Skip to article

Forge: data processing agreement

Version and particulars/annex version: dpa-en-2026-09-18-v2. Instructions version: dpa-instructions-en-2026-09-18-v2.

Parties and applicability

Processor: Ready IT ApS, CVR 38769383, c/o Matt Luccas Phaure Jensen, Viften 18, 1. 1, 2670 Greve, Denmark; contact@readyit.dk.

Customer: the contracting customer identified in the accepted Forge order, with the address and authorised contact recorded for that customer. The order and its recorded electronic acceptance identify the effective agreement date and agreement reference.

This agreement applies where Ready IT processes personal data on the customer's behalf in providing the instructed Forge technical-work service. The customer is controller for data whose purposes and means it determines. Where the customer is itself a processor, Ready IT acts as an authorised subprocessor; the customer's relevant controller instructions and authority apply. References below to controller instructions include that authorised chain.

Buying as a business or a consumer does not by itself decide that data-protection role. Purely personal/household use and Ready IT's own account, security and billing purposes do not become controller-to-processor processing merely because this agreement accompanies the subscription.

Processing particulars and instructions

Subject matter and purpose: hosting and organising the customer's authorised technical-work records and enabling remote technical access, customer/case coordination and, when instructed, hosted Whisper assistance.

Nature: receipt, recording, organisation, storage, authorised retrieval and use of customer/contact/company records, case notes and drafts, device links, selected diagnostic information, files, conversations and tool evidence; communication to the relevant enabled service providers for those functions; and return/deletion as instructed. Hosted Whisper can use relevant records across cases within the authorised workspace. Separate chats are not a new confidentiality boundary.

Duration: while those processing services are provided and while completing the customer's return/deletion instructions, subject to lawful mandatory retention. Cancelling payment and continuing on Free does not end the data processing service or itself instruct deletion.

Data subjects: the customer's users/technicians, customers and their contacts, device users, and other people whose information is included in authorised case, file, diagnostic or conversation material.

Personal-data types: names and contact/business details; workspace and device identifiers; case communications and notes; selected device/account, system, software, network and diagnostic information; and personal data present in the particular authorised files, conversation context and tool results. This description is not an instruction to indiscriminately copy device contents, credentials or unrelated sensitive information. Specific additional categories and purposes must be covered by the customer's lawful instructions before inclusion.

The accepted service order, this annex, the versioned Forge processing instructions and the customer's authorised workspace actions are the documented instructions. The customer determines the lawful basis and required notices for its controlled data and has the authority needed to supply it, grant technical access and issue these instructions. An upstream processor must remain within the relevant controller's instructions and permissions.

Annex: measures, recipients and end of processing

Forge uses Auth0 authentication with Forge-controlled workspace membership, roles and target authorisation/revocation. Native remote access uses encrypted SSH/SFTP through an outbound HTTPS relay. Hosted tools operate within the authorised human/workspace/device scope. Diagnostic collection is explicit, not routine unrestricted collection.

Conversation payloads and checkpoints use application data protection scoped to the workspace and conversation. Whisper files use a private store outside public web roots with scoped access and file-integrity/version checks. Metadata-only access audit is separate from case content and conversation history. These measures do not represent a certification, an all-data encryption claim or a guarantee against every incident.

AWS supplies Bridge hosting in Stockholm (Lightsail eu-north-1) and the CloudFront front door under Ready IT's ordinary AWS account terms, including the incorporated applicable AWS DPA/SCC provisions.

OpenAI Ireland Ltd. supplies the Responses API for instructed hosted Whisper processing. The ordinary Services Agreement, updated 1 December 2025 and effective 1 January 2026, incorporates the DPA through section 5.3. DPA section 4.1 supplies SCC or Article 45 adequacy arrangements for the EEA onward transfers it covers. The project uses Global residency and Standard tier, with store=false; the organisation's model-feedback, evaluation/fine-tuning and API-input/output sharing opt-ins are all disabled. Provider abuse-monitoring and prompt-cache retention remain distinct from Forge's stored conversation history. Neither provider is described as universally EU-only or zero retention.

AWS hosting and OpenAI model processing are relevant subprocessors for the customer technical-work data they receive. Auth0's role in instructed user identity processing must be distinguished from Ready IT's own account administration. Microsoft 365/Graph receives contact correspondence and contract mail; it is a subprocessor under this agreement only to the extent Ready IT instructs it to process the customer's controlled data on the customer's behalf. Stripe's own payment/legal processing is not automatically a technical-work subprocessor relationship.

