Privacy Policy

Last updated: 28 August 2026

Effective from: 28 August 2026

1. Who we are

Futuwise is a project management platform with ready-made workflow templates and AI-assisted guidance, available at www.futuwise.com and app.futuwise.com (together, the "Service").

The Service is operated by:

Futuwise OÜ, registry code 16873687, registered at Herne tn 8-2, Tallinn, 10135, Estonia

Email: futuwise@futuwise.com

In this policy, "we", "us" and "our" mean Futuwise OÜ. "You" means the person whose personal data we process.

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Data protection questions go to futuwise@futuwise.com.

2. Two different roles: controller and processor

This is the most important thing to understand about how we handle data, so we want to be clear about it up front.

We are the controller for personal data relating to the accounts and the running of the Service — your name, email address, login credentials, billing details, support conversations, and technical logs. For this data, we decide why and how it is processed, and this policy describes what we do.

We are a processor for the content you put into the platform — project plans, tasks, phases, descriptions, comments, uploaded files, and any personal data about third parties that appears inside them ("Customer Content"). Here, the controller is you or the organisation whose workspace you belong to. We process Customer Content only on that controller's documented instructions, as set out in our Data Processing Agreement (Section 14).

If you use Futuwise through your employer's or a client's workspace, that organisation decides what goes into the workspace and how long it stays. Questions about that data should go to them first. We will help them respond.

3. What personal data we collect

3.1 Data you give us

CategoryExamplesWhen
Account dataName, email address, password (stored hashed), profile picture, language and notification preferencesOn sign-up and when you edit your profile
Workspace dataWorkspace name, your role, who invited you, the members you inviteWhen a workspace is created or you join one
Billing dataBilling name, billing address, VAT number, plan, invoice history, last four digits and card brandWhen you subscribe to a paid plan
Customer Content*Projects, phases, tasks, deadlines, priorities, comments, attachments, custom templatesWhenever you use the platform
CommunicationsSupport emails, contact form submissions, feedback, survey responsesWhen you contact us
Marketing preferencesNewsletter subscription statusIf you sign up for our newsletter

* We handle Customer Content as a processor on behalf of the workspace controller, not as a controller in our own right. It is listed here so you can see the full picture of what sits on our systems, but Sections 4 and 8 of this policy describe our controller processing. Our obligations for Customer Content are set out in the Data Processing Agreement (Section 14).

We do not collect full payment card numbers. Card details are entered directly into our payment provider's environment and never reach our servers.

3.1a Do you have to provide this data?

Providing your name, email address and password is a contractual requirement — without it we cannot create an Account or provide the Service, so you would not be able to use Futuwise. Providing billing data is a contractual and, for invoicing, a legal requirement for paid plans; without it we cannot take payment. Everything else — profile picture, newsletter subscription, optional profile fields, survey answers — is entirely voluntary, and declining has no consequence beyond the loss of that specific feature.

3.2 Data we collect automatically

CategoryExamples
Technical dataIP address, browser type and version, operating system, device type, screen size, language settings
Usage dataPages and features viewed, actions taken, templates used, session timestamps, referring URL
Log dataRequests to our servers, error reports, security events such as failed login attempts
Cookie dataSession identifiers, preference cookies, analytics identifiers — see Section 10

3.3 Data we receive from third parties

If you sign in with Google, Google sends us your name, email address, profile picture and Google account identifier. We do not receive your Google password and we do not get access to your Gmail, Drive or other Google services.

Our payment provider tells us whether a payment succeeded, the amount, the currency, and the country of the card — not the card number itself.

If someone invited you to a workspace. Where an existing user invites you, we receive your email address — and sometimes your name — from that user, before you have any relationship with us. This notice serves as your information under Article 14 GDPR: the source of the data is the person who invited you and the workspace they belong to; the data concerned is your email address, any name they entered, and the fact of the invitation; we use it to send the invitation and, if you accept, to create your account, on the basis of our legitimate interest in enabling collaboration (Art. 6(1)(f)) and, once you accept, on the basis of our contract with you. If you do not accept, we delete the invitation and the associated email address within 90 days. You can object at any time by emailing futuwise@futuwise.com, and every invitation email includes a way to decline.

