01Who is responsible for your data
The controller of the personal data described here is FOREVER WORKS S.R.L. (trading as Forever Works), a limited liability company incorporated in Romania.
- Controller
- FOREVER WORKS S.R.L.
- Registered office
- Brașov, jud. Brașov, Romania. The full registered address is on record with the Trade Register of Brașov and is provided on request.
- Trade Register
- J08/2983/2021 (ONRC Brașov)
- Tax ID / VAT
- CUI 45079498 · VAT RO45079498
- Contact for privacy
- hello@foreverworks.com
- Data protection officer
- None appointed; the company is not required to appoint one. Privacy requests are handled by the administrator.
02What this policy covers
It covers the website at www.foreverworks.com and its subpages, the email and scheduling channels we publish, and our commercial relationships with clients, prospects and suppliers.
It does not cover the systems we build and operate inside a client's environment. When we handle personal data on a client's behalf we act as a processor under a separate data processing agreement, and the client's own privacy notice governs. Section 10 explains that split. Software we publish on its own, including any mobile application, carries its own privacy notice presented in the product and on its store listing.
03What we process, and why
Visiting this website
The site sets no advertising, profiling or cross-site tracking technology. Two things nevertheless process technical data when a page loads:
- Delivery and security. Our hosting provider processes the request itself: IP address, the page requested, timestamp, user agent, and referrer. This is how a website is served at all, and how abusive traffic is blocked. Legal basis: our legitimate interest in operating a secure, working site (Art. 6(1)(f) GDPR).
- Audience measurement. We use Umami, a privacy-first analytics tool, to count visits and see which pages are read. It sets no cookies, stores no IP address, builds no profile, and cannot follow you to another website. It derives a non-reversible daily identifier from technical data so that one visit is counted once. Legal basis: our legitimate interest in understanding whether the site works (Art. 6(1)(f) GDPR).
Writing to us or booking a call
If you email us, or book a slot through the scheduler on /book, we process your name, email address, the time you chose, and whatever you decide to tell us. We use it to answer you and to prepare and hold the conversation. Legal basis: steps taken at your request before entering into a contract, and the performance of that contract where one follows (Art. 6(1)(b) GDPR); otherwise our legitimate interest in responding to people who contact us (Art. 6(1)(f) GDPR).
Clients, prospects and suppliers
For the people who represent an organisation we work with, we process business contact details, correspondence, contract and delivery records, and billing data. Legal basis: the performance of the contract (Art. 6(1)(b) GDPR), our legal obligations in accounting and tax (Art. 6(1)(c) GDPR), and our legitimate interest in maintaining the commercial relationship (Art. 6(1)(f) GDPR).
What we never do
- We do not sell, rent or trade personal data. There is no advertising on this site.
- We take no automated decision that produces a legal or similarly significant effect on you, and we do not profile you.
- We do not ask for special categories of data (health, beliefs, biometrics and the rest), and we ask you not to send them to us.
04Who else touches it
We keep the list of service providers short, and each one processes data only on our documented instructions, under a contract that meets Art. 28 GDPR.
- Website hosting and delivery
- Vercel Inc. (United States), which serves this site and keeps short-lived request logs.
- Audience measurement
- Umami Software, Inc. (United States), the cookieless analytics described above.
- Email, calendar and documents
- Google Ireland Limited (Google Workspace), which carries our correspondence and the appointment scheduler.
- Accounting and banking
- Our accounting provider and our bank, for invoices, payments and statutory filings.
- Public authorities
- Romanian tax and regulatory authorities, and courts, strictly where the law requires disclosure.
Nobody else receives your data. We disclose it to an authority only where a legal obligation applies, and never in response to an informal request.
05Transfers outside the EEA
Two of the providers above are established in the United States. Where personal data reaches them, the transfer is covered by the safeguards Chapter V GDPR requires: the European Commission's Standard Contractual Clauses, complemented where applicable by the provider's certification under the EU-US Data Privacy Framework, together with encryption in transit and at rest. You can ask us for a copy of the safeguards that apply to a specific transfer.
06How long we keep it
We keep personal data only for as long as the purpose that justified collecting it survives.
- Server and security logs
- Short-lived, retained by our hosting provider and normally deleted within 30 days.
- Analytics
- Aggregated statistics only, with no record identifying an individual visitor.
- Correspondence that leads nowhere
- Up to 3 years from the last message, matching the general limitation period under Romanian law.
- Booking records
- Up to 12 months after the meeting.
- Contracts and delivery records
- For the duration of the engagement and 3 years after it ends, or longer if a claim is pending.
- Invoices and accounting documents
- 10 years, as required by Romanian accounting law.
07Your rights
Under the GDPR you may ask us, at any time, to:
- confirm whether we process data about you, and give you a copy of it (access);
- correct anything inaccurate or incomplete (rectification);
- delete it, where no legal obligation requires us to keep it (erasure);
- pause processing while a dispute about it is resolved (restriction);
- hand it to you, or to another provider, in a structured machine-readable form (portability);
- stop processing carried out on the basis of our legitimate interests (objection). For direct marketing, an objection is absolute and takes effect immediately;
- withdraw a consent you gave, without affecting anything lawfully done before you withdrew it.
Write to hello@foreverworks.com. We answer within one month, and we tell you if a request needs longer than that. Exercising a right costs nothing.
08Complaints
If you think we have handled your data badly, tell us first: it is the fastest way to fix it. You also have the right to complain to the Romanian supervisory authority, or to the authority where you live or work.
- Supervisory authority
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Address
- B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336, Bucharest, Romania
- Website
- dataprotection.ro
09How we protect it
Access to systems holding personal data is limited to the people who need it, protected by multi-factor authentication and unique credentials. Data is encrypted in transit and at rest by the platforms we use. Client work stays in the client's own repositories and accounts wherever the engagement allows, so the smallest possible amount of it is ever held by us. Our approach to vulnerabilities, and how to report one, is set out in Security and Disclosure.
10When a client is the controller
In most engagements the personal data flowing through the systems we build belongs to our client, who decides why and how it is processed. There, the client is the controller and we are the processor: we act only on documented instructions, bind our own subprocessors to the same terms, assist with data subject requests and breach notifications, and delete or return the data at the end of the engagement. Those obligations live in a data processing agreement signed alongside the main contract. If you are the subject of data held in a system we operate for a client, that client's privacy notice is the one that governs, and they are the right first point of contact.
11Children
This website addresses businesses and the people who work in them. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, write to us and we will delete it.
12Changes to this policy
When the way we handle data changes, this page changes with it and the date at the top moves. Material changes affecting people we already hold data about are notified directly where we have a way to reach them. Earlier versions are recoverable from the version history of the repository this site is built from, and we will send you one on request.