Third-party services that process data as part of ForgeStop's NFC authentication platform and the operation of client relationships.
ForgeStop provides 15 days advance written notice before engaging any new sub-processor. Clients may object within 15 days on reasonable data protection grounds. To subscribe to notifications, contact help@forgestop.com.
The following third-party services are currently authorised to process data in connection with ForgeStop's platform and client relationships. All are subject to data protection obligations no less protective than ForgeStop's Data Processing Agreement, whether through a negotiated agreement or acceptance of the provider's standard data processing terms.
| Sub-processor | Location | Processing Activities | Assurance |
|---|---|---|---|
| Amazon Web Services (AWS) | United States | Cloud infrastructure: compute (App Runner), relational database (RDS PostgreSQL), object storage (S3), secrets management (Secrets Manager), identity and access management (Cognito), content delivery (CloudFront), web application firewall (WAF), encryption key management (KMS), monitoring (CloudWatch, CloudTrail). | SOC 2 Type II, ISO 27001, PCI DSS, FIPS 140-2 Level 3 (KMS) |
| Microsoft Corporation | United States / EU | Business productivity and collaboration: email (Outlook), messaging (Teams), document storage (SharePoint, OneDrive) including per-client document spaces, and identity/SSO (Entra ID). Processes client personnel contact details, correspondence, and client-supplied documents. | SOC 2 Type II, ISO 27001, EU Data Boundary options |
| MongoDB Atlas | United States | NoSQL database for analytics data and audit logs. VPC-peered to ForgeStop AWS infrastructure — all traffic over private network, no public internet. Point-in-time recovery with 35-day snapshot retention. | SOC 2 Type II, ISO 27001 |
| Atlassian | United States / EU | Project and knowledge management (Jira, Confluence). Stores service delivery records, meeting notes, and work items which may reference client personnel by name and email. | SOC 2 Type II, ISO 27001 |
| Krisp Technologies | United States only | Meeting recording, transcription, and note generation. Processes voice recordings and transcript content of client representatives participating in recorded meetings. No regional data residency option is available; EEA-origin transfers are made under Standard Contractual Clauses (DPA §8.2). | SOC 2 Type II; HIPAA BAA available |
| Anthropic PBC | United States | AI-assisted processing of meeting transcripts into meeting notes and internal work items, per DPA §5.1(g). Processes transcript content which may include client personnel names and statements. Organisational account only; commercial terms apply. | SOC 2 Type II |
| HubSpot | United States / EU | Customer relationship management. Processes client personnel contact details and commercial relationship records. | SOC 2 Type II, ISO 27001 |
| Stripe Inc. | United States | Payment processing for subscription billing. Tokenised — ForgeStop does not receive or store raw card data. | PCI DSS Level 1 |
| Zoho Corporation | India / United States | Accounting and financial records (Zoho Books) and agreement execution (Zoho Sign). Processes client billing contact details and signatory details. Zoho CRM is not used; ForgeStop's CRM of record is HubSpot. | SOC 2 Type II |
| New Relic | United States | Application performance monitoring (APM). Receives application telemetry, error tracking, and performance metrics. No client personal data transmitted. | SOC 2 Type II, ISO 27001 |
| Mapbox | United States | Geospatial visualization for scan location analytics on the Dashboard. Receives anonymised scan coordinate data for map rendering. | SOC 2 Type II |
| IPStack / PositionStack | Austria / United States | Geolocation API services for scan location resolution. Receives IP-derived approximate location data during authentication events. | Privacy policy available |
| Google reCAPTCHA | United States | Bot protection for product authentication pages. Receives browser interaction signals for bot detection. No personal data shared. | Google SOC 2 Type II, ISO 27001 |
| GitHub | United States | Source code management and CI/CD. Does not process client personal data in the ordinary course. Listed for completeness as part of the service delivery toolchain. | SOC 2 Type II, ISO 27001 |
| Regional Implementation Partners | Per Statement of Work | On-site Batchmaker device installation, NFC production line integration, and initial configuration at client facilities. | NDA + ForgeStop subcontractor security approval |
Platform data — consumer scan events, product records, batch data and Dashboard user accounts — resides on ForgeStop-controlled infrastructure: RDS PostgreSQL (primary database) and MongoDB Atlas (analytics and audit, VPC-peered, private network only). Stripe and Zoho process ForgeStop's own billing and signatory data. New Relic receives application telemetry only. Mapbox and IPStack/PositionStack receive anonymised scan coordinates. Regional implementation partners have physical access to Batchmaker hardware during installation only.
Client relationship data — the names, email addresses, correspondence, documents and, where meetings are recorded, voice and transcript content of client personnel — is processed by the business-operations providers disclosed above: Microsoft (email, Teams, SharePoint, SSO), Atlassian (service records and meeting notes), Krisp (recording and transcription), Anthropic (AI-assisted note generation from transcripts, per DPA §5.1(g)), and HubSpot (CRM). None of these providers receives platform scan data or consumer personal data.
ForgeStop's primary hosting region is us-east-1 (US East — N. Virginia), with disaster recovery replication to us-west-2 (US West — Oregon). Microsoft, Atlassian and HubSpot offer EU processing options. Krisp processes and stores data in the United States only and offers no regional residency; transfers of EEA-origin personal data to Krisp are made under Standard Contractual Clauses (DPA §8.2). Specific region information is available upon request. Data residency in other regions may be available as a custom enterprise arrangement.
AWS, Microsoft, MongoDB Atlas, Atlassian, Krisp, Anthropic, HubSpot, Stripe, Zoho, New Relic, Mapbox, IPStack/PositionStack, Google reCAPTCHA and GitHub are standard platform- and operations-level service providers used across all client engagements. They are disclosed in this Sub-processor List and in the DPA (Annex 2) at contract signing. Per DPA §6.2, these providers are exempt from the 15-day per-engagement client notification requirement. Regional Implementation Partners and any future vendors with direct client data access require notification.
| Date | Change |
|---|---|
| March 2026 | Initial publication. Four sub-processors: AWS, Stripe, Zoho, Regional Implementation Partners. |
| March 2026 (v1.1) | Expanded per CTO review: added MongoDB Atlas, New Relic, Mapbox, IPStack/PositionStack, Google reCAPTCHA. AWS details expanded. Total: 9 sub-processors. |
| September 2026 (v1.2) | Disclosure correction: Microsoft, Atlassian, Krisp, Anthropic and HubSpot added — all in use before v1.1 was published and not previously disclosed. GitHub added for completeness. Zoho narrowed to Books and Sign (CRM migrated to HubSpot). Notes rewritten to distinguish platform data from client relationship data; residency note added for Krisp. Total: 15 sub-processors. Drafted August 2026; approved September 2026. |
← Back to Legal · Data Processing Agreement · Version 1.2 · Last updated: September 2026
.png)
