Last updated 29 August 2026 · Version 0.3.1 (interim)

Privacy Notice

Privacy Notice

Privacy Notice

1. Who we are

1. Who we are

1. Who we are

FORGE Logic is operated by Markus Sullivan, trading as FORGE Logic (“FORGE Logic”, “we”, “us”), established in Greece.

FORGE Logic™ is operated by Markus Sullivan, trading as FORGE Logic (“FORGE Logic”, “we”, “us”), established in Greece.

Postal address: 189 The Pavilion, St Stephens Road, Norwich, NR1 3SJ, United Kingdom. Privacy contact: privacy@forgelogic.app

Postal address: 189 The Pavilion, St Stephens Road, Norwich, NR1 3SJ, United Kingdom. Privacy contact: privacy@forgelogic.app

FORGE Logic intends to incorporate as FORGE Logic OÜ (Estonia). On incorporation, controller responsibilities will transfer to that entity and this Notice will be re-issued. Existing rights and commitments will not be reduced by that transfer.

FORGE Logic intends to incorporate as FORGE Logic OÜ (Estonia). On incorporation, controller responsibilities will transfer to that entity and this Notice will be re-issued. Existing rights and commitments will not be reduced by that transfer.

2. When this notice applies

2. When this notice applies

2. When this notice applies

This Notice applies where FORGE Logic acts as Controller: account administration, website enquiries, beta and design-partner engagement, business contacts, service security, supplier management and communications.

This Notice applies where FORGE Logic acts as Controller: account administration, website enquiries, beta and design-partner engagement, business contacts, service security, supplier management and communications.

Where your organisation uses FORGE Logic and places project, programme, governance or other business information into its FORGE Logic workspace, your organisation normally determines why that information is processed and FORGE Logic acts as Processor for that Customer Data. Requests about that content should be directed to your organisation. FORGE Logic handles it under the Customer’s instructions and the applicable Data Processing Agreement.

Where your organisation uses FORGE Logic and places project, programme, governance or other business information into its FORGE Logic workspace, your organisation normally determines why that information is processed and FORGE Logic acts as Processor for that Customer Data. Requests about that content should be directed to your organisation. FORGE Logic handles it under the Customer’s instructions and the applicable Data Processing Agreement.

3. Personal data we process as controller

3. Personal data we process as controller

3. Personal data we process as controller

Depending on how you interact with FORGE Logic, we may process:

Depending on how you interact with FORGE Logic, we may process:

  • identity and professional details: name, role, employer/organisation, business contact details;

  • account information, user identifiers, organisation membership and permissions;

  • authentication, session and security information;

  • contract, beta or design-partner acceptance and version evidence;

  • communications, support requests and website enquiries (including enquiry type, organisation size and governance-challenge selections from the contact form);

  • administrative and security audit records;

  • email delivery events for service messages we send you;

  • website technical information (IP address, browser, pages viewed) and, only with your consent, advertising measurement identifiers as described in the Cookie Notice;

  • supplier and procurement contact information.

  • identity and professional details: name, role, employer/organisation, business contact details;

  • account information, user identifiers, organisation membership and permissions;

  • authentication, session and security information;

  • contract, beta or design-partner acceptance and version evidence;

  • communications, support requests and website enquiries (including enquiry type, organisation size and governance-challenge selections from the contact form);

  • administrative and security audit records;

  • email delivery events for service messages we send you;

  • website technical information (IP address, browser, pages viewed) and, only with your consent, advertising measurement identifiers as described in the Cookie Notice;

  • supplier and procurement contact information.

Contact-form submissions are handled by our website provider (Framer) and delivered to us by email. The contact form is protected by Cloudflare Turnstile, which checks that the submission is not automated.

Contact-form submissions are handled by our website provider (Framer) and delivered to us by email. The contact form is protected by Cloudflare Turnstile, which checks that the submission is not automated.

Public readiness checks on the website run in your browser. We do not store your answers or results.

Public readiness checks on the website run in your browser. We do not store your answers or results.

We do not currently take payments. If that changes, this Notice will be updated before billing data is collected.

We do not currently take payments. If that changes, this Notice will be updated before billing data is collected.

