FORGE OS
Data Processing Addendum
Last updated: July 28, 2026
This Addendum forms part of the Terms of Service and constitutes the data-processing agreement required by Article 28 GDPR. It applies where you use FORGE OS in a professional capacity and input personal data relating to third parties — for example supplier contacts. Read it with our Privacy Policy.
1. Background and scope
1.1 This Data Processing Addendum (“DPA”) forms part of the FORGE OS Terms of Service (the “Terms”) between the customer identified in the account (“Customer”) and Ateliersavant Europe SAS, SIRET 912 291 283 00014, registered office 17 rue du Pré-Bréda, B.P. 60, 51200 Épernay Cedex, France (“Ateliersavant”, “we”). It is accepted together with the Terms and Privacy Policy through the recorded sign-up acceptance flow.
1.2 This DPA applies where and to the extent the Customer, acting in a professional capacity, inputs, uploads or causes FORGE OS to process personal data relating to third parties (for example supplier contact persons) — “Customer Personal Data” — in respect of which the Customer is a controller under Regulation (EU) 2016/679 (“GDPR”).
1.3 This DPA does not apply to the processing described in Section 2.3 (processing for which Ateliersavant is an independent controller), which is governed by the Privacy Policy.
1.4 In case of conflict, this DPA prevails over the Terms and the Privacy Policy with respect to the processing of Customer Personal Data.
2. Roles
2.1 For Customer Personal Data, the Customer is the controller and Ateliersavant is the processor (Article 28 GDPR).
2.2 Customer warranty. The Customer warrants that it has a valid lawful basis, and has given all required notices and obtained all required consents, for any third-party personal data it inputs into FORGE OS, and that its instructions to Ateliersavant comply with applicable data-protection law. The Customer will indemnify Ateliersavant as set out in the Terms for claims arising from breach of this warranty.
2.3 Independent controller processing. Ateliersavant acts as an independent controller, not as the Customer’s processor, for:
- Customer account and billing data (identity, authentication, subscription, usage);
- aggregated, non-identifiable telemetry as described in the Privacy Policy;
- the FORGE Supplier Registry: company identity, capability signals, certifications and generic business contact points for supplier organisations, generated through AI-assisted research of public sources and verified in the course of campaigns. The Registry is held separately for each Customer account: entries created under one account are not readable by, shared with, or pooled across other Customers, and are deleted when that account is deleted. The Registry never includes the Customer’s identity, the Customer’s commercial terms, quotes, prices, RFQ content or correspondence.
2.4 The legal basis, transparency information and data-subject rights for Section 2.3 processing are set out in the Privacy Policy (Supplier Registry section).
3. Instructions
3.1 Ateliersavant will process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which Ateliersavant is subject; in that case Ateliersavant will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
3.2 The Terms, this DPA, and the Customer’s use of and configuration choices within FORGE OS (including connecting or disconnecting providers, launching campaigns, sending RFQs, and deleting data) constitute the Customer’s complete documented instructions. Additional instructions require written agreement.
3.3 Infringement notice. Ateliersavant will inform the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law. Ateliersavant may suspend the affected processing until the instruction is confirmed or modified, and is not liable for the consequences of such suspension.
4. Confidentiality
Ateliersavant ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security
5.1 Ateliersavant implements and maintains the technical and organisational measures described in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as required by Article 32 GDPR.
5.2 Annex 2 may be updated from time to time, provided the overall level of security is not materially reduced during a subscription term.
6. Sub-processors
6.1 The Customer gives general written authorisationto Ateliersavant’s engagement of the sub-processors listed in the Privacy Policy sub-processor section (the “Sub-processor List”), currently Supabase (database, authentication, storage), Anthropic (AI processing and web search), Vercel (application hosting) and Stripe (payments — Stripe processes Customer billing data as described in the Privacy Policy, rather than Customer Personal Data). Processing locations and transfer safeguards for each are stated in the Sub-processor List.
