Data Processing Agreement

Last updated: August 2026 · Version 1.0

In plain English

When you put your own customers' details into ForgeDash — their name, phone number, vehicle, what you did on the job — those people are your customers, not ours. Under UK data protection law that makes you the controller and us the processor, and the law requires a written contract between us setting out what we may and may not do with that data. This is that contract. It applies automatically when you open a ForgeDash account — there is nothing to sign and nothing to request.

1. Scope and Incorporation

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms & Conditions between ForgeDash Ltd (Company Number 17032281, registered in England and Wales) and the person or business that opens a ForgeDash account ("you", the "Customer").

It applies whenever ForgeDash processes Customer Personal Data on your behalf in the course of providing the ForgeDash platform (the "Services"). In line with Article 28(9) UK GDPR, this DPA is concluded in electronic form: your acceptance of the Terms & Conditions on creating an account constitutes acceptance of this DPA. No separate signature is required. If your organisation requires a countersigned copy, contact [email protected].

Where this DPA conflicts with the Terms & Conditions on the subject of processing personal data, this DPA prevails.

2. Definitions

  • Data Protection Law — the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, each as amended.
  • Customer Personal Data — personal data that you or your team enter into, or generate within, ForgeDash about people other than yourself: principally your own customers and your staff. It does not include your own account and billing data, for which ForgeDash is the controller.
  • Controller, Processor, Data Subject, Processing and Personal Data Breach have the meanings given in the UK GDPR.
  • Sub-processor — any third party engaged by ForgeDash to process Customer Personal Data on our behalf.

3. Roles of the Parties

You are the Controller of Customer Personal Data. You decide what to record about your customers, why, and for how long. You are responsible for having a lawful basis for that processing, for giving your customers the privacy information Articles 13 and 14 require, and for the accuracy of what you enter.

ForgeDash is the Processor of Customer Personal Data. We process it only to run the Services for you, on your instructions, and never for our own purposes.

ForgeDash is a separate Controller of your own account data — your name, email, subscription and billing records, and how you use the platform. That processing is governed by our Privacy Policy, not by this DPA.

Note that where you take a card payment from your customer through Stripe Connect, Stripe acts as an independent controller of that payment data under its own terms. ForgeDash never receives or stores full card details.

4. Processing Instructions

ForgeDash will process Customer Personal Data only on your documented instructions, including on international transfers, unless required to do otherwise by law — in which case we will tell you before processing, unless the law prohibits us from doing so.

Your instructions are: this DPA, the Terms & Conditions, and the actions you take through the ForgeDash interface and APIs. Annex 1 sets out the subject-matter, duration, nature and purpose of the processing, and the categories of data and data subjects.

We will tell you if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to carry out an instruction that would.

We do not sell Customer Personal Data, and we do not use it to train machine-learning models. Receipt images sent to our OCR sub-processor are submitted through an API tier that is contractually excluded from model training.

Special category data. ForgeDash is not designed to hold data revealing health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation, or data relating to criminal convictions. You must not enter such data — including into free-text fields such as job notes or customer notes. If you do so, you do it on your own assessment of lawfulness and without our agreement to process it.

5. Confidentiality of Personnel

ForgeDash ensures that every person authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality — contractual or statutory — that survives the end of their engagement, and that access is granted strictly on a need-to-know basis under our Access Control Policy.

Access to production data is limited, logged, and used only to investigate a fault or to respond to a support request you raise.

6. Security of Processing

ForgeDash implements and maintains appropriate technical and organisational measures under Article 32 UK GDPR, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals. Those measures are set out in Annex 2 and summarised on our Security Overview.

We may update the measures in Annex 2 from time to time, provided the overall level of security is not reduced.

You are responsible for the security measures within your own control: keeping your credentials secret, enabling the authentication options we make available, and removing team members from your organisation when they leave.

7. Sub-processors

You give ForgeDash general written authorisation to engage sub-processors for the purposes described in Annex 3.

Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA. ForgeDash remains fully liable to you for the acts and omissions of its sub-processors.

The current list is in Annex 3. We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your account address and by updating this page. If you reasonably object on data protection grounds within that period, tell us at [email protected] and we will work in good faith to offer an alternative. If we cannot, you may terminate the affected part of the Services without penalty and receive a pro-rata refund of any prepaid fees.

8. International Transfers

Customer Personal Data is stored at rest in the United Kingdom and the European Economic Area — the primary database is hosted in Ireland and our application servers are in Germany.

Certain sub-processors identified in Annex 3 may process data outside the UK. Where they do, ForgeDash relies on one or more of the following: a UK adequacy decision; the ICO's International Data Transfer Agreement (IDTA); or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum, together with any supplementary measures a transfer risk assessment identifies as necessary.

