Review notice: This operational DPA is prepared for licensed-attorney review. Customers with jurisdiction-specific, regulated-data, transfer, or negotiated DPA requirements should request an executed addendum before submitting covered data.
1. Parties and Scope
This Data Processing Addendum ("DPA") supplements the agreement between IRIS Systems LLC, operator of ForgeSystems ("Processor"), and the customer organization using ForgeSystems ("Customer"). It applies when Processor handles personal data submitted to the platform by or for Customer ("Customer Personal Data").
2. Roles
Customer determines the purposes and essential means of processing Customer Personal Data and acts as controller or business unless law provides otherwise. Processor acts as processor or service provider and processes Customer Personal Data to provide, secure, support, and improve the contracted service according to Customer’s documented instructions.
3. Processing Details
- Subject matter: hosting and operating enabled ForgeSystems services, integrations, support, security, and communications.
- Duration: the service term plus the documented retention and deletion period.
- Data subjects: Customer personnel, contacts, clients, prospects, recipients, contractors, and other individuals whose data Customer submits.
- Data categories: account, contact, communication, workflow, document, transaction, technical, and integration data chosen by Customer.
- Sensitive data: not authorized unless an enabled feature and written agreement expressly support the category and safeguards.
4. Processor Obligations
- Process Customer Personal Data only on documented instructions, including service configuration and support requests.
- Ensure personnel authorized to process the data are subject to confidentiality obligations.
- Maintain technical and organizational safeguards appropriate to the service and risk.
- Notify Customer if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.
- Not sell Customer Personal Data or use it for targeted advertising on Processor’s own behalf.
5. Customer Obligations
Customer is responsible for lawful collection, notices, permissions, data accuracy, configuration, user access, retention instructions, and responding to individuals. Customer will not instruct Processor to process data unlawfully or outside supported service boundaries.
6. Security Incidents
Processor will notify Customer without undue delay after confirming a security incident involving Customer Personal Data and will provide information reasonably available for Customer’s response. Notification does not establish fault or liability.
7. Subprocessors
Customer authorizes the provider categories listed on the Subprocessor List. Processor remains responsible for required contractual data-protection obligations imposed on subprocessors for covered processing.
8. Individual Requests
Taking into account the nature of processing, Processor will provide reasonable product or support assistance for requests to access, correct, export, restrict, or delete Customer Personal Data. Customer remains responsible for validating and responding to each request.
9. Return and Deletion
At the end of service, Processor will make supported exports available and delete or de-identify Customer Personal Data according to the agreement and retention schedule, unless law requires retention. Backup deletion may follow established rotation periods.
10. Demonstrating Compliance
Processor will make reasonably available documentation about relevant safeguards and processing. Any additional audit must be proportionate, protect other customers and confidential systems, avoid unreasonable disruption, and be subject to agreed scope and cost.
11. International Transfers
If covered data is transferred across borders, the parties will use an applicable transfer mechanism and supplementary measures where required. Jurisdiction-specific standard clauses or addenda must be executed when applicable; this page alone does not execute those clauses.
12. Conflicts and Contact
This DPA controls over conflicting agreement terms only for covered data-processing obligations. Contact support@forgesystems.io to request an execution copy or jurisdiction-specific addendum.
Operational publication prepared for licensed-attorney review. This status does not represent attorney approval.