Privacy Policy

Thank you for visiting our website and for your interest in our services. When you use our services, your personal data may be processed. The protection of personal data is very important to us. This privacy policy explains how we process personal data and what rights you have. 

  1. General Information

This privacy policy informs you about the handling of your personal data when using our website. In particular, it explains which data we collect and what we use it for. It also informs you about how and for what purpose this is done.

Personal data (“data”) is any information relating to an identified or identifiable person. “Processing” of data means any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organisation, filing, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

The legal basis for data protection can be found in particular in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR) as well as in the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG) and the German Act on Data Protection in Telecommunication and Telemedia (Telekommunikation-Telemedien-Datenschutz-Gesetz, TTDSG).

  1. Controller

The Controller responsible for processing your data is 

Formo Bio GmbH

Stralauer Allee 10-11

10245 Berlin


The controller is any natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

  1. Data Protection Officer

For the protection of your data we appointed a data protection officer:

Gregor Klar

brainosphere1 GmbH

Witzlebenstrasse 21a

14057 Berlin


  1. Scope of Data Processing

We treat your personal data confidentially and in accordance with the statutory data protection regulations and on the basis of this privacy policy. We process your data only as necessary for the purpose of providing a functional and user-friendly internet presence or website and for the provision of our content and services. Failure to provide the data may have legal disadvantages, such as the impracticability of a contract. As part of our data processing, we use various third-party providers in the areas of hosting, online marketing, mailing services and customer relationship management (CRM), each of which processes data on our behalf. We have concluded corresponding data processing agreements with these third-party providers, insofar as the third parties are processors, which ensure that an adequate level of data protection is guaranteed (Art. 28 GDPR).

  1. Data Security

We have taken technical and organisational measures to ensure that the data protection regulations are complied with both by us and by external service providers. For security reasons and to protect the transmission of confidential content that you send to us as the site operator, our website uses SSL or TLS encryption.

  1. Processing of Personal Data

The following overview lists all types of data processed by us, the purposes of their processing, as well as the legal basis for their processing.

  1. Visiting the Website

If you use our website without otherwise transmitting data to us (e.g. by using the contact form), we collect the following data on our web server temporarily via server log files:

  • website from which our website was requested (so-called referrer URL)
  • name and URL of the requested website
  • date and time of access to the website
  • description of the type, language and version of the web browser used
  • IP address of the requesting computer, which is shortened in such a way that it is no longer possible to establish a personal reference.
  • message whether access was successful (access status/ HTTP status code)
  • internet service provider of the accessing system
  • amount of data transferred in each case
  • operating system used and its interface
  • the GMT time zone difference
  • when using a mobile device, if applicable, additionally: country code, language, device name, name of the operating system and version

This processing is technically necessary in order to be able to display our website to you. We also use the data for statistical evaluations to ensure the operational security and stability of our website. The legal basis for this processing is Art. 6 para. 1 p. 1 lit. f GDPR. The processing of the aforementioned data is necessary for the provision of the website and to ensure the stability and operational security of the website and thus serves to protect a legitimate interest of our company.

We also use the data to fulfil our legal obligations for reasons of data security. The legal basis for this processing is Art. 6 para. 1 p. 1 lit. c GDPR.

  1. Registration

You can register on our website. Your email address is required for signing up. After registration, you will receive an email to confirm the registration (“double opt-in”). As part of the registration process, you will be provided with the required mandatory data. The processed data includes in particular the login information (email address, password).

Within the scope of the use of our registration and login functions as well as the use of the user account, we store the IP address and the time of the respective user action. The storage is based on our legitimate interests as well as those of the users in protection against misuse and other unauthorised use. As a matter of principle, this data is not passed on to third parties unless it is necessary for the prosecution of our claims or there is a legal obligation to do so. We process the following data in connection with registration, login and the user account:

  • inventory data (e.g. name, address)
  • contact data (e.g. email address, telephone number if applicable)
  • content data (e.g. entries in the online form)
  • device data (device name, country code if applicable, language, name of operating system and version) 
  • connection data (IP address, mail provider)
  • date and time of registration and confirmation

Processing during registration is carried out on the basis of our legitimate interests for the performance and/or initiation of a user contract, for the provision of customer service, for the administration and/or answering of enquiries, and as a security measure (legal basis: Art. 6 para. 1 p. 1 lit. b GDPR contract performance and pre-contractual enquiries; Art. 6 para. 1 p. 1 lit. f GDPR legitimate interests).

If you have terminated your user account, your data relating to the user account will be deleted, subject to any legal permission, obligation or consent on your part. It is your responsibility to back up your data if you have terminated your account before the end of the contract. Subject to any legal permission, obligation or consent on your part, we are entitled to irretrievably delete all data stored during the term of the contract.

  1. Contact and Emails

If you write to us, e.g. by sending us an email or contact us via the contact form, we store the contact data provided by you, such as name, address, mobile phone number, email and the information provided in your enquiry.

