Last Updated: August 2026
At fortheworld OÜ, we believe privacy is part of good digital infrastructure.
This Privacy Policy explains how we collect, use, store, protect, and otherwise process personal information when you interact with our websites, digital services, platforms, infrastructure, software-enabled services, consultations, and related offerings.
Our approach is guided by a simple principle:
Collect what we need. Protect what we hold. Respect the people behind the data.
1. Who We Are
The services covered by this Privacy Policy are operated by:
fortheworld OÜ
Estonia
fortheworld OÜ operates a number of digital products, services, platforms, and projects that may have their own names, websites, interfaces, or domains.
These may form part of the wider fortheworld ecosystem, including development.city and other services operated by the company.
Where a particular service has additional privacy information, data-processing terms, or service-specific conditions, those terms may apply alongside this Privacy Policy.
2. What Is Personal Data?
Personal data is information that can identify you directly or indirectly.
Depending on how you interact with our services, this may include:
Name
Email address
Telephone number
Organisation or business information
Account information
Booking information
Project information
Billing information
Communications with us
Information submitted through forms
Information provided during consultations or support requests
Technical information relating to your use of our services
Information required to provide a particular service
We do not necessarily collect every category of information from every user.
What we collect depends on what you are doing and which service you are using.
3. Data Minimisation
We follow a principle of data minimisation.
This means that we aim to collect and process only the personal information reasonably necessary for a specific and legitimate purpose.
For example, if a service only needs an email address to provide access or communicate with you, there is no reason to collect unrelated personal information.
Likewise, when information is no longer necessary for the purpose for which it was collected, we aim to delete, anonymise, or otherwise stop retaining it where appropriate and legally possible.
The best data to protect is often data we never needed to collect.
4. Information You Provide
You may provide personal information when you:
Create or use an account
Book a session or appointment
Purchase a service
Start a project
Submit a form
Contact us
Request technical assistance
Subscribe to communications
Participate in a consultation
Provide information during onboarding
Provide information as part of a business relationship
We use this information for the purpose for which it was provided and for other purposes permitted or required by applicable law.
5. Information Collected Automatically
When you interact with digital services, certain technical information may be collected automatically.
Depending on the service and technology involved, this may include:
IP address
Browser type
Device information
Operating system
Access times
Pages or services accessed
Referring information
Error information
Security and diagnostic information
This information may help us:
Operate our services
Maintain security
Detect abuse
Troubleshoot technical problems
Understand service performance
Improve our infrastructure
The exact information collected varies between services.
6. How We Use Personal Information
We may use personal information to:
Provide requested services
Create and manage accounts
Process bookings
Deliver projects
Provide consultations
Communicate with customers and partners
Provide technical support
Process payments
Send service-related notifications
Maintain security
Detect and prevent abuse
Troubleshoot technical problems
Maintain and improve our services
Meet legal, tax, accounting, and contractual obligations
Protect our rights and the rights of others
We do not use personal information for purposes incompatible with the purpose for which it was collected unless permitted or required by applicable law.
7. Legal Bases for Processing
Where the EU General Data Protection Regulation (GDPR) applies, we process personal data using one or more lawful bases provided by the GDPR.
Depending on the circumstances, these may include:
Contract
Processing may be necessary to provide a service, fulfil an order, manage an account, or perform an agreement with you.
Legal Obligation
We may need to process certain information to comply with applicable legal, tax, accounting, regulatory, or other obligations.
Legitimate Interests
We may process information where it is necessary for legitimate interests, such as operating, securing, maintaining, supporting, and improving our services, provided those interests are not overridden by your rights and freedoms.
Consent
Where consent is legally required, we will ask for it before carrying out the relevant processing.
Where processing is based on consent, you may generally withdraw that consent at any time.
Withdrawal does not affect processing that was lawful before consent was withdrawn.
8. Third-Party Services
Our ecosystem may rely on third-party providers.
These may provide services such as:
Hosting
Payments
Authentication
Scheduling
Email
Communication
Analytics
Storage
Automation
Infrastructure
Customer support
Security
Other technical services
Where these providers process personal information on our behalf, we aim to select appropriate providers and establish suitable contractual and technical safeguards where required.
Some third-party services may also process information independently as separate controllers under their own privacy policies.
Where relevant, you should review the privacy information provided by those services.
