Last updated: 28 August 2026
Effective from: 28 August 2026
Futuwise is a project management platform with ready-made workflow templates and AI-assisted guidance, available at www.futuwise.com and app.futuwise.com (together, the "Service").
The Service is operated by:
Futuwise OÜ, registry code 16873687, registered at Herne tn 8-2, Tallinn, 10135, Estonia
Email: futuwise@futuwise.com
In this policy, "we", "us" and "our" mean Futuwise OÜ. "You" means the person whose personal data we process.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Data protection questions go to futuwise@futuwise.com.
This is the most important thing to understand about how we handle data, so we want to be clear about it up front.
We are the controller for personal data relating to the accounts and the running of the Service — your name, email address, login credentials, billing details, support conversations, and technical logs. For this data, we decide why and how it is processed, and this policy describes what we do.
We are a processor for the content you put into the platform — project plans, tasks, phases, descriptions, comments, uploaded files, and any personal data about third parties that appears inside them ("Customer Content"). Here, the controller is you or the organisation whose workspace you belong to. We process Customer Content only on that controller's documented instructions, as set out in our Data Processing Agreement (Section 14).
If you use Futuwise through your employer's or a client's workspace, that organisation decides what goes into the workspace and how long it stays. Questions about that data should go to them first. We will help them respond.
| Category | Examples | When |
|---|---|---|
| Account data | Name, email address, password (stored hashed), profile picture, language and notification preferences | On sign-up and when you edit your profile |
| Workspace data | Workspace name, your role, who invited you, the members you invite | When a workspace is created or you join one |
| Billing data | Billing name, billing address, VAT number, plan, invoice history, last four digits and card brand | When you subscribe to a paid plan |
| Customer Content* | Projects, phases, tasks, deadlines, priorities, comments, attachments, custom templates | Whenever you use the platform |
| Communications | Support emails, contact form submissions, feedback, survey responses | When you contact us |
| Marketing preferences | Newsletter subscription status | If you sign up for our newsletter |
* We handle Customer Content as a processor on behalf of the workspace controller, not as a controller in our own right. It is listed here so you can see the full picture of what sits on our systems, but Sections 4 and 8 of this policy describe our controller processing. Our obligations for Customer Content are set out in the Data Processing Agreement (Section 14).
We do not collect full payment card numbers. Card details are entered directly into our payment provider's environment and never reach our servers.
Providing your name, email address and password is a contractual requirement — without it we cannot create an Account or provide the Service, so you would not be able to use Futuwise. Providing billing data is a contractual and, for invoicing, a legal requirement for paid plans; without it we cannot take payment. Everything else — profile picture, newsletter subscription, optional profile fields, survey answers — is entirely voluntary, and declining has no consequence beyond the loss of that specific feature.
| Category | Examples |
|---|---|
| Technical data | IP address, browser type and version, operating system, device type, screen size, language settings |
| Usage data | Pages and features viewed, actions taken, templates used, session timestamps, referring URL |
| Log data | Requests to our servers, error reports, security events such as failed login attempts |
| Cookie data | Session identifiers, preference cookies, analytics identifiers — see Section 10 |
If you sign in with Google, Google sends us your name, email address, profile picture and Google account identifier. We do not receive your Google password and we do not get access to your Gmail, Drive or other Google services.
Our payment provider tells us whether a payment succeeded, the amount, the currency, and the country of the card — not the card number itself.
If someone invited you to a workspace. Where an existing user invites you, we receive your email address — and sometimes your name — from that user, before you have any relationship with us. This notice serves as your information under Article 14 GDPR: the source of the data is the person who invited you and the workspace they belong to; the data concerned is your email address, any name they entered, and the fact of the invitation; we use it to send the invitation and, if you accept, to create your account, on the basis of our legitimate interest in enabling collaboration (Art. 6(1)(f)) and, once you accept, on the basis of our contract with you. If you do not accept, we delete the invitation and the associated email address within 90 days. You can object at any time by emailing futuwise@futuwise.com, and every invitation email includes a way to decline.
We do not deliberately collect special categories of data under Article 9 GDPR — health data, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, or data concerning sex life or sexual orientation.
Do not put such data into the Service. Our Data Processing Agreement (Section 4) prohibits it without our prior written agreement, because our security measures are designed for ordinary business project data rather than for the heightened risk this data carries. If you do so anyway, you remain the controller for it, you are responsible for having a valid condition under Article 9(2), and you are in breach of the DPA. The same applies to criminal offence data under Article 10.
