Last updated: August 2026 · Version 1.0
In plain English
When you put your own customers' details into ForgeDash — their name, phone number, vehicle, what you did on the job — those people are your customers, not ours. Under UK data protection law that makes you the controller and us the processor, and the law requires a written contract between us setting out what we may and may not do with that data. This is that contract. It applies automatically when you open a ForgeDash account — there is nothing to sign and nothing to request.
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms & Conditions between ForgeDash Ltd (Company Number 17032281, registered in England and Wales) and the person or business that opens a ForgeDash account ("you", the "Customer").
It applies whenever ForgeDash processes Customer Personal Data on your behalf in the course of providing the ForgeDash platform (the "Services"). In line with Article 28(9) UK GDPR, this DPA is concluded in electronic form: your acceptance of the Terms & Conditions on creating an account constitutes acceptance of this DPA. No separate signature is required. If your organisation requires a countersigned copy, contact [email protected].
Where this DPA conflicts with the Terms & Conditions on the subject of processing personal data, this DPA prevails.
You are the Controller of Customer Personal Data. You decide what to record about your customers, why, and for how long. You are responsible for having a lawful basis for that processing, for giving your customers the privacy information Articles 13 and 14 require, and for the accuracy of what you enter.
ForgeDash is the Processor of Customer Personal Data. We process it only to run the Services for you, on your instructions, and never for our own purposes.
ForgeDash is a separate Controller of your own account data — your name, email, subscription and billing records, and how you use the platform. That processing is governed by our Privacy Policy, not by this DPA.
Note that where you take a card payment from your customer through Stripe Connect, Stripe acts as an independent controller of that payment data under its own terms. ForgeDash never receives or stores full card details.
ForgeDash will process Customer Personal Data only on your documented instructions, including on international transfers, unless required to do otherwise by law — in which case we will tell you before processing, unless the law prohibits us from doing so.
Your instructions are: this DPA, the Terms & Conditions, and the actions you take through the ForgeDash interface and APIs. Annex 1 sets out the subject-matter, duration, nature and purpose of the processing, and the categories of data and data subjects.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to carry out an instruction that would.
We do not sell Customer Personal Data, and we do not use it to train machine-learning models. Receipt images sent to our OCR sub-processor are submitted through an API tier that is contractually excluded from model training.
Special category data. ForgeDash is not designed to hold data revealing health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation, or data relating to criminal convictions. You must not enter such data — including into free-text fields such as job notes or customer notes. If you do so, you do it on your own assessment of lawfulness and without our agreement to process it.
ForgeDash ensures that every person authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality — contractual or statutory — that survives the end of their engagement, and that access is granted strictly on a need-to-know basis under our Access Control Policy.
Access to production data is limited, logged, and used only to investigate a fault or to respond to a support request you raise.
ForgeDash implements and maintains appropriate technical and organisational measures under Article 32 UK GDPR, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals. Those measures are set out in Annex 2 and summarised on our Security Overview.
We may update the measures in Annex 2 from time to time, provided the overall level of security is not reduced.
You are responsible for the security measures within your own control: keeping your credentials secret, enabling the authentication options we make available, and removing team members from your organisation when they leave.
You give ForgeDash general written authorisation to engage sub-processors for the purposes described in Annex 3.
Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA. ForgeDash remains fully liable to you for the acts and omissions of its sub-processors.
The current list is in Annex 3. We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your account address and by updating this page. If you reasonably object on data protection grounds within that period, tell us at [email protected] and we will work in good faith to offer an alternative. If we cannot, you may terminate the affected part of the Services without penalty and receive a pro-rata refund of any prepaid fees.
Customer Personal Data is stored at rest in the United Kingdom and the European Economic Area — the primary database is hosted in Ireland and our application servers are in Germany.
Certain sub-processors identified in Annex 3 may process data outside the UK. Where they do, ForgeDash relies on one or more of the following: a UK adequacy decision; the ICO's International Data Transfer Agreement (IDTA); or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum, together with any supplementary measures a transfer risk assessment identifies as necessary.
Taking into account the nature of the processing, ForgeDash assists you by appropriate technical and organisational measures — insofar as this is possible — to respond to requests from data subjects exercising their rights under Chapter III UK GDPR.
In practice, most requests you receive can be answered without our involvement: you can view, correct and delete customer records directly in ForgeDash, and export your organisation's data as a structured JSON file at any time from Profile → Data Export. That export satisfies access and portability requests.
If a data subject contacts ForgeDash directly about data we hold on your behalf, we will not respond substantively. We will tell them to contact you, and notify you without undue delay — except where we are prohibited from doing so by law.
Where a request cannot be satisfied through the interface, we will provide reasonable assistance at no charge, unless the volume of requests is manifestly excessive, in which case we may charge a reasonable fee agreed with you in advance.
ForgeDash assists you, taking into account the nature of processing and the information available to us, in complying with your obligations under Articles 32 to 36 UK GDPR — security of processing, breach notification to the ICO and to individuals, data protection impact assessments, and prior consultation with the ICO.
ForgeDash will notify you without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data. This is deliberately shorter than the 72 hours you have to notify the ICO, so that you have time to act.
