← All legal documents

Privacy Policy

ForgeRP · Last updated 2026-07-23

1. Scope

This Policy explains how ForgeRP handles personal data for the hosted Service. For business records you enter, you are the controller and we are your processor (see the Data Processing Addendum).

2. Data we process

Account data: names, work emails, roles, and authentication data. Passwords are stored only as salted scrypt hashes — never in plaintext.

Customer content: the business records you enter (orders, parts, work orders, HR and onboarding records, etc.). For HR/onboarding this can include employee personal information you choose to store.

Usage and audit data: actions are audit-logged (who did what, when) as a core ERP control, along with limited technical logs for security and reliability.

3. How we use it

We process data to provide, secure, support, and improve the Service, to bill you, and to meet legal obligations. We do not sell personal data and do not use your customer content for advertising.

4. Sharing and subprocessors

We share data only with infrastructure providers needed to run the Service (hosting, email delivery, payment processing, optional bank-connection and text-to-speech providers you enable). See the Subprocessors page for the current list.

5. Retention and security

We retain customer content for the life of your account and for a limited window after termination so you can export it. We apply access controls, encryption in transit, and least-privilege practices. No system is perfectly secure; report concerns to us promptly.

6. Your rights (GDPR / CCPA-CPRA)

Depending on your location you may have rights to access, correct, delete, or export personal data, and to object to or restrict certain processing. For customer content, direct requests to your organization's admin (the controller). For account data, contact privacy@forge-rp.live. We respond to verified requests within the timeframes required by law (generally within 30-45 days).

We do not sell or share personal information as defined by the CCPA/CPRA.

7. International transfers and children

The hosted Service is operated from the United States. Where required, we rely on appropriate transfer mechanisms. The Service is for business use and not directed to children under 16.