9. Connected Accounts & Integrations
Some services may allow you to connect external accounts or systems.
Examples may include calendars, communication services, business applications, or other digital systems.
When you choose to connect an external service, the application may request permissions required to provide the functionality you have selected.
We aim to request only the permissions necessary for that functionality.
The specific information accessed depends on the integration and the permissions you approve.
We do not request access to connected services simply because broader access is technically available.
Access should serve a purpose.
10. Google Calendar Access
Some of our services may allow you to connect your Google Calendar to provide calendar-based scheduling functionality.
When you choose to connect Google Calendar, the application requests the following OAuth permissions where required by the functionality:
https://www.googleapis.com/auth/calendar.readonly
Google defines this scope as allowing an application to see and download any calendar the user can access using Google Calendar.
We use this permission where calendar information is required for the functionality you have requested.
Depending on the service, this may include reading relevant calendar information and events in order to:
Determine calendar availability
Check for existing events
Identify potential scheduling conflicts
Coordinate appointments
Provide calendar-based scheduling functionality
https://www.googleapis.com/auth/calendar.events
Google defines this scope as allowing an application to view and edit events on the user's calendars.
We use this permission where the requested functionality requires the application to create, update, or otherwise manage calendar events on your behalf.
Depending on the service, this may include:
Creating an event for an appointment you have requested
Updating an event when the associated appointment changes
Managing an event associated with a service you have explicitly authorised
Supporting scheduling workflows
Keeping relevant appointment information synchronised with your calendar
We do not describe this permission as read-only or as merely an availability permission because it is not. The permission provides the ability to view and edit calendar events, and our disclosure reflects that capability.
Why These Permissions Are Requested
The requested Calendar permissions are used to provide calendar functionality that you have chosen to use.
The read-only calendar permission is used where the service needs to read calendars and calendar information accessible to you.
The events permission is used where the service needs to create, update, or manage calendar events as part of the requested scheduling functionality.
We do not request these permissions for unrelated purposes.
Google recommends that applications request the most narrowly focused permissions necessary for their functionality and avoid requesting permissions they do not require.
What We Do With Google Calendar Data
Google Calendar data obtained through these permissions is used to provide and support the calendar-related functionality described in this Privacy Policy.
This may include:
Reading relevant calendar information
Checking existing events
Determining availability
Preventing scheduling conflicts
Creating calendar events
Updating calendar events
Supporting appointment and scheduling workflows
We do not use Google Calendar data for advertising.
We do not sell Google Calendar data.
We do not use Google Calendar data to create advertising profiles.
We do not use Google Calendar data for unrelated purposes merely because the application has access to it.
Our use of Google user data is limited to the purposes disclosed in this Privacy Policy and the functionality presented to users.
Google requires applications using Google API Services to provide clear and accurate information about what Google user data they request and why they request it. Google also requires the published privacy policy to accurately disclose how Google user data is accessed, used, stored, and shared.
Sharing of Google Calendar Data
We do not sell or transfer Google Calendar data to advertising platforms, data brokers, or information resellers.
Where a service provider processes Google Calendar data on our behalf, that processing is limited to what is necessary to provide the relevant user-facing functionality and is subject to applicable contractual, technical, and legal safeguards.
Google's User Data Policy places additional restrictions on the use and transfer of Google user data, including requirements concerning limited use, security, and disclosure.
Human Access to Google Calendar Data
We do not allow humans to access Google Calendar data for unrelated purposes.
Where human access is legally required, necessary for security or abuse investigation, or otherwise permitted under applicable Google requirements, such access is limited to the circumstances allowed by those requirements.
Revoking Google Calendar Access
You can revoke the application's access to your Google Account through your Google Account security settings.
If you revoke access, calendar-dependent functionality may stop working or may require you to reconnect your Google Calendar.
11. Google API Services & User Data
Where our services use Google APIs, we handle information obtained through those APIs in accordance with applicable Google API requirements and policies.
We aim to:
Clearly identify what Google information is requested
Explain why the information is required
Request only the permissions necessary for implemented functionality
Use Google user data only for the purposes disclosed to users
Protect Google user data against unauthorised access
Avoid selling or using Google user data for advertising
Provide appropriate controls for users to disconnect or revoke access where applicable
Google's User Data Policy requires developers to accurately represent their identity, the data they request, and the purposes for which that data is used. It also requires developers to request only permissions necessary for implemented features.
