Compliance & Data Protection

Last Updated: August 2026

At fortheworld OÜ, we treat data protection as part of building responsible digital infrastructure.

As an Estonian company operating within the European Union, we take applicable European data-protection requirements seriously, including the General Data Protection Regulation (GDPR) where it applies.

For us, compliance is not simply a document that sits in a folder.

It should influence how digital infrastructure is designed, operated, and maintained.


1. Our Approach to Data Protection

Our approach is based on several principles:

Collect only what is reasonably necessary.

Understand why information is being processed.

Protect the information we hold.

Limit unnecessary access.

Keep information only as long as necessary.

Respect the rights of the people behind the data.

These principles are reflected throughout our Privacy Policy and the way we design and operate our services.


2. GDPR

The General Data Protection Regulation (GDPR) is one of the primary data-protection frameworks applicable to organisations operating in or serving people in the European Economic Area.

Where GDPR applies to our processing activities, we aim to meet the requirements applicable to our role and the particular processing involved.

This includes considering:

  • Lawfulness and transparency

  • Purpose limitation

  • Data minimisation

  • Accuracy

  • Storage limitation

  • Security

  • Accountability

  • Data-subject rights

The specific obligations that apply can depend on the nature of the service, the type of data involved, and whether fortheworld OÜ acts as a controller, processor, or another legally defined role.


3. Privacy by Design

We aim to consider privacy and data protection when designing systems rather than treating them as something to add later.

This can include considering:

  • What information is actually needed

  • Which systems need access to it

  • How long it needs to be retained

  • Who should be able to access it

  • Whether information can be minimised

  • Whether unnecessary data flows can be removed

  • How users can exercise their rights

  • What happens when the information is no longer needed

Good privacy architecture starts before the first user arrives.


4. Data Minimisation

We believe that collecting more information does not automatically create a better service.

Where possible, we aim to limit the information collected to what is reasonably necessary for the intended purpose.

For example, a scheduling workflow may require information necessary to arrange an appointment, but that does not mean it should automatically have access to unrelated information.

Similarly, an integration should not receive information simply because the technical connection makes it possible.

Connect what is necessary. Leave the rest alone.


5. Data Ownership

Where customers provide their own information or content to use a service, they generally retain their rights and interests in that information.

Providing data to fortheworld OÜ for the purpose of using a service does not automatically transfer ownership of that data to us.

However, we may need to process, store, transmit, or otherwise handle the information as necessary to provide the relevant service.

The exact rights and responsibilities can depend on the service and contractual relationship.

Where a project agreement contains specific provisions concerning customer data, those provisions apply to the extent applicable.


6. Controller & Processor Roles

Data-protection responsibilities depend on what we are doing with the information.

For some processing activities, fortheworld OÜ may determine the purposes and means of processing and therefore act as a data controller.

For other services, a customer may determine the purposes and means of processing and fortheworld OÜ may process information on the customer's behalf as a data processor.

In some situations, another legal role or arrangement may apply.

The applicable role should therefore be determined based on the actual service and processing activity rather than assuming that one role applies to everything.

Where required, appropriate contractual arrangements may be established between the parties.


7. Data Processing Agreements

Where fortheworld OÜ processes personal data on behalf of a customer and GDPR or another applicable law requires a data-processing agreement, the relevant contractual arrangements should define the respective responsibilities of the parties.

Depending on the engagement, this may address matters such as:

  • The subject matter of processing

  • The duration of processing

  • The nature and purpose of processing

  • Categories of personal data

  • Categories of data subjects

  • Security requirements

  • Sub-processors

  • Assistance with data-subject rights

  • Data-breach responsibilities

  • Deletion or return of data

The applicable agreement is the authoritative source for the specific contractual relationship.


8. Data Residency & International Transfers

Our company is based in Estonia and operates within the European Union.

We consider the location and transfer of personal information when selecting and configuring infrastructure and third-party services.

Depending on the service, information may be processed by providers operating in different jurisdictions.

Where personal data is transferred outside the European Economic Area, we aim to use appropriate legal mechanisms and safeguards required by applicable data-protection law.

These mechanisms may depend on the provider, destination country, service, and circumstances of the transfer.

EU-based doesn't automatically mean every component of a digital ecosystem is physically located in the EU.

That's why international data transfers need to be considered at the infrastructure level.


9. Security Measures

We take reasonable technical and organisational measures appropriate to the information we process and the services we provide.

Depending on the service, these measures may include:

  • Authentication

  • Access controls

  • Permission management

  • Encryption in transit

  • Secure configuration

  • Monitoring

  • Backups where appropriate

  • Security updates

  • Operational procedures

  • Separation of environments

  • Appropriate access restrictions

The exact security measures vary according to the service and the risks involved.

We do not claim that any digital system is completely immune from security incidents.

Instead, we aim to reduce unnecessary risk, detect problems where possible, respond appropriately, and continuously improve.


