Terms governing how ForgeStop processes data on behalf of brand partners and clients.
This Data Processing Agreement ("DPA") forms part of the agreement between ForgeStop Technology Corp. ("ForgeStop", "Processor") and the counterparty identified in the applicable Master Service Agreement or Statement of Work ("Client", "Controller") for the provision of ForgeStop's NFC/RFID product authentication platform services.
This DPA establishes the rights and obligations of each party with respect to data protection in compliance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDPA), Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), and the California Consumer Privacy Act (CCPA).
"ForgeStop Operational Data" means all raw data generated by ForgeStop's platform infrastructure including scan events, authentication results, scan timestamps, non-identifying device signatures, and approximate geolocation signals. ForgeStop is an independent Data Controller of this data.
"Client Brand and Product Data" means data specific to the Client's brand, products, packaging configurations, SKU identifiers, and product metadata. The Client retains ownership.
"Client Personal Data" means any Personal Data of the Client's employees, representatives, or end consumers shared with or collected through the ForgeStop platform. ForgeStop processes this data solely as Processor.
"Sub-processor" means any third party engaged by ForgeStop to process Client Personal Data on behalf of the Controller.
"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Personal Data.
3.1 ForgeStop acts in a dual capacity:
3.2 Each party is individually responsible for complying with Applicable Data Protection Law in its respective capacity.
3.3 The Client is responsible for ensuring a lawful basis for providing Personal Data to ForgeStop.
ForgeStop shall process Client Personal Data only as necessary to provide the authentication platform services described in the applicable MSA/SOW, and in accordance with the Client's documented instructions. Categories of data and processing details are set out in Annex 1.
5.1 ForgeStop implements and maintains appropriate technical and organisational measures including:
5.2 ForgeStop shall regularly test, assess, and evaluate the effectiveness of its security measures.
6.1 The Client provides general authorisation for ForgeStop to engage Sub-processors, subject to this Section 6.
6.2 Current Sub-processors are listed in Annex 2. ForgeStop provides 15 days advance written notice before engaging new Sub-processors.
6.3 Client may object within 15 days on reasonable data protection grounds. If unresolved, Client may terminate the affected SOW.
6.4 ForgeStop imposes data protection obligations no less protective than this DPA on each Sub-processor, whether through a negotiated agreement or by acceptance of the Sub-processor's standard data processing terms. ForgeStop remains fully liable for Sub-processor acts and omissions.
7.1 ForgeStop shall notify the Client without undue delay and within 72 hours of becoming aware of any Security Incident affecting Client Personal Data.
7.2 Notification shall include: nature of incident, categories and approximate number affected, likely consequences, measures taken/proposed, and ForgeStop contact point.
7.3 ForgeStop shall cooperate with the Client's investigation, supervisory authority notification, and remediation.
8.1 ForgeStop's platform is hosted on AWS, US-based regions (primary: us-east-1; disaster recovery: us-west-2). Data may be processed outside the Client's home jurisdiction.
8.2 Certain Sub-processors listed in Annex 2 process data exclusively in the United States and do not offer regional data residency options. This includes Krisp, which stores meeting recordings and transcripts on US-based servers only. Where such a Sub-processor processes Client Personal Data originating in the European Economic Area, transfers are made under Standard Contractual Clauses or another recognised transfer mechanism.
8.3 ForgeStop shall ensure appropriate safeguards for cross-border transfers: Standard Contractual Clauses (SCCs) where GDPR applies, contractual provisions meeting applicable law, or other recognised transfer mechanisms.
8.4 ForgeStop shall confirm specific processing regions upon request.
ForgeStop shall assist the Client in responding to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection). ForgeStop shall forward direct Data Subject requests to the Client and shall not respond directly unless instructed or required by law.
10.1 ForgeStop retains Client Personal Data only as long as necessary for the services or as required by law.
10.2 Upon termination: Client has a 60-day export window. Client Personal Data returned or securely deleted within 90 days following the export window, except where retention is required by law.
10.3 ForgeStop Operational Data retained up to 2 years (ForgeStop is independent Controller). Client Brand and Product Data retained up to 1 year post-termination for reactivation, audit, or legal purposes, then purged or anonymised.
10.4 Individual user data deletion requests honoured within 30 days.
10.5 Written confirmation of deletion provided upon request.
10.6 Automated backup retention: RDS PostgreSQL backups purged after 14 days (production). MongoDB Atlas snapshots purged after 35 days. S3 noncurrent versions purged after 90 days via lifecycle rules.
10.7 Meeting recordings and transcripts generated under §5.1(g) are retained in accordance with ForgeStop's Information Classification & Handling Policy and are deleted on request.
11.1 ForgeStop shall make available information necessary to demonstrate DPA compliance and contribute to audits, subject to 60 days advance notice and confidentiality obligations.
11.2 ForgeStop may satisfy audits via documentation (certifications, reports, pen test results, written Q&A). On-site or remote access at ForgeStop's reasonable discretion with written consent.
11.3 Client bears own audit costs. Limited to once per calendar year unless required by supervisory authority or following confirmed Security Incident.