4. How we obtain personal data

4. How we obtain personal data

4. How we obtain personal data

Directly from you; from your organisation when it creates or administers your access; through your use of the service; from authentication, hosting, email and security providers; from business correspondence; and from publicly available professional sources where appropriate for normal B2B contact activity.

Directly from you; from your organisation when it creates or administers your access; through your use of the service; from authentication, hosting, email and security providers; from business correspondence; and from publicly available professional sources where appropriate for normal B2B contact activity.

5. Purposes and legal bases

5. Purposes and legal bases

5. Purposes and legal bases

Service/account delivery — create accounts, authenticate users, administer organisation access, communicate service information. Legal basis: contract where you are the contracting professional; otherwise legitimate interests in performing our agreement with your organisation and providing the service securely.

Service/account delivery — create accounts, authenticate users, administer organisation access, communicate service information. Legal basis: contract where you are the contracting professional; otherwise legitimate interests in performing our agreement with your organisation and providing the service securely.

Security and integrity — prevent unauthorised access, investigate misuse, maintain audit evidence, respond to incidents, protect the website from automated abuse. Legal basis: legitimate interests; legal obligation where applicable.

Security and integrity — prevent unauthorised access, investigate misuse, maintain audit evidence, respond to incidents, protect the website from automated abuse. Legal basis: legitimate interests; legal obligation where applicable.

Enquiries and pre-contract communication — respond to contact-form enquiries, beta access requests, design-partner and commercial discussions. Legal basis: steps requested before entering a contract; legitimate interests in B2B communications.

Enquiries and pre-contract communication — respond to contact-form enquiries, beta access requests, design-partner and commercial discussions. Legal basis: steps requested before entering a contract; legitimate interests in B2B communications.

Business relationship — manage customer and supplier contacts, service notices, professional correspondence. Legal basis: legitimate interests.

Business relationship — manage customer and supplier contacts, service notices, professional correspondence. Legal basis: legitimate interests.

Website measurement — our website provider (Framer) provides aggregated, cookieless site measurement. Legal basis: legitimate interests in understanding site use.

Website measurement — our website provider (Framer) provides aggregated, cookieless site measurement. Legal basis: legitimate interests in understanding site use.

Advertising measurement — where you accept marketing cookies, Google Ads and LinkedIn measure whether a visit or contact-form enquiry followed an advertisement. Legal basis: consent (cookie banner). Nothing is loaded before consent, and you can withdraw consent at any time via Cookie Settings in the website footer.

Advertising measurement — where you accept marketing cookies, Google Ads and LinkedIn measure whether a visit or contact-form enquiry followed an advertisement. Legal basis: consent (cookie banner). Nothing is loaded before consent, and you can withdraw consent at any time via Cookie Settings in the website footer.

Direct marketing email — not currently undertaken. Any future promotional email will rely on consent or lawful B2B legitimate interests with easy opt-out.

Direct marketing email — not currently undertaken. Any future promotional email will rely on consent or lawful B2B legitimate interests with easy opt-out.

Legal claims and compliance — Legal basis: legal obligation; legitimate interests.

Legal claims and compliance — Legal basis: legal obligation; legitimate interests.

6. Customer workspace content

6. Customer workspace content

6. Customer workspace content

FORGE Logic does not acquire ownership of Customer Data by processing it. Customer Data, customer-specific organisational knowledge and outputs generated from Customer Data remain the Customer’s property, subject to third-party rights and the Customer Agreement.

FORGE Logic does not acquire ownership of Customer Data by processing it. Customer Data, customer-specific organisational knowledge and outputs generated from Customer Data remain the Customer’s property, subject to third-party rights and the Customer Agreement.

Customer Data is not used to train FORGE Logic or third-party general AI models.

Customer Data is not used to train FORGE Logic or third-party general AI models.

7. AI-assisted processing

7. AI-assisted processing

7. AI-assisted processing

FORGE Logic uses AI-assisted functionality to generate governance outputs. Where Customer Personal Data is sent to an AI provider to deliver a requested service, FORGE Logic acts under the Customer’s instructions and the provider is a Subprocessor.

