Privacy Policy
Last updated: 31 May 2026
This Privacy Policy explains how FutureFormers ("FutureFormers", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit future-formers.com, register for our mentorship programme, or use our platform at app.future-formers.com (collectively, the "Service").
We are committed to handling your data lawfully, transparently, and in line with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Who we are
The data controller responsible for your personal data under the GDPR is:
Rachel Nkwinja Ngonga
trading as FutureFormers
Klingerstrasse 10, 51143 Cologne
Germany
Email: e-contact@future-formers.com
FutureFormers is operated as a sole proprietorship and is not currently incorporated as a separate legal entity.
2. What data we collect
2.1 Data you give us when you sign up
- Account identifiers from Google Sign-In: your Google account email address, full name, profile picture URL, and the Google subject identifier ("sub").
- Profile data you choose to provide on the "almost done" step: date of birth, country, city, and phone number (E.164 format).
- Programme registration: if you join via the public waitlist form, we collect the name, email, age range, country, and current activity you submit, plus your selection of "intended cycle".
2.2 Data we generate as you use the Service
- Role & group membership: whether you are a potential participant, mentee, mentor, administrator, or founder, and which mentorship cycle and group(s) you belong to.
- Questionnaire responses: your free-text, single-choice, multiple-choice, and ranked answers to questionnaires we or your mentor assign to you.
- Session participation: the scheduled sessions in your group, your attendance status (where recorded), and any private notes your mentor writes about a session (mentees do not see other people's notes).
- Email engagement: whether transactional emails we send you are delivered, bounced, or rejected. We do not run open/click tracking pixels.
2.3 Technical data collected automatically
- Server logs from our hosting providers: your IP address, user-agent, request paths, and timestamps. These are kept short-term to detect abuse and debug errors.
- Analytics: see §10 below.
3. How we use your data
We use your personal data only for the following purposes:
- To create and manage your FutureFormers account and authenticate you.
- To match you to a mentorship cycle, group, and (where applicable) a mentor.
- To schedule sessions, create Google Calendar events on the operator's calendar, and add you as an attendee so you receive the meeting invitation and Google Meet link.
- To send you transactional emails (registration confirmation, session reminders, mentor messages within the programme).
- To collect and review questionnaire responses that inform the mentorship process.
- To enforce our Terms of Service, prevent abuse, and comply with our legal obligations.
- To improve the Service (aggregated, non-identifying analysis only).
We do not sell your personal data, and we do not use it for advertising or behavioural profiling.
4. Legal basis (GDPR Article 6)
- Performance of a contract (Art. 6(1)(b)): everything required to deliver the mentorship programme you signed up for.
- Legitimate interests (Art. 6(1)(f)): security, abuse prevention, basic service analytics.
- Consent (Art. 6(1)(a)): optional profile fields and analytics cookies where applicable. You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): retention of records where required by tax or commercial law.
5. Sharing with third parties
We share personal data only with the processors and service providers we need to operate the Service. Each operates under a data processing agreement (DPA) with appropriate safeguards.
- Google Ireland Ltd. / Google LLC — Google Sign-In (authentication) and Google Calendar API (event creation, Meet link generation, calendar invitations).
- Supabase, Inc. — managed PostgreSQL database and authentication backend that stores your account, profile, role, and questionnaire data.
- Cloudflare, Inc. — hosting of the public website, application, and the API worker that processes requests.
- Amazon Web Services, Inc. — Amazon Simple Email Service (SES), used to deliver our transactional emails.
- Google Analytics (Google Ireland Ltd.) — basic visitor analytics on the public landing page only; see §10.
We do not share your data with any other third party except where required by law (e.g., in response to a binding court order or formal regulatory request).
6. Google API Services & user data
Limited Use disclosure. FutureFormers' use and transfer to any other app of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google Sign-In to authenticate you. We receive your Google account email, name, profile picture URL, and subject identifier. We use these only to create or sign you in to your FutureFormers account.
- We use the Google Calendar API through a service account with domain-wide delegation that impersonates a dedicated FutureFormers Workspace user. When an administrator schedules a session in your group, we create a Calendar event on that Workspace user's calendar, attach a Google Meet conference, and add the group's mentees and mentors as attendees so Google can email each of them the invitation. We store the resulting event ID and Meet link only to keep the calendar event in sync when the schedule changes.
- We do not use Google user data for advertising, do not sell it, and do not transfer it to anyone other than the providers listed in §5 acting strictly as our processors.
- We do not use Google user data to train generalised AI/ML models.
- Human access to Google user data is limited to operators investigating a specific user-reported issue with the user's explicit permission, or where required by law.
7. International transfers
Some of the processors in §5 are based in the United States. Where personal data is transferred outside the EU/EEA, we rely on:
- The European Commission's Standard Contractual Clauses (SCCs) where applicable; and
- The EU–U.S. Data Privacy Framework for providers certified under it.
8. Data retention
- Account & profile data: retained while your account is active and for up to 12 months after deletion to handle any disputes, then erased.
- Waitlist registrations: retained while the cycle you registered for is still upcoming, plus 12 months, then erased.
- Questionnaire responses: retained for the duration of the cycle they relate to, plus 24 months for programme evaluation, then anonymised or erased.
- Calendar events: deleted from the operator's calendar when the related session is deleted in our system.
- Server logs: retained for up to 30 days for security and debugging.
9. Your rights
Subject to the GDPR, you have the right to:
- Access the personal data we hold about you (Art. 15);
- Correct inaccurate or incomplete data (Art. 16);
- Erase your data ("right to be forgotten") subject to legal retention requirements (Art. 17);
- Restrict or object to processing (Art. 18, 21);
- Receive a copy of your data in a portable format (Art. 20);
- Withdraw consent at any time, without affecting the lawfulness of past processing (Art. 7(3));
- Lodge a complaint with a supervisory authority. In Germany this is the data protection authority of the federal state in which you reside; you can find the list at bfdi.bund.de.
To exercise any of these rights, email e-contact@future-formers.com. We respond within one month.
10. Cookies & analytics
The application at app.future-formers.com does not use tracking cookies. We use sessionStorage only to keep you signed in during a browsing session; this is cleared when you close the tab.
The public landing page at future-formers.com loads Google Analytics (measurement ID G-W1GHEMG138) to count visitors and understand how people find us. Google Analytics may set cookies on your browser. IP addresses are anonymised before storage. You can opt out at any time using the Google Analytics opt-out browser add-on.
11. Children & minimum age
FutureFormers is intended for users aged 16 and older. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has registered, please contact us and we will delete the account.
12. Security
We protect your data with a combination of:
- TLS encryption for all network traffic;
- Authentication tokens that expire and are bound to your browser session;
- Role-based access control and row-level security in the database;
- Restricted access to production systems, limited to the operator;
- Regular review of dependencies and access logs.
No system is perfectly secure. If we discover a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and, where required, notify you directly.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page and, for material changes, we will notify registered users by email before the changes take effect.
For any question about this Privacy Policy or how we process your personal data, email e-contact@future-formers.com.