Privacy
Morfee makes documents out of data you send it. That data is yours and it is here because you put it here. This page says what happens to it, in the order somebody actually asks.
Who is responsible
furō solutions, Kloostertuin 28, 6029TL Sterksel, KvK 93759304, VAT NL005041366B14. Questions about your data go to info@furo.solutions, and are answered by a person.
For the data inside your documents you are the controller and we are the processor. That relationship is written out in the processor agreement, which applies to every account without anybody having to sign anything.
What is stored
Three kinds of thing, and they are worth telling apart.
Your account
Your email address, the name of your organization, when you last signed in, and which browsers hold a session. There is no password, because signing in is a link sent to that address.
Your templates
The HTML you paste, the sample JSON you paste beside it, and the fields you pointed at. The sample stays with the template on purpose: it is what the builder shows you and what the preview renders. If your sample contains a real customer's details, those details are stored. Use made-up data in the sample and nothing real is kept.
The documents you make
The data in a render request is used to make the document and is not stored: what is
written down is that a document was made, from which template, how long it took and how big it was. The
document itself is kept only if you asked for a link instead of the file (?format=url), and then
it sits in object storage for a day so your flow can fetch it. After that the night shift removes it.
Where it stands
On a virtual server rented from Hetzner Online GmbH, inside the EU, with one database file on its own disk. The nightly backup is copied to Cloudflare R2, which is where the handed-out documents go as well. Nothing is copied to a country outside the EU by this installation.
Who else touches it
Four services, and each one only gets what it needs to do its job.
- Hetzner Online GmbH, the server this runs on.
- Cloudflare (R2), the backups and the documents handed out as a link.
- Resend, the sign-in links, invitations, invoices and warnings. It sees the address and the message, nothing from inside your templates.
- Mollie, the direct debit. It sees what a payment needs and nothing else; we never see your bank details.
No analytics, no advertising trackers, no third-party fonts or scripts on any page. The only cookie is the one that keeps you signed in.
How long it stays
- A deleted template: thirty days in the bin, then gone, including from the backups that roll over.
- A document handed out as a link: one day in object storage.
- The line saying a document was made: kept, because it is what your usage and your invoice are counted from.
- Backups: the most recent ones, rolling. Older ones are removed as new ones arrive.
- Your account and your templates: until you remove them. Ask us and an organization is removed with everything in it.
- Invoices: seven years, because Dutch tax law says so.
What you can ask for
Everything the GDPR gives you: a copy of what is here, a correction, removal, and a copy in a form you can take elsewhere. In practice the API already hands your templates back in full, and one email removes an organization with everything in it. Write to info@furo.solutions and you get an answer inside a month, almost always the same week.
Not happy with the answer? You can complain to the Autoriteit Persoonsgegevens.
Security, plainly
Signing in is a link to your mailbox, so that mailbox is the lock: protect it. Sessions last thirty days and you can end all the others from your account. An API key is shown once and stored as a fingerprint, so a leaked key can be revoked but never read back. Traffic runs over TLS, a document can never reach an address inside our network, and data from a render is escaped before it lands in a document.
Last changed on 19 August 2026.