FORGE OS
Privacy Policy
Last updated: August 4, 2026
This policy explains how personal data is handled when you use FORGE OS, and the rights you have under the GDPR. It forms part of, and should be read with, our Terms of Service.
1. Who we are; our two roles
FORGE OS is a procurement-intelligence workspace operated by Ateliersavant Europe SAS (SIRET 912 291 283 00014, VAT FR43912291283), registered office 17 rue du Pré-Bréda, B.P. 60, 51200 Épernay Cedex, France ("Ateliersavant", "we", "us"). We act in two distinct roles:
- As data controller — for the personal data we determine the purposes of: your account, authentication, usage, billing, and support data. This policy governs that processing.
- As data processor — for any third-party personal data you choose to enter into the product (for example, the names, emails, and details of supplier contacts within your supplier records, RFQs, and quotes). For that data, you are the controller: you decide why and how it is processed, and you are responsible for having a valid lawful basis, for providing any required notices to those individuals, and for handling their requests. We process such data only on your documented instructions to provide the service, as set out in Section 4 and Section 13.
2. Data we collect
When you create an account we collect your email address and authentication details. As you use the product we store the content you create — product briefs, projects, supplier records, RFQs, and quotes (which may contain third-party personal data you provide). We also process limited usage and technical data (e.g. request logs, IP address, device/browser information, timestamps) to operate, secure, and debug the service, and billing dataneeded to manage your subscription. We do not intentionally collect special-category data, and you should not submit it.
At registration, and at any time in Settings, you may optionally tell us your country and a WhatsApp number. Both are entirely optional, both can be changed or cleared by you at any time, and the product is fully functional without either. We use them to prioritise the regions and support hours we invest in, and to reach you about your account. We do not infer your location from your IP address or any other signal — if you have not told us your country, we do not have it — and we never share your number with suppliers.
If you connect an optional third-party service, we also store the identifiers needed to maintain that connection — for example your Google account identifier and access tokens, or your Telegram chat identifier.
3. How and why we use data (purposes and legal bases — controller data)
We process the personal data for which we are controller:
- to perform our contract with you (providing the service, authentication, support, verifying that the suppliers we surface actually exist, and managing your subscription);
- on the basis of our legitimate interests in securing, maintaining, debugging, analysing, and improving the service, preventing abuse and fraud, and developing our products using aggregated or de-identified data (balanced against your rights);
- to comply with legal obligations (such as accounting, tax, and responding to lawful requests); and
- where required, on the basis of your consent (for example, connecting an optional Google/Gmail account). You can withdraw consent at any time, without affecting prior processing.
4. AI processing and web search
To generate sourcing analysis, RFQs, and quote summaries, the relevant text you provide (such as product briefs and supplier or quote details) is sent to Anthropic's Claude API for processing. We send only the content needed to produce the result you requested. Anthropic processes this data as our subprocessor under data-protection terms and does not use it to train its models.
To check that a supplier is real rather than invented by an AI model, FORGE OS also runs web searches. These are performed by Claude as part of the same processing, and contain the supplier’s company name and country together with general terms such as “manufacturer” or “official site” — they do notcontain your brief, your commercial terms, your identity, or your contact details. We do not currently use any separate third-party search provider; if we introduce one, it will be named in Section 5 before it is used.
Publicly available information returned by those searches — which may include a company’s published business contact details — is stored in the supplier record in your workspace. Where that information identifies an individual, you are the controller for it (see Section 1) and are responsible for the notice and lawful-basis obligations that follow, including where personal data is obtained from a source other than the individual.
AI output is generated automatically and may be inaccurate; it is decision support only (see our Terms).
4a. Supplier intelligence we process as a controller
Supplier Registry. To make sourcing results better and faster, FORGE OS keeps a record of supplier organisations it has already verified as real: company identity, website, capability information, certifications, and a generic business contact point where one is published — a departmental address such as sales@, info@ or export@, and sometimes a business WhatsApp or WeChat number. This comes from AI-assisted research of publicly available sources and from verification that occurs during sourcing campaigns.
We do notrecord the names of individual employees, and we never guess an address: an address that cannot be found published on a live page is discarded rather than inferred from the company’s domain.
A Registry is held separately for each customer account. Entries created by one customer are never readable by, shared with, or pooled across other customers, and are deleted when that account is deleted. Contact details are stored only so the same customer does not have to re-discover them; they are never fed back into our AI models, which receive only company name, country, website and capability signals.
For the Supplier Registry, Ateliersavant Europe SAS is the controller, and our legal basis is legitimate interest (Article 6(1)(f) GDPR) in operating a business-to-business supplier-discovery service. The Registry contains business contact data only: it never includes our customers’ identities, prices, quotes, RFQ content, correspondence, or any commercial terms.
How long we keep it. Contact details are erased 12 months after an entry was last used in a sourcing campaign — business contacts go stale quickly, and a stale one has no value to anyone. The remaining company record (name, country, website, capabilities) is kept up to 24 months from that same point and then deleted. Both clocks reset whenever the entry is used again.
Your rights as a supplier contact. If you are a supplier representative and want to access, correct or remove your business contact details, or object to this use, email inquiries@ateliersavant.com or simply reply to any message you receive from us — we will act within one month. Removal erases the contact details from every account’s Registry, not just the one that contacted you. We keep the company record, which identifies no individual.
When we first contact you, that email tells you where your details came from and how to have them removed, so you do not have to find this page to exercise the right.
