Legal

Security practices

How Formalini protects documents, accounts and extracted data, and how to report a vulnerability.

Last updated: 15 September 2026

Protecting your documents

Original files are held in private storage that is not publicly reachable. Viewing a page uses a short-lived link generated for you at that moment, and links expire. Data is encrypted in transit and at rest by our hosting provider.

Separation between accounts

Every document, template and record is tied to a workspace, and database-level access rules mean a request can only read rows in workspaces the signed-in person belongs to. Personal spaces are private to their owner unless the owner shares them with named household members.

Access and accountability

Access to your data is limited and traceable.

  • Roles decide who can invite people, change templates and approve documents.
  • Share links can be limited, given an expiry date, and revoked; views are counted.
  • Processing, correction, approval and delivery events are recorded against the document.
  • API keys are workspace-scoped, shown once, and can be revoked at any time.

Availability and recovery

The application and database are managed services with automated backups held by our hosting provider. Outbound deliveries that fail are retried with increasing delays and can be replayed, so a temporary outage on your side does not lose data.

Reporting a vulnerability

Email security@formalini.com with enough detail to reproduce the issue. We acknowledge reports within three working days and will not pursue researchers who act in good faith, avoid other people’s data and give us reasonable time to fix the problem.

Who you are contracting with

  • Trader: Pascalini Marco Irinel, PFA (Formalini)
  • Country of establishment: Romania
  • Registered address: Romania, Sibiu, Cisnadie, 555300, Str Grigore Ionescu 82
  • Tax identification number: 25962868
  • Legal contact: legal@formalini.com
  • Billing contact: billing@formalini.com