Forma Labs Technologies

Privacy Policy

Effective August 5, 2026

Scope note

This policy covers the Forma Labs corporate website, inquiries, marketing and business administration, and provides a high-level explanation of personal information processed in connection with AI implementation consulting. Belonga and InForma are excluded and maintain separate privacy policies. Client-controlled consulting data is also governed by the applicable consulting agreement, statement of work, data processing addendum, confidentiality agreement, and any project-specific data and AI use schedule.

1. Who we are and when this policy applies

Contact us at privacy@formalabstech.com or info@formalabstech.com, or by mail at 2503D N Harrison St PMB 2104, Arlington, VA 22207-1640, United States.

For personal information collected through our website, marketing, business development, contracting, billing, vendor management, and our own corporate operations, Forma Labs generally acts as a controller or business that determines why and how the information is processed.

When a consulting client provides personal information or grants access to systems containing personal information for us to process solely on the client’s documented instructions, Forma Labs generally acts as a processor, service provider, or contractor for that client. In that context, the client’s privacy notice and our contract with the client govern the primary purposes of processing. This policy does not replace those agreements.

2. Personal information we collect

2.1 Website, inquiry, and relationship information

Contact and inquiry information, such as name, business email address, telephone number, company or organization, role, and the message or files you submit.

Business communications contained in emails, meeting requests, videoconferences, proposals, contracts, procurement documents, certifications, grant materials, and related correspondence.

Client, prospect, vendor, partner, adviser, and professional contact information.

Billing and transaction records, including invoices, payment status, tax records, and limited payment-related information processed through approved payment providers.

Scheduling, referral, or vendor-registration information you choose to provide.

Standard website and security log information, such as IP address, browser type, device information, and access times, collected automatically through our website and hosting infrastructure. Forma Labs does not currently use non-essential cookies, analytics, advertising technology, or session-replay tools. If that changes, this policy will be updated in advance to disclose the categories, purposes, providers, and available controls before any such technology is used.

2.2 Consulting engagement information

The information processed during a consulting engagement depends on the project and the client’s instructions. It may include:

Client-provided datasets, documents, emails, policies, contracts, meeting materials, support tickets, project records, drawings, specifications, databases, and system exports.

Workforce and stakeholder information, including names, roles, business contact information, interview notes, survey responses, workshop participation, workflow observations, and training records.

Customer, applicant, tenant, patient, student, vendor, or other third-party information incidentally or intentionally contained in client materials.

System architecture, configuration, security, access, audit, and operational information.

AI prompts, model outputs, test cases, evaluation results, quality scores, error logs, agent activity, and automation records.

Temporary credentials or authorized access information used to enter client systems.

Sensitive or regulated information only when specifically approved, necessary for the engagement, and subject to appropriate contractual and technical controls.

2.3 Sources of information

Directly from you when you contact or engage with us.

From the organization you represent or from a client that authorizes us to process information.

From approved service providers, referral partners, professional advisers, procurement portals, and public or professional sources.

From systems, applications, and devices that you or a client authorize us to access.

3. How we use personal information

Respond to inquiries and evaluate potential client, vendor, funding, procurement, employment, referral, or partnership relationships.

Prepare proposals, statements of work, contracts, invoices, and other engagement documents.

Administer consulting engagements and provide AI-readiness assessments, workflow mapping, stakeholder research, governance programs, prototypes, integrations, automations, training, implementation support, and related services.

Conduct interviews, surveys, workshops, testing, quality review, troubleshooting, performance monitoring, security review, and adoption measurement as authorized by the client.

Test and evaluate AI model or automation outputs for accuracy, reliability, safety, bias, security, and fitness for the approved use case.

Manage client, vendor, partner, adviser, and professional communications.

Operate, secure, maintain, and improve our website and corporate systems.

Comply with legal, tax, accounting, procurement, insurance, grant, certification, security, fraud-prevention, and recordkeeping obligations.

Protect our rights, safety, systems, personnel, clients, and the public.