5. Subprocessors and connected services
Processors acting on our behalf. These providers process personal data only on our instructions, under appropriate data-processing terms:
- Supabase (Supabase Pte. Ltd, Singapore) — database, authentication, file storage. Data is stored in Japan (AWS ap-northeast-1). Transfers rely on the Standard Contractual Clauses(Module 2, controller to processor) incorporated in Supabase’s data-processing addendum.
- Anthropic— AI processing and web search (see Section 4). Processed in the United States; transfers rely on the Standard Contractual Clauses incorporated in Anthropic’s data-processing addendum.
- Vercel — application hosting. Processed in the United States; transfers rely on the Standard Contractual Clauses incorporated in Vercel’s data-processing addendum.
- Stripe— payment processing (see Section 7). Transfers rely on the Standard Contractual Clauses incorporated in Stripe’s data-processing addendum, which forms part of its services agreement.
Third-party services you choose to connect. These operate under their own terms and privacy policies, as independent recipients rather than as our processors. We transmit data to them only because, and only for as long as, you have connected them:
- Google — Gmail send/read and Sheets export (see Section 8)
- Telegram — delivery of notifications you have asked to receive (see Section 8a)
We do not sell your personal data or share it for advertising.
We may add, replace, or remove providers as the service evolves, and will impose equivalent protections on any replacement. We keep this list current, and where we act as your processor we will notify you of an intended addition or replacement of a processor in advance, so that you have an opportunity to object before the change takes effect. Material changes are reflected by the “Last updated” date above.
6. International transfers
Some of the providers in Section 5 are located outside the EEA (e.g. in the United States) — this includes our AI, hosting, and payment providers. Where we transfer personal data outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision, so the data keeps an essentially equivalent level of protection. Where you connect a third-party service (Section 5, second list), that transfer takes place under your instruction and under that provider's own terms.
7. Payment data
Subscription payments are handled by Stripe. Card details are entered with and stored by Stripe — we do not receive or store your full card number.We receive limited billing information (such as subscription status and the last digits/brand of the card) needed to manage your plan.
8. Optional Gmail connection
If you connect a Google account, FORGE OS requests Gmail permissions so it can send RFQs from your address and read replies that relate to your quotes. This connection is entirely optional, based on your consent, and used onlyto send and retrieve the messages tied to your sourcing workflow. FORGE OS's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time from your Google Account's security settings or by disconnecting in FORGE settings, after which we stop accessing your mailbox.
8a. Optional Telegram notifications
If you connect a Telegram chat, FORGE OS sends you notifications about your own sourcing activity — for example that an RFQ was sent, that a supplier replied, or that a decision needs you. These messages contain the supplier or vendor name and a short summary of the event, together with a link back into the product. This connection is entirely optional and based on your consent, and is used only to notify you.
Telegram receives and stores this message content in order to deliver it, on its own infrastructure and under its own terms and privacy policy, as an independent recipient rather than as our processor. Messages sent by bots are not end-to-end encrypted. You should not treat Telegram notifications as a confidential channel, and we recommend against connecting one if your sourcing activity is commercially sensitive. You can disconnect at any time in FORGE settings, after which we stop sending messages; messages already delivered remain in your Telegram account.
9. Security
We use reasonable and appropriate technical and organisational measuresdesigned to protect personal data (such as encryption in transit, access controls, and use of reputable infrastructure providers). However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for the security of any data you export from the service.
10. Personal data breaches
If a personal data breach affecting your data occurs, we will assess and, where required by the GDPR, notify the competent supervisory authority and/or affected individuals within the applicable time limits. Where we act as your processor, we will notify you without undue delay so that you, as controller, can meet your own notification obligations.
11. Retention and deletion
We keep your account and content for as long as your account is active, and for a limited period afterwards where needed to meet legal, accounting, tax, or security obligations (for example, invoices are kept for the statutory retention period), after which it is deleted or anonymised. We may retain de-identified or aggregated data, and routine backups for a limited cycle. You can request export or deletion of your data at any time by contacting us. On account deletion, copies are purged from live systems and rolling backups within 90 days, matching the commitment in our DPA §9. The immutable record of your acceptance of the Terms, this policy and the DPA is retained as legal evidence; it contains no third-party personal data.
12. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing, including processing based on legitimate interests. To exercise these rights, email us at the address below; we may need to verify your identity and will respond within the statutory time limits. Where a request relates to data we process on behalf of a customer (Section 1), we will refer you to that customer as controller. You also have the right to lodge a complaint with your supervisory authority — in France, the CNIL (cnil.fr).
13. Customers acting as controllers (our DPA)
If you use FORGE OS in a professional capacity and input personal data relating to third parties (for example supplier contacts), you are the controller of that data and Ateliersavant Europe SAS acts as your processor. That processing is governed by our Data Processing Addendum (the “DPA”), which forms part of the Terms of Service and constitutes the data-processing agreement required by Article 28 GDPR.
The DPA covers, among other things: processing only on your documented instructions, confidentiality, security measures, sub-processor engagement and change notice, assistance with data-subject requests and breach obligations, deletion or return of data at the end of the service, audit rights, and international-transfer safeguards.
You remain responsible for having a valid lawful basis, and for giving any required notices and obtaining any required consents, for third-party personal data you input.
14. Changes to this policy
We may update this policy as the service and legal requirements evolve. Material changes will be reflected by the "Last updated" date above and, where appropriate, notified to you.
15. Contact
Ateliersavant Europe SAS — 17 rue du Pré-Bréda, B.P. 60, 51200 Épernay Cedex, France. Questions about privacy or a data request? Email inquiries@ateliersavant.com.
FORGE OS