FORGE Data Processing Addendum
Version date: August 15, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement governing a customer’s use of this service (the “Agreement”) between Mediator Solutions LLC (“Provider”) and the customer identified in the Agreement (“Customer”).
This DPA applies to Provider’s processing of Customer Personal Data on Customer’s behalf in connection with the FORGE Service.
If Customer and Provider have signed a separate data processing agreement covering the same processing, the signed agreement supersedes this DPA to the extent of a conflict.
1. Definitions
1.1 Applicable Data Protection Law
“Applicable Data Protection Law” means a privacy, data-protection, or data-security law that applies to the processing of Customer Personal Data under the Agreement, including where applicable U.S. state comprehensive privacy laws and regulations.
The phrase does not imply that every privacy statute applies to Provider or Customer in every circumstance. Applicability depends on the relevant law’s territorial scope, thresholds, exemptions, entity type, data type, and processing activity.
1.2 Customer Data
“Customer Data” has the meaning stated in the FORGE Terms of Service.
1.3 Customer Personal Data
“Customer Personal Data” means personal information, personal data, or a similar category of information contained in Customer Data that Provider processes on behalf of Customer and that is protected by Applicable Data Protection Law.
1.4 Controller and Processor
“Controller” includes a “business” or other entity that determines the purposes and means of processing personal data. “Processor” includes a “service provider,” “contractor,” or other entity that processes personal data on behalf of a Controller, as those terms are defined by Applicable Data Protection Law.
1.5 Security Incident
“Security Incident” means a confirmed unauthorized acquisition of, access to, use of, disclosure of, alteration of, or destruction of Customer Personal Data in Provider’s possession or control that triggers a notification or response obligation under Applicable Data Protection Law.
Unsuccessful attempts, scans, pings, denial-of-service attacks, blocked requests, or other events that do not compromise Customer Personal Data are not Security Incidents for purposes of this DPA.
1.6 Subprocessor
“Subprocessor” means a third party engaged by Provider to process Customer Personal Data on Provider’s behalf in connection with the Service.
2. Roles of the parties
2.1 Customer as Controller
For Customer Personal Data, Customer generally acts as the Controller and determines:
- what Customer Personal Data is entered into FORGE;
- why Customer collects or uses that data;
- which people Customer authorizes to access the workspace;
- how long Customer needs the data, subject to product and legal constraints;
- whether Customer has a lawful basis or permission to process the data.
2.2 Provider as Processor
Provider acts as Processor for Customer Personal Data to the extent Provider processes it solely to provide, secure, support, maintain, or improve the Service on Customer’s documented instructions and for purposes permitted by the Agreement and Applicable Data Protection Law.
2.3 Provider’s independent processing
Provider may act as an independent Controller or business for limited information processed for Provider’s own legitimate purposes, such as:
- account administration;
- direct billing records;
- Provider’s legal and tax obligations;
- fraud prevention;
- security of Provider systems;
- enforcing the Agreement;
- establishing or defending legal claims;
- service communications with Provider’s own users;
- information Provider is required by law to retain or process independently.
Such processing is governed by the FORGE Privacy Policy and Applicable Data Protection Law rather than by Customer’s instructions under this DPA.
3. Customer instructions
Provider will process Customer Personal Data only:
- to provide the Service described in the Agreement;
- as necessary to perform Customer’s configuration and actions in the Service;
- according to Customer’s documented support or account instructions;
- as otherwise expressly permitted by the Agreement or this DPA;
- where required by applicable law.
The Agreement, Customer’s configuration and use of the Service, and Customer’s authorized support requests constitute Customer’s documented instructions.
If Provider reasonably believes an instruction violates Applicable Data Protection Law, Provider may suspend the affected processing and notify Customer unless the law prohibits notice.
4. Purpose limitation
Provider will not process Customer Personal Data for a materially unrelated purpose except:
- on Customer’s documented instruction;
- with lawful authorization from the relevant individual where required;
- as required by law;
- for Provider’s limited independent purposes identified in Section 2.3.
