Formius

Privacy Policy

How Formius handles personal information on the Formius platform (v1.1).

Version 1.1 · Effective 5 August 2026

Locked design-partner packaging v1.1. Operational facts match the live Formius stack as of the effective date. Registered entity name and ABN on commercial signature blocks may be confirmed separately with counsel.

1. Who we are

Formius (“Formius”, “we”, “us”) provides an invite-gated operations platform for trade and related businesses (quotes, jobs, documents, client portal, and related tools). We operate primarily under the laws of Queensland, Australia.

Contact for privacy matters: privacy@formius.io (or support@formius.io).

2. Scope

This policy covers personal information processed when you:

  • request access, sign up, or sign in to Formius;
  • use Formius as staff of a customer organisation;
  • interact with a customer’s client portal or public quote/accept links;
  • contact us for support.

Customer organisations are typically the controller of their client and job data. Formius acts as a processor / service provider for that customer data, and as a controller for platform account, billing, and security data we need to run the service. A Data Processing Addendum (DPA) is available for design partners — see Subprocessors and ask us for the schedule.

3. What we collect

  • Account data: name, email, authentication credentials, MFA factors, organisation membership and role.
  • Organisation data: business profile, branding, settings, invites.
  • Operational data you enter: clients, sites, quotes, jobs, invoices, documents, photos, messages, and related records.
  • Portal / public link data: tokenised access logs, acceptance actions, limited device/IP metadata for security.
  • Technical logs: app diagnostics, error reports (e.g. Sentry), rate-limit and audit events — with secrets scrubbed where configured.
  • Optional analytics / leads: if configured, limited usage metrics (e.g. Google Analytics) or lead-form fields from connected Meta assets.

4. Why we use it

  • Provide and secure the Formius service (including MFA for privileged roles);
  • Host and process customer operational records as instructed by the organisation;
  • Send transactional email (invites, quotes, portal notices) via our email provider;
  • Prevent abuse (rate limits, audit logging, fraud/security monitoring);
  • Comply with law and respond to lawful requests;
  • Where authorised under a design-partner DPA (Schedule A), analyse operational and commercial metrics (e.g. close rates, average revenue, pipeline and cycle indicators) for organisation performance, platform improvement, and aggregated / de-identified industry benchmarking — see Security FAQ. Formius does not sell customer personal information as a business model.

5. Sharing

We use infrastructure and product subprocessors listed on our Subprocessors page (for example hosting, database, email, payments, accounting sync, and error monitoring). Formius does not sell customer personal information as a business model.

6. International transfers

Some subprocessors may process data outside Australia. Where that occurs, we rely on appropriate contractual and provider safeguards. Design partners can request location detail for specific processors.

7. Security

We use TLS in transit, provider encryption at rest, multi-tenant access controls (including RLS and membership checks), invite-gated onboarding, privileged MFA, and related controls described in our Security FAQ. No method is perfect; report suspected incidents to support@formius.io.

8. Retention

We retain account and organisation data for the life of the customer relationship and a reasonable wind-down period. Customer-controlled records follow the organisation’s instructions and our deletion/export runbooks. Portal tokens and security logs are retained only as needed for the service and abuse prevention.

9. Your choices

Organisation admins manage team access. Individuals may request access, correction, or deletion of personal information we hold as controller by emailing privacy@formius.io. Client data held for a customer organisation should usually be requested via that organisation first.

10. Australian Privacy Principles

We design Formius with the Australian Privacy Principles in mind for personal information we handle. The Australian Privacy Principles are legal obligations under the Privacy Act — not a certification scheme. Formius does not claim independent privacy certification or verified compliance with every applicable privacy law. If the Privacy Act / APPs or other privacy law applies to your use, this policy and our DPA are intended to support that relationship.

If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC) — see oaic.gov.au.

11. Children

Formius is a business operations platform and is not directed at children. We do not knowingly collect personal information from children for their own accounts.

12. Changes

We may update this policy. Material changes for design partners will be communicated by email or in-product notice where practical. The version and effective date above identify the current locked text.

Privacy Policy