FORGE Logic uses AI-assisted functionality to generate governance outputs. Where Customer Personal Data is sent to an AI provider to deliver a requested service, FORGE Logic acts under the Customer’s instructions and the provider is a Subprocessor.

AI output is decision support, not an autonomous decision. Material outputs require human review.

AI output is decision support, not an autonomous decision. Material outputs require human review.

8. Who we share personal data with

8. Who we share personal data with

8. Who we share personal data with

We share Personal Data only with providers necessary to operate the service, and only to the extent needed for their role.

We share Personal Data only with providers necessary to operate the service, and only to the extent needed for their role.

  • Supabase — database and authentication for the FORGE Logic application — EU (AWS eu-west-1, Ireland)

  • Vercel — application hosting and delivery — EU

  • Resend — transactional service email — EU

  • OpenAI — AI generation (API; no training on our data) — United States, Standard Contractual Clauses

  • Framer B.V. (Netherlands) — website hosting, contact-form handling, aggregated site measurement — EU, with sub-hosting that may involve US transfer under EU–US Data Privacy Framework / SCCs

  • Cloudflare — contact-form abuse protection (Turnstile) and DNS — global; EU/US, Standard Contractual Clauses

  • Google Ireland Limited — Google Tag Manager and Google Ads advertising measurement (consent only) — EU/US, Standard Contractual Clauses

  • LinkedIn Ireland Unlimited Company — LinkedIn Insight Tag advertising measurement (consent only) — EU/US, Standard Contractual Clauses

  • Google Workspace — business email and documents — EU/US, Standard Contractual Clauses

  • Apple (TestFlight/App Store) — SCRIBE iOS beta distribution — United States

  • Supabase — database and authentication for the FORGE Logic application — EU (AWS eu-west-1, Ireland)

  • Vercel — application hosting and delivery — EU

  • Resend — transactional service email — EU

  • OpenAI — AI generation (API; no training on our data) — United States, Standard Contractual Clauses

  • Framer B.V. (Netherlands) — website hosting, contact-form handling, aggregated site measurement — EU, with sub-hosting that may involve US transfer under EU–US Data Privacy Framework / SCCs

  • Cloudflare — contact-form abuse protection (Turnstile) and DNS — global; EU/US, Standard Contractual Clauses

  • Google Ireland Limited — Google Tag Manager and Google Ads advertising measurement (consent only) — EU/US, Standard Contractual Clauses

  • LinkedIn Ireland Unlimited Company — LinkedIn Insight Tag advertising measurement (consent only) — EU/US, Standard Contractual Clauses

  • Google Workspace — business email and documents — EU/US, Standard Contractual Clauses

  • Apple (TestFlight/App Store) — SCRIBE iOS beta distribution — United States

A separate Subprocessor List for Customer Data will be published before commercial launch.

A separate Subprocessor List for Customer Data will be published before commercial launch.

We may disclose information where required by law, court order or competent authority, or where reasonably necessary to establish, exercise or defend legal claims.

We may disclose information where required by law, court order or competent authority, or where reasonably necessary to establish, exercise or defend legal claims.

9. International transfers

9. International transfers

9. International transfers

FORGE Logic’s primary data platform is in the EU (Ireland). Some providers process or permit access to Personal Data outside the EEA/UK. Where a restricted transfer occurs we rely on an adequacy decision, European Commission Standard Contractual Clauses with supplementary measures where required, the UK International Data Transfer Addendum where UK GDPR applies, or another lawful safeguard.

FORGE Logic’s primary data platform is in the EU (Ireland). Some providers process or permit access to Personal Data outside the EEA/UK. Where a restricted transfer occurs we rely on an adequacy decision, European Commission Standard Contractual Clauses with supplementary measures where required, the UK International Data Transfer Addendum where UK GDPR applies, or another lawful safeguard.

