Forever Works
Legal · 01

Privacy policy.

We collect as little as the work allows. This policy states exactly what that is, why we are allowed to hold it, who else touches it, and what you can make us do about it.

Last updated 6 August 2026Issued by FOREVER WORKS S.R.L.CUI 45079498

01Who is responsible for your data

The controller of the personal data described here is FOREVER WORKS S.R.L. (trading as Forever Works), a limited liability company incorporated in Romania.

Controller
FOREVER WORKS S.R.L.
Registered office
Brașov, jud. Brașov, Romania. The full registered address is on record with the Trade Register of Brașov and is provided on request.
Trade Register
J08/2983/2021 (ONRC Brașov)
Tax ID / VAT
CUI 45079498 · VAT RO45079498
Contact for privacy
hello@foreverworks.com
Data protection officer
None appointed; the company is not required to appoint one. Privacy requests are handled by the administrator.

02What this policy covers

It covers the website at www.foreverworks.com and its subpages, the email and scheduling channels we publish, and our commercial relationships with clients, prospects and suppliers.

It does not cover the systems we build and operate inside a client's environment. When we handle personal data on a client's behalf we act as a processor under a separate data processing agreement, and the client's own privacy notice governs. Section 10 explains that split. Software we publish on its own, including any mobile application, carries its own privacy notice presented in the product and on its store listing.

03What we process, and why

Visiting this website

The site sets no advertising, profiling or cross-site tracking technology. Two things nevertheless process technical data when a page loads:

  • Delivery and security. Our hosting provider processes the request itself: IP address, the page requested, timestamp, user agent, and referrer. This is how a website is served at all, and how abusive traffic is blocked. Legal basis: our legitimate interest in operating a secure, working site (Art. 6(1)(f) GDPR).
  • Audience measurement. We use Umami, a privacy-first analytics tool, to count visits and see which pages are read. It sets no cookies, stores no IP address, builds no profile, and cannot follow you to another website. It derives a non-reversible daily identifier from technical data so that one visit is counted once. Legal basis: our legitimate interest in understanding whether the site works (Art. 6(1)(f) GDPR).

Writing to us or booking a call

If you email us, or book a slot through the scheduler on /book, we process your name, email address, the time you chose, and whatever you decide to tell us. We use it to answer you and to prepare and hold the conversation. Legal basis: steps taken at your request before entering into a contract, and the performance of that contract where one follows (Art. 6(1)(b) GDPR); otherwise our legitimate interest in responding to people who contact us (Art. 6(1)(f) GDPR).

Clients, prospects and suppliers

For the people who represent an organisation we work with, we process business contact details, correspondence, contract and delivery records, and billing data. Legal basis: the performance of the contract (Art. 6(1)(b) GDPR), our legal obligations in accounting and tax (Art. 6(1)(c) GDPR), and our legitimate interest in maintaining the commercial relationship (Art. 6(1)(f) GDPR).

What we never do

  • We do not sell, rent or trade personal data. There is no advertising on this site.
  • We take no automated decision that produces a legal or similarly significant effect on you, and we do not profile you.
  • We do not ask for special categories of data (health, beliefs, biometrics and the rest), and we ask you not to send them to us.

04Who else touches it

We keep the list of service providers short, and each one processes data only on our documented instructions, under a contract that meets Art. 28 GDPR.

Website hosting and delivery
Vercel Inc. (United States), which serves this site and keeps short-lived request logs.
Audience measurement
Umami Software, Inc. (United States), the cookieless analytics described above.
Email, calendar and documents
Google Ireland Limited (Google Workspace), which carries our correspondence and the appointment scheduler.
Accounting and banking
Our accounting provider and our bank, for invoices, payments and statutory filings.
Public authorities
Romanian tax and regulatory authorities, and courts, strictly where the law requires disclosure.

Nobody else receives your data. We disclose it to an authority only where a legal obligation applies, and never in response to an informal request.

05Transfers outside the EEA

Two of the providers above are established in the United States. Where personal data reaches them, the transfer is covered by the safeguards Chapter V GDPR requires: the European Commission's Standard Contractual Clauses, complemented where applicable by the provider's certification under the EU-US Data Privacy Framework, together with encryption in transit and at rest. You can ask us for a copy of the safeguards that apply to a specific transfer.

06How long we keep it

We keep personal data only for as long as the purpose that justified collecting it survives.

Server and security logs
Short-lived, retained by our hosting provider and normally deleted within 30 days.
Analytics
Aggregated statistics only, with no record identifying an individual visitor.
Correspondence that leads nowhere
Up to 3 years from the last message, matching the general limitation period under Romanian law.
Booking records
Up to 12 months after the meeting.
Contracts and delivery records
For the duration of the engagement and 3 years after it ends, or longer if a claim is pending.
Invoices and accounting documents
10 years, as required by Romanian accounting law.

07Your rights

Under the GDPR you may ask us, at any time, to:

  • confirm whether we process data about you, and give you a copy of it (access);
  • correct anything inaccurate or incomplete (rectification);
  • delete it, where no legal obligation requires us to keep it (erasure);
  • pause processing while a dispute about it is resolved (restriction);
  • hand it to you, or to another provider, in a structured machine-readable form (portability);
  • stop processing carried out on the basis of our legitimate interests (objection). For direct marketing, an objection is absolute and takes effect immediately;
  • withdraw a consent you gave, without affecting anything lawfully done before you withdrew it.

Write to hello@foreverworks.com. We answer within one month, and we tell you if a request needs longer than that. Exercising a right costs nothing.

08Complaints

If you think we have handled your data badly, tell us first: it is the fastest way to fix it. You also have the right to complain to the Romanian supervisory authority, or to the authority where you live or work.

Supervisory authority
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Address
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336, Bucharest, Romania

09How we protect it

Access to systems holding personal data is limited to the people who need it, protected by multi-factor authentication and unique credentials. Data is encrypted in transit and at rest by the platforms we use. Client work stays in the client's own repositories and accounts wherever the engagement allows, so the smallest possible amount of it is ever held by us. Our approach to vulnerabilities, and how to report one, is set out in Security and Disclosure.

10When a client is the controller

In most engagements the personal data flowing through the systems we build belongs to our client, who decides why and how it is processed. There, the client is the controller and we are the processor: we act only on documented instructions, bind our own subprocessors to the same terms, assist with data subject requests and breach notifications, and delete or return the data at the end of the engagement. Those obligations live in a data processing agreement signed alongside the main contract. If you are the subject of data held in a system we operate for a client, that client's privacy notice is the one that governs, and they are the right first point of contact.

11Children

This website addresses businesses and the people who work in them. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, write to us and we will delete it.

12Changes to this policy

When the way we handle data changes, this page changes with it and the date at the top moves. Material changes affecting people we already hold data about are notified directly where we have a way to reach them. Earlier versions are recoverable from the version history of the repository this site is built from, and we will send you one on request.