Legal · Privacy policy · Last updated 13 September 2026
Privacy policy
How Forgeby handles personal data: on this website, at the door, and inside the Forgeby platform. If you are here because someone used Forgeby to contact you, or you were told your details are in our records, the page written for you is the privacy notice for business contacts. This policy does not vary that notice.
1. Who we are
Forgeby is a service of Zmart Com West AB, Swedish organisation number 559019-9161, Gothenburg, Sweden. A registered name change to Forgeby AB is in progress; it is the same company either way. That company is the data controller for the personal data described on this page: it decides what is held and why, and it is responsible for it under the General Data Protection Regulation (GDPR).
For privacy matters write to privacy@forgeby.com. For anything else, partner@forgeby.com.
2. What this website collects
When you email us, you actively provide:
- your name
- your company name
- your email address
- the message you choose to send
That data is used solely to respond to you and, where relevant, to discuss a potential engagement. It is not shared with third parties, not sold, and not used for marketing communications.
The site runs one performance script, Vercel Speed Insights, and no visitor analytics. It measures how fast a page loads and sends that measurement, the page URL and a connection-speed class to Vercel, our hosting provider, which is named in Annex B of the data processing agreement. It sets no cookie and writes nothing to your browser, so it cannot recognise you on a later visit, and it does not read the referrer. The cookies page describes exactly what it sends. Until 24 August 2026 this page named Plausible, which was never loaded; that was corrected, and this describes what runs.
Like any web server, ours writes access logs (IP address and browser user agent). They exist for security and abuse prevention only, are not used to profile anyone, and are purged at 90 days.
3. What we deliberately do not load
There is no cookie banner on this site because there is nothing to consent to. The marketing site loads no advertising tags, no Google Tag Manager, no LinkedIn Insight Tag, and no visitor-identification service such as Albacross. No consent-gated tracker of any kind is loaded. If that ever changes, a consent step will come first and this page will say so. The cookie policy describes the full picture, including the session state the app keeps in your own browser.
4. The door
Markets shows aggregate counts from our library: how many companies we can see in a market, and what is known about them in bulk. The counts are about companies, not people. You do not identify yourself to look. There is no account, no email gate, and nothing to type; the only data involved in serving the door is the ordinary access log described in section 2.
5. Signing up and signing in
Sign-up is for companies that sell IT products or services in Europe. You sign in with your work email address; there is no Google login and no social login of any kind. At sign-up we verify the domain of your email address is a company mailbox; a personal mailbox does not get an account.
What we process for your account: your work email address, your name, and the company you sign up under. The legal basis is GDPR Article 6(1)(b): taking steps at your request before entering a contract, and then performing it. In your browser, the app keeps session state locally (localStorage); it is not a tracking mechanism and it never leaves your device except to authenticate you to us. Detail is in the cookie policy.
6. The Forgeby platform and customer data
Separately from this website, we operate the Forgeby platform (formerly Alloy) for those customers. In the platform, Forgeby processes business-contact data of prospects (name, work title, business email and phone, public professional profile, employer) to identify and manage B2B opportunities. For business prospecting the lawful basis is legitimate interest (documented, and available on request). Forgeby is the controller for the library. You are the controller of your own outreach. Where Forgeby processes a customer's own data on their behalf, Forgeby acts as a data processor under our Data Processing Agreement.
Platform data is hosted in the EU and encrypted in transit and at rest, with row-level isolation between customers. A named individual is only ever visible inside an authenticated partner workspace, never on a public surface of ours.
When a customer connects a CRM, contact and engagement data syncs to that CRM under the customer's own instructions. The connectors currently offered are HubSpot, Lime, Pipedrive, Salesforce, webCRM and OnePageCRM; each CRM processes that data under its own terms, and where a connected CRM processes data outside the EU/EEA the transfer is covered by Standard Contractual Clauses.
If a customer invites Rune, the AI co-worker in the platform, to a meeting, capture and transcription run only after an explicit consent gate and are handled by SAS Spoke (Meeting BaaS) in the EU.
A partner may connect their own mailbox and calendar, Outlook or Google, so that Rune can prepare a meeting before they walk into it. It is optional, it is never a condition of using Forgeby, and one person connects it for their own seat rather than for a company. The sign-in is brokered by WorkOS, which holds the resulting token; Forgeby never receives or stores a mailbox password or any other provider credential.
The access is read only, and the permissions are fixed in advance rather than chosen at the time: Calendars.Read, Mail.Read and User.Read on Microsoft; calendar.readonly and gmail.readonly on Google. Not one of them can send, reply, delete, or change anything.
What Forgeby actually reads is narrower than those permissions allow:
- from the calendar, the events in the day being prepared
- from the mailbox, the subject line, the sender and the date only; message bodies are never requested and never received
- only for the outside people attending a specific meeting, at most five messages each, and colleagues at the partner's own email domain are removed from that list before the mailbox is queried at all
None of it is written to the library. It is read at the moment a brief is asked for, used to answer, and not kept afterwards. A partner can disconnect a mailbox or a calendar at any time from the integrations page, which withdraws that access.