Send administrative or service-related communications about the Website; if Forma Labs introduces newsletters, event notices, or other marketing communications in the future, only where permitted and with an unsubscribe option.

When we act as a processor or service provider, we process client-controlled personal information only for the contracted business purpose and according to the client’s documented instructions, unless applicable law requires otherwise.

4. AI systems and client data

Forma Labs may use AI systems, automation platforms, transcription tools, cloud infrastructure, and related technology to perform approved consulting tasks. We apply data minimization and use only providers, accounts, and configurations approved for the relevant engagement.

We do not use client-controlled personal information for Forma Labs’ independent advertising or unrelated marketing.

We do not use client-controlled personal information to train a public or general-purpose AI model unless the client expressly authorizes that use in writing and the use is legally permissible.

We do not submit client information to personal, consumer, or otherwise unapproved AI accounts.

Where appropriate, we redact, pseudonymize, aggregate, or de-identify information before using an external AI provider.

Provider selection may consider contractual confidentiality, model-training restrictions, retention settings, security, subprocessors, hosting location, and available enterprise controls.

Project-specific restrictions, approved providers, prohibited data categories, and retention settings should be documented in the engagement’s data and AI use schedule.

5. Employment and high-impact decisions

Our consulting services may assess workflows, systems, adoption patterns, organizational processes, or aggregate workforce needs. Unless expressly agreed under a separately reviewed service, Forma Labs does not independently make employment, disciplinary, promotion, termination, credit, housing, insurance, healthcare, education, or other legally significant decisions about individuals.

If a client requests an AI use case that may materially affect an individual, the engagement must undergo additional legal, privacy, security, fairness, governance, and human-oversight review before implementation.

6. Legal bases, where applicable

Performance of a contract or steps requested before entering into a contract.

Our legitimate interests in operating, securing, and developing our business and services, provided those interests are not overridden by applicable rights.

Compliance with legal obligations.

Consent, where required for optional marketing, non-essential cookies, recordings, or other specific processing.

Other legal bases available under applicable law.

7. How we disclose personal information

Service providers supporting website hosting, email, forms, scheduling, videoconferencing, document management, CRM, analytics, security, accounting, payment processing, cloud infrastructure, automation, AI systems, transcription, and professional operations, subject to appropriate restrictions.

Professional advisers, including attorneys, accountants, insurers, auditors, and compliance advisers.

Clients, authorized project partners, subcontractors, primes, funders, government agencies, procurement entities, or implementation partners when required for an authorized proposal or engagement.

Authorities or other parties when disclosure is required by law or reasonably necessary to protect rights, safety, systems, or prevent fraud.

A successor entity in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.

We do not sell personal information collected through our website, business operations, or consulting inquiry process. We do not share personal information for cross-context behavioral advertising.

Subprocessors and approved consulting vendors

When Forma Labs acts as a processor or service provider, the applicable contract may identify or provide a process for approving subprocessors. We remain responsible for imposing appropriate privacy, confidentiality, and security obligations on approved subprocessors.

8. Cookies, analytics, and marketing

At this time, formalabstech.com does not use non-essential cookies, analytics, advertising technology, pixels, embedded media, or session-replay tools; only the standard website and security log information described in Section 2.1 is collected automatically. If Forma Labs begins using additional cookies, analytics, or similar technology, this policy will be updated in advance to disclose the categories, purposes, providers, consent mechanism, and available user controls.

Forma Labs does not currently send marketing or newsletter emails. If that changes, marketing messages will include an unsubscribe method and will not be combined with required transactional, contractual, security, or service communications.

9. Retention and disposal

We retain personal information only as long as reasonably necessary for the purposes described in this policy, the applicable engagement, legal and contractual obligations, dispute resolution, security, and appropriate business records. Retention depends on the record category and context.

Website inquiries and unsuccessful proposals are retained for a defined business-development period.

Contracts, invoices, tax, procurement, and accounting records are retained for the legally or contractually required period.

Client-controlled project data, temporary exports, credentials, recordings, prompts, outputs, and working copies are retained only for the engagement period and agreed closeout period unless the client instructs otherwise or law requires retention.

