Legal information
Privacy
Information about privacy, cookies/storage and data processing on the Formdia Property website.
a product of Formdia GmbH
Frohheimstrasse 8
9325 Roggwil TG
Switzerland
VAT no. CHE-220.558.499
Phone: +41 71 511 43 99
Commercial register: Kanton Thurgau
Legal contact: legal@formdiaproperty.com
Version: 2026-08-30 · Language: English
A. General
This Privacy Policy describes which personal data Formdia Property processes in connection with the public website, the contact form, and the SaaS application, for what purpose this occurs, and what rights data subjects have.
B. Controller
The controller responsible for the processing of personal data is Formdia GmbH, Frohheimstrasse 8, 9325 Roggwil TG, Switzerland. Formdia Property is a product of Formdia GmbH. Data-protection-related and legal inquiries may be addressed to `legal@formdiaproperty.com`.
Within the SaaS application, not every processing activity is automatically processing on behalf of a customer. The following distinction applies, which is also described in the separate DPA (there, Section 3):
A. Customer/Case Data (Processing on Behalf). For property and case data, data of participating persons, findings/defects, key information, photos, signatures, and the documents generated from them (Sections H–L), the respective company customer is independently the controller; Formdia Property acts as a processor pursuant to the DPA to this extent.
B. Formdia Property's Own Purposes. For managing the contract and company account, primary user/account administration insofar as necessary for contract operation (Sections F–G), login and security data (Section M), abuse/rate-limiting/security logs (Sections N–O), public contact and support inquiries (Section D), as well as future billing/invoicing data of its own, Formdia Property is independently the controller within the meaning of applicable data protection law.
C. Public Website
When visiting the public Formdia Property website, the following categories of data may be processed: IP address and request/security logs (technically, to detect abuse and for operational security), browser and user-agent information, language preference, technically necessary cookies/storage, and the stored consent preference. When the contact form loads, Cloudflare Turnstile may additionally be used for bot defense (Section Q). Analytics or marketing services are mentioned and used only if they are actually active; at the time of this text, no such service is active.
D. Contact / Support
If the contact form is used, the information entered (including name, email address, message) is processed to respond to the inquiry. The recipient is `support@formdiaproperty.com`; technical delivery takes place via the sender address `noreply@formdiaproperty.com`, with "Reply-To" set to the email address provided by the sender. Sending is secured by bot protection (Turnstile), origin verification, and rate limiting. The contact form is disabled by default and becomes publicly usable only after deliberate activation.
E. SaaS App
Sections F–O apply additionally to the use of the SaaS application by registered company accounts.
F. Company/Tenant Data
*Controller: Formdia Property (own contract/account administration, Category B).* Formdia Property processes the company data provided by the customer upon registration (including company name, address, and contact information) to open the account and personalize the platform. This registration/account administration data is Formdia Property's own processing (Category B) and not processing on behalf of the customer. Self-service registration additionally stores email verification status (as a hashed token, never stored in plaintext), the expiry of pending registration, and the time, language, and version identifier of the explicit acceptance of the GTC/Privacy Policy; a raw IP value is not permanently stored for this purpose. Access is additionally secured by bot protection (Cloudflare Turnstile, see Section Q) and registration rate limiting. Automated invoicing runs, dispatch, payment detection, and productive invoicing remain not activated; the productive tax rate must be confirmed before genuine invoicing.
G. User Data
*Controller: Formdia Property, insofar as necessary for contract operation (account administration, roles, credentials; Category B).* For each user of a company account, name, email address, role, and account status are processed, exclusively within the respective company account (tenant isolation). Credentials are not stored in plaintext (Section X).
H. Case/Property Data
*Controller: customer as controller, Formdia Property as processor (Category A, see DPA).* In the course of cases, Formdia Property processes the property, module, findings, and key data recorded by the customer. This data is stored and displayed exclusively within the respective company account.
I. Data of Participating Persons
*Controller: customer as controller, Formdia Property as processor (Category A, see DPA).* In the course of a case, third-party personal data may be recorded, in particular of owners, landlords, property managers, tenants, buyers, experts, service providers, or other participants. This data is processed exclusively to document the respective case on behalf of the customer; the customer is responsible for the lawfulness of the recording and for informing data subjects (see GTC Section 17).