9. Assistance with Data Subject Rights

Taking into account the nature of the processing, ForgeDash assists you by appropriate technical and organisational measures — insofar as this is possible — to respond to requests from data subjects exercising their rights under Chapter III UK GDPR.

In practice, most requests you receive can be answered without our involvement: you can view, correct and delete customer records directly in ForgeDash, and export your organisation's data as a structured JSON file at any time from Profile → Data Export. That export satisfies access and portability requests.

If a data subject contacts ForgeDash directly about data we hold on your behalf, we will not respond substantively. We will tell them to contact you, and notify you without undue delay — except where we are prohibited from doing so by law.

Where a request cannot be satisfied through the interface, we will provide reasonable assistance at no charge, unless the volume of requests is manifestly excessive, in which case we may charge a reasonable fee agreed with you in advance.

10. Assistance with Your Wider Obligations

ForgeDash assists you, taking into account the nature of processing and the information available to us, in complying with your obligations under Articles 32 to 36 UK GDPR — security of processing, breach notification to the ICO and to individuals, data protection impact assessments, and prior consultation with the ICO.

11. Personal Data Breach Notification

ForgeDash will notify you without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data. This is deliberately shorter than the 72 hours you have to notify the ICO, so that you have time to act.

Our notification will describe, to the extent known at the time:

  • the nature of the breach, including the categories and approximate number of data subjects and records affected
  • the likely consequences of the breach
  • the measures taken or proposed to address it and to mitigate its effects
  • a named contact point for further information

Where the full picture is not available at once, we will provide information in phases without further undue delay rather than wait. We will not make any public statement identifying you as affected without your prior written consent, unless legally required.

The decision whether to notify the ICO or affected individuals is yours as controller.

12. Return and Deletion on Termination

On termination of the Services, and at your choice, ForgeDash will delete or return all Customer Personal Data:

  • Return — you may export your full dataset as JSON from the dashboard at any time before your account closes. We recommend doing so before you cancel. If you have already lost access, ask us within 30 days and we will produce the export for you.
  • Deletion — we delete Customer Personal Data from live systems within 30 days of account closure, and from encrypted backups within a further 90 days as those backups age out on their normal rotation.

One exception, and it is a legal one: where UK law requires ForgeDash to retain records — principally financial and transaction records subject to HMRC retention periods — we retain only what the law requires, for no longer than it requires, and continue to protect it under this DPA. We will tell you what has been retained and why.

Deleting a customer record inside ForgeDash while your account remains open is your own controller decision and takes effect immediately in live systems, subject to the same backup rotation.

13. Audits and Information Rights

ForgeDash makes available to you all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate.

In the first instance, we will satisfy an audit request by providing:

  • this DPA, our Information Security Policy and Access Control Policy
  • our Incident Response Plan and Data Classification & Retention Policy
  • the current sub-processor register, with residency and certification detail
  • the third-party certifications and audit reports of our infrastructure sub-processors (for example SOC 2 Type II reports), where their terms allow us to share them
  • written responses to a reasonable security questionnaire

Where that is genuinely insufficient to demonstrate compliance, you may request an on-site or remote audit, on at least 30 days' written notice, no more than once in any 12-month period (unless required by a supervisory authority or following a Personal Data Breach), during normal business hours, subject to confidentiality undertakings, and conducted so as not to disrupt the Services or the confidentiality of other customers' data. Each party bears its own costs.

ForgeDash is a small business and does not currently hold ISO 27001 or SOC 2 certification of its own. We state that plainly rather than imply otherwise; our infrastructure sub-processors are certified, and our own controls are documented in the policies listed above.

14. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms & Conditions.

Nothing in this DPA limits either party's liability to a data subject, or excludes any liability that cannot lawfully be excluded — including under Article 82 UK GDPR or for death or personal injury caused by negligence, or for fraud.

15. Duration, Changes and Governing Law

This DPA takes effect when you accept the Terms & Conditions and continues for as long as ForgeDash processes Customer Personal Data on your behalf. Clauses that by their nature should survive termination — confidentiality, deletion, liability — do so.

We may update this DPA to reflect changes in law, in our sub-processors, or in the Services. Where a change materially reduces your rights or our obligations, we will give you at least 30 days' notice by email before it takes effect. The version number and date at the top of this page identify the current version.

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex 1 — Details of Processing

Required by Article 28(3) UK GDPR.

Subject matter and duration

Provision of the ForgeDash business operating system — job management, invoicing, quoting, customer records, expense capture and financial reporting — to UK self-employed tradespeople, currently automotive mechanics. Processing continues for the duration of your subscription and the deletion periods in clause 12.

Nature and purpose of processing

Collection, recording, organisation, structuring, storage, retrieval, encryption, consultation, use, transmission by email, and erasure — solely to operate the Services on your instructions. This includes generating invoices, quotes and job records; sending those documents and reminders to your customers by email; hosting a token-gated portal where your customer can view and pay an invoice; extracting expense data from receipt images you upload; and looking up vehicle details from a registration mark you enter.