For Microsoft Exchange Online/Graph processing within this agreement's scope, the ordinary Microsoft agreement incorporates the Products and Services DPA. Its May 2026 Data Transfers provisions cover the United States and other Microsoft/subprocessor operating countries with the stated location safeguards and 2021 SCCs for EEA transfers. The DPA identifies the Microsoft Ireland Operations Limited to Microsoft Corporation SCC arrangement; those transfer entities are not an invented description of Ready IT's billing counterparty. Contract-mail application sending permissions are restricted to one mailbox.

Okta, Inc. supplies Auth0 Free through the EU tenant under Ready IT's existing standard online terms. Its function is authentication and identity/access processing of sign-in identity/profile information and security metadata; Forge separately controls workspace membership and permissions. Its role in customer-instructed identity processing is distinct from Ready IT's own account administration. The EU tenant does not establish EEA-only support or onward processing.

Okta's published processing/security terms and January 2026 DPA are available at https://www.okta.com/legal/trustandcompliance/. That published DPA describes SCCs for restricted transfers within its scope. This annex does not represent a separately signed Okta DPA, vendor-confirmed Free-plan coverage or an independent certification of those arrangements.

General subprocessor authorisation applies to the identified on-behalf processing and its applicable arrangements, not an undisclosed additional purpose. Supplier terms/safeguards can be obtained through contact@readyit.dk.

The customer may send specific instructions, rights requests and an end-of- service return/deletion choice to contact@readyit.dk. Directory/case records have no general automatic expiry; scratch-file expiry, access-audit retention and financial records follow their distinct purposes. The end-of-processing obligation below is not replaced by those application timers.

The controlled manual process for return/deletion requests and restoration reconciliation has been adopted. Matt handles the request, verifies its scope and authority, and records affected data/copies, continuing recovery dependencies and any specific retention exception. A superseded recovery copy is reviewed when its rollback need ends and a suitable successor recovery route is established. Before restored data is released, the affected scope is reconciled against completed deletions, restrictions and pending rights cases. Actions, remaining copies and exceptions are recorded separately from the intake decision.

The rolling seven-generation automatic snapshot policy and the historical local rollback/migration copies are identified. They are not unknown storage systems, and no automatic purge or completed customer-data erasure is asserted.

The manual execution route uses authorised, customer/workspace-scoped PostgreSQL administration and access to specifically identified service files. The operator determines the relevant record/file scope, relationships and protections, including protected conversation material, and any applicable retention exception for the particular instruction before execution. No generic automated tenant-wide export/erasure endpoint or previously completed customer deletion is represented by this arrangement.

The historical recovery copies have a recorded disposition queue. The current release's predeployment context is temporarily retained for its identified rollback dependency; continuing need for the other historical copies remains unresolved and subject to a bounded review. Those unresolved copies are neither invented legal holds nor already-disposed data. Disposal candidates remain separate from authority to execute a specific operation.

Required processing terms

  1. Ready IT processes personal data only on documented controller instructions, including instructions on transfers outside the EU/EEA, unless applicable Union or Member State law requires otherwise. In that case it informs the controller of the legal requirement before processing unless that law prohibits notification on important public-interest grounds.

  2. Persons authorised to process personal data must be committed to confidentiality or subject to an appropriate statutory confidentiality duty. Ready IT implements the measures required by GDPR Article 32.

  3. The controller gives general written authorisation for the subprocessors identified in the completed annex. Ready IT informs the controller of intended additions or replacements so the controller has an opportunity to object. No undisclosed list or blank annex establishes authorisation for a supplier. Ready IT imposes the same applicable data-protection obligations by contract on subprocessors, including sufficient guarantees for appropriate technical and organisational measures, and remains responsible to the controller for the subprocessor's performance of those obligations.

  4. Taking account of the nature of processing, Ready IT assists the controller through appropriate technical and organisational measures, insofar as possible, to fulfil obligations to respond to data-subject rights requests. It assists compliance with GDPR Articles 32-36, taking account of the nature of processing and information available to it.

  5. Ready IT notifies the controller without undue delay after becoming aware of a personal-data breach. This does not replace the controller's own applicable notification and communication obligations.

  6. At the controller's choice, Ready IT deletes or returns all personal data after the end of the processing services and deletes existing copies unless Union or Member State law requires retention. The actual return/deletion and backup arrangements must be recorded consistently with this obligation.

  7. Ready IT makes available information necessary to demonstrate compliance with GDPR Article 28 and allows for and contributes to audits, including inspections, conducted by the controller or an auditor mandated by it.

  8. Ready IT immediately informs the controller if, in its opinion, an instruction infringes GDPR or other Union or Member State data-protection provisions.