This DPA remains in effect for the duration of ForgeStop's processing of Client Personal Data. Sections 5, 7, 10, and 11 survive termination.
Governed by the governing law of the applicable MSA. Where GDPR applies, DPA provisions interpreted in accordance with GDPR regardless of MSA governing law.
| Field | Detail |
|---|---|
| Subject Matter | NFC/RFID product authentication platform services |
| Duration | Duration of MSA/SOW + 60-day export window + 90-day deletion period |
| Nature of Processing | Collection, storage, retrieval, analysis, deletion |
| Purpose | Product authentication, batch management, scan analytics, and the administration of the client relationship (correspondence, meeting records, service delivery coordination) |
| Data Subject Categories | End consumers scanning NFC products; Client personnel (Dashboard/Batchmaker users, and Client representatives participating in meetings or correspondence with ForgeStop) |
| Personal Data Categories | Consumer: approximate geolocation, device type, browser, OS, language, timestamp, tag ID. Personnel: name, email, role, Cognito credentials, and — where meetings are recorded — voice recordings and transcript content |
| Special Categories | None |
See the full Sub-processor List for details and change notifications. Corrected August 2026; approved September 2026 — Microsoft, Atlassian, Krisp, Anthropic and HubSpot added; Zoho narrowed.
| Sub-processor | Location | Processing Activities | Assurance |
|---|---|---|---|
| Amazon Web Services (AWS) | United States | Cloud infrastructure: compute (App Runner), database (RDS PostgreSQL), storage (S3), secrets (Secrets Manager), identity (Cognito), CDN (CloudFront), WAF, encryption (KMS), monitoring (CloudWatch/CloudTrail) | SOC 2 Type II, ISO 27001, PCI DSS |
| Microsoft Corporation | United States / EU | Email (Outlook), messaging (Teams), document storage (SharePoint, OneDrive) incl. per-client document spaces, identity/SSO (Entra ID). Processes Client personnel contact details, correspondence, and Client-supplied documents. | SOC 2 Type II, ISO 27001, EU Data Boundary options |
| MongoDB Atlas | United States | NoSQL database for analytics and audit logs. VPC-peered (private network). | SOC 2 Type II, ISO 27001 |
| Atlassian | United States / EU | Project and knowledge management (Jira, Confluence). Service delivery records, meeting notes and work items which may reference Client personnel by name and email. | SOC 2 Type II, ISO 27001 |
| Krisp Technologies | United States only | Meeting recording, transcription and note generation. Voice recordings and transcript content of Client representatives in recorded meetings. No regional residency option — see §8.2. | SOC 2 Type II; HIPAA BAA available |
| Anthropic PBC | United States | AI-assisted processing of meeting transcripts into notes and internal work items, per §5.1(g). Organisational account only; commercial terms apply. | SOC 2 Type II |
| HubSpot | United States / EU | Customer relationship management. Client personnel contact details and commercial relationship records. | SOC 2 Type II, ISO 27001 |
| Stripe Inc. | United States | Payment processing (tokenised — no raw card data) | PCI DSS Level 1 |
| Zoho Corporation | India / United States | Accounting (Zoho Books) and agreement execution (Zoho Sign). Billing contact and signatory details. Zoho CRM is not used; ForgeStop's CRM of record is HubSpot. | SOC 2 Type II |
| New Relic | United States | Application performance monitoring (APM). No client personal data. | SOC 2 Type II, ISO 27001 |
| Mapbox | United States | Geospatial visualization for scan analytics. Anonymised coordinates. | SOC 2 Type II |
| IPStack / PositionStack | Austria / US | Geolocation APIs for scan location resolution. | Privacy policy available |
| Google reCAPTCHA | United States | Bot protection for authentication pages. No personal data shared. | Google SOC 2 Type II |
| GitHub | United States | Source code management and CI/CD. Does not process Client Personal Data in the ordinary course; listed for completeness. | SOC 2 Type II, ISO 27001 |
| Regional Implementation Partners | Per SOW | On-site Batchmaker installation, production line integration | NDA + ForgeStop approval |
To subscribe to sub-processor change notifications, contact help@forgestop.com.
| Version | Date | Change |
|---|---|---|
| 1.0 | March 2026 | Initial publication. |
| 1.1 | March 2026 | Sub-processor list expanded (MongoDB Atlas, New Relic, Mapbox, IPStack/PositionStack, Google reCAPTCHA). Backup retention specifics (§10.6). AWS regions specified. |
| 1.2 | September 2026 | Sub-processor disclosure correction: Microsoft, Atlassian, Krisp, Anthropic and HubSpot added to Annex 2 (already in use; not previously disclosed); GitHub added for completeness; Zoho narrowed to Books and Sign. New §5.1(g) AI-assisted processing. §5.1(b) Entra ID; §5.1(d) per-client document spaces; §6.4 standard terms; §8.2 US-only residency; §10.7 recording retention; Annex 1 extended. Drafted August 2026; approved September 2026. |
This document is a template and does not constitute legal advice. Must be reviewed by licensed counsel before execution with any counterparty.
← Back to Legal · Version 1.2 · Last updated: September 2026
.png)