12. Payments
When you make a payment, payment information may be processed by third-party payment providers.
We generally do not need to store complete payment-card details ourselves.
The relevant payment provider may process payment information according to its own privacy policy, security requirements, and contractual terms.
We may receive limited payment-related information necessary for purposes such as:
Confirming a transaction
Managing subscriptions
Issuing invoices
Accounting
Refunds
Customer support
Fraud prevention
13. Communications
If you contact us, we may retain the communication and relevant contact information in order to:
Respond to your request
Provide support
Maintain project history
Resolve disputes
Improve our services
Meet legal or contractual obligations
Where appropriate, communications may be organised through email, ticketing, project-management, support, or other systems.
Keeping a record of relevant interactions can help us maintain context and avoid asking you to repeat information.
14. Data Retention
We do not keep personal information indefinitely simply because we can.
We aim to retain information only for as long as reasonably necessary for the purposes for which it was collected, including legitimate business, contractual, legal, accounting, security, and dispute-resolution requirements.
Retention periods may therefore vary depending on:
The type of information
The purpose of processing
The service involved
Legal requirements
Contractual obligations
Security requirements
Potential disputes or claims
When information is no longer required, we aim to delete, anonymise, or otherwise securely dispose of it where appropriate and legally possible.
15. Data Security
We take reasonable technical and organisational measures appropriate to the nature of the information and the services we provide.
Depending on the service, these measures may include:
Encryption in transit
Access controls
Authentication mechanisms
Permission management
Secure configuration
Monitoring
Backups where appropriate
Security updates
Operational procedures
No internet service can honestly guarantee absolute security.
Security is therefore treated as an ongoing process rather than a one-time feature.
16. International Data Transfers
Our company is based in Estonia and operates within the European Union.
Depending on the services and third-party providers involved, personal information may nevertheless be processed in countries outside the European Economic Area.
Where applicable, we seek to use appropriate legal mechanisms and safeguards for international transfers in accordance with applicable data-protection law.
The specific transfer arrangements may depend on the provider and service involved.
17. Your Rights
Where GDPR or other applicable data-protection law grants you rights over your personal information, these may include the right to:
Access your personal data
Correct inaccurate information
Request deletion
Restrict processing
Object to certain processing
Receive certain information in a portable format
Withdraw consent where processing relies on consent
Lodge a complaint with a relevant supervisory authority
These rights are not absolute and may be subject to legal exceptions or limitations.
If you would like to exercise a right, contact us through the privacy or general contact channel provided for the relevant service.
18. Children's Privacy
Our services are generally intended for adults and organisations.
We do not knowingly design our services to collect personal information from children where doing so would require parental or guardian consent and we do not have that consent.
If you believe that a child has provided personal information to us in circumstances where it should not have been collected, please contact us.
19. Cookies & Similar Technologies
Some services may use cookies or similar technologies.
These may be used for:
Authentication
Security
Functionality
Preferences
Analytics
Service performance
The specific technologies used vary between services.
For more information, please see our Cookie Policy.
20. Changes to This Privacy Policy
Our services and technologies may change.
We may therefore update this Privacy Policy from time to time.
When we make changes, we'll update the Last Updated date.
If a change is material and applicable law requires additional notice, we will provide that notice through an appropriate channel.
If the way we use Google user data changes in a manner that requires additional disclosure or consent under applicable Google requirements, we will update the relevant privacy disclosures and obtain any required user consent before using the data for the new purpose.
We encourage you to review this page periodically.
21. Contact
If you have a question about privacy, personal information, Google Calendar access, or how your data is handled, please contact us through the privacy or general contact channel associated with the relevant service.
When contacting us about your personal data, please provide enough information for us to understand the request.
We'd rather answer a privacy question clearly than leave you wondering what happens to your information.
Our Privacy Principle
Technology gives organisations enormous power to collect and process information.
We don't believe that means they should collect everything.
Our approach is simple:
Collect less.
Explain why.
Protect what we hold.
Respect people's choices.
Delete what we no longer need.
And when you give us access to another service — such as your Google Calendar — use that access only for the functionality you asked us to provide.
That's what data minimalism means to us.
#ForPeopleForPlanet