Privacy policy for the Forma app

Version: 1 — Date: 13 October 2025

This policy applies to the use of the Forma platform (app) and the marketing website. We act as controller for platform and account data. For patient and booking data handled for practices, we act as processor; the respective practice remains the controller.

Controller

Andre Zimpel (freelancer)

Henriettenstraße 65, 09112 Chemnitz, Germany

Email: hello@useforma.io

Domain: useforma.io

Data protection officer: not appointed (not required)

Categories of personal data

  • Accounts/organizations/members: name, email, roles, organization data (name, logo, contact details, address, and time-zone metadata)
  • Session/usage data: session token, durations, IP address, user agent, and rate-limit metadata
  • Services/bookings: appointment times, service, price/currency, status, buffers/segments, and rescheduling information
  • Patients (on behalf of the practice): identity, contact details/address, booking for another person; optional insurance status/medical information; internal practice notes
  • Communication: OTP emails, booking confirmations/cancellations, and ICS calendar files (no free-form message content)
  • Product feedback/support: message, category, impact, PagePath, and user agent
  • Analytics: app usage data (PostHog – EU)

Purposes of processing

  • Operation and provision of the platform (authentication, organizations/members/services)
  • Appointment and patient management for practices (on their behalf)
  • Security, stability, and prevention of misuse (rate limiting and technical logs)
  • Product improvement (feedback and app analytics)

Legal bases

  • Article 6(1)(b) GDPR (contract/pre-contractual steps): accounts, platform operation, and booking processes
  • Article 6(1)(f) GDPR (legitimate interests): security, stability, and product improvement
  • Article 6(1)(a) GDPR (consent): non-essential analytics/convenience functions, where used
  • Article 9 GDPR (special categories) for patient data: the practice is the controller; we process only on documented instructions (generally Article 9(2)(h) GDPR in conjunction with Section 22 BDSG)

Recipients/processors (subprocessors)

We do not disclose data to independent third parties for their own purposes. We use processors (data processing agreement; for third-country transfers, EU SCCs plus supplementary measures):

Current configuration: PostHog EU region, Neon EU (Frankfurt), maxcluster EU (Germany), and Hetzner EU (Germany).

  • Vercel (hosting/CDN/serverless) — Vercel Inc., USA; primary EU operation possible, global CDN; safeguards: data processing agreement and, where applicable, EU SCCs
  • Neon (database) — Neon, Inc., USA; EU region (Frankfurt); data processing agreement; EU SCCs; encryption in transit and at rest
  • maxcluster (email) — maxcluster GmbH, Germany; EU (Germany); data processing agreement; no third-country transfer
  • PostHog (app analytics) — PostHog Inc./PostHog Limited; EU Cloud configured; data processing agreement; where applicable, EU SCCs; UK adequacy decision
  • Hetzner (file storage) — Hetzner Online GmbH, Germany; EU (Germany); data processing agreement; no third-country transfer; only signed, non-public files

Transfers to third countries

Processing takes place predominantly within the EU/EEA. Globally distributed CDN/edge infrastructure (for example Vercel) may result in technical transfers to third countries; we use EU SCCs and supplementary safeguards for these transfers (TLS, encryption at rest, and minimized access).

Cookies and similar technologies

  • Required (app): authentication/session cookies (no consent required)
  • App analytics (PostHog): EU region, data-minimizing; depending on the configuration, consent may be required

Email/ICS

We send OTP emails and booking confirmations/cancellations with ICS calendar files. Content is minimized (no diagnoses/medical details and no free-form message content). Typical details are name, service, therapist, date/time, location, and, where applicable, price.

Retention periods

  • Sessions: 7 days
  • Account/organization/operational data: until deletion/end of contract or for the duration of statutory obligations
  • App logs/rate-limit data: for technically necessary periods
  • Patient/booking data (practice responsibility): storage according to the practice’s instructions and retention periods

Security of processing (summary of technical and organizational measures)

  • TLS for the app/APIs; provider-side encryption at rest
  • RBAC, least privilege, restrictive secret/key management; MFA recommended for administrator access
  • Backup/restore (for example database snapshots), monitoring/alerting, and basic audit logs
  • Hardening/patching, regular updates, and defensive logging (no PHI in logs)
  • Data minimization in emails/ICS

Data subject rights (DSAR)

You have rights of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent. Send requests relating to platform/account data to hello@useforma.io. Send requests relating to practice/patient data to the respective practice. We generally respond within one month.

Right to object (Article 21 GDPR)

Where we process data on the basis of legitimate interests, you may object on grounds relating to your particular situation.

Automated decision-making/profiling

None takes place.

Children

We do not specifically target minors; bookings are made by or through legal guardians via the practice.

Changes

The currently published version of this policy applies (Version 1 — 13 October 2025).

Supervisory authority/right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority. The competent authority at the controller’s registered office is the data protection authority of the Free State of Saxony.

PDF

The PDF version is available here: Forma-Privacy-Policy.pdf