3.4 What we do not collect

We do not deliberately collect special categories of data under Article 9 GDPR — health data, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, or data concerning sex life or sexual orientation.

Do not put such data into the Service. Our Data Processing Agreement (Section 4) prohibits it without our prior written agreement, because our security measures are designed for ordinary business project data rather than for the heightened risk this data carries. If you do so anyway, you remain the controller for it, you are responsible for having a valid condition under Article 9(2), and you are in breach of the DPA. The same applies to criminal offence data under Article 10.

We do not collect location data from GPS or mobile device sensors. We infer only an approximate country from your IP address, for security and tax purposes.

4. Why we process your data, and on what legal basis

PurposeData usedLegal basis (Art. 6 GDPR)
Creating and running your account; providing the platformAccount, workspace, technical dataContract — Art. 6(1)(b)
Processing payments, invoicing, dunningBilling, account dataContract — Art. 6(1)(b); legal obligation for invoices — Art. 6(1)(c)
Generating AI suggestions and guidance (paid AI features)The specific Customer Content you submit to the AI featureWe act as processor here, on the workspace controller's documented instructions under Art. 28. The controller determines its own legal basis; our contractual basis with the customer is Art. 6(1)(b)
Sending service emails (invitations, password resets, billing notices, changes to terms)Account dataContract — Art. 6(1)(b)
Keeping the Service secure; preventing fraud and abuseTechnical, log, account dataLegitimate interests — Art. 6(1)(f): our interest in protecting the platform, our users and our business from unauthorised access, fraudulent sign-ups and abuse
Diagnosing faults and improving reliability and featuresUsage, technical, log dataLegitimate interests — Art. 6(1)(f): our interest in keeping the Service working correctly and developing a product our users want
Analytics and understanding how the Service is usedCookie and usage dataConsent — Art. 6(1)(a), through the cookie banner
Sending newsletters and product marketingEmail address, marketing preferencesConsent — Art. 6(1)(a), withdrawable at any time
Responding to support requestsCommunications, account dataContract or legitimate interests — Art. 6(1)(b)/(f)
Meeting accounting, tax and legal obligationsBilling data, transaction recordsLegal obligation — Art. 6(1)(c)
Establishing, exercising or defending legal claimsWhatever is relevant to the claimLegitimate interests — Art. 6(1)(f): our interest in protecting our legal position
Transferring the business in a merger, acquisition or sale of assetsAccount and billing dataLegitimate interests — Art. 6(1)(f): our interest in being able to restructure or sell the business as a going concern

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded the processing is proportionate and within what you would reasonably expect. You can object at any time (Section 8) and we will stop unless we have compelling grounds that override your interests.

Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing that already happened.

5. AI features

Our Premium plan includes AI-assisted guidance and automations. This section explains exactly what happens.

What is sent. When you use an AI feature, we send the relevant content — for example, the project description, task list or phase you are working on — to a third-party AI model provider so that a suggestion can be generated. We send only what the feature needs. We do not send your whole workspace, and we do not send billing data or passwords.

What the provider does with it. We use AI providers under business or enterprise terms that prohibit them from using our submissions to train their models. Providers may retain inputs and outputs for a limited period for abuse monitoring, after which they are deleted. Our current AI provider(s) are listed in our subprocessor list (Section 6).

No automated decisions about you. AI output in Futuwise is a suggestion. It does not produce legal effects for you and it does not significantly affect you within the meaning of Article 22 GDPR. Nothing is decided automatically — a human always chooses whether to act on a suggestion.

Accuracy. AI-generated content can be wrong or incomplete. Do not rely on it as professional, legal, financial or medical advice.

Turning it off. AI features are only available on plans that include them, and they only run when you trigger them. If you do not use them, no content is sent to an AI provider. Workspace administrators can disable AI features for a workspace.

6. Who we share your data with

We do not sell your personal data. We never have and we do not intend to. We share it in four situations.

