Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Forja ("Processor") and the customer who runs one or more projects on Forja ("Controller"). It applies whenever a project processes personal data of the Controller's own customers, visitors or users.
1. Roles
The Controller decides why and how personal data is processed inside its projects (visitors, sign-ups, bookings, purchases, messages). Forja processes that data only to provide the service and only on the Controller's documented instructions, which are the Terms, this DPA and the settings the Controller chooses in the admin.
2. Nature and purpose of processing
Hosting, storage, backup, display and transmission of the Controller's project data; sending e-mail on the Controller's behalf; processing payments through the Controller's Stripe account; generating content with AI when the Controller asks for it; producing statistics without cookies.
3. Categories of data and data subjects
Visitors (page views without identifiers), users of the project (name, e-mail, password hash, sign-in provider), customers (bookings, purchases, invoices, messages), and any data the Controller places in content or forms. Special categories of data must not be collected unless the Controller has a lawful basis and tells us.
4. Sub-processors
Forja uses the following sub-processors, each under a written agreement with equivalent obligations: Hetzner Online GmbH (servers and backups, Finland, EU); Stripe Payments Europe Ltd (payments); Resend, Inc. (e-mail); Google Ireland Ltd (optional sign-in); Anthropic PBC and OpenAI OpCo LLC (AI generation, only for content submitted to those features); Namecheap, Inc. (domain registration on request). We will announce new sub-processors by e-mail at least 15 days in advance; the Controller may object on reasonable grounds.
5. Location and transfers
Project data is stored and processed in the European Union. Where a sub-processor processes data outside the EU, the transfer is covered by the European Commission's standard contractual clauses or an adequacy decision.
6. Security
Encryption in transit (TLS), encrypted secrets at rest, one isolated database per project, two-factor authentication for administrators, daily backups kept for 30 days, audit log of administrative actions, least-privilege access by Forja staff limited to operating the service.
7. Assistance and rights of data subjects
The Controller can export, correct and delete personal data from the project's admin. Forja assists with requests it receives directly by forwarding them to the Controller within 5 working days and, where the Controller cannot act alone, by performing the operation on its instruction.
8. Personal data breaches
Forja notifies the Controller without undue delay, and at the latest within 48 hours of becoming aware, of a breach affecting the Controller's project data, with the information needed to meet the Controller's own notification duties.
9. Deletion and return
On termination, or on the Controller's request, Forja returns the project data in a common format (the Export function) and deletes it from live systems immediately and from backups within 30 days, unless retention is required by law.
10. Audits
On written request, no more than once a year, Forja provides the information reasonably needed to demonstrate compliance with this DPA, including a description of technical and organisational measures and a list of sub-processors.
11. Confidentiality and staff
Persons authorised to process personal data are bound by confidentiality and receive appropriate instructions.
12. Duration and law
This DPA lasts as long as Forja processes personal data for the Controller and is governed by the laws of Ireland. In case of conflict with the Terms, this DPA prevails on matters of data protection.
Contact for data protection matters: hello@forja.build. Last updated: 6 September 2026.