Privacy Policy
How Former collects, uses and protects your personal data in accordance with the GDPR.
Last updated: 16 June 2026
1. Controller
The controller responsible for the processing of personal data on this website is:
Sellrock UG (haftungsbeschränkt) Kölner Str. 43a 90425 Nürnberg Germany
Email: [email protected] Website: https://former.cc
2. Roles and processing on behalf of customers
For personal data processed when you visit our website, register, use account and billing functions, contact support or interact with security features, Sellrock UG (haftungsbeschränkt) acts as controller within the meaning of the GDPR.
For personal data that customers enter into Former, such as names, contact details, photos, signatures, GPS data, protocols, forms or other content, Former generally acts as a processor under Art. 28 GDPR. The respective customer is the controller for this data. A data processing agreement (DPA) is available.
3. What data we process
Depending on how you use our services, we process the following categories of personal data:
• Account data: name, email, password (hashed), company affiliation, role and permissions • Usage and log data: IP address, browser type, device and request data, pages visited, timestamps and security events • Content data: forms, submissions, protocols, uploaded documents, photos, signatures, files and other data you enter into the platform • Location data: GPS data where such features are enabled and used • Metadata: status, timestamps, user assignments, form and submission metadata, and audit logs • Payment and billing data: billing address, plan, payment status and tax-relevant information • Communication data: messages sent to our support or through forms • AI and vector data: inputs, search queries, extracted document text, searchable text derived from submissions, embeddings and related metadata where AI features are enabled or used
4. Purposes and legal bases
We process personal data for the following purposes:
• Providing and operating the platform (Art. 6(1)(b) GDPR – contract performance) • Processing customer data on behalf of the respective customer (Art. 28 GDPR) • Security, abuse prevention, access protection, error analysis and audit logging (Art. 6(1)(f) GDPR – legitimate interest) • Billing, payment processing and accounting (Art. 6(1)(b) and (c) GDPR) • Customer communication and support (Art. 6(1)(b) and (f) GDPR) • Providing optional AI features, semantic search and assistant functions where requested or enabled (Art. 6(1)(b) GDPR or as part of processing on behalf of the customer) • Product analysis and platform improvement where this can be done without consent-required tracking or where consent has been given (Art. 6(1)(f) or (a) GDPR)
5. Hosting, infrastructure and processors
Our production infrastructure is operated by Hetzner Online GmbH in Germany. According to the current configuration, the server location is Nürnberg, Germany. Files and media are stored in S3-compatible object storage provided by Hetzner in Germany.
We use Cloudflare, Inc. to provide CDN, DNS, DDoS protection and security services. In this context, IP addresses, request data, URLs, headers, timestamps and security-related events may be processed.
Depending on the feature used, we engage carefully selected service providers, in particular:
• Hetzner Online GmbH – hosting, server and storage infrastructure in Germany • Cloudflare, Inc. – CDN, DNS, DDoS protection and web security • IONOS SE – email delivery via SMTP • Stripe – payment processing where paid plans are booked • Sentry or trafficlog.app – error monitoring and technical diagnostics • Qdrant – internally operated vector database for AI-powered search and assistant functions • OpenAI, Anthropic or OpenAI-compatible providers – external AI providers only when corresponding AI features are actively used
Where required, we conclude data processing agreements with processors under Art. 28 GDPR. A current list of processors is available on request.
6. Cookies and analytics
We use strictly necessary cookies and similar technologies required to operate the platform, for example for authentication, session security, CSRF protection and language preferences. According to § 25 para. 2 TTDSG/DDG these cookies do not require consent.
We currently do not use analytics or marketing cookies. If we introduce consent-required analytics or marketing services in the future, we will only do so after obtaining prior consent and providing updated information. For details on the cookies we use, please see our cookie policy.
7. AI features
Former offers optional AI features to support the creation, analysis and processing of forms, documentation and submissions. These include, for example, form generation from prompts, reconstruction from PDF text or images, text correction, semantic search and assistant functions.
These features are used on request by the user or where the customer has enabled AI indexing or AI search features for forms, fields or submissions. Content provided by users is first processed within the Former infrastructure and may be stored in an internal vector database (Qdrant) as embeddings and related metadata to improve search and assistant functions.
Content is transmitted to external AI providers, in particular OpenAI, Anthropic or OpenAI-compatible providers, only to the extent necessary for the AI feature requested by the user or for the embedding generation required for that feature. Not every uploaded file is automatically transmitted to external AI providers. For PDF-based AI features, the extracted text is processed according to the current implementation; for image-based AI features, image data may be processed.
Customers can disable AI features or AI indexing at form, field or submission level. In that case, the corresponding content is not processed for AI-powered search or analysis functions.
8. Data sharing and international transfers
We do not sell personal data. We only share data with contractually bound service providers, processors or other recipients where this is necessary to provide the Service, where the customer initiates the transfer, or where we are legally required to do so.
Where data is transferred outside the European Economic Area, we ensure appropriate safeguards under Art. 44 et seq. GDPR, such as adequacy decisions, Standard Contractual Clauses or supplementary protective measures. This may be relevant in particular for Cloudflare, OpenAI, Anthropic, Stripe or comparable service providers.
9. Retention and deletion
We keep personal data only as long as necessary for the purposes described above or required by statutory retention periods. Accounting and tax-relevant records are typically retained for 6 to 10 years under German commercial and tax law. Account data is deleted on request, subject to these obligations.
Customers can delete forms, submissions and other content or initiate deletion. To prevent abusive or accidental deletion, sensitive content is deleted only after the request has been confirmed and a safety period has expired. For form deletions, a recovery period of usually 7 days is currently provided. After this period expires, the affected data is permanently removed unless statutory retention obligations apply.
10. Backups
We create backups to ensure availability, recoverability and integrity of the platform. Backup copies may remain available for a limited period even after deletion and are then automatically overwritten or deleted on a regular cycle.
11. Your rights
Under the GDPR you have the right to:
• Access (Art. 15) • Rectification (Art. 16) • Erasure (Art. 17) • Restriction of processing (Art. 18) • Data portability (Art. 20) • Object to processing (Art. 21) • Withdraw consent at any time, without affecting prior processing • Lodge a complaint with a supervisory authority
To exercise your rights, contact us at [email protected]. Where we process personal data as a processor for a customer, we forward requests from data subjects to the respective customer or support the customer in handling the request.
12. Security
We apply technical and organisational measures to protect your data, including TLS encryption in transit, encryption at rest, role-based access control, tenant separation, access restrictions, audit logs, security monitoring and regular backups.
13. Changes to this policy
We may update this privacy policy to reflect changes in our services, infrastructure or the law. The current version is always available at this URL. Material changes will be announced in advance within the product.