Data Processing Agreement.

Operated by Waelas Ltd · last updated September 2026

When you use Forge to take bookings, send invoices or keep client records, you decide what personal data about your clients goes in and why. That makes you the controller of it, and Waelas Ltd (“Forge”, “we”) your processor. This agreement sets out how we handle that data for you. It forms part of the Terms of Service and applies automatically; you do not need to sign anything.

Your own account data (your name, email, billing) is different: for that we are the controller, as the Privacy Policy explains.

1. What we process, and why

  • Subject matter and purpose: providing Forge to you — booking pages, calendars, polls, proposals, invoices, client records, emails and reminders to your clients, and the other features you use.
  • Duration: for as long as you have a Forge account, then deletion as set out in section 9.
  • Data subjects: people who book with you, your clients and leads, their guests, poll voters, and anyone else whose details you add.
  • Personal data: names, email addresses, phone numbers if you ask for them, booking times and details, answers to your booking and intake questions, messages, invoices and payment status, signatures on proposals, and photos poll voters choose to add.
  • Special category data: Forge is not designed for it. If you collect health or other special category data through your own questions, you are responsible for having a lawful basis and for telling your clients.

2. Your instructions

We process this data only on your documented instructions — which are these Terms, this agreement and the way you configure and use Forge — unless the law requires otherwise, in which case we will tell you first unless the law forbids it. If we believe an instruction breaks data protection law, we will tell you.

3. Confidentiality

Everyone at Waelas Ltd who can access your clients’ data is bound by confidentiality, and accesses it only to run the service, to support you when you ask, or to meet a legal obligation.

4. Security

We keep the technical and organisational measures in Annex 2 in place, appropriate to the risk, and we review them as the service changes.

5. Subprocessors

You give us general authorisation to use the subprocessors listed in section 4.1 of our Privacy Policy. We will give you at least 14 days’ notice by email before adding or replacing one. You can object on reasonable data protection grounds; if we cannot address the objection, you can close your account before the change takes effect. We put a written agreement with each subprocessor that protects the data at least as well as this one, and we remain responsible to you for them.

Services you connect yourself — your calendar, Notion, your own webhooks — are not our subprocessors. You authorise them directly, under your own agreement with them (Privacy Policy §4.2).

6. Helping you meet your obligations

  • Your clients’ rights: Forge lets you find, correct, export and delete a client’s data. If a client contacts us directly, we will pass the request to you rather than answer it ourselves, and help you respond.
  • Assessments: we will give you the information you reasonably need for a data protection impact assessment or to consult a regulator.

7. Personal data breaches

If we become aware of a breach affecting your clients’ data we will tell you without undue delay, and in any event within 48 hours, with what we know about what happened, the data and people affected, and what we are doing about it. We will keep you updated and help you meet your own duty to notify the regulator and your clients.

8. International transfers

Our database and application run in London. Some subprocessors are in the United States. Where data leaves the UK or the European Economic Area we rely on an adequacy decision (including the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified) or on the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses. By accepting this agreement, where you are in the EEA and we receive your data in the UK, the UK’s EU adequacy decision covers the transfer.

9. When you leave

When you delete your account we delete your clients’ personal data immediately from the live service, and it leaves our backups within 30 days, unless the law requires us to keep it. Before you delete, you can download your bookings, invoices, leads and clients as CSV from Reports, or email us and we will return a full copy.

10. Audits and information

We will make available the information you reasonably need to show we meet these obligations, answer reasonable written questions, and allow an audit by you or an auditor you appoint (bound by confidentiality), on reasonable notice, no more than once a year unless a breach or a regulator requires otherwise.

11. Liability and order of precedence

Liability under this agreement is governed by the Terms of Service. If this agreement and the Terms conflict on the protection of personal data, this agreement wins.

Annex 1 — Parties

Controller: the Forge account holder (you).
Processor: Waelas Ltd, a company registered in England and Wales (No. 16397759), 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Contact: support@forge.page.

Annex 2 — Security measures

  • All traffic to Forge is encrypted in transit (HTTPS with HSTS); the database and file storage are encrypted at rest by their providers.
  • Calendar access tokens are encrypted again by us with AES-256-GCM before they are stored.
  • Passwords are never stored — only a salted hash. Email addresses are verified before a password account can be used, and sign-in is rate-limited.
  • Every signed-in action checks the account it acts for; public links to bookings, invoices, proposals and portals use unguessable tokens.
  • Error reports have cookies, credentials and those tokens stripped before they leave our servers.
  • The database is hosted in London with point-in-time recovery covering the previous seven days.
  • Uploaded files are size- and type-checked, and images are re-encoded before storage.
  • Production access is limited to Waelas Ltd staff who need it, with secrets held in our hosting provider’s secret store, never in code.