Data Processing Agreement (DPA)

← Back to Legal
Legal

Data Processing Agreement

Terms governing how ForgeStop processes data on behalf of brand partners and clients.

Version: 1.2 Effective: September 2026 Classification: Public

Key Terms at a Glance

  • ForgeStop acts as both Controller and Processor — Controller for platform operational data; Processor for client personal data.
  • 72-hour incident notification for all clients, not just GDPR-covered.
  • 60-day export window at end of contract, followed by 90-day deletion of client personal data.
  • Annual audit right — satisfied via documentation, reports, and Q&A.
  • Sub-processor transparency — 15 days advance notice before any new sub-processor.
  • AI-assisted processing disclosed — human-initiated, organisational accounts only, no restricted data, human review of output (§5.1(g)).
Version 1.2 — Sub-processor disclosure correction. Annex 2 now lists five providers that were already in use but not previously disclosed: Microsoft, Atlassian, Krisp, Anthropic, and HubSpot. This is a correction to the published list, not a notice of new engagements. See the Sub-processor List and the change log below.

1. Purpose

This Data Processing Agreement ("DPA") forms part of the agreement between ForgeStop Technology Corp. ("ForgeStop", "Processor") and the counterparty identified in the applicable Master Service Agreement or Statement of Work ("Client", "Controller") for the provision of ForgeStop's NFC/RFID product authentication platform services.

This DPA establishes the rights and obligations of each party with respect to data protection in compliance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDPA), Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), and the California Consumer Privacy Act (CCPA).

2. Definitions

"ForgeStop Operational Data" means all raw data generated by ForgeStop's platform infrastructure including scan events, authentication results, scan timestamps, non-identifying device signatures, and approximate geolocation signals. ForgeStop is an independent Data Controller of this data.

"Client Brand and Product Data" means data specific to the Client's brand, products, packaging configurations, SKU identifiers, and product metadata. The Client retains ownership.

"Client Personal Data" means any Personal Data of the Client's employees, representatives, or end consumers shared with or collected through the ForgeStop platform. ForgeStop processes this data solely as Processor.

"Sub-processor" means any third party engaged by ForgeStop to process Client Personal Data on behalf of the Controller.

"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Personal Data.

3. Roles and Responsibilities

3.1 ForgeStop acts in a dual capacity:

  • (a) As an independent Data Controller for ForgeStop Operational Data — in connection with operating, maintaining, and improving its authentication platform.
  • (b) As a Data Processor for Client Personal Data — processing solely per the Client's documented instructions.

3.2 Each party is individually responsible for complying with Applicable Data Protection Law in its respective capacity.

3.3 The Client is responsible for ensuring a lawful basis for providing Personal Data to ForgeStop.

4. Scope of Processing

ForgeStop shall process Client Personal Data only as necessary to provide the authentication platform services described in the applicable MSA/SOW, and in accordance with the Client's documented instructions. Categories of data and processing details are set out in Annex 1.

5. Data Security Measures

5.1 ForgeStop implements and maintains appropriate technical and organisational measures including:

  • (a) Encryption: TLS 1.2+ in transit; AES-256 at rest backed by AWS KMS (FIPS 140-2 Level 3). API keys encrypted with AES-256-CBC before database storage.
  • (b) Access Control: Microsoft Entra ID provides single sign-on for ForgeStop personnel access to federated business systems. AWS IAM Identity Center with role-based groups and tiered permission sets governs infrastructure access. AWS Cognito for client authentication. Production databases in private VPC subnets only. Tenant isolation enforced via JWT claims on every API request.
  • (c) Secrets Management: AWS Secrets Manager (machine/code) + 1Password Business (human access). CI/CD uses GitHub Actions OIDC (keyless). API keys rotated per ForgeStop's API Key & Secrets Lifecycle Policy.
  • (d) Infrastructure and Document Isolation: Separate VPC per environment. Logical data segregation per client via tenant ID scoping on all database queries. Client documents and correspondence held outside the platform are stored in dedicated per-client SharePoint spaces with need-to-know access; access to one client's space does not confer access to another's.
  • (e) Audit Logging: AWS CloudTrail for infrastructure; structured application audit logging with actor, role, IP, and field-level change history.
  • (f) Personnel: All personnel with access to Client Personal Data bound by confidentiality obligations.
  • (g) AI-Assisted Processing: ForgeStop uses AI tools in defined internal workflows — principally transcription of recorded meetings and generation of meeting notes and internal work items from those transcripts. Where such workflows involve Client Personal Data: processing is initiated by an authorised team member per item, never automated or in bulk; AI tools run under organisational accounts subject to the vendor's commercial terms, personal accounts prohibited; data classified Restricted under ForgeStop's Information Classification & Handling Policy (credentials, API keys, encryption keys) is never processed by any AI tool; AI output is reviewed by a person before it is relied on or communicated to a Client; the AI vendors engaged are disclosed in Annex 2.