10. Sub-Processors & Service Providers

Digital services often depend on other infrastructure.

Depending on the service, we may use third-party providers for:

  • Hosting

  • Cloud infrastructure

  • Authentication

  • Payments

  • Email

  • Scheduling

  • Storage

  • Analytics

  • Security

  • Automation

  • Customer support

  • Other technical functions

Where we use providers to process personal data on our behalf, we aim to select appropriate providers and establish the required contractual and data-protection safeguards.

Where a provider acts independently as a controller, its own privacy documentation and legal responsibilities may also apply.


11. Google & Connected Services

Some services may allow users to connect external accounts or services.

Where Google APIs or other third-party APIs are used, we disclose the relevant data access and purposes in our Privacy Policy and applicable service documentation.

For example, our Google Calendar integration may request:

https://www.googleapis.com/auth/calendar.readonly

and

https://www.googleapis.com/auth/calendar.events

where those permissions are necessary for the implemented calendar functionality.

The Google Calendar permissions are described in detail in our Privacy Policy, including what each permission allows, why it is required, and how the resulting Google user data is used.

We do not treat access to a connected account as permission to use unrelated information.

A connection should have a purpose.


12. Data Subject Rights

Where GDPR or other applicable data-protection law applies, individuals may have rights concerning their personal information.

Depending on the circumstances, these can include:

Right of Access

You may have the right to request access to personal information held about you.

Right to Rectification

You may request correction of inaccurate or incomplete personal information.

Right to Erasure

In certain circumstances, you may request deletion of personal information.

This is sometimes referred to as the right to be forgotten.

Right to Restriction

You may have the right to ask that processing of your personal information be restricted in certain circumstances.

Right to Object

You may have the right to object to particular types of processing, including certain processing based on legitimate interests or direct marketing.

Right to Data Portability

Where applicable, you may have the right to receive certain personal information in a structured, commonly used, and machine-readable format and to transmit it to another controller.

Right to Withdraw Consent

Where processing is based on consent, you can generally withdraw that consent.

Withdrawal does not affect processing that was lawful before the withdrawal.

These rights are subject to applicable legal conditions and exceptions.


13. How to Exercise Your Rights

If you want to exercise a data-protection right, contact us through the privacy or general contact channel associated with the relevant service.

Please provide enough information for us to understand:

  • Who you are

  • What service or relationship your request concerns

  • What right you are seeking to exercise

  • Any information necessary to locate the relevant data

We may need to verify your identity before providing personal information or making changes.

This is a security measure designed to prevent someone else from requesting access to your information.

We will handle requests within the timeframes required by applicable law.

Where permitted by law, we may ask for additional information where necessary to clarify or process a request.


14. Complaints

If you believe that your personal information has been handled inappropriately, we encourage you to contact us first so that we can investigate the matter.

You may also have the right to lodge a complaint with the relevant data-protection supervisory authority.

For organisations established in Estonia, the relevant supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

Your rights to contact a supervisory authority are not dependent on first contacting us where applicable law gives you a direct right to complain.


15. Personal Data Breaches

A personal data breach can involve the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

We maintain processes intended to help us identify, assess, respond to, and manage potential security and data-protection incidents.

Where applicable law requires notification to a supervisory authority or affected individuals, we will follow the relevant legal requirements.

The response to an incident depends on its nature, scope, risk, and the applicable legal obligations.


16. Data Retention

Compliance also means knowing when information should no longer be kept.

We aim to retain personal information only for as long as reasonably necessary for its intended purpose or as required for legitimate legal, contractual, accounting, security, or other obligations.

Retention periods therefore vary according to:

  • The type of information

  • The service

  • The purpose of processing

  • Legal requirements

  • Contractual requirements

  • Security considerations

  • Potential disputes or claims

When information is no longer required, we aim to delete, anonymise, or securely dispose of it where appropriate.


17. Documentation & Accountability

Data protection is not only about technology.

It also requires appropriate processes and documentation.

Depending on the nature and scale of our processing activities, this may include maintaining appropriate records, policies, agreements, assessments, procedures, or other documentation required by applicable law.

We aim to keep our data-protection practices understandable and proportionate to the services we provide.


18. Continuous Improvement

Technology changes.

Regulations change.

Providers change.

The risks associated with digital infrastructure change.

Our data-protection practices therefore need to evolve as well.

We periodically review how information is collected, processed, stored, shared, protected, and deleted.

Where we identify opportunities to improve privacy or reduce unnecessary data processing, we aim to make those improvements.

Compliance is not something you finish.

It is something you maintain.


The Short Version

Collect less.

Know why you're collecting it.

Limit access.

Protect what you hold.

Keep it only as long as necessary.

Respect people's rights.

Be transparent about the infrastructure behind the service.

And when something changes:

Update the process. Improve the system. Keep learning.

That's what responsible digital infrastructure looks like.

Build better. Connect smarter. Scale sustainably.

#ForPeopleForPlanet


Was this article helpful?