Our notification will describe, to the extent known at the time:
Where the full picture is not available at once, we will provide information in phases without further undue delay rather than wait. We will not make any public statement identifying you as affected without your prior written consent, unless legally required.
The decision whether to notify the ICO or affected individuals is yours as controller.
On termination of the Services, and at your choice, ForgeDash will delete or return all Customer Personal Data:
One exception, and it is a legal one: where UK law requires ForgeDash to retain records — principally financial and transaction records subject to HMRC retention periods — we retain only what the law requires, for no longer than it requires, and continue to protect it under this DPA. We will tell you what has been retained and why.
Deleting a customer record inside ForgeDash while your account remains open is your own controller decision and takes effect immediately in live systems, subject to the same backup rotation.
ForgeDash makes available to you all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance, we will satisfy an audit request by providing:
Where that is genuinely insufficient to demonstrate compliance, you may request an on-site or remote audit, on at least 30 days' written notice, no more than once in any 12-month period (unless required by a supervisory authority or following a Personal Data Breach), during normal business hours, subject to confidentiality undertakings, and conducted so as not to disrupt the Services or the confidentiality of other customers' data. Each party bears its own costs.
ForgeDash is a small business and does not currently hold ISO 27001 or SOC 2 certification of its own. We state that plainly rather than imply otherwise; our infrastructure sub-processors are certified, and our own controls are documented in the policies listed above.
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms & Conditions.
Nothing in this DPA limits either party's liability to a data subject, or excludes any liability that cannot lawfully be excluded — including under Article 82 UK GDPR or for death or personal injury caused by negligence, or for fraud.
This DPA takes effect when you accept the Terms & Conditions and continues for as long as ForgeDash processes Customer Personal Data on your behalf. Clauses that by their nature should survive termination — confidentiality, deletion, liability — do so.
We may update this DPA to reflect changes in law, in our sub-processors, or in the Services. Where a change materially reduces your rights or our obligations, we will give you at least 30 days' notice by email before it takes effect. The version number and date at the top of this page identify the current version.
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Required by Article 28(3) UK GDPR.
Provision of the ForgeDash business operating system — job management, invoicing, quoting, customer records, expense capture and financial reporting — to UK self-employed tradespeople, currently automotive mechanics. Processing continues for the duration of your subscription and the deletion periods in clause 12.
Collection, recording, organisation, structuring, storage, retrieval, encryption, consultation, use, transmission by email, and erasure — solely to operate the Services on your instructions. This includes generating invoices, quotes and job records; sending those documents and reminders to your customers by email; hosting a token-gated portal where your customer can view and pay an invoice; extracting expense data from receipt images you upload; and looking up vehicle details from a registration mark you enter.
| Category | Examples |
|---|---|
| Contact details | Name, email address, phone number, postal address |
| Vehicle data | Registration mark, make, model, MOT and tax status, mileage, damage notes and walkaround photographs |
| Commercial records | Jobs, quotes, invoices, line items, payment status, appointment history |
| Free-text notes | Customer notes and job notes you write |
| Uploaded documents | Receipt and supplier invoice images, and the data extracted from them |
| Payment references | Stripe identifiers, amounts and status. Never full card numbers — these never reach ForgeDash systems |
| Team account data | Team member name, email, role and access history |
No special category data under Article 9, and no criminal offence data under Article 10, is intended or instructed — see clause 4.
Continuous, for the duration of the Services.
Required by Articles 28(3)(c) and 32 UK GDPR.
Current as at the date at the top of this page. Changes are notified under clause 7.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage, server-side functions | All Customer Personal Data | Ireland (EU) |
| netcup GmbH | Application and workflow server hosting | Data in transit through the application, and uploaded receipt images during processing | Germany (EU) |
| Stripe | Subscription billing and, where you enable it, customer invoice payments via Stripe Connect | Payment metadata and customer references. No full card data reaches ForgeDash | EU / USA |
| Resend | Transactional email — invoices, quotes, reminders | Recipient name and email address, document contents | EU / USA |
| Google (Gemini API) | Optical character recognition on receipts and supplier invoices you upload | The image content of documents you upload. Excluded from model training | EU / USA |
| Cloudflare | DNS, CDN, DDoS protection, web application firewall | Network traffic metadata, IP addresses. Data in transit only — no storage of record content | Global edge network |
| Sentry | Application error monitoring | Diagnostic data and request context, with personal data scrubbing applied | EU / USA |
| DVLA | Vehicle enquiry lookup from a registration mark you enter | Vehicle registration mark. No personal details of the keeper are requested or returned | United Kingdom |
Not a sub-processor: our receipt-processing workflow engine (Windmill) is self-hosted on our own netcup server. It is our own infrastructure, not a third-party service, and adds no additional sub-processor.
For any question about this DPA, a data subject request, a security concern, or an audit request:
ForgeDash Ltd
Kaspars Rancans, Director — responsible for data protection
14 Willow Way, Wisbech, UK
Email: [email protected]
Company Number: 17032281 · ICO Registration No: ZC095670 · Registered in England and Wales
See also our Privacy Policy, Terms & Conditions and Security Overview.