Data portability and data location
See also our Terms of ServiceSee also our Privacy Policy
Contents
1. About this page
This page explains how you take your data with you from Future Fluent, and where your data is kept.
It is the register of data structures, formats and standards referred to in clause 12.3 of the General Licence Terms for Future Fluent. It also holds the information on jurisdiction and protection against governmental access referred to in clause 14.4.
The page is our information under Article 26(b) and Article 28(1) of the Data Act, Regulation (EU) 2023/2854. We update it when the export functions, the data structure or our subcontractors change. The date at the top shows the last change.
2. Export it yourself
You can export the following directly in the service at any time. This also works in read-only mode.
| Data | Where in the service | Format |
|---|---|---|
| Report under the VS standard, all modules for one reporting period | The VS report, export button | iXBRL (.xhtml), XBRL (.xbrl), EFRAG VSME digital template (.xlsx), Excel (.xlsx), CSV, PDF |
| Greenhouse gas accounts | The Scope 1, Scope 2 and Scope 3 pages | Excel (.xlsx), one file per scope |
| Greenhouse gas inventory summary | The greenhouse gas overview | |
| SFDR indicators | SFDR export | JSON and CSV |
| Change log | My activity (your own changes), and the change history for Scope 1, Scope 2 and suppliers | Excel (.xlsx) |
| Suppliers | The suppliers page, export button | Excel (.xlsx) with company, contact person, e-mail, status, annual spend and country. The file contains the suppliers shown with the current filter. |
| Dashboards with custom KPIs | Custom KPIs | |
| Uploaded supporting documents and evidence files | On the record the file was uploaded to | Original file format, one file at a time |
| Custom KPI values, supplier responses, comments, users and roles | No separate export file today | Included in the full export, see section 5 |
Known limitations
- VS report exports cover one reporting period at a time and include all modules. There is no separate file per module.
- The VS report CSV has two columns, Field and Value. Field names are the service's internal names. Values with several parts, such as tables, are written as JSON in the cell.
- In the greenhouse gas Excel files the emission factor is one text value with value, unit and source. Data year and GWP version are not in separate columns. They are in the full export where they are recorded.
- The change log in Excel does not show the reason given for a change. The reason is in the full export.
- PDF files are for people to read. Use the other formats to move data to another system.
3. Data structure of a full export
The full export is taken from the service database. Each table below is delivered as its own file. Each row has an id. Tables link through id fields, such as company_id, facility_id and reporting_period_id. A description of every field comes with the export.
The list covers every table that holds Customer Data and the main fields of each table. The description that comes with the export covers every field.
Company and facilities
- companies: name, org_number, vat_number, address_line1, address_line2, postal_code, city, country, phone, parent_company_id
- company_relationships: parent_company_id, child_company_id, relationship_type, ownership_percentage, consolidation_method, effective_from, effective_to
- facilities: name, facility_type, address, postal_code, city, country, country_code, latitude, longitude, employee_count, floor_area_m2, is_primary, is_active
- reporting_periods: reporting_year, fiscal_year, start_date, end_date, status, deadline
- company_financial_data: year, quarter, revenue, expenses, profit, assets, employees, currency
- intercompany_eliminations: parent_company_id, source_company_id, target_company_id, reporting_year, category_key, elimination_tco2e (emissions eliminated when the group is consolidated)
Report data under the VS standard
- vsme_reports: reporting_period_id, status, version, template_version
- vsme_disclosures: report_id, disclosure_code, status, version
- vsme_compliance_logs: disclosure_id (the disclosure identifier, B1 to B11 and C1 to C9), action, form_data (all form fields at the time of saving, as JSON), field_name, previous_value, new_value, user_name, user_email, created_at, reporting_period_id
- social_metrics_cache: the values for B9, B10 and C5 that the service has calculated, such as accident rate, pay gap and employee turnover
- reports and report_templates: saved reports and report templates (title, report_type, report_data, sections)
- vsme_template_exports: exports of the EFRAG VSME digital template that the service has saved (export_format, template_version, exported_at)
- readiness_scans: analyses of an earlier report that you uploaded (file_name, status, overall_score, gaps, strengths, extraction_results, reviewed_data)
- Tables with structured data per module. Where the field source_disclosure exists, it names the disclosure the row belongs to.
