This notice explains how reform processes personal data across account creation, product use, support, and billing-related workflows.
Who we are
Stefano Pompei, Carrer Beat Nicolas Factor 11, 46007 Valencia, ES, tax identifier Y7554839C is the controller for account, billing, security, support, and legal-compliance data. Privacy contact: privacy@paqu.io.
For customer form content, the customer determines the purposes and means and reform acts as processor or service provider under the Data Processing Agreement.
Data we collect
Account and workspace data. This includes identity, email, organization membership, and information you submit while using the product.
Authentication data. We process sign-in details, session data, and optional social sign-in data needed to secure access.
Support and legal data. We keep communications, access requests, and compliance records needed to respond to requests and protect the service.
Optional browser telemetry. If you enable consent-based analytics or diagnostics, we may receive limited product-usage or error data from your browser.
Billing data. If you create or manage paid subscriptions, billing contact and transaction-related data may be processed.
Connection and approximate-location data. We process IP addresses and may derive an approximate country to operate and secure the service, apply country-based pricing, and prevent fraud or abuse. GeoLite country lookups run locally on reform infrastructure; visitor IP addresses are not sent to MaxMind for the lookup.
Referral program data. If you apply a referral reward, we record the referral token, when you applied it, and which paid organizations it covers. If you join the referral program as a referrer, we and FirstPromoter process your account, contact, payout, and tax details and the commissions earned. See the Referral Program Terms.
How we use data
Operate and secure the service. We use personal data to authenticate users, maintain organizations, enforce access controls, and keep reform available.
Respond to you. We use submitted data to answer support requests, evaluate access requests, and communicate product or compliance updates.
Improve reliability. We use operational data to troubleshoot incidents and improve the product when the relevant lawful basis or consent applies.
Third-party services
Core service providers used on our behalf are listed on the Subprocessors page.
If you choose social sign-in, Google or GitHub will also process authentication data under their own notices. If you use paid features, Stripe may process billing and payment data under its own legal terms.
For the referral program, FirstPromoter receives the email address and an internal identifier of referred customers, plus payment, refund, and cancellation events for referred paid organizations, so referrers can be credited and paid.
Cookies, retention, and rights
Browser storage and consent choices are described in the Cookie Policy.
You can request access, correction, deletion, export, or other privacy assistance by emailing support@paqu.io. Retention varies by data class and is managed under our internal retention policy.
Security, incident response, and transfers
We use technical and organizational safeguards. These include encryption in transit and at rest, access controls, audit logging, and incident-response procedures.
If we confirm a security incident affecting personal data, we investigate, contain, and notify affected customers or other parties when required by contract or law. Security or privacy questions can be sent to support@paqu.io.
reform uses European-region configurations for core application hosting, database infrastructure, browser telemetry, and object storage. Some supporting services may still involve limited cross-border processing; where required, we rely on appropriate contractual and legal transfer safeguards.