Last updated: September 2026
This Data Processing Agreement (“DPA”) forms a schedule to, and is part of, the ForgeFox Terms of Service (the “Terms”) between:
ForgeFox is registered with the Information Commissioner’s Office (ICO), registration reference ZC195932.
This DPA applies to the extent that ForgeFox processes personal data on behalf of the Operator in connection with the ForgeFox platform (the “Service”). How ForgeFox handles personal data for its own purposes is explained in our Privacy Policy.
1.1 Terms used in this DPA have the meaning given in UK Data Protection Law. In addition:
1.2 A reference to a statute or statutory provision is a reference to it as amended or re-enacted.
2.1 For the purposes of UK Data Protection Law, the Operator is the Controller of the Controller Personal Data (typically the personal data of the Operator’s own clients and, where applicable, staff), and ForgeFox is the Processor, processing that Personal Data only on behalf of and on the documented instructions of the Operator.
2.2 ForgeFox is an independent Controller only for Personal Data it processes for its own purposes (for example, the Operator’s own account, billing and support data). That processing is covered by the ForgeFox Privacy Policy, not by this DPA.
2.3 Each party will comply with its obligations under UK Data Protection Law. The Operator is responsible for having a lawful basis (and, where Special Category Data is involved, a valid Article 9 condition) for the Processing it instructs ForgeFox to carry out, and for giving all necessary notices to, and where required obtaining consents from, Data Subjects.
3.1 Subject-matter. The provision of the Service, a multi-tenant booking and business-management platform, under which ForgeFox processes Controller Personal Data on the Operator’s behalf.
3.2 Duration. For the term of the Terms and until deletion or return of the data under clause 10.
3.3 Nature and purpose. Collection, recording, organisation, structuring, storage, retrieval, transmission, hosting, display and deletion of Personal Data, carried out only to provide and support the Service, including online booking, customer records, digital waivers, appointment confirmations and reminders, payment facilitation (including saved cards for no-show fees where the Operator enables them), member attendance records, video hosting where enabled, and related business-management functions.
3.4 The types of Personal Data and categories of Data Subjects are set out in Annex 1.
ForgeFox will:
4.1 Documented instructions. Process Controller Personal Data only on the Operator’s documented instructions (including about international transfers), unless required to do otherwise by law, in which case ForgeFox will, where legally permitted, tell the Operator of that legal requirement before Processing. The Terms, this DPA, and the Operator’s use of the configuration options within the Service are the Operator’s complete and documented instructions. ForgeFox will tell the Operator if, in its opinion, an instruction infringes UK Data Protection Law.
4.2 Confidentiality. Ensure that people authorised to process Controller Personal Data are bound by an appropriate duty of confidentiality and process the data only as needed to perform their duties.
4.3 Security (Article 32). Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2.
4.4 Data Subject rights. Taking into account the nature of the Processing, assist the Operator by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights (including access, rectification, erasure, restriction, portability and objection). If a Data Subject sends such a request directly to ForgeFox, ForgeFox will promptly forward it to the Operator and will not respond directly except to confirm receipt or on the Operator’s instructions.
4.5 Compliance duties. Taking into account the nature of Processing and the information available to ForgeFox, assist the Operator in meeting its obligations under Articles 32 to 36 of the UK GDPR, including security of processing, Personal Data Breach notification, communicating breaches to Data Subjects, data protection impact assessments, and prior consultation with the ICO.
4.6 Breach notification. Notify the Operator without undue delay after becoming aware of a Personal Data Breach affecting Controller Personal Data, as set out in clause 9.
4.7 Records. Keep records of processing activities carried out on behalf of the Operator as required by Article 30(2) of the UK GDPR.
5.1 General authorisation. The Operator gives ForgeFox general written authorisation to engage Sub-processors to process Controller Personal Data, subject to this clause 5. The Sub-processors authorised at the date of this DPA are listed in Annex 3.
5.2 Flow-down terms. ForgeFox will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA (in particular the requirements of Article 28(3) of the UK GDPR). If a Sub-processor fails to meet its data protection obligations, ForgeFox remains fully liable to the Operator for that Sub-processor’s performance.
5.2A Payment providers. Stripe, Square, SumUp and PayPal are not ForgeFox Sub-processors. The Operator connects its own account with its chosen payment provider and contracts with that provider directly, and the provider acts as an independent controller for the payment data it processes (as required of it by financial services and anti-money-laundering law). ForgeFox passes a customer’s booking and contact details to the Operator’s payment provider only on the Operator’s instruction, to take the payment or save the card the customer has agreed to. The Operator is responsible for its own agreement with that provider. These providers are listed in Part B of Annex 3 for transparency.
5.3 Changes and objection. ForgeFox will give the Operator prior notice (for example by email to the Operator’s account contact and/or by updating Annex 3 on this page) of any intended addition or replacement of a Sub-processor, so the Operator can object. If the Operator has a reasonable, data-protection-related objection, the parties will discuss it in good faith. If it cannot be resolved, the Operator may, as its sole remedy, end the affected part of the Service under the Terms.
6.1 ForgeFox will store and process Controller Personal Data in the United Kingdom and/or the European Economic Area (EEA) where reasonably practicable. In particular, ForgeFox’s primary database, authentication and file storage (Supabase) are hosted in the EU.
6.2 Where providing the Service requires a transfer of Controller Personal Data to a country outside the UK that is not covered by UK adequacy regulations, ForgeFox will ensure an appropriate transfer mechanism is in place, such as the UK IDTA, the UK Addendum to the EU SCCs, or a valid adequacy decision (for example the UK Extension to the EU-US Data Privacy Framework), together with any supplementary measures required following a transfer risk assessment.