Provider will not sell Customer Personal Data or use Customer Personal Data for cross-context behavioral advertising.
Where a U.S. state privacy law imposes service-provider, processor, or contractor restrictions, Provider will process the covered Customer Personal Data only for the limited and specified purposes stated in the Agreement and this DPA, subject to statutory exceptions.
5. Customer obligations
Customer represents and warrants that:
- it has a lawful basis, right, or authority to collect and disclose Customer Personal Data to Provider;
- it has provided legally required privacy notices;
- its instructions comply with Applicable Data Protection Law;
- it will not instruct Provider to perform unlawful processing;
- it will not use FORGE for prohibited highly sensitive or regulated information unless Provider has expressly agreed in writing to support that use;
- it will reasonably manage workspace access, team invitations, and account security.
Customer remains responsible for responding to individuals about Customer’s own processing purposes, legal basis, retention decisions, and business practices.
6. Confidentiality
Provider will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality.
Provider will limit access to Customer Personal Data to personnel and service providers that reasonably require access to perform their responsibilities.
Customer must likewise maintain appropriate confidentiality controls for its own authorized users.
7. Security measures
Provider will maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, alteration, or disclosure.
Current safeguards may include, as appropriate to the relevant system:
- authenticated server-side access controls;
- secure signed session mechanisms;
- HTTPS/TLS for data in transit;
- encrypted managed database services;
- server-side encryption for stored upload objects;
- limited-duration presigned upload URLs;
- authorization checks that restrict access to the appropriate business or job;
- email-based authentication with short-lived verification codes;
- request-rate limits and authentication-attempt controls;
- logging and monitoring for security, reliability, and abuse prevention;
- payment-card processing through a specialized payment provider rather than routine storage of complete card credentials in FORGE’s application database;
- access restrictions for production systems and infrastructure;
- backup and recovery processes appropriate to the deployed environment.
Customer acknowledges that security controls evolve. Provider may replace a security measure with another measure that provides materially comparable or better protection, taking into account the nature of the Service, risks, technical feasibility, and industry practices.
8. Security Incident response
Provider will maintain procedures for identifying, investigating, containing, and responding to suspected Security Incidents.
If Provider confirms a Security Incident involving Customer Personal Data, Provider will notify Customer without undue delay after confirmation and will provide information reasonably available to Provider that Customer needs to evaluate its own notification obligations.
Notification may include, to the extent known and appropriate:
- the nature of the incident;
- categories of affected data;
- approximate categories or number of affected data subjects or records, where reasonably determinable;
- known or likely consequences;
- containment or remediation steps taken or planned;
- a contact point for follow-up.
Provider may provide information in phases as an investigation progresses.
Notification of a Security Incident is not an admission of fault, liability, or legal breach.
Customer is responsible for making notices to its clients, employees, regulators, or other third parties where Customer is legally required to do so, unless Applicable Data Protection Law expressly assigns that obligation to Provider.
9. Subprocessors
Customer authorizes Provider to use Subprocessors to operate the Service.
Provider’s subprocessors are listed in the Subprocessors document.
Provider will require a Subprocessor that processes Customer Personal Data on Provider’s behalf to protect that data through obligations appropriate to the service and Applicable Data Protection Law.
Provider remains responsible for the performance of its Subprocessors to the extent required by the Agreement and Applicable Data Protection Law.
10. Changes to Subprocessors
Provider may add, replace, or remove Subprocessors as the Service evolves.
If a signed order form or enterprise agreement requires advance notice of new material Subprocessors, Provider will provide that notice by the method and within the period stated in that agreement.
For ordinary self-service Service, publication of an updated Subprocessor list, email, in-product notice, or another reasonable channel may serve as notice where legally sufficient.
If Applicable Data Protection Law gives Customer a right to object to a new Subprocessor, Customer must make a good-faith objection based on a reasonable data-protection concern. The parties will attempt to resolve the concern, which may include reasonable configuration changes, an alternative provider where commercially feasible, or termination of the affected Service if no reasonable solution exists.
