested by an individualRequested pre-contract steps where applicable; any consent or other basis needed for the actual recipient disclosure is explained in the request form before submission.

We balance legitimate interests against people's rights and can explain the relevant assessment on request. Workspace processing on a customer's behalf follows the customer's documented instructions; its own lawful basis must be explained by that customer. We do not rely on accepting this notice as blanket consent.

Required information is identified at collection. Without an email we cannot provide an email-based account or reply to a waitlist request. Optional marketing, public publication and non-essential measurement are not required to use the private beta. Public-calculator price-request distribution is disabled in this initial beta. Before enabling it, we will provide the specific request notice, recipient information and applicable choices.

5. Who may receive information

Authorised Glavrio staff and contracted service providers may access information only as needed for their work, under appropriate confidentiality and data-protection obligations. The current service-provider register identifies hosting, security, email delivery and backup providers, their purposes, locations and relevant safeguards.

Other users receive only information made available through project permissions, messages or an enabled discovery feature. If you publish a profile, its selected fields become public. Downloaded reports go to the people you choose. A private note is excluded from client-report templates; the permitted financial fields depend on the template.

We may disclose necessary information to advisers, competent authorities or courts where lawfully required or necessary for a legal claim. In an actual business transfer, necessary data may be disclosed under confidentiality, with notice and lawful safeguards where required.

We do not sell private project data, disclose it to advertisers for targeting or use it to train general-purpose AI models. An optional lead introduction is a disclosed request-routing service, not permission to sell your workspace records.

6. Locations and international transfers

Our primary workspace hosting is with Hetzner in Finland, within the EEA. Cloudflare provides network/security services and, on protected forms, Turnstile. Its global service may process technical and request data, including content transmitted to deliver the requested page or action, outside the EEA. When we send operational email, the email delivery provider listed in the register processes the recipient and message information needed for delivery.

For transfers requiring safeguards, we use an applicable adequacy decision or appropriate safeguards such as the European Commission's standard contractual clauses, together with additional measures where needed. The register identifies the actual transfer arrangements. Ask [email protected] for information or a copy of relevant safeguards, with necessary confidential material redacted.

Cloudflare processes Turnstile signals on our behalf to protect the site and also acts as a separate controller for improving its bot-detection capabilities, as explained in its Turnstile Privacy Addendum. This may involve IP address, browser/network signals and the site origin.

If you choose to open an external calendar form, the event details shown before the transfer are sent to that provider. An ICS download does not connect your calendar account or create live synchronisation. Google sign-in and payment processing are not enabled in this beta.

7. How long information is kept

InformationRetention
Account profile and private workspace contentWhile the service relationship is active; removed from active systems within 30 days after confirmed closure, sooner where law requires.
Public visibility, access links and sessionsDisabled on closure or the applicable unpublish/revoke action.
Restricted backupsExpire within 30 days after active deletion, so some copies may remain up to 60 days after closure. They are used only for recovery, and deletions are reapplied before restored data is made available.
WaitlistUntil admission, withdrawal or 12 months after your last genuine interaction, whichever comes first.
Routine security/access logsNormally 30 days; necessary incident evidence may be isolated longer for investigation or legal claims. Provider-specific periods are in the register.
Support correspondenceNormally 24 months after resolution; unnecessary project details are removed sooner.
Optional marketing contact detailsUntil withdrawal or 24 months without genuine engagement. Minimal suppression information may remain to respect your opt-out.
Minimal contract, acceptance and consent evidenceNormally 3 years after the relationship or consent ends; longer only where a documented legal obligation or claim requires it.

If you request a provider switch, the agreed transition and at least 30-day protected retrieval period in Terms section 12 precede the deletion timetable above. Only authorised retrieval remains after normal project access ends; mandatory erasure requirements take priority.

The sample session expires after 30 minutes and its project content is held in temporary memory, with expired samples removed during bounded cleanup. It is not saved to your permanent workspace. Security logs and any copies you download have their own lifecycle.

We retain only necessary records under a legal hold, restrict their use and review the need. A professional customer's own retention responsibilities may differ. Closing your account does not erase another customer's lawfully held records or files already received by others.

8. Cookies and similar storage

We use the following first-party storage for requested functions:

NamePurposeLifetime
pw_sessionSecure authenticated accessUp to 12 hours; revoked sooner on sign-out or closure.
pw_demoSeparate temporary sample session30 minutes.
langRemember your chosen languageUp to 1 year.
pw_consentRemember optional-cookie choice, when such a choice is offeredUp to 1 year.
pw-schedule-scroll in sessionStorageRestore schedule scroll position after your actionConsumed on restoration or ends with the browser tab session.

Cloudflare security/challenge technology processes the technical signals necessary to protect the requested service. Any security cookies or storage used in the deployed configuration are described in the provider register. A security label does not authorise unrelated tracking.

Optional analytics are disabled for the initial beta covered by this notice. If introduced, we will first explain the provider, purpose, cookies and retention and request consent wherever required. Accept and Reject will be equally accessible; Cookie preferences will let you change your choice. Refusing optional analytics does not prevent use of the service.

We may maintain genuinely anonymous aggregate service counts; where information can identify or track someone, it must have the appropriate lawful basis and, for non-essential device access, any required consent. We do not treat first-party or cookieless technology as automatically exempt.

9. Your rights and choices

Subject to applicable conditions, you can request access, correction, erasure, restriction and portability of your personal data. You can object to processing based on legitimate interests, and you can always object to direct marketing. Withdraw consent at any time without affecting earlier lawful processing.

Contact [email protected]. We may ask for proportionate verification and will not request unnecessary identity documents. We normally respond within one month; complex or numerous requests may need up to two further months, with reasons provided within the first month. Requests are normally free, subject to the limited exceptions allowed by law.

A workspace export is useful but does not replace your right to request all personal data within the applicable scope. If we act as processor, we will help the relevant customer/controller respond and tell you who to contact where appropriate.

You may complain directly to the Lithuanian State Data Protection Inspectorate, the Latvian Data State Inspectorate, or another competent authority, including where you usually live or work. You do not have to contact us first.

10. Security and automated decisions

We use technical and organisational safeguards appropriate to the risks, including restricted access, protected authentication, encrypted network transport, backup controls and incident handling. No online service can guarantee absolute security. We do not claim end-to-end encryption, a particular certification or that authorised staff can never access records.

Formendi does not make solely automated decisions about people that produce legal or similarly significant effects. Automatic budget calculations are project arithmetic, not a credit or eligibility assessment. Abuse controls may temporarily restrict requests; contact us if you think they prevented legitimate access.

11. Children

Formendi accounts are intended for adults using the service professionally. We do not knowingly offer accounts to children. Do not enter unnecessary information about children or household members. Contact us if such information has been submitted improperly.

12. Changes

We may update this notice when our practices or legal obligations change. We identify the effective date and give prominent notice of material changes. A new notice does not itself create consent for a new purpose. Previous versions are kept in our legal archive.

Project budgets, schedules and client reports for interior design, renovation and landscape professionals. From the makers of the four free calculators.

Product

Home Capabilities Plans Blog Try sample Request access Sign in

Tools

BudgetOrdersCosts & paymentsChanges and selectionsClient reportsScheduleClientsSuppliersCalculator estimate
Operator Glavrio, UAB 307648878 [email protected]
Help Terms of Use Privacy Notice Data Processing Agreement Service providers Cookie preferences
EnglishLietuviųLatviešu