6.1 Service providers (subprocessors)

We use third parties to run the Service. Each one is bound by a written contract that limits them to processing data on our instructions and requires appropriate security. The current list:

Providers that handle Customer Content (we act as processor; these are the subprocessors under our DPA):

ProviderWhat they doData involvedLocation
HerokuCloud hosting, database, backupsAll Customer Content and account dataEurope
AWSStorageAll Customer uploaded contentEurope
MailtrapTransactional email deliveryRecipient name, email address, notification contentEurope
OpenAIGenerating AI suggestionsOnly the content you submit to an AI featureUSA

Providers that handle data we control (account, billing, support and analytics data):

ProviderWhat they doData involvedLocation
StripePayment processing, invoicing, taxBilling data, card data (held by them, not us)Dublin, Ireland
Google Ireland LimitedGoogle sign-in for EEA usersAccount identifier, email addressIreland (EEA)
Google LLCAnalytics, where data reaches the US entityUsage and cookie dataUnited States

We keep this list current. If we add or replace a provider that handles Customer Content, we notify affected workspace customers by email at least 30 days before the change takes effect — you do not need to subscribe to anything to receive that notice — and they may object under Section 5 of our Data Processing Agreement.

6.2 Other users in your workspace

Project management is collaborative. Other members of a workspace can see your name, profile picture, email address, and the content you create or are assigned to. Workspace owners and administrators can see all content in the workspace, manage members, and export or delete workspace data.

6.3 Legal and safety

We may disclose data where we are legally required to, or where it is necessary to establish or defend legal claims, enforce our Terms of Service, or protect the rights and safety of users or the public. Where we are permitted to tell you about such a request, we will.

6.4 Business transfers

If we are involved in a merger, acquisition, restructuring or sale of assets, personal data may transfer to the acquiring party. We will notify you before your data becomes subject to a different privacy policy, and you will be able to delete your account first.

7. International transfers

We host and process data within the European Economic Area wherever we can. Some of our providers — particularly AI, analytics and payment providers — process data in the United States or other countries outside the EEA.

Where data leaves the EEA, we rely on one of the following safeguards under Chapter V GDPR:

  • an adequacy decision by the European Commission, including the EU–US Data Privacy Framework where the recipient is certified under it; or
  • the European Commission's Standard Contractual Clauses, combined with supplementary technical and organisational measures such as encryption in transit and at rest and data minimisation.

You can request a copy of the relevant safeguards by emailing futuwise@futuwise.com.

8. Your rights

Your right to object

You have the right to object at any time, on grounds relating to your particular situation, to our processing of your personal data based on legitimate interests, including profiling. If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.

Where we process your personal data for direct marketing, you have the right to object at any time, with no exceptions and no need to give a reason. If you object, we will stop immediately.

To object, email futuwise@futuwise.com or use the unsubscribe link in any marketing email. This right is given to you by Article 21 GDPR.

Under the GDPR you have the following rights. They apply to data for which we are the controller. For Customer Content, direct your request to the workspace controller — we will forward it and assist them.

RightWhat it meansArticle
AccessGet confirmation of whether we process your data, and a copy of itArt. 15
RectificationHave inaccurate data corrected or incomplete data completedArt. 16
ErasureHave your data deleted where one of the grounds appliesArt. 17
RestrictionHave processing paused while a dispute about accuracy or lawfulness is resolvedArt. 18
PortabilityReceive data you gave us in a structured, machine-readable format, or have it sent to another providerArt. 20
ObjectionObject to processing based on legitimate interests; object to direct marketing at any time, with no exceptionsArt. 21
Withdraw consentWithdraw consent for anything based on it, without affecting past processingArt. 7(3)
No automated decisionsNot be subject to decisions based solely on automated processing producing legal or similarly significant effects — we do not make such decisionsArt. 22

How to exercise them. Email futuwise@futuwise.com from the address on your account, or use the settings in the app where available. We respond within one month. If a request is complex we may extend by up to two further months and will tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive.

We may need to verify your identity before acting, to make sure we are not disclosing someone else's data.

Complaints. If you think we have handled your data unlawfully, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, www.aki.ee, info@aki.ee. You may also complain to the authority in your country of residence or workplace.