11. Individual and consumer rights
Taking into account the nature of the processing and information available to Provider, Provider will provide reasonable assistance to Customer in responding to verified requests from individuals exercising rights under Applicable Data Protection Law.
Such requests may include access, correction, deletion, portability, or objection rights where applicable.
If an individual sends Provider a request concerning Customer Personal Data for which Customer is the Controller, Provider may:
- refer the individual to Customer;
- notify Customer of the request;
- act on the request only on Customer’s documented instruction, except where law requires Provider to act independently.
Provider is not required to disclose Customer’s confidential account information to a requester who cannot be appropriately verified.
12. Deletion and return
During the subscription, Customer may use available Service functions to retrieve, modify, archive, or delete Customer Data.
After termination or expiration, Provider will delete or return Customer Personal Data according to the Agreement, Customer’s documented instructions, the capabilities of the Service, and Provider’s ordinary retention and backup processes, unless law requires continued retention.
Customer acknowledges that:
- deletion from active production tables or interfaces may not instantly erase encrypted backups;
- security logs, payment records, legal holds, dispute records, and accounting information may be retained for lawful purposes;
- backup copies may remain isolated until overwritten or expired according to the applicable backup cycle;
- data retained solely for legal or backup purposes will remain protected and will not be returned to ordinary production use except for recovery, security, legal compliance, or another legitimate purpose.
13. Data minimization
Provider designs FORGE to process information reasonably related to the Service. Customer is responsible for avoiding unnecessary personal data in free-form notes, uploads, and business records.
Provider may implement size limits, field limits, file-type restrictions, retention tools, or other controls that reduce unnecessary risk.
14. Highly sensitive and regulated data
Unless expressly agreed in writing, the Service is not intended as the system of record for:
- protected health information requiring a HIPAA business associate agreement;
- full payment-card credentials;
- Social Security numbers or equivalent government identifiers;
- private cryptographic keys or seed phrases;
- classified information;
- biometric identification templates;
- information requiring specialized government or defense accreditation;
- other categories identified as prohibited in the Terms or Acceptable Use Policy.
Customer must not infer that Provider accepts a specialized regulated-data obligation merely because a general text field or upload feature can technically receive the data.
15. Audits and compliance information
Where Applicable Data Protection Law requires Provider to make information available demonstrating compliance with processor obligations, Provider will provide reasonable information appropriate to the Service and the risk.
Unless a signed enterprise agreement provides broader rights, Customer’s audit right will ordinarily be satisfied through one or more of:
- written responses to reasonable security or privacy questionnaires;
- copies or summaries of relevant third-party reports that Provider is permitted to share;
- documentation of Provider’s security practices;
- a remote compliance meeting;
- another reasonable evidence mechanism.
Customer may not conduct penetration testing, production vulnerability scanning, physical data-center inspection, access to another customer’s data, or access to Provider source code under this Section unless Provider separately authorizes the activity in writing.
If an on-site audit is legally required and cannot reasonably be satisfied by existing documentation, the parties will agree on scope, timing, confidentiality, security, and cost allocation. Audits must not unreasonably disrupt Provider’s business or compromise other customers.
16. Regulatory inquiries
Provider will reasonably assist Customer with a regulator inquiry concerning Provider’s processing of Customer Personal Data where:
- the inquiry is legally valid;
- the requested information is within Provider’s control;
- Customer provides reasonable notice and context;
- the assistance does not require Provider to waive privilege or disclose another customer’s confidential information.
Provider may charge reasonable fees for unusually burdensome assistance not caused by Provider’s breach, if permitted by the Agreement and Applicable Data Protection Law.
17. Government requests
If Provider receives a legally binding request from a government authority for Customer Personal Data, Provider will, unless prohibited by law:
- review the request for apparent legal validity;
- seek clarification or narrow an overbroad request where reasonably appropriate;
- notify Customer where legally permitted and appropriate;
- disclose only information reasonably responsive to the valid request.