- b3_energy_consumption (B3): facility_id, electricity_renewable_mwh, electricity_non_renewable_mwh, fuels_renewable_mwh, fuels_non_renewable_mwh, total_mwh
- b4_pollution_emissions (B4): pollutant_code, pollutant_name, emission_medium, quantity_kg, quantity_tonnes, measurement_method, is_above_eprtr_threshold
- b5_facility_biodiversity and b5_nature_oriented_areas (B5): facility_id, total_land_area_ha, is_in_sensitive_area, proximity_type, has_action_plan, area_type, area_ha
- water_consumption_data (B6): withdrawal_total and withdrawal per source, discharge_total and discharge per recipient, water_consumption, is_high_water_stress_area, unit
- waste_disclosures: ewc_code, waste_type, waste_description, disposal_method, quantity_kg, quantity_tonnes, is_diverted_from_disposal, waste_handler_name
- b8_workforce_metrics (B8): metric_type, contract_type, gender, country, value, unit
- work_accident_records, pay_gap_details, employee_turnover_details, governance_incidents, human_rights_policies, human_rights_incidents
- climate_transition_plans, ghg_reduction_targets, climate_risk_assessments, climate_risks, environmental_management_disclosures, pollution_disclosures, biodiversity_impact_data, controversial_revenue_disclosures, comprehensive_other_disclosures
Greenhouse gas data
- emissions_detail, one row per activity record: scope (1, 2 or 3), ghg_protocol_category, category_key, sub_category, activity_data (JSON with quantity, unit and other activity details), emission_factor_used (JSON with the factor value, unit and source, and where available the source year and GWP set), emissions_tco2e, tco2e_location_based, tco2e_market_based, biogenic_co2_tco2e, calculation_method, source_type, data_quality_score, uncertainty_percentage, reporting_period_start, reporting_period_end, facility_id, notes, is_superseded, superseded_by
- company_emission_factors (your own factor libraries): name, co2e_factor, unit, scope, activity_type, fuel_or_activity, geography, source_database, source_url, data_year, gwp_set
- custom_emission_factors: name, co2e_factor, unit, source_name, data_year, gwp_version, geography
- emission_factor_overrides: custom_emission_factor, factor_unit, reason, source_description, source_url, valid_from, valid_until
- The factors from our factor library that were used in your calculations: name, co2e_factor, co2_factor, ch4_factor, n2o_factor, unit, source_database, data_year, gwp_version, geography, version
- ghg_settings: base_year, consolidation_approach, boundary_rationale, scope3_excluded_categories, scope3_materiality_threshold
- emission_methodology_assignments, ghg_period_approvals, supplier_pcf_entries
- integration_data (data fetched from systems you have connected): integration_type, period_start, period_end, ghg_scope, ghg_category, ghg_emissions_kg, emission_factor_used, emission_factor_source
- invoice_extractions and invoice_line_items (imported invoices): supplier_name, invoice_number, invoice_date, currency, total_net, total_vat, total_gross, and invoice lines with description, quantity, unit, amount_net
- activity_energy, activity_vehicles, activity_travel and activity_goods (activity data for energy, vehicles and machinery, travel and purchases): period or date, type, quantity, unit, facility_id or supplier_id, calculated_emissions and data_quality_score
- accounting_transactions (transactions from a connected accounting system): transaction_date, account_code, description, amount, currency, supplier_name, emission_category, calculated_emissions
- spend_accounts_imported, spend_account_mappings, spend_account_category_mappings and emission_category_mappings (spend per account and how accounts map to categories and factors): account_number, account_name, amount, currency, supplier_name, nace_code, category_key, scope
- ghg_accounting_sessions, ghg_calculation_results and ghg_hotspots (imports of spend data and their results)
- ghg_base_year_events, scope3_verification_log, data_quality_flags, historical_import_jobs and batch_import_jobs (events that affect the base year, Scope 3 verification, data quality flags and imports)
- emissions_monthly and emissions_snapshots: monthly and per-period totals that the service has calculated
- environmental_data: year, month, energy_consumption, carbon_emissions, water_usage, waste_generated, renewable_energy_percentage
Targets, scenarios, climate risk and analyses
- emission_targets: scope, target_type, baseline_year, baseline_value, target_year, target_value, status
- reduction_initiatives: name, category, scope, estimated_reduction_tco2e, actual_reduction_tco2e, estimated_cost, actual_cost, start_date, end_date, implementation_status
- emission_scenarios, carbon_pricing_scenarios and carbon_cost_allocations: scenarios, carbon prices and allocated costs