At engagement completion, client-controlled personal information is returned or securely deleted according to the contract, subject to legal holds and the ordinary expiration of secure backups.

Forma Labs may retain final deliverables, general methodologies, templates, and genuinely de-identified or aggregated learnings only when contractually permitted and when they do not identify the client or an individual.

10. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information and the engagement. Depending on the system and project, safeguards may include:

Multi-factor authentication, role-based access, and least-privilege access.

Encryption in transit and at rest where supported and appropriate.

Approved-device, secure file-transfer, and credential-vault requirements.

Separate client workspaces or controlled project repositories.

Access logging, periodic access review, and timely access removal.

Vendor due diligence and approved-tool requirements.

Restrictions on downloading client data to personal devices or entering it into unapproved AI services.

Incident response, secure disposal, and personnel confidentiality obligations.

No system is perfectly secure. If a security incident affects personal information, we will investigate and provide notifications or assistance as required by applicable law and contract.

11. Data subject and consumer privacy rights

11.1 Requests concerning information controlled by Forma Labs

Depending on your location and applicable law, you may have rights to access, know, correct, delete, restrict, object to, or obtain a copy of personal information, withdraw consent, appeal certain decisions, or use an authorized agent. We will not discriminate against you for exercising an applicable privacy right.

11.2 Requests concerning client-controlled information

When Forma Labs processes personal information on behalf of a consulting client, the client is generally responsible for responding to privacy requests. If we receive a request concerning client-controlled information, we may redirect the request to the client and provide reasonable contractual assistance without independently changing or disclosing the information unless authorized or legally required.

Submit requests to privacy@formalabstech.com. We may take reasonable steps to verify identity and authority.

12. International transfers

Forma Labs operates from the United States. Personal information may be processed in the United States and in other countries where approved service providers operate. Where required, we use recognized contractual or legal transfer mechanisms and appropriate safeguards. Project-specific location and transfer requirements may be documented in the consulting agreement or data and AI use schedule.

13. Children

The Forma Labs corporate website and consulting services are directed to businesses and are not intended for children under 18. We do not knowingly collect personal information directly from children through the website. Forma Labs does not currently accept consulting engagements that involve children’s personal information; if that changes, the engagement will require dedicated legal review and appropriate contractual and security safeguards before it begins.

14. Job applicants and workforce information

If Forma Labs begins accepting job applications or employing personnel at a scale that requires a separate applicant or workforce privacy notice, that notice will describe the information collected and used for recruitment, screening, employment administration, payroll, benefits, security, and legal compliance.

15. Third-party sites and services

Our website or communications may link to third-party websites, scheduling tools, social networks, or embedded services. Their privacy practices are governed by their own notices. Forma Labs is not responsible for third-party practices except to the extent required by applicable law or contract.

16. Changes to this policy

We will update the “Last updated” date when this policy changes. If a change materially affects your rights or how we use personal information, we will provide notice through the relevant website, service, or email before the change takes effect where required. Prior versions may be retained for compliance records.

17. Contact us

Questions, privacy requests, or concerns may be sent to privacy@formalabstech.com or info@formalabstech.com, or by mail to Forma Labs Technologies, LLC, 2503D N Harrison St PMB 2104, Arlington, VA 22207-1640, United States.

This policy is published in English. Any translation is provided for convenience only; if there is a conflict, the English version governs.

Appendix A — Consulting data governance documents

Forma Labs intends to use the following supporting documents as appropriate to the engagement:

Consulting services agreement or master services agreement.

Statement of work defining scope, systems, deliverables, and authorized purposes.

Mutual or one-way confidentiality agreement.

Data Processing Addendum addressing controller/processor obligations.

Project-specific data and AI use schedule identifying approved providers, data categories, prohibited data, access, retention, return/deletion, recording and transcript rules, and permitted de-identified uses.

Information security schedule or client security questionnaire.

Subprocessor list and change-notification process.

Incident response and notification procedure.

This document is published in English. Any translation is provided for convenience only; if there is a conflict, the English version governs.