Provider is not required to litigate every government request at its own expense.
18. International transfers
Provider is a U.S. entity, and Customer Personal Data may be processed in the United States and other jurisdictions in which Provider or its Subprocessors operate.
This U.S. DPA does not by itself constitute European Union Standard Contractual Clauses, the U.K. International Data Transfer Addendum, or another jurisdiction-specific international transfer instrument.
If a non-U.S. market or Customer requires a specific transfer mechanism, the parties must enter or incorporate the applicable transfer terms before relying on this DPA as the sole transfer mechanism.
19. California service-provider and contractor commitments
To the extent the CCPA applies and Provider receives Personal Information from Customer in a service-provider or contractor role, Provider will:
- process the Personal Information only for the business purposes and services specified in the Agreement and this DPA or as otherwise permitted by the CCPA;
- not sell or share the Personal Information as those terms are defined by the CCPA, except as legally permitted within the service-provider or contractor relationship;
- not retain, use, or disclose Personal Information outside the direct business relationship except as permitted by law;
- not combine Customer Personal Data with personal information received from another person or collected from Provider’s own interaction with an individual except as permitted by applicable CCPA rules;
- provide the same level of privacy protection required by applicable provisions of the CCPA for the covered processing;
- notify Customer if Provider determines it can no longer meet an applicable service-provider obligation and allow Customer to take reasonable steps to stop and remediate unauthorized use where required by law.
Nothing in this Section prevents Provider from using information for security, fraud prevention, debugging, internal Service quality, legal compliance, or another purpose expressly permitted to a service provider or contractor by applicable law.
20. Other U.S. state processor commitments
Where another U.S. state privacy law applies to Provider as Customer’s processor, Provider will comply with processor obligations applicable to the covered processing, which may include:
- processing according to Customer instructions;
- confidentiality;
- appropriate security;
- reasonable assistance with consumer rights;
- assistance concerning security and data-protection assessments where required;
- subprocessor contractual controls;
- deletion or return at the end of services subject to legal exceptions;
- providing information reasonably necessary to demonstrate compliance.
The parties intend this DPA to satisfy generally applicable processor-contract requirements to the extent reasonably possible without pretending that every state’s statute uses identical language.
21. Artificial intelligence and model training
Provider will not use Customer Personal Data to train a general-purpose public artificial-intelligence model unless:
- the Agreement is updated to permit that use;
- Customer provides any contractually required authorization;
- Provider provides any legally required notice;
- any legally required consent or opt-out is honored.
This restriction does not prohibit security systems, fraud detection, ordinary software logic, or internal analytics that do not constitute general-purpose public model training.
22. De-identified and aggregated information
Provider may create aggregated or de-identified information from Service operations where permitted by law, provided Provider takes reasonable measures designed to prevent the information from being used to identify an individual where the law requires such measures.
Provider will not attempt to re-identify information that has been de-identified under a law that prohibits re-identification, except to test whether de-identification controls are effective where legally permitted.
23. Business continuity and backups
Provider may maintain encrypted or otherwise protected backups and disaster-recovery copies to support Service continuity and recovery.
Backups may not reflect deletion or correction immediately. If a backup is restored, Provider will use reasonable processes to reapply applicable deletions or corrections where practicable and legally required.
24. Cooperation
Each party will provide the other with information reasonably necessary to meet applicable privacy obligations, taking into account the nature of the Service and the information available to that party.
Neither party is required to disclose privileged material, another customer’s confidential information, internal security details that would create material risk, or information it is legally prohibited from disclosing.
25. Liability
The liability provisions, disclaimers, exclusions, and caps in the Agreement apply to this DPA unless a signed agreement expressly states otherwise or Applicable Data Protection Law prohibits application of a particular limitation.
26. Term and survival
This DPA remains in effect while Provider processes Customer Personal Data under the Agreement.
Confidentiality, security, deletion, legal-retention, liability, and other provisions that by their nature must continue after termination will survive for as long as Provider retains Customer Personal Data.
