Data Processing Agreement
Last updated July 14, 2026
This page summarizes the Data Processing Agreement ("DPA") available to Forge.dev customers who process personal data through the Service, in line with our obligations under GDPR, the UK GDPR, and comparable data protection laws.
Scope
The DPA applies where a customer ("Controller") uses Forge to process personal data — for example, contributor names embedded in commit history or account data synced from a connected identity provider — and Forge ("Processor") processes that data solely on the Controller's documented instructions.
Sub-processors
Forge maintains an up-to-date list of sub-processors engaged to provide the Service, each bound by data protection terms consistent with this DPA. Customers are notified of material changes to this list in advance, with the opportunity to object.
Security measures
Technical and organizational measures — encryption in transit and at rest, access controls, audit logging, and regular independent review — are described in full on our Security page and incorporated into the DPA by reference.
Data subject rights
Forge will assist Controllers in responding to data subject requests (access, correction, deletion) related to personal data processed through the Service, consistent with the technical means available to us.
International transfers
Where personal data is transferred outside the customer's region, Forge relies on Standard Contractual Clauses or an equivalent lawful transfer mechanism.
Need a signed copy?
Our team can countersign a DPA for your organization on request.