5.2 ForgeStop shall regularly test, assess, and evaluate the effectiveness of its security measures.

6. Sub-processing

6.1 The Client provides general authorisation for ForgeStop to engage Sub-processors, subject to this Section 6.

6.2 Current Sub-processors are listed in Annex 2. ForgeStop provides 15 days advance written notice before engaging new Sub-processors.

6.3 Client may object within 15 days on reasonable data protection grounds. If unresolved, Client may terminate the affected SOW.

6.4 ForgeStop imposes data protection obligations no less protective than this DPA on each Sub-processor, whether through a negotiated agreement or by acceptance of the Sub-processor's standard data processing terms. ForgeStop remains fully liable for Sub-processor acts and omissions.

7. Security Incident Notification

7.1 ForgeStop shall notify the Client without undue delay and within 72 hours of becoming aware of any Security Incident affecting Client Personal Data.

7.2 Notification shall include: nature of incident, categories and approximate number affected, likely consequences, measures taken/proposed, and ForgeStop contact point.

7.3 ForgeStop shall cooperate with the Client's investigation, supervisory authority notification, and remediation.

8. International Data Transfers

8.1 ForgeStop's platform is hosted on AWS, US-based regions (primary: us-east-1; disaster recovery: us-west-2). Data may be processed outside the Client's home jurisdiction.

8.2 Certain Sub-processors listed in Annex 2 process data exclusively in the United States and do not offer regional data residency options. This includes Krisp, which stores meeting recordings and transcripts on US-based servers only. Where such a Sub-processor processes Client Personal Data originating in the European Economic Area, transfers are made under Standard Contractual Clauses or another recognised transfer mechanism.

8.3 ForgeStop shall ensure appropriate safeguards for cross-border transfers: Standard Contractual Clauses (SCCs) where GDPR applies, contractual provisions meeting applicable law, or other recognised transfer mechanisms.

8.4 ForgeStop shall confirm specific processing regions upon request.

9. Data Subject Rights

ForgeStop shall assist the Client in responding to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection). ForgeStop shall forward direct Data Subject requests to the Client and shall not respond directly unless instructed or required by law.

10. Data Retention and Deletion

10.1 ForgeStop retains Client Personal Data only as long as necessary for the services or as required by law.

10.2 Upon termination: Client has a 60-day export window. Client Personal Data returned or securely deleted within 90 days following the export window, except where retention is required by law.

10.3 ForgeStop Operational Data retained up to 2 years (ForgeStop is independent Controller). Client Brand and Product Data retained up to 1 year post-termination for reactivation, audit, or legal purposes, then purged or anonymised.

10.4 Individual user data deletion requests honoured within 30 days.

10.5 Written confirmation of deletion provided upon request.

10.6 Automated backup retention: RDS PostgreSQL backups purged after 14 days (production). MongoDB Atlas snapshots purged after 35 days. S3 noncurrent versions purged after 90 days via lifecycle rules.

10.7 Meeting recordings and transcripts generated under §5.1(g) are retained in accordance with ForgeStop's Information Classification & Handling Policy and are deleted on request.

11. Audit Rights

11.1 ForgeStop shall make available information necessary to demonstrate DPA compliance and contribute to audits, subject to 60 days advance notice and confidentiality obligations.

11.2 ForgeStop may satisfy audits via documentation (certifications, reports, pen test results, written Q&A). On-site or remote access at ForgeStop's reasonable discretion with written consent.

11.3 Client bears own audit costs. Limited to once per calendar year unless required by supervisory authority or following confirmed Security Incident.

12. Term and Termination

This DPA remains in effect for the duration of ForgeStop's processing of Client Personal Data. Sections 5, 7, 10, and 11 survive termination.

13. Governing Law

Governed by the governing law of the applicable MSA. Where GDPR applies, DPA provisions interpreted in accordance with GDPR regardless of MSA governing law.


