Who is responsible
FTM is currently operated by an individual; the planned Latvian company is not yet the controller. This notice covers visitors, account holders, people contacting support and individuals named in company records. The current operator is responsible for processing purposes they determine. Original source authorities are responsible for their own processing.
Before publication as a finalized notice, the operator’s legal identity and address must be confirmed. Contact FTM at the email below for privacy matters. This draft must also be completed with confirmed provider, transfer and retention details.
Data you provide and technical information
- Accounts: email address, password hash if you set a password, verification status, role and permissions, account timestamps and authentication/session information.
- Optional Google sign-in: Google provides your email address, email-verification status and a stable Google account identifier. FTM requests only identity and email access. It does not request access to your Gmail messages, Drive files or contacts, and does not retain Google access or refresh tokens.
- Choosing Google takes you to Google, where its own privacy information applies. FTM uses a necessary browser cookie and server-side verification state to secure the sign-in request. Requests expire after ten minutes. The saved Google account connection is removed when you disconnect Google or delete your FTM account; disconnecting does not delete your Google account.
- Saved features: monitoring selections, groups, preferences, detected-change history and notification delivery information linked to your account.
- Support: your messages, ticket details, correspondence and preferences for reply notifications.
- Technical and security data: IP address, browser/user-agent information, request metadata and error or security logs generated when you use the service.
- Browser storage: authentication cookies, language/theme preferences and your cookie-consent choice. Optional analytics is described separately below.
Personal information in company records
Company data may also be personal data. Depending on the source and access permissions, records may include names, positions, ownership or beneficial-owner links, dates, addresses and personal identifiers. These are obtained indirectly from official registers, published datasets and source services, rather than directly from every person named.
Publicly displayed records can be seen by visitors and may be indexed by search engines. Some fields are restricted by access controls. Public availability is not an exemption from GDPR: a valid legal basis, necessity, accuracy and appropriate disclosure limits still need to be assessed.
You can request access, correction, restriction, erasure or object to FTM’s processing even if you have never created an FTM account. Deleting an FTM account does not delete the original public register or automatically remove a separate registry record about you.
Why information is used and the legal bases
The processing map below is the proposed basis for the service and must be checked against actual operations before this draft is finalized.
- Account, saved monitoring and requested support: performance of a contract or steps at your request before a contract, where the processing is objectively necessary (GDPR Article 6(1)(b)).
- Service security, abuse prevention and proportionate diagnostics: legitimate interests in operating a secure, reliable service, balanced against affected individuals’ rights (Article 6(1)(f)).
- Company-record research and display: a proposed legitimate interest in making business information accessible (Article 6(1)(f)). The operator must document necessity, balancing, disclosure limits and the Article 14 information arrangements; publication by a source alone does not establish this basis.
- Optional usage analytics: your consent (Article 6(1)(a)), together with applicable rules on access to information stored on your device.
- Compliance with a specific legal duty: Article 6(1)(c), only where such a duty actually applies. It is not a general justification to keep all data.
Cookies, local storage and analytics
Necessary storage supports sign-in, your chosen language/theme and remembering your privacy choice. Blocking it can prevent account features or cause preferences to be forgotten. Your cookie choice is saved in your browser’s local storage and currently has no automatic expiry in the application.
Optional PostHog analytics loads only after you allow analytics. It measures page visits and interactions, can record masked sessions and display optional surveys, and may process device/browser information, identifiers and connection metadata. Survey answers you choose to submit are sent to PostHog; do not include sensitive information. Recordings mask all inputs, visible text and element attributes. Captured URL/referrer properties and replay URL metadata have query strings and fragments removed. Account, authentication, support and administration pages are excluded. Heatmaps, console capture and network headers/bodies are disabled.
You may reject analytics and still use the service. Use Manage cookie choices on this page or Cookie settings in the footer to change your decision. Withdrawal stops future optional analytics and clears the PostHog browser storage targeted by the application; it does not by itself erase analytics already held by the provider.
Cookie lifetimes, analytics retention and the deployed provider configuration must be verified before this notice is finalized.
Who receives data and where it is processed
Authorized staff and service providers may access data as needed for hosting, email delivery, support, security and, with consent, analytics. Contractual and access controls must match their role. Lawful requests from competent authorities are assessed under the applicable law. Publicly displayed registry data has the wider audience described above.
The operator has confirmed Hetzner hosting in Helsinki, Finland; Zoho Mail email services in the Netherlands; and PostHog EU analytics in Frankfurt, Germany. All three stated locations are in the EU. The contracting provider entities, data-processing agreements, subprocessor access and any processing outside those locations still need confirmation. An EU hosting location alone does not exclude international transfers.
Before any restricted transfer outside the EEA, the operator must identify an applicable GDPR Chapter V mechanism, such as an adequacy decision or appropriate safeguards, and any additional measures required. The final notice must explain actual transfers and how to obtain information about safeguards.
How long data is kept
Retention must be tied to a defined purpose. The operator must confirm actual periods or sufficiently specific criteria for each category and implement deletion or review; this draft does not claim that an unverified automatic deletion schedule exists.
- Account and monitoring data: needed while providing the selected account features; the account-deletion flow removes the active account and associated monitoring data.
- Support: needed to resolve requests and any justified follow-up or claim. Account deletion removes the support tickets you opened; messages in other retained conversations and any separate correspondence need their own retention assessment.
- Security logs and abuse records: retain only for a documented security or claims period, with restricted access.
- Backups: confirm the rotation period and how erased data is prevented from being restored to active use.
- Analytics: confirm retention and deletion settings with PostHog. Withdrawing cookie consent is separate from requesting deletion of stored data.
- Registry history: assess source availability, correction, continuing relevance and a documented retention/review policy; account deletion does not control this separate processing.
Your rights and how to use them
Depending on the processing and the conditions in the GDPR, you may request access and a copy, correction, erasure, restriction or data portability. Portability applies to qualifying automated processing based on consent or contract. You may withdraw consent at any time without affecting the lawfulness of earlier processing.
You may object to processing based on legitimate interests for reasons relating to your situation. FTM must assess the objection and stop unless it demonstrates an applicable overriding ground or needs the data for legal claims. Objections to direct marketing must be respected.
Email the contact below, describe the request and identify the relevant account or record. Include a company registration number or page link when useful. Only proportionate additional information should be requested to verify identity; do not send an identity-document copy unless a justified need and secure method have been agreed.
GDPR requests must normally be answered within one month. If complexity or the number of requests requires an extension of up to two further months, you must be informed within the first month with reasons. Requests are normally free; any lawful refusal or fee must be explained.
Complaints and supervisory authority
You can contact FTM about concerns or lodge a complaint with Latvia’s Data State Inspectorate (DVI). You may also complain to a competent supervisory authority in the EU, in particular where you habitually reside, work or where the alleged infringement occurred. You do not have to complete an FTM support process before exercising this right.
Security, automated decisions and updates
The application uses password hashing, HTTP-only authentication cookies and permission checks. Effective security also depends on deployment, access management, monitoring and provider arrangements; no service can promise absolute security.
The reviewed features display records and send monitoring notifications. They do not implement a solely automated decision about an individual with legal or similarly significant effects. A source’s company rating is not an FTM individual decision. Any future such processing needs a separate assessment and disclosure.
This notice must be updated when purposes, providers or material processing arrangements change. New optional processing that needs consent must not start merely because the notice has changed.