- facility_risk_assessments (climate, water and nature risk per site): facility_id, latitude, longitude, risk levels for flood, drought, heat and storm, water stress, distance to protected areas, data sources and assessment dates
- supplier_location_risk_assessments: the same risk assessment for supplier locations
- emission_alerts, emissions_anomalies, emission_forecasts, emission_recommendations and emission_financial_analysis: alerts, anomalies, forecasts, suggestions and calculations that the service has produced
Custom KPIs
- custom_kpis: name, description, unit, formula_definition, data_source_type, target_value, target_direction, visualization_type
- kpi_values: kpi_id, year, quarter, month, value, dimension_values, notes
- kpi_dimensions: name, labels
- custom_datasets, custom_dataset_series, custom_dataset_values
- user_dashboards and dashboard_kpis: dashboard names and layout
Suppliers and supplier responses
- suppliers: company_name, vat_number, country, address, nace_code, contact_person_name, contact_person_email, spend_category, annual_spend, status
- supplier_locations: address, country_code, latitude, longitude
- supplier_submissions: reporting_year, scope_1_emissions, scope_2_location_based, scope_2_market_based, calculated_emissions, calculation_method, emission_factor_per_unit, quantity, product_service, has_sbti_targets, has_external_verification, verification_details, additional_comments, submitted_at, reviewed_at
- supplier_documents: file_name, uploaded_at
- supplier_communications: channel, message_type, sent_at, opened_at
- supplier_scores and supplier_segments: score and segment per supplier
- supplier_invitations: when invitations were sent, opened and expire (expires_at, accessed_at). The invitation links themselves are not exported.
Comments
- record_comments: table_name, record_id, comment_text, created_by_name, created_at, parent_comment_id
- emission_comments: scope, category_key, comment_text, is_resolved, parent_comment_id
- submission_comments: submission_id, field_name, comment_text, resolved
- task_assignments: instructions, response, review_feedback
Change log
- data_change_log: changed_at, changed_by_name, change_type, module_type, disclosure_id, record_type, record_id, field_path, field_label, old_value, new_value, change_reason, source_type, batch_id, reporting_period_id
- kpi_change_log: kpi_id, change_type, old_value, new_value, changed_by_name, changed_at
- emissions_audit_trail: emission_record_id, action, old_values, new_values, reason, created_at
- vsme_compliance_logs, see above
Users and roles
- profiles: first_name, last_name, email, job_title
- user_company_memberships: role, is_primary, invited_at, accepted_at
- user_permission_grants: permission, scope_numbers, category_keys, facility_ids
- auditor_assignments: auditor_user_id, expires_at, scope_restrictions
- task_assignments: assigned_to, access_level, module_type, disclosure_id, field_name, status, due_date
- team_invitations: email, invited_as, status, expires_at
Connections, tasks and messages
- accounting_connections, email_connections and integration_credentials: which systems you have connected, their status and last sync. Access tokens are not exported.
- integration_sync_log: when data was fetched and how many records were created or updated
- webhook_subscriptions: event_type, webhook_url, is_active. The secret key is not exported.
- scheduled_tasks: title, task_type, frequency, next_due_date, status
- notifications: title, message, type, created_at, read
- shared_insights: insight_type, insight_data, expires_at. The share links are not exported.
- support_messages, chat_conversations and chat_messages: your messages to our support and our replies
- customer_success_bookings: sessions booked with us
- error_logs: error reports linked to your company, with any description the user wrote
Uploaded files
All files are delivered in their original format, with a list showing which record each file belongs to.
- emission_evidence (evidence for greenhouse gas records): file_name, mime_type, file_size, uploaded_at, emission_record_id
- supplier_documents (files from suppliers)
- invoice_extractions (imported invoices): file_name, mime_type, file_size
- ixbrl_documents (iXBRL reports saved by the service): file_name, reporting_period_start, reporting_period_end
Not included
Under clause 12.2 of the General Licence Terms, the export does not include the service software and calculation models, our library of emission factors and other reference data, aggregated data, or security logs. The factors used in your calculations are included. Login details and access tokens for systems you have connected are not exported, for security reasons. The logs of deleted companies and reports are security logs. Our own administrative records about the customer relationship, such as demo requests, donation records and which features the account has access to, are not Customer Data and are not included either.