J. Photos
*Controller: customer as controller, Formdia Property as processor (Category A, see DPA).* Photos captured in the course of a case are stored privately with tenant isolation. From each original photo, a display and a preview version are additionally generated server-side. A package-dependent retention period pursuant to Section U of the Retention Periods (below) applies to original photos.
K. Signatures
*Controller: customer as controller, Formdia Property as processor (Category A, see DPA).* Digital signatures captured in the course of a case are stored as part of the case documentation and incorporated into the generated PDF document.
L. PDF/Documents/Exports
*Controller: customer as controller, Formdia Property as processor (Category A, see DPA).* Completed cases are generated as a PDF and made available to the customer for retrieval. Owner/Admin users may additionally trigger a structured tenant export pursuant to the "Tenant Export V1" section of the Service Description; this is logged (time, triggering user, scope, checksum), without logging the export content itself.
M. Login/Security
*Controller: Formdia Property (own security/operational purposes, Category B).* Upon login, login time, IP address, and basic device/browser information are logged for security purposes (login activity). Passwords are stored exclusively as a server-side computed hash value (PBKDF2, no plaintext storage). A secure, "HttpOnly" session cookie is used for sessions.
N. IP / Technical Metadata
*Controller: Formdia Property (own security/operational purposes, Category B).* IP addresses and technical metadata are processed to detect abuse, to secure login processes, and for rate limiting, and are not used for marketing purposes.
O. 2FA / Trusted Devices
*Controller: Formdia Property (own security/operational purposes, Category B).* If a user uses two-factor authentication (TOTP), the associated secret is stored encrypted; recovery codes are stored exclusively as a hash value. When the "Trusted Device" function is used, a separate, likewise "HttpOnly" cookie with a limited validity period (30 days) is set to avoid repeated two-factor prompts on the same device.
P. Cookies / Storage
The public website and the SaaS application are treated strictly separately:
- Public Website: technically necessary cookies/storage, the consent selection itself, and — only after actual activation — statistics or marketing cookies.
- SaaS App: session cookie, trusted-device cookie; no marketing or tracking cookies.
Cookie settings are permanently accessible via the footer of the public website.
Q. Turnstile
Cloudflare Turnstile is used to protect against automated abuse. For this purpose, Turnstile processes technical signals in the visitor's browser for bot/abuse detection; according to current Cloudflare documentation, the actual form input (e.g., name, email address, message text, or, in the case of registration, the account/company information) is not processed by Turnstile as form content.
Turnstile is used in two separate places with differing activation status:
- Public contact form (Section D): present, active depending on the activation of the contact form itself.
- Self-service registration of the SaaS application (Section F): a dedicated Turnstile widget secures registration (hostname and action verification against the Cloudflare `siteverify` interface); registration is not possible without a successful challenge.
R. Email
Formdia Property does not use a separate sender subdomain for technical mail dispatch — every sender address sits directly on `formdiaproperty.com`:
- A) Public contact email (Section D): inquiries from the public contact form are, once activated, forwarded from `noreply@formdiaproperty.com` to `support@formdiaproperty.com`.
- B) App registration/transactional email (Section F): self-service registration for the SaaS application is currently disabled for Formdia Property, so no email verification is sent at present. Once activated, it would likewise be sent from `noreply@formdiaproperty.com`, with replies/support inquiries handled via `support@formdiaproperty.com`. Beyond these two cases, there are currently no further transactional app emails; none are claimed here in advance.
The regular mailboxes of the `@formdiaproperty.com` domain (e.g., `legal@`, `billing@`, `info@`) are operated via METANET/Plesk (Section S) and are independent of the dispatch channel named above.
S. Service Providers / Subprocessors
Currently actually in use: Cloudflare (hosting, network security, bot protection/Turnstile) and METANET/Plesk (operation of the existing email mailboxes of the `@formdiaproperty.com` domain). The email dispatch infrastructure for the contact function and the app registration/verification email (Section R) is not currently active for this test environment. Further service providers (e.g., payment, analytics, ticketing, global address lookup, AI features) are currently not yet selected or active and will be listed as service providers only once actually activated. The complete, currently maintained list is on the dynamic "Subprocessors" page.
