Legal · Compliance · Last updated 13 September 2026
Compliance
The questions a buyer's legal team asks, answered with what we actually do rather than what sounds reassuring. Where a number appears here it was measured, and it says when. The binding documents are the privacy policy, the data processing agreement and the privacy notice for business contacts; this page explains them, it does not vary them.
1. Is Forgeby GDPR compliant?
“GDPR compliant” is not a certificate anyone can issue, so a vendor claiming it flatly is telling you nothing. What we can do is show the work: a named lawful basis with an assessment behind it, sources recorded per record, an Article 14 route that is published rather than promised, suppression that survives a later import, and an absolute right to object that costs one email. Each of those is described below, and each is checkable.
2. What is your lawful basis?
Legitimate interest, Article 6(1)(f), for business-to-business professional contact in a professional context. The interest is helping tech partners find and reach companies that plausibly need what they sell. We hold professional information only: no home addresses, no personal email, nothing about anyone's private life. We profile companies, not people.
The right to object under Article 21 is absolute for direct marketing, and we treat it as such. There is no balancing test to win and we do not ask for a reason.
3. Where does the data actually come from?
Four sources, and we will not claim fewer:
- Official business registers and national statistical sources.
- Licensed business-data providers, under contract.
- Public web pages and public search results. Web pages are read by the Forgeby crawler, which names itself in your logs and obeys robots.txt; it is described in full on the crawler page. Decision-makers found in public search results, including public professional profiles those results return, are resolved by Serper, which is named in Annex B.
- Our founder's own professional network export.
We say this plainly because some competitors claim their database comes only from publicly accessible sources while buying a people layer from providers they decline to name. If a supplier cannot tell you who they bought from, that is the answer.
4. How do you satisfy Article 14?
This is the obligation that applies when data was not collected from the person it describes, and it is where most B2B data vendors are exposed. Article 14(5)(b) allows an organisation to be excused from messaging every individual where that would be a disproportionate effort — but only on condition that the information is made publicly available instead. The enforcement record is consistent: the penalties in this area have landed on companies that had neither route, not on companies that chose publication over mass email.
So we published. The privacy notice for business contacts exists in seven languages — English, Swedish, Norwegian, Danish, Finnish, French and Dutch — and each version names the local supervisory authority alongside the Swedish IMY, because Article 77 lets a person complain where they live rather than where we are.
Measured on 15 August 2026: of 338,265 business contacts, 336,295 are covered by a published notice in a language that person would read. The remaining 1,970 are records with no resolved country, so no language can be chosen for them with any confidence; we would rather report that number than round it away.
We also do not send mass email to the library in the name of “notifying” it. Emailing several hundred thousand people who never asked to hear from us would be the harm, dressed as the remedy.
5. What do you refuse to hold?
We do not buy scraped social-network data, and we do not log in to or crawl a social network. Purchasing a scrape does not launder it, and the fines in this area have repeatedly landed on the buyer rather than the scraper. We also hold no special-category data: nothing about health, religion, politics, trade union membership, sex life or ethnicity, and we do not infer any of it.
6. What is my responsibility as a customer?
When you use Forgeby to contact someone, you are the controller of that outreach. That means the message is yours: you decide who to write to and what to say, you answer for it, and you keep your own record of anyone who tells you to stop. Where we process your own data on your behalf, we act as your processor. The split is written into the data processing agreement.
What you do not have to carry is the library itself. We are the controller for that, we published the Article 14 notice for it, and we answer the requests that come to us. Some vendors push all of that onto the customer; we think that is how a small partner ends up answering for a database they never built.
7. Someone has asked me where I got their details. What do I say?
Answer them directly, promptly, and honestly. You may use this:
“I found your professional details through Forgeby, a business-to-business platform used by tech partners. Your information came from public business registers, licensed business-data providers, public web pages and search results, or the professional network of Forgeby's founder, and it is held in a professional context only. Forgeby publishes a standing privacy notice explaining this at forgeby.com/notice, including how to object.
If you would rather not hear from me again, say so and I will stop immediately and keep a record so it does not happen again. You can also object to Forgeby directly at privacy@forgeby.com, which removes you regardless of what I do.”
The second route matters. A person who tells you to stop should not have to trust that you passed it on.
8. How does someone opt out, and what actually happens?
One email to privacy@forgeby.com saying “opt out”. That is the whole process. We stop, we do not ask why.
Mechanically, the objection is recorded and the contact details are stripped from the record. We suppress rather than delete, and the distinction is deliberate: if we erased the row entirely we would also erase the fact that you objected, and the next time that person appeared in a register or a provider file they would be re-added as though nothing had happened. The suppression is enforced in the database itself and survives re-import, which is the only version of an opt-out worth having. The person becomes unreachable through Forgeby and stays that way.
If you would prefer full erasure rather than suppression, ask, and we will explain exactly what remains and why before doing anything.
9. Where does the data live, and what AI touches it?
Data at rest lives in the EU, on Forgeby's own AWS infrastructure in the Stockholm region (eu-north-1). AI processing runs on Amazon Bedrock using EU inference profiles. One model path runs with Anthropic PBC in the United States under Standard Contractual Clauses, for tasks needing live web search and as a fallback when the EU route is unavailable; a prompt on that path can carry the company being researched and business contact details, and it is not used to train models. The full picture, including every sub-processor, is in the privacy policy.
10. Are you SOC 2 or ISO 27001 certified?
No. We hold no security certification today and we are not going to imply one is imminent to make this page look better. ISO 27001 is the standard we design against — least privilege, EU residency, encrypted at rest and in transit, access through a single audited path — but designing against a standard is not the same as being audited to it, and only one of those is worth writing down. If that changes, this page will say so, with a date and an auditor.
11. Who do I contact, and who do I complain to?
Privacy matters: privacy@forgeby.com. Anything else: partner@forgeby.com.
Forgeby is a service of Zmart Com West AB, Swedish organisation number 559019-9161, Gothenburg, Sweden. A registered name change to Forgeby AB is in progress; it is the same company either way.
You may complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), at imy.se — or, under Article 77, to the supervisory authority where you live. Each language version of the privacy notice names the relevant local authority.
This page describes how Forgeby operates and is written to be accurate rather than comfortable. It is not legal advice, and it does not create rights beyond those in the privacy policy and the data processing agreement.