We do not collect location data from GPS or mobile device sensors. We infer only an approximate country from your IP address, for security and tax purposes.
| Purpose | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Creating and running your account; providing the platform | Account, workspace, technical data | Contract — Art. 6(1)(b) |
| Processing payments, invoicing, dunning | Billing, account data | Contract — Art. 6(1)(b); legal obligation for invoices — Art. 6(1)(c) |
| Generating AI suggestions and guidance (paid AI features) | The specific Customer Content you submit to the AI feature | We act as processor here, on the workspace controller's documented instructions under Art. 28. The controller determines its own legal basis; our contractual basis with the customer is Art. 6(1)(b) |
| Sending service emails (invitations, password resets, billing notices, changes to terms) | Account data | Contract — Art. 6(1)(b) |
| Keeping the Service secure; preventing fraud and abuse | Technical, log, account data | Legitimate interests — Art. 6(1)(f): our interest in protecting the platform, our users and our business from unauthorised access, fraudulent sign-ups and abuse |
| Diagnosing faults and improving reliability and features | Usage, technical, log data | Legitimate interests — Art. 6(1)(f): our interest in keeping the Service working correctly and developing a product our users want |
| Analytics and understanding how the Service is used | Cookie and usage data | Consent — Art. 6(1)(a), through the cookie banner |
| Sending newsletters and product marketing | Email address, marketing preferences | Consent — Art. 6(1)(a), withdrawable at any time |
| Responding to support requests | Communications, account data | Contract or legitimate interests — Art. 6(1)(b)/(f) |
| Meeting accounting, tax and legal obligations | Billing data, transaction records | Legal obligation — Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | Whatever is relevant to the claim | Legitimate interests — Art. 6(1)(f): our interest in protecting our legal position |
| Transferring the business in a merger, acquisition or sale of assets | Account and billing data | Legitimate interests — Art. 6(1)(f): our interest in being able to restructure or sell the business as a going concern |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded the processing is proportionate and within what you would reasonably expect. You can object at any time (Section 8) and we will stop unless we have compelling grounds that override your interests.
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing that already happened.
Our Premium plan includes AI-assisted guidance and automations. This section explains exactly what happens.
What is sent. When you use an AI feature, we send the relevant content — for example, the project description, task list or phase you are working on — to a third-party AI model provider so that a suggestion can be generated. We send only what the feature needs. We do not send your whole workspace, and we do not send billing data or passwords.
What the provider does with it. We use AI providers under business or enterprise terms that prohibit them from using our submissions to train their models. Providers may retain inputs and outputs for a limited period for abuse monitoring, after which they are deleted. Our current AI provider(s) are listed in our subprocessor list (Section 6).
No automated decisions about you. AI output in Futuwise is a suggestion. It does not produce legal effects for you and it does not significantly affect you within the meaning of Article 22 GDPR. Nothing is decided automatically — a human always chooses whether to act on a suggestion.
Accuracy. AI-generated content can be wrong or incomplete. Do not rely on it as professional, legal, financial or medical advice.
Turning it off. AI features are only available on plans that include them, and they only run when you trigger them. If you do not use them, no content is sent to an AI provider. Workspace administrators can disable AI features for a workspace.
We do not sell your personal data. We never have and we do not intend to. We share it in four situations.
We use third parties to run the Service. Each one is bound by a written contract that limits them to processing data on our instructions and requires appropriate security. The current list:
Providers that handle Customer Content (we act as processor; these are the subprocessors under our DPA):
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Heroku | Cloud hosting, database, backups | All Customer Content and account data | Europe |
| AWS | Storage | All Customer uploaded content | Europe |
| Mailtrap | Transactional email delivery | Recipient name, email address, notification content | Europe |
| OpenAI | Generating AI suggestions | Only the content you submit to an AI feature | USA |
Providers that handle data we control (account, billing, support and analytics data):
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Stripe | Payment processing, invoicing, tax | Billing data, card data (held by them, not us) | Dublin, Ireland |
| Google Ireland Limited | Google sign-in for EEA users | Account identifier, email address | Ireland (EEA) |
| Google LLC | Analytics, where data reaches the US entity | Usage and cookie data | United States |
We keep this list current. If we add or replace a provider that handles Customer Content, we notify affected workspace customers by email at least 30 days before the change takes effect — you do not need to subscribe to anything to receive that notice — and they may object under Section 5 of our Data Processing Agreement.
Project management is collaborative. Other members of a workspace can see your name, profile picture, email address, and the content you create or are assigned to. Workspace owners and administrators can see all content in the workspace, manage members, and export or delete workspace data.
We may disclose data where we are legally required to, or where it is necessary to establish or defend legal claims, enforce our Terms of Service, or protect the rights and safety of users or the public. Where we are permitted to tell you about such a request, we will.
If we are involved in a merger, acquisition, restructuring or sale of assets, personal data may transfer to the acquiring party. We will notify you before your data becomes subject to a different privacy policy, and you will be able to delete your account first.
We host and process data within the European Economic Area wherever we can. Some of our providers — particularly AI, analytics and payment providers — process data in the United States or other countries outside the EEA.
Where data leaves the EEA, we rely on one of the following safeguards under Chapter V GDPR:
You can request a copy of the relevant safeguards by emailing futuwise@futuwise.com.
Your right to object
You have the right to object at any time, on grounds relating to your particular situation, to our processing of your personal data based on legitimate interests, including profiling. If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
Where we process your personal data for direct marketing, you have the right to object at any time, with no exceptions and no need to give a reason. If you object, we will stop immediately.