6.3 Some Sub-processors listed in Annex 3 (for example, payment, messaging and hosting providers) may process limited Personal Data outside the UK/EEA. Where they do, ForgeFox relies on the mechanisms in clause 6.2 and the Sub-processors’ own certifications and contractual safeguards.
7.1 ForgeFox will make available to the Operator all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Operator or an auditor mandated by the Operator.
7.2 ForgeFox may first provide relevant third-party certifications, audit reports or a completed security questionnaire. If these are not enough to demonstrate compliance, the Operator may request an audit, which will be: (a) on reasonable prior written notice (at least 30 days, except where required sooner by the ICO or following a Personal Data Breach); (b) during normal business hours; (c) no more than once in any 12-month period unless required by the ICO or following a Personal Data Breach; (d) carried out so as to minimise disruption to ForgeFox’s business; and (e) subject to appropriate confidentiality obligations. The Operator will bear its own audit costs.
8.1 The Operator warrants that its instructions and the Controller Personal Data comply with UK Data Protection Law, and that it has given all required privacy notices and, where relevant, obtained all required consents, including, where the Operator collects Special Category Data (such as health information in digital waivers or intake forms), a valid condition for processing under Article 9 of the UK GDPR. The Operator, as Controller, decides whether and how to collect such data using the Service.
8.2 The Operator will also meet the operator obligations set out in the Terms, including publishing its own privacy notice and telling customers about no-show fees and member attendance rules before they book or join.
9.1 ForgeFox will notify the Operator without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Controller Personal Data.
9.2 The notification will, to the extent known and permitted by law, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and reduce its effects, together with a point of contact.
9.3 ForgeFox will cooperate with the Operator and take reasonable steps as directed by the Operator to help investigate, mitigate and remedy the breach. As between the parties, the Operator (as Controller) is responsible for any notification to the ICO and/or affected Data Subjects, unless agreed otherwise in writing.
10.1 During the term, ForgeFox will delete or anonymise a Data Subject’s Personal Data when the Operator instructs it to, for example by using the erasure tools in the Service. On termination or expiry of the Terms, ForgeFox will, at the Operator’s choice, delete or return all Controller Personal Data and delete existing copies, unless UK law requires continued storage.
10.2 Unless the Operator instructs otherwise, ForgeFox will take the Operator’s booking page offline immediately on cancellation, keep Controller Personal Data for 30 days after the account closes, and then permanently delete or anonymise it. ForgeFox keeps financial and legal records (such as payment and invoice records and the Operator’s acceptance of the Terms) for 6 years from the end of the financial year they relate to, for tax and company-law purposes, with Data Subjects’ names and contact details removed.
10.3 Signed waivers. The Operator instructs ForgeFox to keep each signed waiver (including any health information in it) so the Operator can defend a legal claim, for 6 years after the date of the booking it relates to or, if the person it covers was under 18 when it was signed, until that person’s 21st birthday, whichever is later. ForgeFox then deletes it. This applies after the account closes and after a Data Subject asks for erasure, but only for as long as set out here. During that time ForgeFox stores the waiver securely, does not use it for anything else, and gives it only to the Operator or where the law requires. The Operator may instruct ForgeFox to delete waivers sooner.
10.4 This DPA continues to apply to any retained data for as long as it is held.
11.1 Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms. This DPA does not increase either party’s aggregate liability beyond the cap in the Terms, except to the extent such a limitation is not permitted by UK Data Protection Law.
12.1 Order of precedence. If this DPA and the Terms conflict about the Processing of Controller Personal Data, this DPA prevails.
12.2 Governing law and jurisdiction. This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
12.3 Changes to this DPA. ForgeFox may update this DPA to reflect changes in law, Sub-processors or the Service, in line with the change-notification provisions of the Terms. Material changes will be notified to the Operator.
Categories of Data Subjects
Types of Personal Data
Nature and purpose of processing
Provision, operation and support of the Service, as described in clause 3.
Duration
For the term of the Terms and until deletion or return under clause 10.
Without limiting clause 4.3, ForgeFox implements measures including:
These measures are reviewed and updated as the Service and the state of the art change.
Part A: Sub-processors
| Sub-processor | Purpose | Primary processing location |
|---|---|---|
| Supabase | Database, authentication and file storage hosting | EU |
| Vercel | Application hosting | US, and a global network (with appropriate safeguards) |
| Brevo | Transactional email and SMS | EU |
| Twilio | SMS messaging (booking confirmations and reminders) | UK / EEA / US (with appropriate safeguards) |
| PostHog | Product analytics and fault diagnosis (form inputs masked) | EU |
| Cloudflare | Video hosting and delivery (Cloudflare Stream) | Global network, including the US (with appropriate safeguards) |
| Upstash | Rate-limiting. Not currently in use; listed because it may be re-enabled | EU / US (with appropriate safeguards) |
Part B: Payment providers (independent controllers, see clause 5.2A)
| Provider | Purpose | Primary processing location |
|---|---|---|
| Stripe | Payment processing, including saved cards for no-show fees | UK / EEA / US (with appropriate safeguards) |
| Square | Payment processing, including saved cards for no-show fees | UK / EEA / US (with appropriate safeguards) |
| SumUp | Payment processing | UK / EEA (with appropriate safeguards) |
| PayPal | Payment processing | UK / EEA / US (with appropriate safeguards) |
Part C: Providers that do not receive Controller Personal Data
ForgeFox also uses Anthropic (AI writing tools, US) and Google (business listing look-ups, US). They receive only the Operator’s own business content, such as service descriptions and business details, and never customer data. They are listed here for transparency.
We will update this list as described in clause 5.3.
info@forgefox.uk
ForgeFox Ltd, 124 City Road, London, EC1V 2NX, United Kingdom