Annex 1 — Processing Details

FieldDetail
Subject MatterNFC/RFID product authentication platform services
DurationDuration of MSA/SOW + 60-day export window + 90-day deletion period
Nature of ProcessingCollection, storage, retrieval, analysis, deletion
PurposeProduct authentication, batch management, scan analytics, and the administration of the client relationship (correspondence, meeting records, service delivery coordination)
Data Subject CategoriesEnd consumers scanning NFC products; Client personnel (Dashboard/Batchmaker users, and Client representatives participating in meetings or correspondence with ForgeStop)
Personal Data CategoriesConsumer: approximate geolocation, device type, browser, OS, language, timestamp, tag ID. Personnel: name, email, role, Cognito credentials, and — where meetings are recorded — voice recordings and transcript content
Special CategoriesNone

Annex 2 — Approved Sub-processors

See the full Sub-processor List for details and change notifications. Corrected August 2026; approved September 2026 — Microsoft, Atlassian, Krisp, Anthropic and HubSpot added; Zoho narrowed.

Sub-processorLocationProcessing ActivitiesAssurance
Amazon Web Services (AWS)United StatesCloud infrastructure: compute (App Runner), database (RDS PostgreSQL), storage (S3), secrets (Secrets Manager), identity (Cognito), CDN (CloudFront), WAF, encryption (KMS), monitoring (CloudWatch/CloudTrail)SOC 2 Type II, ISO 27001, PCI DSS
Microsoft CorporationUnited States / EUEmail (Outlook), messaging (Teams), document storage (SharePoint, OneDrive) incl. per-client document spaces, identity/SSO (Entra ID). Processes Client personnel contact details, correspondence, and Client-supplied documents.SOC 2 Type II, ISO 27001, EU Data Boundary options
MongoDB AtlasUnited StatesNoSQL database for analytics and audit logs. VPC-peered (private network).SOC 2 Type II, ISO 27001
AtlassianUnited States / EUProject and knowledge management (Jira, Confluence). Service delivery records, meeting notes and work items which may reference Client personnel by name and email.SOC 2 Type II, ISO 27001
Krisp TechnologiesUnited States onlyMeeting recording, transcription and note generation. Voice recordings and transcript content of Client representatives in recorded meetings. No regional residency option — see §8.2.SOC 2 Type II; HIPAA BAA available
Anthropic PBCUnited StatesAI-assisted processing of meeting transcripts into notes and internal work items, per §5.1(g). Organisational account only; commercial terms apply.SOC 2 Type II
HubSpotUnited States / EUCustomer relationship management. Client personnel contact details and commercial relationship records.SOC 2 Type II, ISO 27001
Stripe Inc.United StatesPayment processing (tokenised — no raw card data)PCI DSS Level 1
Zoho CorporationIndia / United StatesAccounting (Zoho Books) and agreement execution (Zoho Sign). Billing contact and signatory details. Zoho CRM is not used; ForgeStop's CRM of record is HubSpot.SOC 2 Type II
New RelicUnited StatesApplication performance monitoring (APM). No client personal data.SOC 2 Type II, ISO 27001
MapboxUnited StatesGeospatial visualization for scan analytics. Anonymised coordinates.SOC 2 Type II
IPStack / PositionStackAustria / USGeolocation APIs for scan location resolution.Privacy policy available
Google reCAPTCHAUnited StatesBot protection for authentication pages. No personal data shared.Google SOC 2 Type II
GitHubUnited StatesSource code management and CI/CD. Does not process Client Personal Data in the ordinary course; listed for completeness.SOC 2 Type II, ISO 27001
Regional Implementation PartnersPer SOWOn-site Batchmaker installation, production line integrationNDA + ForgeStop approval

To subscribe to sub-processor change notifications, contact help@forgestop.com.


Change Log

VersionDateChange
1.0March 2026Initial publication.
1.1March 2026Sub-processor list expanded (MongoDB Atlas, New Relic, Mapbox, IPStack/PositionStack, Google reCAPTCHA). Backup retention specifics (§10.6). AWS regions specified.
1.2September 2026Sub-processor disclosure correction: Microsoft, Atlassian, Krisp, Anthropic and HubSpot added to Annex 2 (already in use; not previously disclosed); GitHub added for completeness; Zoho narrowed to Books and Sign. New §5.1(g) AI-assisted processing. §5.1(b) Entra ID; §5.1(d) per-client document spaces; §6.4 standard terms; §8.2 US-only residency; §10.7 recording retention; Annex 1 extended. Drafted August 2026; approved September 2026.

This document is a template and does not constitute legal advice. Must be reviewed by licensed counsel before execution with any counterparty.

← Back to Legal · Version 1.2 · Last updated: September 2026