4. Standards and specifications
- iXBRL (.xhtml): an XHTML file with embedded XBRL tags (Inline XBRL), encoded in UTF-8.
- XBRL (.xbrl): an XML instance under XBRL 2.1, encoded in UTF-8.
- Taxonomy: the files use the namespace of the EFRAG VSME taxonomy, version 2024-12-17, but do not refer to EFRAG's official entry point for that version (https://xbrl.efrag.org/taxonomy/vsme/2024-12-17/vsme-all.xsd). They therefore cannot be validated against the taxonomy. EFRAG has since published newer versions of the taxonomy. If you need a file in EFRAG's official format, use the EFRAG VSME digital template.
- EFRAG VSME digital template (.xlsx): version 1.1.0. The template's formulas are replaced by their calculated values.
- Excel (.xlsx): Office Open XML, ISO/IEC 29500.
- CSV: UTF-8.
- VS report: comma separator, all values in double quotes, and a first row Field,Value.
- SFDR indicators: semicolon separator, with a byte order mark (BOM) at the start so that Excel reads the characters correctly.
- JSON: RFC 8259, UTF-8. The SFDR file contains metadata, sfdrIndicators (pai, name, value, unit, dataQuality, table), benchmarkCompliance and coverage.
- PDF: for reading.
- Codes in the data: disclosure identifiers B1 to B11 and C1 to C9 under the VS standard, scopes and categories under the GHG Protocol, NACE codes, and waste codes from the European Waste Catalogue (EWC).
- Full export: CSV in UTF-8, one file per table with field names in the first row, or JSON. Feel free to say which format you prefer when you ask for the export.
5. Ask for a full export
Send a written request to support@futurefluent.tech and say which company it concerns. We deliver the export in CSV or JSON. Feel free to say which you prefer.
- We deliver the export free of charge within 15 working days. If you ask for more than two full exports in a calendar year, delivery may take up to 25 working days.
- The export contains all Customer Data in CSV or JSON with a description of the fields, and all files you have uploaded in their original format.
- You can ask for a full export at any time, also in read-only mode.
- We answer reasonable questions about export formats and data structure at no extra cost.
After the agreement ends you have 90 days to collect your data. During that time you have access to the service, can use all export functions and can ask for a full export. It is free of charge. We remind you by e-mail at least 14 days before the period ends. Within 30 days after the period ends we delete your data from the service.
6. Where the data is kept
Future Fluent AB is a Swedish limited company. The agreement with you is governed by Swedish law.
Your data is stored in the service database and file storage in a data centre in Stockholm (AWS region eu-north-1). An encrypted nightly backup of the database is kept at GitHub. The server functions of the service run in the data centre closest to the user, see the table. The data centres are run by subcontractors based outside the EU. The laws of those countries may give authorities there the right to request data from them.
| Service | Provider and domicile | Where data is processed | Basis for transfers of personal data |
|---|---|---|---|
| Database, login and file storage | Supabase Pte. Ltd., Singapore. Hosting by Amazon Web Services, Inc. (USA). Support by Supabase, Inc. (USA). | AWS data centre in eu-north-1 (Stockholm). Storage in the EU. | For access from outside the EU/EEA, for example for support: standard contractual clauses under Decision (EU) 2021/914, module three |
| Server functions (Supabase Edge Functions) | Supabase Pte. Ltd., Singapore, with the same subcontractors as above | The Supabase data centre closest to whoever calls the function. For users in Europe this is normally a data centre in the EU (Frankfurt, Dublin or Paris), in Switzerland (Zurich) or in the UK (London). For users outside Europe it can be, for example, in the USA or Asia. The functions process the data while the call runs. The database and file storage stay in Stockholm. | Within the EU no transfer mechanism is needed. Switzerland and the UK: Commission adequacy decisions. Other countries: standard contractual clauses under Decision (EU) 2021/914, module three |
| Web hosting and content delivery (CDN) for the web application | Netlify, Inc., USA | USA. The web application is delivered through Netlify's global network, and each visitor connects to a nearby server. The service database and file storage are not at Netlify. | EU-US Data Privacy Framework, Decision (EU) 2023/1795. Standard contractual clauses if the framework is declared invalid or Netlify does not renew its certification. |
| E-mail: invitations, reminders, notifications and support cases | Plus Five Five, Inc., which runs Resend, USA | USA. Resend stores account data, e-mail metadata and logs in the USA. | EU-US Data Privacy Framework and standard contractual clauses under Decision (EU) 2021/914 |
