Skip to content
unforged DevelopersSecurityHow we testPricing
Sign in Get started
Get started

Legal

Data processing addendum

Last updated 29 September 2026 · Version 1.0

Contents
  1. 01Scope and roles
  2. 02The processing
  3. 03Your instructions
  4. 04Your responsibilities
  5. 05Our people
  6. 06Security measures
  7. 07Subprocessors
  8. 08Helping you meet your obligations
  9. 09Personal data breaches
  10. 10Deletion or return
  11. 11Audits
  12. 12International transfers
  13. 13No training
  14. 14Contact
01

Scope and roles

In short This addendum is part of the terms of service. You are the controller of customer data; we process it for you, on your instructions.

This addendum forms part of the terms of service between you and GitGlue Ltd. It applies when we process personal data in the documents, reference signatures and other data you send to Unforged (customer data) on your behalf. For that data you are the controller and we are your processor, under the UK GDPR and, where it applies, the EU GDPR. If this addendum and the terms conflict on data protection, this addendum wins.

02

The processing

In short What we process, about whom, why, and for how long: the details Article 28 asks for.

  • Subject matter and purpose: checking signatures on documents against the reference signatures you enrol, returning verdicts with reasons, and keeping the history you ask us to keep.
  • Nature: receiving, storing, comparing, retrieving and deleting data, and delivering results by API, webhook and the dashboard.
  • Data subjects: the people whose signatures and documents you send us, and anyone named in those documents.
  • Types of data: documents, reference signatures, check results, the subject references you use to identify people, and your webhook settings. Signatures and their comparison can be biometric data, a special category.
  • Duration: documents and results are kept for your organisation’s history-retention setting: 90 days by default, and you can choose from 30 minutes to 10 years, or indefinitely. Uploaded documents are kept with their results under the same setting. Reference signatures are kept until you delete them; a check that a learned reference came from is kept while that reference exists. At the end of the service, see deletion or return.
03

Your instructions

In short We act only on your documented instructions: these terms, your settings and your API calls.

We process customer data only on your documented instructions: these terms, the settings you choose and the requests you make through the API and the dashboard. If we think an instruction breaks data protection law, we will tell you. If the law requires us to process customer data otherwise, we will tell you first unless the law forbids it.

04

Your responsibilities

In short Signatures can be biometric data. You need a lawful basis, and any consent the law requires, for what you send us.

You are responsible for having a lawful basis for the processing, including a condition for special category data where one is needed, for getting any consent the law requires from the people whose signatures you send, and for telling them how their data is used. Reference learning is off by default; if you switch it on, approved signatures are added to that same person’s references only, and you are responsible for having a basis for keeping them.

05

Our people

In short Everyone who can access customer data is bound to keep it confidential.

Only people who need access to run and support Unforged can reach customer data, and each of them is bound by a duty of confidentiality.

06

Security measures

In short We protect customer data with the technical and organisational measures described on our security page.

We apply appropriate technical and organisational measures to protect customer data, including encryption in transit, isolation between organisations, access control, and audit logging. The measures, and how they work, are described on our security page. We may improve them over time, but will not make them less protective overall.

07

Subprocessors

In short These vendors help us run Unforged. We tell you before we add or replace one, and you can object.

You authorise us to use the subprocessors below. Each is bound by written terms that protect customer data at least as well as this addendum, and we remain responsible for them.

Subprocessors, as of the date above
NamePurposeDataLocation
Amazon Web ServicesHosting: the servers, database, file storage, queues and keys that run UnforgedAll customer data, and account and usage recordsLondon, UK (eu-west-2)
CloudflareDNS, the network in front of unforged.ai (the website and dashboard), and cookieless website analyticsTraffic to unforged.ai in transit, including documents uploaded in the dashboard, and anonymous page-view analytics (page, referrer, country, device). API traffic does not pass through it.See the vendor’s terms
WorkOSSign-in, single sign-on and directory syncUsers’ names, email addresses, organisation memberships and rolesSee the vendor’s terms
StripePayments, invoices and usage billingOrganisation name, billing email, payment details and counts of billable checksSee the vendor’s terms
ResendSending our transactional emailRecipients’ email addresses, and the contact-form requests and other messages we sendSee the vendor’s terms
Google WorkspaceOur own email, including [email protected]What you send us by email, and contact-form requestsSee the vendor’s terms

Before we add or replace a subprocessor, we update this page and email your account owners. If you object on reasonable data protection grounds, tell us at [email protected]; we will work with you on it, and if we cannot resolve it you may stop using the affected service.

