Data Processing Agreement

Last updated: July 17, 2026

Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between a37 Inc. ("Processor" or "Forge") and the entity agreeing to these terms ("Controller" or "Customer") for the provision of our AI security, governance, and observability platform and related services (the "Services").

This DPA applies where and only to the extent that Forge processes Personal Data on behalf of the Customer in the course of providing the Services, and such Personal Data is subject to Data Protection Laws of the European Union, the European Economic Area, the United Kingdom, or Switzerland, or to U.S. state privacy laws. The additional terms in the section titled "United States State Privacy Laws" apply to Personal Data subject to U.S. state privacy laws.

Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Forge on behalf of the Customer.
  • "Data Protection Laws" means all applicable laws relating to data protection and privacy, including the GDPR (EU 2016/679), the UK GDPR, the Swiss Federal Act on Data Protection, and U.S. state privacy laws (including the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), and comparable laws in other U.S. states).
  • "Business," "Service Provider," "Sell," "Share," and "Deidentified" have the meanings given to them under the applicable U.S. state privacy laws. For Personal Data subject to those laws, the Customer is the Business and Forge is the Service Provider.
  • "Sub-processor" means any third party engaged by Forge to process Personal Data on behalf of the Customer.
  • "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
  • "Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.

Scope and Purpose of Processing

Forge will process Personal Data only as necessary to provide the Services to the Customer and in accordance with the Customer's documented instructions. The details of the processing are as follows:

Subject Matter: Provision of Forge's AI security, governance, and observability Services, including discovery, inventory, monitoring, and policy enforcement across the AI activity and sources the Customer connects.

Duration: For the term of the agreement between Forge and the Customer, plus the period until deletion of all Personal Data.

Nature and Purpose: Processing of Customer Data to detect, inventory, analyze, and govern AI activity, to generate findings and evidence, and to enforce policies as part of the Services.

Categories of Data Subjects: Customer employees, contractors, end users, and other individuals whose data is included in Customer Data.

Types of Personal Data: Name, email address, job title, IP address, usage data, and any other Personal Data contained within Customer Data submitted to the Services.

Obligations of the Processor

Forge shall:

  • Process Personal Data only on documented instructions from the Customer, unless required by applicable law
  • Not sell or share Personal Data, and process Personal Data only for the purposes of providing the Services and, on a de-identified and aggregated basis, to operate, secure, and improve the quality of the Services, as permitted by applicable law
  • Ensure that persons authorized to process Personal Data have committed themselves to confidentiality
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
  • Not engage another processor without prior specific or general written authorization of the Customer
  • Assist the Customer in responding to requests from Data Subjects exercising their rights under Data Protection Laws
  • Assist the Customer in ensuring compliance with obligations related to security of processing, data protection impact assessments, and prior consultation with supervisory authorities
  • At the choice of the Customer, delete or return all Personal Data after the end of the provision of Services, and delete existing copies unless storage is required by law
  • Make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for audits

AI and Model Training

Forge will not use Personal Data to train, fine-tune, or improve any foundation model, large language model, chatbot, or other generally available machine-learning model or artificial intelligence tool, and will not otherwise use Personal Data to make inferences about any Data Subject except as necessary to provide the Services to the Customer in accordance with the Customer's documented instructions.

Forge may operate, secure, analyze, and improve the Services and develop its models only using data that is de-identified and aggregated so that it cannot reasonably be associated with the Customer or any Data Subject. Forge will not attempt to re-identify any such data except as permitted by applicable law. This section is consistent with, and does not limit, the restrictions in the "United States State Privacy Laws" section below.

Security Measures

Forge implements and maintains appropriate technical and organizational security measures, including:

  • Encryption of Personal Data in transit (TLS 1.3) and at rest (AES-256)
  • Measures to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems
  • Regular testing, assessing, and evaluating the effectiveness of security measures
  • Infrastructure and processes designed to meet the SOC 2 Type II criteria
  • Role-based access controls and multi-factor authentication
  • Regular security training for all personnel with access to Personal Data

Sub-processors

The Customer provides general authorization for Forge to engage sub-processors. Forge maintains a current list of sub-processors at forge.ai/subprocessors.

Forge will notify the Customer of any intended changes to the list of sub-processors at least 30 days in advance, giving the Customer the opportunity to object. If the Customer objects, Forge will make reasonable efforts to provide an alternative or the Customer may terminate the affected Services.

Where Forge engages a sub-processor, it shall impose data protection obligations no less protective than those set out in this DPA by way of a contract. Forge remains fully liable for the performance of its sub-processors.

International Data Transfers

Forge will not transfer Personal Data to a country outside the European Economic Area, the United Kingdom, or Switzerland unless appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission
  • An adequacy decision by the relevant authority

Data Breach Notification

Forge will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach. The notification will include:

  • A description of the nature of the breach, including categories and approximate number of Data Subjects and records concerned
  • The name and contact details of Forge's contact point for further information
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach

Data Subject Rights

Forge will assist the Customer in fulfilling its obligations to respond to Data Subject requests, including requests for access, rectification, erasure, restriction, portability, and objection. Forge will promptly notify the Customer if it receives a request directly from a Data Subject and will not respond to such request unless authorized by the Customer or required by applicable law.

Audit Rights

Forge will make available to the Customer on request all information reasonably necessary to demonstrate compliance with this DPA. The Customer may conduct an audit, either itself or through an appointed third-party auditor, with reasonable advance notice and during normal business hours. Forge will cooperate with such audits and provide reasonable assistance.

United States State Privacy Laws

This section applies to Personal Data subject to U.S. state privacy laws, including the CCPA. For such Personal Data, the Customer is the Business and Forge is the Service Provider, and Forge processes Personal Data solely to perform the Services under the agreement between the parties (the "Business Purpose").

Forge will:

  • Not Sell or Share Personal Data, and not retain, use, or disclose Personal Data for any purpose other than the Business Purpose or as otherwise permitted by applicable U.S. state privacy laws
  • Not retain, use, or disclose Personal Data outside the direct business relationship between the parties
  • Not combine Personal Data with personal information from other sources, except as permitted by applicable U.S. state privacy laws (for example, to detect security incidents or protect against fraudulent or illegal activity)
  • Comply with its obligations under applicable U.S. state privacy laws, provide the level of privacy protection those laws require, and notify the Customer if it determines it can no longer meet those obligations
  • Where either party discloses Deidentified data, maintain and use it only in deidentified form and not attempt to reidentify it, except as permitted by applicable law

The Customer may take reasonable and appropriate steps to help ensure that Forge uses Personal Data consistent with the Customer's obligations under applicable U.S. state privacy laws, and to stop and remediate any unauthorized use. Forge certifies that it understands and will comply with the restrictions in this section.

Term and Termination

This DPA shall remain in effect for the duration of Forge's processing of Personal Data on behalf of the Customer. Upon termination of the Services, Forge will, at the Customer's choice, delete or return all Personal Data within 90 days, except where retention is required by applicable law. Forge will, on the Customer's written request, certify in writing that it has done so. This obligation does not apply to data that Forge holds in de-identified and aggregated form that cannot reasonably be associated with the Customer or any Data Subject, which Forge may retain as described in the "AI and Model Training" section.

Contact Us

For questions about this DPA or to request a signed copy, please contact us:

a37 Inc.

Email: team@forge.ai