FORGEBY Name your market

Trust and security

Read at the source. Sent by a human.

Every company in the library comes from an official public business register, read at the source. We run no scraper against a network behind a login, and we do not log in to or crawl a social network. People come from three accountable places: a provider named in Annex B, licensed under contract, which warrants its own lawful basis; decision-makers found in public search results, including public professional profiles those results return; and our founder's own professional network export. What a partner uploads, a member's own connections export included, is that partner's own record, in its own workspace. All four source categories are named in the Article 14 notice, which governs. Rune drafts. A person sends.

EU-resident by design Public registers at the source No social-network crawling Four named sources Suppression registers honoured Person data behind sign-in A human sends

Last reviewed 13 September 2026

01 · Where the companies come from

Every source is named.

Each market's public business register, read under its own terms. Never somebody else's copy.

Category oneOfficial public business registersCompany fact from each market's register: legal entity, registration number, sector, size band, registered address.
Category twoWhat a company publishes itselfCloud posture, measured from what a company publishes to the open internet. Nothing behind a login, nothing from a profile.
Category threeWhat you bringYour own records, in your own workspace. Not trained on, not resold, exportable and erasable at will.

Full provenance is available on request. Every attribute we hold traces to one of the categories named in the notice and to the named source behind it. The register-level detail comes in writing, under the data processing agreement. Ask at privacy@forgeby.com and you get it.

Public business registers · read at the source · under each register's own terms · aggregate bands only on public pages · provenance per attribute on request

02 · The hard rules

Four things we do not do.

We run no scraper behind a login. We do not log in to or crawl a social network, and buying a scrape does not launder it. What we do read, public search results and our founder's own export from his own account, is stated above.
We do not show people in public. Public pages carry counts and bands. Never a name, an email, a phone number or a title.
We do not send anything automatically. Rune drafts. A person reads, decides and sends from their own inbox. No mass send, no autopilot.
We do not file anything into AWS by ourselves. Rune prepares the paperwork. A human at the partner reviews it and submits it in AWS Partner Central.

03 · The lawful channel

The market decides the channel.

Marketing law differs by country. The product applies each market's lawful contact channel for you.

Suppression

Suppression before a draft exists.

Where a market publishes an objection or advertising-protection register, it is applied at the source. A company or person on one is screened out before anything is written.

Applied, not taught

The rule travels with the record.

Every record carries the lawful way in for its market before anything is drafted. The rule is applied in the product, not published.

Legitimate interest

Documented, and balanced.

Business contact data of a person in a professional role is processed on documented legitimate interest, balanced and written down, for business-to-business contact only. We process what the role needs and nothing beyond it.

Objection

How to say no.

Where business contact details were obtained from somewhere other than the person, the source categories and the route to object are set out in the privacy policy, with the article-level basis. An objection stops the processing.

04 · The sign-in line

Person data lives behind sign-in. Always.

There is one line on this product and it does not move. Before sign-in, counts. After sign-in, inside your own isolated workspace, the work. Sign-up is for companies that sell IT products or services in Europe. A company mailbox is the door; free mail addresses are refused. AWS partners see their published AWS record on the way in.

Public, no account
  • How many companies are in a market
  • How the cloud posture splits, as bands
  • How many decision roles sit on a company, as a count
  • Which funded door an account shape tends to open
Behind sign-in, inside your workspace
  • The account-level read
  • Named roles and business contact details
  • Drafts, approvals and the send from your own inbox
  • Your own records, isolated from every other partner's
  • Privacy notice

Workspaces are separated by row-level security in the database itself. An unauthenticated caller holds no database privileges: the public surface reaches a few read-only aggregate endpoints and nothing else. No partner can see another partner's records.

05 · Rune

Rune drafts. A human sends.

Rune is openly an AI and says so on every surface. He is never the last decision.

A person approves every sendRune writes. He contacts no one on his own, in any channel, ever.
Every run is loggedWhat he read, wrote and did is visible to the partner it was done for.
Every workspace has a spend capEnforced in code, not in a policy document.
His output is checked against its sourceWhat he cannot stand behind is flagged, not asserted.

06 · Where it lives

EU-resident at rest, with stated exceptions.

The stated exceptions are the spoken voice (ElevenLabs, United States, Standard Contractual Clauses; the text Rune speaks and nothing else) and the inference fallback when the EU model path is unavailable. Your workspace, your records and the library sit at rest in the EU, in Stockholm. Reasoning runs in the EU by default, on Amazon Bedrock in the same region. Data is encrypted in transit with TLS 1.2 or better and at rest with AES-256. Secrets stay server-side, never handed to a browser.

One caveat, stated plainly: some inference runs outside the EU under Standard Contractual Clauses. That covers live web search, which the EU region does not offer, streamed responses, which our EU integration does not yet support, and fallback when the EU route is unavailable. No customer records are stored there. Every processor is named and versioned in the data processing agreement and sub-processor list, and that list is the authoritative one.

Rune's spoken voice is synthesised by ElevenLabs in the United States under Standard Contractual Clauses. Only the sentence to be spoken leaves the EU, and the voice function refuses it outright if it carries an e-mail address or a phone number. Reasoning and every record stay in the EU as above. A visitor's spoken lines are counted per browser and per address, and the purse has a cap.

Meeting capture and transcription, when a partner chooses to use them, run with EU providers on EU soil. Both the platform and the meeting layer refuse to start without consent recorded.

07 · Objection and erasure

The route, in plain words.

If you want out, one email does it.

Write and say what you want: access to what we hold, a correction, an objection to the processing, or erasure. We answer within one month, as the law requires, and sooner in practice.

An erasure is a suppression as well as a delete. The record is removed and the identifier is held on a suppression list so the next load of the register does not quietly bring it back. That is the only thing that survives an erasure.

For a security issue, give us reasonable time to fix it before public disclosure. We will tell you what we found and when it was closed.

08 · What we do not claim

GDPR-aligned. Not ISO certified.

Forgeby is a Swedish company built to GDPR. The proof is not a seal, it is the machinery, and every piece is public:

  • Data at rest in the EU, in Stockholm.
  • The Article 14 notice, in plain language, with an absolute one-email opt-out.
  • Your rights answered in 14 days, half the month the law allows (privacy).
  • National suppression registers honoured in the data itself: reklamspärr, NIX, reklamebeskyttelse.
  • No scraper of ours runs against a network behind a login, and we do not log in to or crawl a social network. Person data comes from a provider named in Annex B, licensed under contract; from public search results, including public professional profiles those results return; or from our founder's own professional network export. We can tell any person which of the four categories their record came from.
  • The data processing agreement and its full sub-processor table, published.
  • Nothing sold, no ad trackers, and no consent banner because nothing consent-gated loads (cookies).

ISO 27001 is on the roadmap and we are not certified today. We do not claim certifications we have not earned. This page changes on the day that does.

The fastest way to judge this is to open your market. Ten seconds, no account, no person data.

Name your market

This page describes our posture in good faith. It is not a contract. The binding terms are in your agreement and in the data processing agreement.