Services the Customer itself connects — for example the Customer’s own Google account or Telegram chat — are independent services chosen by the Customer, not sub-processors.
6.2 Changes. Ateliersavant will give at least 30 days’ prior noticeof any intended addition or replacement of a sub-processor, by updating the Sub-processor List and notifying the Customer’s account email, giving the Customer the opportunity to object on reasonable data-protection grounds. Absent an objection within 30 days of notice, the change is deemed accepted.
6.3 Ateliersavant imposes on each sub-processor, by contract, data-protection obligations materially equivalent to those in this DPA, and remains fully liable to the Customer for the performance of the sub-processor’s obligations.
6.4 Objection remedy.If the Customer objects on reasonable data-protection grounds and Ateliersavant cannot reasonably provide the Service without the new sub-processor, either party may terminate the affected Service. This is the Customer’s sole and exclusive remedy for a sub-processor change.
7. Assistance
7.1 Taking into account the nature of the processing, Ateliersavant will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). In the first instance this assistance is provided through the self-service export, correction and deletion capabilities of FORGE OS. If a data subject contacts Ateliersavant directly about Customer Personal Data, Ateliersavant will (where the Customer is identifiable) refer the request to the Customer without undue delay and will not respond on the merits except as required by law.
7.2 Taking into account the nature of processing and the information available to it, Ateliersavant will assist the Customer in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data-protection impact assessments and prior consultation).
7.3 Assistance under this Section that is materially disproportionate, repetitive, or caused by the Customer’s own breach may be charged at reasonable rates notified in advance.
8. Personal-data breach
Ateliersavant will notify the Customer without undue delay after becoming awareof a personal-data breach affecting Customer Personal Data, and will provide the information reasonably required by Article 33(3) GDPR as it becomes available. Ateliersavant’s notification of, or response to, a breach is not an acknowledgement of fault or liability.
9. Deletion and return
9.1 At the end of the provision of the Service, at the Customer’s choice, Ateliersavant will delete or return all Customer Personal Data. Return is effected through the Service’s export capabilities; deletion is effected through account deletion, with residual copies purged from live systems and rolling backups within 90 days.
9.2 Ateliersavant may retain data to the extent required by Union or Member State law (for example accounting and tax records), and retains the immutable record of the Customer’s acceptance of the Terms, Privacy Policy and this DPA, which contains no Customer Personal Data of third parties.
9.3 Data held in providers connected under the Customer’s own accounts (for example the Customer’s Google Sheets, Drive, Gmail or Box) is under the Customer’s control and is unaffected; disconnection revokes Ateliersavant’s access without any migration being required.
10. Audit
10.1 Ateliersavant will make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, in the first instance through: this DPA, the Privacy Policy, the Sub-processor List, Annex 2, sub-processor DPAs and certifications, and written responses to reasonable security questionnaires (at most once per 12-month period).
10.2 Where that information is insufficient to demonstrate compliance, the Customer (or an independent auditor mandated by it, not a competitor of Ateliersavant) may conduct an audit, subject to: at least 30 days’ written notice; at most once in any 12-month period, save where required by a supervisory authority or following a material breach; normal business hours, minimal disruption, and confidentiality undertakings; no accessto other customers’ data, to Ateliersavant’s or its other customers’ confidential information, or to sub-processor premises (sub-processor compliance is demonstrated through their audit reports and certifications); and the Customer bearing its own costs and Ateliersavant’s reasonable costs of supporting the audit.
10.3 Audit findings are confidential and may be used only to verify compliance with this DPA.
11. International transfers
11.1 Ateliersavant is established in France. The primary data store is hosted in Japan. Certain other sub-processors process data outside the EEA, including in the United States, as indicated in the Sub-processor List.