To object, email futuwise@futuwise.com or use the unsubscribe link in any marketing email. This right is given to you by Article 21 GDPR.
Under the GDPR you have the following rights. They apply to data for which we are the controller. For Customer Content, direct your request to the workspace controller — we will forward it and assist them.
| Right | What it means | Article |
|---|---|---|
| Access | Get confirmation of whether we process your data, and a copy of it | Art. 15 |
| Rectification | Have inaccurate data corrected or incomplete data completed | Art. 16 |
| Erasure | Have your data deleted where one of the grounds applies | Art. 17 |
| Restriction | Have processing paused while a dispute about accuracy or lawfulness is resolved | Art. 18 |
| Portability | Receive data you gave us in a structured, machine-readable format, or have it sent to another provider | Art. 20 |
| Objection | Object to processing based on legitimate interests; object to direct marketing at any time, with no exceptions | Art. 21 |
| Withdraw consent | Withdraw consent for anything based on it, without affecting past processing | Art. 7(3) |
| No automated decisions | Not be subject to decisions based solely on automated processing producing legal or similarly significant effects — we do not make such decisions | Art. 22 |
How to exercise them. Email futuwise@futuwise.com from the address on your account, or use the settings in the app where available. We respond within one month. If a request is complex we may extend by up to two further months and will tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive.
We may need to verify your identity before acting, to make sure we are not disclosing someone else's data.
Complaints. If you think we have handled your data unlawfully, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, www.aki.ee, info@aki.ee. You may also complain to the authority in your country of residence or workplace.
| Data | Retention period |
|---|---|
| Account data | While your account is active, then deleted from the live Service within 30 days of account deletion |
| Customer Content | While the workspace exists; deleted from the live Service within 30 days of the earliest of workspace deletion, account termination, or a deletion request, subject to the workspace controller's own instructions |
| Backups | Rolling backups retained for a further 14 days after live deletion, then overwritten — so full erasure completes within 30 days |
| Billing records and invoices | 7 years from the end of the financial year, as required by the Estonian Accounting Act |
| Security and access logs | 12 months |
| Analytics data | 14 months |
| Support correspondence | 3 years from the last message |
| Marketing consent records | Until consent is withdrawn, plus 3 years to evidence the consent |
| Unaccepted workspace invitations | 90 days, then deleted |
| Data relevant to a legal claim | Until the claim and any appeal period are concluded |
Deleted data persists in encrypted backups for the backup period above before being overwritten. During that window it is not restored into the live Service except in a disaster recovery event, and it stays protected by the security measures in Section 11.
We use the following categories:
Strictly necessary. Session and authentication cookies, security tokens, load balancing. These are required for the Service to work and are set without consent under Article 5(3) of the ePrivacy Directive.
Preference. Remembering your language, theme, and interface choices. These are not strictly necessary, so we set them only with your consent — except where the setting is one you chose yourself in that session and storing it is what you asked for.
Analytics. Understanding which features are used and where people get stuck. Set only with your consent.
Marketing. We do not use advertising or remarketing cookies.
We protect your data with measures appropriate to the risk, including:
No system is perfectly secure. If a breach occurs, what happens depends on which data is affected:
Data we control — account, billing, support, log and analytics data. We notify the Estonian Data Protection Inspectorate without undue delay and, where feasible, within 72 hours of becoming aware of the breach, where it is likely to result in a risk to people's rights and freedoms. Where the risk is high, we also notify the affected individuals without undue delay.
Customer Content, where we are processor. We notify the workspace controller without undue delay and in any event within 48 hours of becoming aware of the breach, with the information set out in Section 7 of our Data Processing Agreement. It is then for that controller — not us — to notify their supervisory authority and their data subjects.
The Service is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children under 16. If we learn that we have, we will delete it. If you believe a child has given us personal data, contact futuwise@futuwise.com.
We send product and marketing emails only if you have opted in, or if you are an existing customer and the message concerns similar products — the soft opt-in under the Estonian Electronic Communications Act. Every marketing email contains an unsubscribe link, and unsubscribing takes effect immediately. Service emails — invitations, password resets, billing, security and legal notices — are part of the Service and cannot be opted out of while you have an account.
If you use Futuwise as an organisation and we process personal data on your behalf, our Data Processing Agreement forms part of our contract with you and satisfies Article 28 GDPR. It covers the subject matter and duration of processing, our obligations, the subprocessor list, the technical and organisational measures, audit rights, breach notification, and the arrangements for transfers.
You do not need to sign a separate copy — it applies automatically when you accept our Terms of Service. If your organisation requires a countersigned version, email futuwise@futuwise.com.
We may update this policy as the Service and the law change. The "Last updated" date at the top always reflects the current version. If a change materially affects your rights or how we use your data, we will notify you by email or through the Service at least 30 days before it takes effect, so that you have time to review it and, if you disagree, close your account.
Questions, requests and complaints about this policy:
Futuwise OÜ, registry code 16873687, registered at Herne tn 8-2, Tallinn, 10135, Estonia
Email: futuwise@futuwise.com