27. Conflict
For matters specifically concerning processing of Customer Personal Data:
- a mutually signed market-specific DPA or transfer addendum controls;
- a mutually signed enterprise agreement or order form controls to the extent it expressly modifies data-processing obligations;
- this DPA controls;
- the general Terms control.
28. Governing law
Unless a signed agreement or non-waivable Applicable Data Protection Law requires otherwise, this DPA is governed by the governing-law and venue provisions in the FORGE Terms of Service.
Annex I — Details of Processing
A. Subject matter
Provider processes Customer Personal Data to provide the FORGE business-management Service, including authentication, workspace administration, client/contact records, job records, estimates, invoices, receipts, team access, authorized file uploads, customer support, billing entitlement, security, and related operational functions.
B. Duration
Processing continues for the term of the Agreement and for a reasonable post-termination period necessary for deletion, return, backup expiration, legal retention, dispute handling, security, accounting, and compliance.
C. Nature and purpose
Processing operations may include collection, receipt, organization, storage, retrieval, consultation, display, transmission to authorized users or Subprocessors, modification at Customer’s direction, generation of business documents, backup, security analysis, deletion, and other operations required to provide the Service.
D. Categories of data subjects
Depending on Customer’s use, data subjects may include:
- Customer account owners;
- Customer’s employees, contractors, and team members;
- Customer’s clients or customers;
- prospective clients entered by Customer;
- vendors and business contacts;
- individuals appearing in job photographs or records where Customer lawfully uploads such information;
- support contacts.
E. Categories of Customer Personal Data
Depending on use:
- names;
- business names;
- email addresses;
- phone numbers;
- service or job addresses;
- notes and descriptions;
- job details and status;
- estimate and invoice information;
- due dates and payment status;
- photographs and uploaded images;
- team membership information;
- internal Customer identifiers entered into supported fields;
- related business correspondence.
F. Special categories / highly sensitive data
No special category or highly sensitive data is required for ordinary FORGE operation. Customer is instructed not to use FORGE as a repository for prohibited highly sensitive or specially regulated data unless a signed agreement expressly authorizes the use case.
Annex II — Technical and Organizational Measures
Provider’s measures are risk-based and may evolve. Current controls include, as applicable:
A. Access control
- authenticated user sessions;
- role and workspace-based authorization checks;
- business ownership and membership controls;
- restrictions on upload access;
- account and team invitation controls.
B. Authentication
- passwordless email verification;
- six-digit random verification codes;
- short expiration periods;
- hashed or cryptographically derived code verification values;
- request-rate limiting;
- attempt limits;
- secure signed session cookies.
C. Encryption
- TLS/HTTPS for network transport on deployed Service routes;
- managed encrypted database infrastructure;
- server-side encryption for supported object uploads;
- payment credentials handled by a specialized payment provider rather than stored in ordinary application records.
D. Data isolation
- business/workspace identifiers associated with business records;
- server-side authorization before data operations;
- upload keys scoped to authorized business/job contexts;
- database relationships and constraints that preserve workspace boundaries.
E. Availability and resilience
- managed infrastructure;
- cloud-provider redundancy and recovery capabilities appropriate to deployed services;
- backups or recovery mechanisms appropriate to the relevant service;
- controlled deployment and source management.
F. Logging and incident response
- application and infrastructure diagnostics;
- billing event deduplication and reconciliation records;
- security and authentication logs appropriate to the Service;
- procedures to investigate and respond to suspected incidents.
G. Data minimization
- bounded account fields;
- file-type and file-size restrictions;
- guidance prohibiting unnecessary sensitive information;
- product limits on user and business capacity;
- limited-purpose processing.
H. Vendor management
- use of established cloud, payment, email-delivery, and hosting providers;
- provider terms and data-protection commitments appropriate to their functions;
- maintenance of a Subprocessor list;
- ability to replace providers when necessary for security, reliability, legal, or operational reasons.
Annex III — Contact
Mediator Solutions LLC
Email: [email protected]