11.2 The database provider contracts through an entity established in Singapore, which is not the subject of an adequacy decision. Transfers to it are therefore made under the European Commission’s Standard Contractual Clauses (2021/914), Module 2 (controller to processor), as incorporated in its data-processing addendum. The Japanese hosting region is a data-residency commitment, not the transfer safeguard — the safeguard is the Clauses.
11.3 For transfers to sub-processors outside the EEA not covered by an adequacy decision, the Customer authorisesthose transfers provided each is covered by the European Commission’s Standard Contractual Clauses(2021/914) — for transfers by Ateliersavant as processor, Module 3 (processor to processor) as incorporated in the relevant sub-processor’s DPA — together with any supplementary measures reasonably required. Where the recipient is certified under the EU–US Data Privacy Framework, that certification may be relied on instead.
11.4 The Sub-processor List states, per sub-processor, the processing location and the transfer safeguard relied upon.
12. Liability
To the maximum extent permitted by law, the aggregate liability of each party under or in connection with this DPA is subject to the exclusions and the aggregate cap set out in the Terms, it being agreed that liability under the Terms and this DPA is a single combined aggregate, not separate caps. Nothing in this DPA limits liability that cannot be limited under applicable law (including fraud, gross negligence, or personal injury) or either party’s liability to data subjects under Article 82 GDPR; as between the parties, responsibility for Article 82 claims is allocated according to each party’s responsibility for the damage.
13. Duration, precedence, law
13.1 This DPA takes effect upon acceptance of the Terms and remains in force for as long as Ateliersavant processes Customer Personal Data.
13.2 Governing law and jurisdiction follow the Terms.
13.3 If any provision of this DPA is held invalid, the remainder remains in force, and the invalid provision is replaced by a valid provision that most closely reflects its intent.
Annex 1 — Description of processing
- Subject-matter: provision of FORGE OS, an AI-assisted sourcing and procurement platform (supplier discovery, RFQ generation and dispatch, reply ingestion, quote extraction and comparison, reporting).
- Duration:the term of the Customer’s account, plus the deletion window in §9.
- Nature and purpose:hosting and storage; AI-assisted analysis and generation; sending and receiving RFQ correspondence through the Customer’s connected email account; extraction and structuring of quotes; synchronisation to storage providers connected by the Customer; display and export.
- Categories of data subjects:contact persons and representatives of the Customer’s actual or prospective suppliers; the Customer’s own personnel appearing in correspondence.
- Types of personal data: business contact data (name, role, business email, business phone), correspondence content sent or received through the Service, identifiers contained in documents the Customer uploads.
- Sensitive data: none intended; prohibited by the Terms.
Annex 2 — Technical and organisational measures
- Access control: authentication via Supabase Auth; row-level security on all multi-tenant tables scoped to organisation membership; server-side authorisation gates on all operational routes.
- Encryption: TLS in transit; encryption at rest at the infrastructure layer; application-layer AES-256-GCM encryption of stored OAuth tokens, with per-user derived keys, authentication tags, and a key-version field enabling rotation.
- Minimisation: OAuth scopes requested at the minimum necessary; telemetry aggregated and de-identified; prohibited-data blocklist enforced in logging.
- Segregation: organisation-scoped data model; no cross-tenant access paths; sub-processor access limited to what their function requires.
- Integrity and audit: immutable, deny-mutation acceptance-evidence and audit-log tables; migrations version-controlled against the live database.
- Availability: managed infrastructure with provider-level backup and recovery; durable outbox queue for outbound operations.
- Operational security: rate-limiting on unauthenticated endpoints; server-side gating of AI executions; least-privilege service-role usage; secrets held in environment variables only.
- Personnel: access limited to authorised persons bound by confidentiality.
- Incident response: breach detection, classification and notification per §8; 30-day rolling application-log retention with content redaction.
Annex 3 — Sub-processors
The current Sub-processor List, with functions, processing locations and transfer safeguards, is maintained in the Privacy Policy and applies as updated in accordance with §6.2.
FORGE OS