Legal

Data Processing Agreement

Last updated July 14, 2026

This page summarizes the Data Processing Agreement ("DPA") available to Forge.dev customers who process personal data through the Service, in line with our obligations under GDPR, the UK GDPR, and comparable data protection laws.

Scope

The DPA applies where a customer ("Controller") uses Forge to process personal data — for example, contributor names embedded in commit history or account data synced from a connected identity provider — and Forge ("Processor") processes that data solely on the Controller's documented instructions.

Sub-processors

Forge maintains an up-to-date list of sub-processors engaged to provide the Service, each bound by data protection terms consistent with this DPA. Customers are notified of material changes to this list in advance, with the opportunity to object.

Security measures

Technical and organizational measures — encryption in transit and at rest, access controls, audit logging, and regular independent review — are described in full on our Security page and incorporated into the DPA by reference.

Data subject rights

Forge will assist Controllers in responding to data subject requests (access, correction, deletion) related to personal data processed through the Service, consistent with the technical means available to us.

International transfers

Where personal data is transferred outside the customer's region, Forge relies on Standard Contractual Clauses or an equivalent lawful transfer mechanism.

Need a signed copy?

Our team can countersign a DPA for your organization on request.

Contact us