Insofar as you contact us in the context of an existing contractual relationship or contact us in advance for information about our range of services or our other services, the data and information you provide will be processed for the purpose of dealing with and answering your contact enquiry on the legal basis of Art. 6 para 1 p. 1 lit. b GDPR. Insofar as you have consented to the processing for the purpose of answering your enquiry, the legal basis is Art. 6 para. 1 p. 1 lit. a GDPR. Otherwise, we process your data to protect our legitimate interests in accordance with Art. 6 para. 1 p. 1 lit. f GDPR for the purpose of responding appropriately to customer/contact enquiries.

  1. Data Processing of Applicants

When you apply for a job with us, we process the information and personal data you provide for the purpose of managing the application process. This data includes your name, email address, address and telephone number, age, work history, qualifications, country of residence, language skills and any other personal information you provide as part of your interaction with us. We may also ask you for additional information to help us with our recruitment process and if you are offered a job, such as your date of birth and employment records. Processing may also take place electronically. This is particularly the case when an applicant submits relevant application documents to us electronically, for example by email. 

We process your personal data in order to fulfil our contractual or pre-contractual obligations on the legal basis of Art. 6 para. 1 p. 1 lit. b GDPR or, if applicable, for the implementation of the employment relationship with you (Section 26 BDSG). If you have consented to processing for the purpose of handling your application, the legal basis is Art. 6 para. 1 p. 1 lit. a GDPR.

In the event that we do not conclude an employment contract with the applicant, the application documents will be automatically deleted two months after notification of the rejection decision, provided that no other legitimate interests prevent deletion. Another legitimate interest in this sense is, for example, a duty to provide evidence in proceedings under the German General Act on Equal Treatment (Allgemeines Gleichbehandlungsgesetz, AGG).

  1. Newsletter 

You have the possibility to subscribe to our newsletter. With our newsletter we inform you about us and our offers. Only your email address is required to register for the newsletter. If you register for the newsletter, your email address will be transmitted to us (or our mail provider) and stored there. After registering, you will receive an email to confirm your registration (“double opt-in”). In this context, we (or our mail provider) process the following data:

  • inventory data (e.g. name, address)
  • contact data (e.g. email address, telephone number if applicable)
  • content data (e.g. entries in the online form)
  • device data (device name, country code if applicable, language, name of operating system and version) 
  • connection data (IP address, mail provider)
  • date and time of registration and confirmation

We use the provider Mailchimp, Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA, to send the newsletter. Mailchimp is a service to organize and analyze the sending of newsletters. For this purpose, we forward your email address and the information whether you have signed up for the newsletter and/or for further product information to Mailchimp.

With the help of Mailchimp, we can analyze our newsletter campaigns. When you open an email sent with Mailchimp, a file contained in the email (known as a web beacon) connects to the Mailchimp servers in the USA. This allows us to determine whether a newsletter message was opened and which links were clicked. In addition, technical information is recorded (e.g. time of registration, IP address, browser type and operating system). This information is used for the statistical evaluation of newsletter campaigns. The results of these analyses can be used to better adapt future newsletters to the interests of the recipients. 

Our newsletter is sent on the basis of your prior express consent, Art. 6 para. 1 p. 1 lit. a GDPR. The engagement of Mailchimp is based on our legitimate interests in efficient and secure delivery. The legal basis in this respect is Art. 6 para. 1 p. 1 lit. f GDPR.

You can revoke your consent to the processing of data for the purpose of sending the newsletter or the evaluation of the associated data at any time. The revocation can be made via a link contained in each newsletter or by sending a separate message to us.

  1. Cookies and other third-party tools

We use cookies, plug-ins and other tools and technologies from us or third-party providers. Listed below are the third-party providers and the purpose of use, including marketing and analytical purposes.


Cookies are small files that are stored on the end device used and saved by the browser. Cookies serve to make our offer more user-friendly, effective and secure. There are different types of cookies that are used for different purposes. Some cookies ensure that our offers function properly or that you are recognised on your end device after successful registration (“necessary cookies”). By placing these necessary cookies, we make it easier for you to visit our offers and use the services available there. We place other cookies to analyse user preferences and thus improve our offers (“advanced cookies”).

We only place advanced cookies with your consent. When you visit our services for the first time, you will see a pop-up explaining cookies. Once you click on the relevant consent button, you agree to our use of the particular cookies selected, each of which is described in the pop-up as well as in this Privacy Policy. If you want to manage your consent or receive further information on the cookies used on our website click here [LINK to Cookie-Banner].

When cookies are used, the following data is processed depending on the browser setting:

  • usage data (e.g. websites visited, interest in content, access times), 
  • meta/communication data (e.g. device information, IP addresses)
  • location data (data indicating the location of an end user’s terminal device).

