Privacy Policy

Last updated: March 6, 2026

1. Controller

The controller responsible for data processing on this website is:

FORMM Media & Marketing
Edisonstrasse 63
12459 Berlin
Germany
Email: hello@formm.agency
Phone: (+49) 030 20 966 321

2. Data We Collect

2.1 Account Data

When you create an account, we collect:
• Email address
• Password (encrypted)
• Account creation date
• Subscription tier (free, starter, pro)

2.2 Brand Analysis Data

When you use our analysis tool, we store:
• Brand name
• Industry
• Target audience
• Brand values and personality
• Analysis results (archetype, design system, etc.)

2.3 Technical Data

Our hosting provider (Vercel) automatically collects:
• IP address
• Browser type and version
• Date and time of access
• Pages visited
• Referring website

3. Legal Basis for Processing

We process your data based on:
Contract performance (Art. 6(1)(b) GDPR): To provide our services
Legitimate interests (Art. 6(1)(f) GDPR): To improve our service and prevent fraud
Consent (Art. 6(1)(a) GDPR): Where you have given explicit consent

4. Third-Party Services

4.1 Supabase (Authentication & Database)

We use Supabase for authentication and data storage.
Privacy Policy: https://supabase.com/privacy

4.2 OpenAI (Data Processing)

We use OpenAI's GPT-4o to match your brand data against our proprietary Neuroscience Matrix (based on Jung, Kahneman, Scheier, and StoryBrand frameworks).
Important: We do NOT use AI to analyze or interpret your brand. AI is only used to compare your data with our established neuroscience frameworks.
Privacy Policy: https://openai.com/privacy
Note: Your data is not used to train OpenAI's models (API data retention policy).

4.3 Vercel (Hosting)

This website is hosted on Vercel.
Privacy Policy: https://vercel.com/legal/privacy-policy

5. Data Retention

We retain your data as long as:
• Your account is active
• Required by law (e.g., tax records: 10 years)
• Necessary for legitimate business purposes

You can request deletion of your account and data at any time.

6. Your Rights (GDPR)

You have the right to:
Access your personal data
Rectification of incorrect data
Erasure ("right to be forgotten")
Restriction of processing
Data portability
Object to processing
Withdraw consent at any time

To exercise these rights, contact us at: hello@formm.agency

7. Data Security

We implement appropriate technical and organizational measures to protect your data:
• SSL/TLS encryption (HTTPS)
• Encrypted password storage
• Regular security updates
• Access controls and authentication

8. Cookies

This website uses only essential cookies for authentication (session management). No tracking or analytics cookies are used.

9. International Data Transfers

Your data may be processed in:
• European Union (Supabase, Vercel EU regions)
• United States (OpenAI API)
Data transfers to the US are covered by Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.

10. Children's Privacy

Our service is not intended for children under 16. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes via email or a prominent notice on our website.

12. Contact & Complaints

For privacy-related questions or complaints:
Email: hello@formm.agency

You also have the right to lodge a complaint with a supervisory authority:
Berlin Commissioner for Data Protection and Freedom of Information
Friedrichstr. 219
10969 Berlin
Germany
Website: www.datenschutz-berlin.de