Privacy Policy
1. Overview
This privacy policy informs you about the processing of your personal data when using our website.
Responsible Entity
FormPost
Moritz Mair
Lindenweg 20
64291 Darmstadt
Germany
Email: mail [at] energyforecast.de
Data Collection
When you register we collect your email address and your password (stored encrypted). When you subscribe to a paid plan, your billing address is added and, for business customers, the company name and VAT identification number. During use we process the data you enter as well as technical data collected automatically when visiting the website (e.g. IP address, browser, operating system, access time).
Purpose of Data Processing
We process your data to provide our website and its functions, as well as to improve our services.
Your Rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and the right to object to processing (Art. 21 GDPR). You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). If you have any questions, please contact the address mentioned above.
2. Hosting
We host our website at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Details on data processing can be found at https://www.hetzner.com/de/rechtliches/datenschutz.
The legal basis is Art. 6 Para. 1 lit. f GDPR (legitimate interest in reliable website provision) or Art. 6 Para. 1 lit. a GDPR if consent has been given.
3. Cookies
Our website uses cookies. These are small text files that are stored on your device and enable technically necessary functions.
We distinguish between temporary session cookies, which are automatically deleted after your visit, and permanent cookies, which remain on your device for a longer period.
Technically necessary cookies are stored on the basis of Art. 6 Para. 1 lit. f GDPR. You can set your browser to inform you about the setting of cookies and to allow them only in individual cases or to generally reject them.
4. Payment processing and invoicing
For paid plans we process payments via Mollie B.V., Amsterdam, Netherlands. You enter your payment details directly with Mollie; they are processed there and are not transmitted to us in plain text. We only receive the payment status and an identifier to match the payment. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).
For the order we collect your billing address (name, street, postcode, city, country) and, for business customers, additionally the company name and VAT identification number. We store this data on our server and transmit it to Haufe-Lexware GmbH & Co. KG (lexware office), Germany, in order to issue legally compliant invoices and credit notes. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR (statutory invoicing obligation).
All of the service providers named above process your data within the EU. No data is transferred to third countries outside the EU.
5. Email dispatch
To send emails (notifications about form submissions, registration confirmations, password resets as well as payment and invoice notices) we use an SMTP server of Strato AG, Germany. The recipient address and the content of the respective email are processed for this purpose. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).
6. Spam protection for form submissions
So that our customers' forms cannot be used to send automated bulk messages, we check every submission for indications of machine origin. Without that check the service could be abused for sending spam.
For this we evaluate technical characteristics of the submission process: a hidden form field that only automated programs fill in, the answer to a simple task on our confirmation page, and characteristics of the request and how that page was used – such as whether JavaScript runs, how much time passes between opening and sending, and whether the input came from an actual input device.
From the content of a submission we derive nothing but structural measures – text length, word count, the number of links it contains, the share of particular characters. The text itself is neither stored nor examined for this purpose; what remains stored is only the submission we hold for our customer anyway.
To recognise repeated submissions from the same network, we additionally store a short encrypted value derived from the address range. It cannot be turned back into an IP address.
Spam protection runs entirely on our own servers in Germany. We use no external captcha or fraud detection service, we pass none of this data to third parties, and we create no identifier that would allow visitors to be tracked across different websites or visits.
The characteristics collected for spam protection are stored separately from the submission and deleted after 90 days at the latest – and sooner, as soon as the corresponding submission is deleted.
The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in preventing abusive use. Towards our customers we act as a processor in doing so.
7. Retention period
We store your account data for as long as your user account exists. After it is deleted, the data is removed unless statutory retention obligations require otherwise.
Invoices and the associated invoice data are retained for ten years due to commercial and tax law obligations (§ 147 AO, § 257 HGB).
Form submissions are stored until you delete them or the associated form.
8. Legal bases at a glance
We process your data on the following legal bases:
- Art. 6 (1) (b) GDPR – Performance of a contract (provision of the service, payment processing)
- Art. 6 (1) (c) GDPR – Legal obligation (invoicing and tax retention obligations)
- Art. 6 (1) (f) GDPR – Legitimate interest (hosting, system stability, detection of misuse and spam)
9. Data Security
We implement technical and organizational security measures to protect your data. Please note, however, that data transmission on the Internet may have security vulnerabilities and complete protection against access by third parties is not possible.
10. Use of artificial intelligence
We use AI-assisted tools in developing this website – for programming, drafting text and translation.
Every published text is read and approved by a human before it goes live. Responsibility for the content remains with the provider named above.
These tools work with the source code and the texts of this website. They are given no access to our users' personal data or to the contents of form submissions.
The service itself works without artificial intelligence. Spam protection relies on fixed rules and technical measures, not on a learned model and not on judging what the messages say; section 6 sets out what is collected.
Last updated: September 2026