If personal data is processed when necessary cookies are used, this is based on Art. 6 para. 1 p. 1 lit. f DSGVO due to legitimate interests of quality assurance and a technically flawless presentation of the website. The processing of personal data when using advanced cookies is based on your consent (Art. 6 para. 1 p. 1 lit. a DSGVO).

Social Media

We are present on various social media platforms and process user data within this framework in order to communicate with users active there or to offer information about us. User data is usually processed within social networks for market research and advertising purposes. For example, usage profiles can be created based on the usage behaviour and resulting interests of the users. The usage profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are usually stored on the users’ computers, in which the usage behaviour and the interests of the users are stored. Furthermore, data independent of the devices used by the users may also be stored in the usage profiles (especially if the users are members of the respective platforms and are logged in to them). For a detailed presentation of the respective forms of processing and the options to object (opt-out), we refer to the data protection declarations and information provided by the operators of the respective networks.

In the case of requests for information and the assertion of data subject rights, we would also like to point out that these can be asserted most effectively with the providers. Only the providers have access to the users’ data and can take appropriate measures and provide information directly. If you still need help, you can contact us.

Twitter, Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, website:; privacy policy: 

LinkedIn, LinkedIn Ireland Unlimited Company Wilton Place, Dublin 2, Ireland; website:; privacy policy:

YouTube, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; website:; privacy policy:

Instagram, Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland; website:; privacy policy: 

  1. Other Processing Purposes

We also process your personal data in order to fulfil other legal obligations that we may have in connection with our business activities. These include in particular retention periods under commercial, trade or tax law. We process your personal data in accordance with Article 6 para. 1 p. 1 lit. c of the GDPR (legal basis) to fulfil a legal obligation to which we are subject.

We also process your personal data in order to be able to assert our rights and enforce our legal claims. We process your personal data in order to be able to defend ourselves against legal claims and insofar as this is necessary for the defence or prosecution of criminal offences. We process your personal data on the legal basis of Art. 6 para. 1 p. 1 lit. f GDPR to protect our legitimate interests, insofar as we assert legal claims or defend ourselves in legal disputes or we prevent or investigate criminal offences.

  1. Storage and Deleting of Data

For hosting services we use SiteGround Hosting Ltd. 7th Floor, 50 Broadway London SW1H 0DB with its servers based in Frankfurt. SiteGround functions as our processor with which we concluded a respective data processing agreement. The data processed by us will be deleted in accordance with the legal requirements as soon as their consents permitted for processing are revoked or other permissions cease to apply (e.g. if the purpose of processing this data has ceased to apply or it is not necessary for the purpose). This means that we only store your personal data for as long as it is required for the respective processing purpose and limit the storage period to the minimum necessary. In addition, we only store your data if we are entitled or obliged to do so in accordance with statutory retention periods (for example in accordance with the German Commercial Code (HGB) or the German Fiscal Code (AO). 

Our data protection information may also contain further details on the retention and deletion of data, which have priority for the respective processing.

  1. Your Rights

You have the following rights: 

  • the right to information, 
  • the right to correction or deletion 
  • the right to restrict processing, 
  • the right to data portability,
  • the right to revoke your consent with effect for the future.
  • the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 para. 1 p. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. 

To exercise your aforementioned rights, you can send an email to […]. In addition, you also have the right to lodge a complaint with a data protection supervisory authority.

If you have any questions with regard to the processing of your data, feel free to contact us at any time.

  1. Disclosure of Data / Third Country Transfers

As a matter of principle, we only pass on your data to third parties if you have consented to this or if there is another legal basis. If we use third-party tools that process your data outside the EU/EEA, we ensure that the legal requirements of Art. 44 et seq. GDPR for such a third country transfer are met and that your data is processed in the third country concerned in accordance with the European data protection standard. With regard to the United States the data transfer is based on the adequacy decision of the EU commission of 10.7.2023 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate level of protection of personal data under the EU-US Data Privacy Framework. In case of third country data transfers not covered by an adequacy decision we rely on the so-called EU standard contractual clauses (SCCs), which we conclude with the respective provider. Additionally, in accordance with the requirements of the ECJ (“Schrems II”), a case-by-case risk analysis is carried out with regard to the respective third country transfer in order to ensure that your data is processed lawfully in the third country concerned and, in particular, that access to your data by state authorities is prevented.

  1. Linked Content

This privacy policy applies only to this website. However, the Website may also contain external links or hyperlinks to Internet pages of other providers. They are to be distinguished from our own content. This third-party content does not originate from us, nor do we have any influence on the content of third-party sites. If you are forwarded to other pages via links within the website, please inform yourself there about the respective handling of your data.

  1. Automated Decision Making / Profiling

We do not use automated decision making or profiling (an automated analysis of your personal circumstances).

  1. Amendment of this Privacy Policy

This privacy policy is currently valid and corresponds to the status of February 2023. Due to the further development of our website and offers on it or due to changed legal or official requirements, it may become necessary to change this privacy policy.