Google Workspace data, and the Limited Use rule. Forgeby's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms, and these are commitments rather than a restatement: Gmail and Google Calendar data reaches a human only when that person asks Rune to prepare their own meeting; it is never sold, never transferred to anyone except to provide or improve that feature at the partner's direction or where the law requires it, and it is never used to train generalised or foundation models. It is read to answer one question and not retained afterwards.
7. Business contacts, and where their data came from
Some of what the platform holds is business contact information we did not collect from the person it describes. GDPR Article 14 requires us to tell those people what we hold, where it came from, why, and how to make it stop. The authoritative version of that is the privacy notice for business contacts. In brief, the sources are four: official business registers, licensed business-data providers, public web pages and public search results (web pages are read by the Forgeby crawler, which names itself in your logs and obeys robots.txt, and decision-makers found in public search results, including public professional profiles those results return, are resolved by Serper), and our founder's own professional network export. We do not log in to or crawl a social network. We hold professional information in a professional context only: no home addresses, no personal email, nothing about anyone's private life, and we profile companies, not people.
The right to object to direct marketing is absolute. One email to privacy@forgeby.com saying “opt out” is the whole process. We stop, we do not ask why, and we record the objection so a later import cannot undo it.
8. Where data lives, and the AI that touches it
Data at rest lives in the EU: a self-hosted database on Forgeby's own AWS infrastructure in the Stockholm region (eu-north-1). AWS acts as a data processor under GDPR Article 28. The website and the Forgeby web application run on Vercel, with serverless functions pinned to Stockholm (arn1).
AI processing runs on Amazon Bedrock using EU inference profiles. For tasks that need live web search, and as a fallback when the EU route is unavailable, one model path runs with Anthropic PBC in the United States under Standard Contractual Clauses. A prompt on that path can carry the company being researched and business contact details; it is not used to train models.
Email correspondence is hosted by GoDaddy, the domain and email provider for Forgeby's mailboxes. Their practices are described at godaddy.com/legal. Transfers outside the EU are safeguarded under standard contractual clauses where they occur.
9. Sub-processors
The full, current sub-processor list is Annex B of the Data Processing Agreement. In summary: Amazon Web Services (hosting, database, AI inference via Amazon Bedrock, transactional email, EU Stockholm), Vercel Inc. (hosting of the web application and page-load performance measurement, EU Stockholm), WorkOS, Inc. (sign-in, identity and the optional mailbox and calendar connection, United States, Standard Contractual Clauses), AssemblyAI, Inc. (speech-to-text when a user dictates, EU Ireland), FullEnrich SAS and Icypeas (contact enrichment when a user asks for a named contact, EU France), Serper.dev (web search for a company's website, a business contact's public professional profile link, and decision-makers found in public search results, United States, Standard Contractual Clauses), Vainu Finland Oy (Finnish company register data, EU Finland), Anthropic PBC (AI inference for tasks needing live web search and as fallback, United States, Standard Contractual Clauses), ElevenLabs, Inc. (voice synthesis of Rune's spoken lines, United States, Standard Contractual Clauses), SAS Spoke (meeting capture and transcription, only when a customer invites Rune to a meeting, EU France), Slack Technologies (Rune in Slack, only for a workspace a customer connects), and the CRM a customer chooses to connect (HubSpot, Lime, Pipedrive, Salesforce, webCRM or OnePageCRM, each per its own region). Customers get at least 30 days' prior notice of an intended addition or replacement. Objection is sent to privacy@forgeby.com. A sustained objection that we cannot accommodate is a ground to terminate; unused prepaid fees for the remaining term are refunded pro rata. The procedure is in section 3 of the data processing agreement.
10. How long data is kept
| Inquiry correspondence | Up to 24 months from the last interaction, then deleted. |
|---|---|
| Engagement records | For the duration of the engagement, then for the period required by Swedish accounting law (typically 7 years). |
| Access logs | Purged at 90 days. |
| Account data | For the life of the account; deleted when the account closes, except what the accounting row above requires us to keep. |
| Business-contact records | For as long as the information remains professionally relevant, reviewed periodically. After an objection, only the minimum needed to make sure the person is not added again. Detail in the privacy notice. |
11. Your rights under GDPR
You have the right to:
- request access to the personal data Forgeby holds about you
- request correction of inaccurate data
- request deletion of your data (the “right to be forgotten”)
- object to processing, or request restriction of processing
- request your data in a portable format
- withdraw consent at any time, where processing rests on consent (for example, a recorded meeting)
- lodge a complaint with the Swedish Authority for Privacy Protection (IMY), or with the supervisory authority where you live
To exercise any of these rights, email privacy@forgeby.com. Requests are handled within 14 days, half the one month the law allows.
12. Changes to this policy
This policy may be updated as Forgeby's practices evolve. The date at the top of this page reflects the most recent revision, and a change never lowers a protection described here without notice.
13. Contact
For any privacy-related question or request:
Forgeby, a service of Zmart Com West AB (org.nr 559019-9161), Gothenburg, Sweden
privacy@forgeby.com