9. How long we keep data

DataRetention period
Account dataWhile your account is active, then deleted from the live Service within 30 days of account deletion
Customer ContentWhile the workspace exists; deleted from the live Service within 30 days of the earliest of workspace deletion, account termination, or a deletion request, subject to the workspace controller's own instructions
BackupsRolling backups retained for a further 14 days after live deletion, then overwritten — so full erasure completes within 30 days
Billing records and invoices7 years from the end of the financial year, as required by the Estonian Accounting Act
Security and access logs12 months
Analytics data 14 months
Support correspondence3 years from the last message
Marketing consent recordsUntil consent is withdrawn, plus 3 years to evidence the consent
Unaccepted workspace invitations90 days, then deleted
Data relevant to a legal claimUntil the claim and any appeal period are concluded

Deleted data persists in encrypted backups for the backup period above before being overwritten. During that window it is not restored into the live Service except in a disaster recovery event, and it stays protected by the security measures in Section 11.

10. Cookies and similar technologies

We use the following categories:

Strictly necessary. Session and authentication cookies, security tokens, load balancing. These are required for the Service to work and are set without consent under Article 5(3) of the ePrivacy Directive.

Preference. Remembering your language, theme, and interface choices. These are not strictly necessary, so we set them only with your consent — except where the setting is one you chose yourself in that session and storing it is what you asked for.

Analytics. Understanding which features are used and where people get stuck. Set only with your consent.

Marketing. We do not use advertising or remarketing cookies.

11. Security

We protect your data with measures appropriate to the risk, including:

  • encryption in transit (TLS 1.2 or higher) and encryption at rest for databases and backups;
  • passwords stored using a modern one-way hashing algorithm — we never store them in readable form;
  • role-based access control, with staff access limited to what their job requires and logged;
  • network isolation, firewalls and regular dependency and vulnerability patching;
  • automated backups with periodic restore testing;
  • written confidentiality obligations for everyone with access to personal data.

No system is perfectly secure. If a breach occurs, what happens depends on which data is affected:

Data we control — account, billing, support, log and analytics data. We notify the Estonian Data Protection Inspectorate without undue delay and, where feasible, within 72 hours of becoming aware of the breach, where it is likely to result in a risk to people's rights and freedoms. Where the risk is high, we also notify the affected individuals without undue delay.

Customer Content, where we are processor. We notify the workspace controller without undue delay and in any event within 48 hours of becoming aware of the breach, with the information set out in Section 7 of our Data Processing Agreement. It is then for that controller — not us — to notify their supervisory authority and their data subjects.

12. Children

The Service is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children under 16. If we learn that we have, we will delete it. If you believe a child has given us personal data, contact futuwise@futuwise.com.

13. Marketing

We send product and marketing emails only if you have opted in, or if you are an existing customer and the message concerns similar products — the soft opt-in under the Estonian Electronic Communications Act. Every marketing email contains an unsubscribe link, and unsubscribing takes effect immediately. Service emails — invitations, password resets, billing, security and legal notices — are part of the Service and cannot be opted out of while you have an account.

14. Data Processing Agreement

If you use Futuwise as an organisation and we process personal data on your behalf, our Data Processing Agreement forms part of our contract with you and satisfies Article 28 GDPR. It covers the subject matter and duration of processing, our obligations, the subprocessor list, the technical and organisational measures, audit rights, breach notification, and the arrangements for transfers.

You do not need to sign a separate copy — it applies automatically when you accept our Terms of Service. If your organisation requires a countersigned version, email futuwise@futuwise.com.

15. Changes to this policy

We may update this policy as the Service and the law change. The "Last updated" date at the top always reflects the current version. If a change materially affects your rights or how we use your data, we will notify you by email or through the Service at least 30 days before it takes effect, so that you have time to review it and, if you disagree, close your account.

16. Contact

Questions, requests and complaints about this policy:

Futuwise OÜ, registry code 16873687, registered at Herne tn 8-2, Tallinn, 10135, Estonia

Email: futuwise@futuwise.com

 

Uncomplicated project management platform for everyone.
futuwise@futuwise.com
© 2025 Futuwise