10. Retention

10. Retention

10. Retention

We keep Personal Data only as long as necessary for the purpose for which it is held. Interim schedule:

We keep Personal Data only as long as necessary for the purpose for which it is held. Interim schedule:

  • Website enquiries and business correspondence: active purpose plus 24 months from last contact

  • Account identity: deleted or anonymised when no longer required; pseudonymised audit evidence may be retained for security/accountability

  • Security and audit logs: 12 months

  • Email delivery events: 12 months

  • Advertising measurement identifier (_gcl_au cookie): 90 days; see the Cookie Notice

  • Customer workspace content: per Customer instructions and the DPA — not governed by this Notice

  • Contract and legal records: applicable statutory and claims periods

  • Website enquiries and business correspondence: active purpose plus 24 months from last contact

  • Account identity: deleted or anonymised when no longer required; pseudonymised audit evidence may be retained for security/accountability

  • Security and audit logs: 12 months

  • Email delivery events: 12 months

  • Advertising measurement identifier (_gcl_au cookie): 90 days; see the Cookie Notice

  • Customer workspace content: per Customer instructions and the DPA — not governed by this Notice

  • Contract and legal records: applicable statutory and claims periods

11. Security

11. Security

11. Security

FORGE Logic uses technical and organisational measures designed to protect Personal Data: authenticated access, organisation and role controls, encryption in transit and infrastructure-level encryption at rest, privileged-access restrictions and security logging.

FORGE Logic uses technical and organisational measures designed to protect Personal Data: authenticated access, organisation and role controls, encryption in transit and infrastructure-level encryption at rest, privileged-access restrictions and security logging.

No hosted service can guarantee absolute security. The service is in beta; do not enter information you are not permitted to share.

No hosted service can guarantee absolute security. The service is in beta; do not enter information you are not permitted to share.

12. Your rights

12. Your rights

12. Your rights

Subject to applicable law you may: access your Personal Data; correct it; request deletion; restrict processing; object to processing based on legitimate interests; receive certain data in portable form; withdraw consent; and complain to a Supervisory Authority.

Subject to applicable law you may: access your Personal Data; correct it; request deletion; restrict processing; object to processing based on legitimate interests; receive certain data in portable form; withdraw consent; and complain to a Supervisory Authority.

Contact privacy@forgelogic.app. We respond within one month. If your request concerns Customer workspace content, we may refer it to the organisation that controls that data.

Contact privacy@forgelogic.app. We respond within one month. If your request concerns Customer workspace content, we may refer it to the organisation that controls that data.

13. Automated decision-making

13. Automated decision-making

13. Automated decision-making

FORGE Logic does not make solely automated decisions about individuals that produce legal or similarly significant effects. AI functionality is decision support under human governance.

FORGE Logic does not make solely automated decisions about individuals that produce legal or similarly significant effects. AI functionality is decision support under human governance.

14. Children and consumers

14. Children and consumers

14. Children and consumers

FORGE Logic is a professional/business service for users aged 18 or over. It is not offered as a consumer or children’s service.

FORGE Logic is a professional/business service for users aged 18 or over. It is not offered as a consumer or children’s service.

15. Complaints and supervisory authority

15. Complaints and supervisory authority

15. Complaints and supervisory authority

Please contact us first at privacy@forgelogic.app.

Please contact us first at privacy@forgelogic.app.

You may complain to the Hellenic Data Protection Authority (dpa.gr) as the authority for FORGE Logic’s establishment, or to the Supervisory Authority of your own EU Member State. UK individuals may complain to the Information Commissioner’s Office (ico.org.uk) where UK GDPR applies.

You may complain to the Hellenic Data Protection Authority (dpa.gr) as the authority for FORGE Logic’s establishment, or to the Supervisory Authority of your own EU Member State. UK individuals may complain to the Information Commissioner’s Office (ico.org.uk) where UK GDPR applies.

16. Changes to this notice

16. Changes to this notice

16. Changes to this notice

Material changes are versioned with an effective date. A change to this Notice does not amend Customer contractual rights or the DPA. See also the FORGE Logic Cookie Notice at forgelogic.app/legal/cookies.

© 2026 FORGE Logic · Markus Sullivan t/a FORGE Logic

© 2026 FORGE Logic™ · Markus Sullivan t/a FORGE Logic

© 2026 FORGE Logic™ · Markus Sullivan t/a FORGE Logic