| AI-assisted document analysis, for example of invoices (Gemini API) | Google Cloud EMEA Limited, Ireland | Wherever Google or its subcontractors have facilities, including the USA. Uploaded files are deleted after 48 hours. Prompts and responses are kept for 55 days for abuse detection. | EU-US Data Privacy Framework. Standard contractual clauses if that mechanism is not available. |
| E-mail and documents for support, migration and quality review (Google Workspace) | Google Cloud EMEA Limited, Ireland | Wherever Google or its subcontractors have facilities, including the USA | EU-US Data Privacy Framework. Standard contractual clauses if that mechanism is not used. |
| Encrypted nightly backup of the service database (GitHub Actions) | GitHub, Inc., USA | USA and other countries where GitHub's cloud providers have data centres. The backup is encrypted with the age encryption tool before it is stored, and only we hold the key. For the few minutes the job runs, unencrypted data is on the job's temporary server, which is deleted when the job ends. Daily copies are deleted after 8 days and weekly copies after 15 days. Uploaded files are not included in the backup. | EU-US Data Privacy Framework, Decision (EU) 2023/1795. Standard contractual clauses under Decision (EU) 2021/914 if the framework is declared invalid or GitHub does not renew its certification. |
Documents are sent for AI analysis only when a user uses the function, or when you have asked us in writing to use it. You can choose not to use the AI functions.
The transfer mechanisms in the table apply to personal data. For data that is not personal data, the same contracts and the measures in section 7 apply.
For geocoding addresses, climate and elevation data and looking up company and VAT details, the service sends addresses, coordinates and company or VAT numbers to external lookup services: OpenStreetMap Nominatim, Copernicus, Open-Elevation, the EU VAT register VIES and Nordic company registers. This data normally concerns companies and sites, not people, so these services are not sub-processors under the data processing agreement.
7. Measures against unlawful governmental access
This is how we protect non-personal data against access by authorities in countries outside the EU, where that access would conflict with EU law or Swedish law.
Technical measures
- Your data is stored in a database and file storage in Stockholm.
- Stored data is encrypted with AES-256 by the database provider, which manages the keys. Our nightly backups of the database are encrypted with age before they are stored, and only we hold the key. Uploaded files are not included in the backups.
- All communication with the service is encrypted over HTTPS (TLS).
- Access tokens and login details for systems you connect are encrypted in the application with AES-GCM.
- Row level security in the database keeps customers' data apart. A user can only reach data for the companies the user belongs to.
Organisational measures
- Our staff access your data only when needed, for example when you ask for support, during migration or to fix errors.
- Documents are sent to the AI subcontractor only when a user uses the AI function or when you have asked for it in writing.
Contractual measures
- We use your data only to deliver the service, give support, fix errors and handle security incidents, and where law or a decision by an authority requires it. In addition, we may produce anonymised, aggregated statistics from data that is not personal data, under clause 7.4 of the General Licence Terms. You can say no to this. We do not sell your data.
- If we must disclose data under law or a decision by an authority, we will tell you first where possible.
- Employees, consultants and subcontractors who see your data must be bound by the same confidentiality as we are.
- Subcontractors that process personal data are bound by written agreements with the same data protection obligations as ours.
- We notify you at least 30 days before we engage a new sub-processor that will process personal data on your behalf. You can object and, as a last resort, terminate the agreement.
What the law says
Article 32 of the Data Act applies to us. A decision by a court or authority outside the EU to hand over non-personal data may only be recognised if it is based on an international agreement, such as a mutual legal assistance treaty. Under Article 32(5) we must inform you before we comply with such a request. The exception is a request for law enforcement purposes, for as long as needed to keep that activity effective. If there is no such agreement, the authority may only receive the data if the conditions in Article 32(3) are met, including that the decision is reasoned and proportionate and that an objection can be reviewed by a court in that country. We then provide the minimum amount of data permitted (Article 32(4)).
8. Contact
Future Fluent AB, reg. no. 559203-6759
Questions about export, formats and data structure: support@futurefluent.tech
Questions about data protection: morten@futurefluent.tech
Last updated 2026-09-26