08

Helping you meet your obligations

In short We help you answer data subject requests and with impact assessments and regulator enquiries.

We help you answer requests from data subjects. You can find a person’s data by the subject reference you gave them, and delete a subject, with their references and files, through the API. If a data subject contacts us directly, we pass the request to you and do not answer it ourselves unless you ask us to.

We also give you reasonable help with data protection impact assessments, consultations with regulators, and your security obligations, taking into account the information we have.

09

Personal data breaches

In short If a breach affects customer data, we tell you without undue delay and help you respond.

If we become aware of a personal data breach affecting customer data, we will tell you without undue delay. We will give you the information you need to meet your own obligations, as it becomes available: what happened, the data and people likely to be affected, the likely consequences, and what we are doing about it.

10

Deletion or return

In short While the service runs, customer data is deleted on your retention setting. At the end, you export your results through the API, and we delete other customer data when you ask.

While the service runs, customer data is deleted on your retention setting, and you can delete subjects and references at any time through the API.

At the end of the service, return is by exporting your results through the API; other customer data is deleted when you ask us to, unless law requires us to keep it. When your account closes we delete your organisation’s records (settings, keys and check history). Stored files — documents, reference images and result files — are deleted when you ask us to (email [email protected]), unless law requires us to keep them. Billing and audit records are kept, as the terms describe. Database backups are kept for 7 days, so data deleted from the database leaves them within 7 days.

11

Audits

In short We give you the information you need to check we comply, and allow a reasonable audit at most once a year.

We will make available the information you reasonably need to show that we meet this addendum. On request, we will allow a reasonable audit or inspection by you or an independent auditor you choose, bound by confidentiality, with reasonable notice and at a time agreed with us. Audits are limited to once a year, unless a regulator requires more or a breach makes one necessary.

12

International transfers

In short Customer data is stored in London. Where a subprocessor handles it outside the UK or EU, safeguards apply.

Customer data is stored with Amazon Web Services in London (eu-west-2). Where a subprocessor may process customer data outside the UK or the EU, we rely on an adequacy decision or appropriate safeguards where applicable, such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses.

13

No training

In short Customer data is never used to train anything.

We never use customer data to train anything, and we never sell it. The one opt-in, reference learning, adds approved signatures to that same person’s references in your organisation and nowhere else.

14

Contact

In short Questions about this addendum go to [email protected].

Email [email protected], or write to GitGlue Ltd, 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE.

Unforged is a product of GitGlue Ltd, registered in England and Wales, company no. 16899910. Registered office: 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE. Email [email protected].

On this page

  1. 01Scope and roles
  2. 02The processing
  3. 03Your instructions
  4. 04Your responsibilities
  5. 05Our people
  6. 06Security measures
  7. 07Subprocessors
  8. 08Helping you meet your obligations
  9. 09Personal data breaches
  10. 10Deletion or return
  11. 11Audits
  12. 12International transfers
  13. 13No training
  14. 14Contact
unforged Talk to us
  • Unforged Nib
  • Use cases
  • Developers
  • Security
  • Responsible disclosure
  • How we test
  • Compare
  • Guides
  • Glossary
  • Pricing
  • About
  • Terms
  • Privacy
  • DPA & subprocessors
  • Cookies
© 2026 GitGlue Ltd unforged.ai · api.unforged.sh

Unforged is a product of GitGlue Ltd Registered in England and Wales, company no. 16899910 3rd Floor, 86-90 Paul Street, London EC2A 4NE [email protected]