T. International Processing
It is not assured that all data is stored exclusively in Switzerland. The service providers used (Cloudflare, METANET/Plesk) may, depending on the technical configuration, also process data outside Switzerland.
U. Retention Periods
Retention periods are differentiated by data category. For account/tenant, case, and PDF data, the following commercially resolved target policy applies after the end of the contract: day 0–30 after the end of the contract is the 30-day grace period pursuant to GTC Section 34 with full read, download, and export access. Day 31–90 is a restricted internal retention phase: operational access remains restricted, while the data itself remains internally preserved (recovery/reactivation window). From day 90 onward, operational tenant and case data is intended to be deleted.
- Account/tenant data: day 0–30 active access phase, day 31–90 restricted internal retention, deletion intended from day 90 onward.
- Case data and PDFs: same structure as account/tenant data.
- Original photos: package-dependent, technically defined retention period, independent of contract status — Solo 90 days, Team 180 days, Business 365 days, Enterprise with no fixed cap (individual), extendable via a valid retention add-on; thereafter, only the original is removed, while the display/preview version remains in place.
- Display/preview photos: remain in place for as long as the associated case exists, corresponding to the same active/restricted access phase as case data.
- Login/security logs: regular retention period 180 days, thereafter deletion/anonymization, insofar as technically and legally appropriate. In the event of a specific security incident, abuse case, or ongoing security investigation, the records relevant thereto may be retained longer until conclusion of that investigation; mandatory statutory exceptions remain reserved. No blanket unlimited storage.
- Support communications: regular retention period 24 months after conclusion of the respective support inquiry, thereafter deletion/anonymization. Longer retention takes place only insofar as necessary for an ongoing contract, to preserve legal claims, in connection with a security incident, or due to a mandatory statutory obligation.
- Billing/invoices: once active, in accordance with statutory retention obligations; specific statutory periods are not stated numerically here.
- Backups: after the intended deletion of operational data (from day 90 onward), residual data may, for technical reasons, still exist for up to a further 30 days (at most until day 120 after the end of the contract) in technical backup copies. Backups serve exclusively for technical disaster recovery, do not constitute a customer archive, are not subject to normal productive access, and are overwritten/removed in the regular backup cycle.
- Export files: the tenant export is made available to the customer directly for download and is not permanently retained server-side; only log data of the export process (time, scope, checksum) is retained.
Statutorily required contract, invoice, or tax/accounting data is retained separately, independently of this, in accordance with the respectively applicable statutory periods.
V. End of Contract / Grace
After the end of the contract, a grace period with read and export access applies for 30 days (day 0–30) pursuant to GTC Section 34. Day 31–90 is a restricted internal retention phase without operational customer access. From day 90 onward, operational tenant and case data is intended to be deleted, with a possible technical backup residual period of up to a further 30 days (see Section U). No immediate complete deletion occurs directly after the grace period.
Clearly distinct from this process is a restriction of access due to default of payment (status "payment required"/"suspended" pursuant to GTC Section 30 and the Price and Service Terms): such a restriction is not an end of contract, does not lead into the grace period, and ends with full settlement of payment through reactivation of the account, without Customer Data being affected.
W. Data Subject Rights
Data subjects have — insofar as applicable under the applicable law — rights of access, rectification, erasure, restriction of processing, objection, data portability, as well as withdrawal of consent given and the right to lodge a complaint with the competent supervisory authority. Requests may be submitted via the contact details named in Section B. If a request concerns personal data that a customer processes in the course of its own cases, Formdia Property forwards the request to the responsible customer, insofar as Formdia Property acts as a processor in that respect.
X. Data Security
Formdia Property employs technical and organizational measures to protect personal data, in particular tenant isolation, role-based access control, encrypted transmission (TLS), secure password hashing, optional two-factor authentication, security headers, protection against cross-origin abuse, and rate limiting for security-relevant actions. See Annex B (TOMs) of the DPA for details. Absolute security cannot be assured.
Y. Changes to This Privacy Policy
Formdia Property may amend this Privacy Policy, in particular in connection with changes to the platform or the legal situation. The then-current version is available via the public website.
Z. Privacy Contact
Please direct privacy-related inquiries to `legal@formdiaproperty.com` or by mail to Formdia GmbH, Frohheimstrasse 8, 9325 Roggwil TG, Switzerland.