Categories of data subject

  • Your customers — the individuals and businesses you invoice and do work for
  • Your team members — anyone you invite into your ForgeDash organisation
  • Individuals named incidentally in documents you upload, such as a supplier contact on a receipt

Categories of personal data

CategoryExamples
Contact detailsName, email address, phone number, postal address
Vehicle dataRegistration mark, make, model, MOT and tax status, mileage, damage notes and walkaround photographs
Commercial recordsJobs, quotes, invoices, line items, payment status, appointment history
Free-text notesCustomer notes and job notes you write
Uploaded documentsReceipt and supplier invoice images, and the data extracted from them
Payment referencesStripe identifiers, amounts and status. Never full card numbers — these never reach ForgeDash systems
Team account dataTeam member name, email, role and access history

No special category data under Article 9, and no criminal offence data under Article 10, is intended or instructed — see clause 4.

Frequency of transfer

Continuous, for the duration of the Services.

Annex 2 — Technical and Organisational Measures

Required by Articles 28(3)(c) and 32 UK GDPR.

Encryption

  • TLS 1.2 or higher for all data in transit, with HSTS enforced
  • Encryption at rest for the database, object storage and backups
  • Additional application-layer encryption for the most sensitive fields. Customer email addresses and phone numbers are encrypted into separate ciphertext columns by a database trigger on write, so no code path can store them in plaintext. Reads go through a controlled view or function. A one-way blind index permits exact-match lookup without exposing the value

Access control and tenant isolation

  • PostgreSQL Row Level Security on every tenant table — the isolation boundary is enforced by the database itself, not by application code
  • Role-based access control within each organisation (owner, admin, mechanic, member)
  • Least-privilege administrative access, reviewed periodically; privileged service credentials are never exposed to the browser
  • Password hashing and managed session handling via our authentication provider
  • Customer-facing invoice portal links are gated by encrypted, expiring tokens

Network and application security

  • Cloudflare DDoS protection and Web Application Firewall in front of all public endpoints
  • Content Security Policy and hardened security response headers, verified by automated tests on every deployment
  • Strict origin allow-listing on server-side functions
  • Secrets held in the server-side runtime environment and never shipped to the browser

Resilience, backup and recovery

  • Automated encrypted database backups with point-in-time recovery
  • Backups retained independently of the primary application stack
  • Documented business continuity and disaster recovery arrangements

Monitoring and assurance

  • Immutable, append-only audit logging of security-relevant events
  • Application error monitoring with personal data scrubbing
  • Automated dependency and secret scanning on the source repository
  • Periodic security review and vulnerability assessment

Organisational measures

  • Written Information Security, Access Control, Change Management, and Data Classification & Retention policies
  • A documented Incident Response Plan with defined roles and notification timelines
  • Confidentiality obligations binding on all personnel with data access
  • Vendor risk assessment before engaging any sub-processor that touches personal data
  • Data minimisation and retention limits applied per data class

Annex 3 — Authorised Sub-processors

Current as at the date at the top of this page. Changes are notified under clause 7.

Sub-processorPurposeData processedLocation
SupabaseDatabase, authentication, file storage, server-side functionsAll Customer Personal DataIreland (EU)
netcup GmbHApplication and workflow server hostingData in transit through the application, and uploaded receipt images during processingGermany (EU)
StripeSubscription billing and, where you enable it, customer invoice payments via Stripe ConnectPayment metadata and customer references. No full card data reaches ForgeDashEU / USA
ResendTransactional email — invoices, quotes, remindersRecipient name and email address, document contentsEU / USA
Google (Gemini API)Optical character recognition on receipts and supplier invoices you uploadThe image content of documents you upload. Excluded from model trainingEU / USA
CloudflareDNS, CDN, DDoS protection, web application firewallNetwork traffic metadata, IP addresses. Data in transit only — no storage of record contentGlobal edge network
SentryApplication error monitoringDiagnostic data and request context, with personal data scrubbing appliedEU / USA
DVLAVehicle enquiry lookup from a registration mark you enterVehicle registration mark. No personal details of the keeper are requested or returnedUnited Kingdom

Not a sub-processor: our receipt-processing workflow engine (Windmill) is self-hosted on our own netcup server. It is our own infrastructure, not a third-party service, and adds no additional sub-processor.

Contact

For any question about this DPA, a data subject request, a security concern, or an audit request:

ForgeDash Ltd

Kaspars Rancans, Director — responsible for data protection

14 Willow Way, Wisbech, UK

Email: [email protected]

Company Number: 17032281 · ICO Registration No: ZC095670 · Registered in England and Wales

See also our Privacy Policy, Terms & Conditions and Security Overview.