Privacy policy
Last updated Version 1.1
Contents
Who we are
In short GitGlue Ltd runs Unforged and is the controller of the personal data this policy describes.
GitGlue Ltd (company no. 16899910, registered in England and Wales; registered office 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE) provides Unforged at unforged.ai. For the personal data this policy describes, we are the controller under the UK GDPR and, where it applies, the EU GDPR.
Our two roles
In short We are the controller for account, billing and website data. For the documents and signatures our customers send, we are their processor.
- Controller. We decide how account, billing and website data is used: the data about you as a user, a customer contact or a visitor.
- Processor. The documents, reference signatures and check results our customers send are their data (customer data). We process it only on their instructions.
What we collect and why
In short Only what we need to run your account, bill for it, answer you and keep the service secure.
| Data | What it is | Why | Lawful basis |
|---|---|---|---|
| Account data | Your name, email address, the organisations you belong to and your role in each, from our sign-in provider. A record of the actions you take in the dashboard and API (the audit log). | To give you an account, let you work in your organisations, and keep a record of who did what. | Contract (providing the service); legitimate interests (security and accountability). |
| Billing data | Your organisation’s name and billing email, and the number of billable checks. Card and payment details go straight to Stripe; we never see your card number. | To charge for Unforged, send invoices and keep accounts. | Contract; legal obligation (tax and accounting records). |
| Support | What you send us by email, and our replies. | To answer you and fix problems. | Legitimate interests (helping our customers); contract, where you are one. |
| Contact form | Your name, email, company, topic and message. We store only a hashed form of your IP address, used to limit abuse. | To reply to you, and to stop the form being abused. | Legitimate interests (answering enquiries; preventing abuse). |
| Server logs | Technical records of requests and errors. Customer references in them are replaced by a keyed hash. | To run Unforged securely and fix faults. | Legitimate interests (security and reliability). |
Where we rely on legitimate interests, we have weighed them against your rights, and you can object (see your rights, below). We set no analytics cookies: see the cookie policy, and website analytics, next.
Website analytics
In short Cookieless analytics on our public website: page views, referrer, country and device, never your identity.
We use Cloudflare Web Analytics on our public website (unforged.ai). It is cookieless: it sets no cookie and does not fingerprint your device, so it cannot follow you across other sites. It records the page you visited, the referring site, your country and your device type — never your name, email or IP address.
We use this only to understand how our website is used and to improve it. The lawful basis is legitimate interests (running and improving our website), weighed against your privacy; it sets no cookie and stores nothing on your device, so there is no consent banner. It never runs on the signed-in dashboard.
Customer data
In short Documents, signatures and results belong to our customer, who decides how they are used. The data processing addendum covers them.
If your signature, or a document you signed, was checked with Unforged, the organisation that sent it is the controller. Ask them about how they use it; if you contact us, we will pass your request on to them.
We process customer data for our customers under our data processing addendum, which covers what we process, how long it is kept, our subprocessors, and how we help customers answer your requests. We never use customer data to train anything.
Who we share it with
In short A small set of vendors who help us run Unforged, listed on the DPA page. We never sell personal data.
We share personal data only with vendors who help us run Unforged:
- Amazon Web Services. Hosting: the servers, database, file storage, queues and keys that run Unforged.
- Cloudflare. DNS, the network in front of unforged.ai (the website and dashboard), and cookieless website analytics.
- WorkOS. Sign-in, single sign-on and directory sync.
- Stripe. Payments, invoices and usage billing.
- Resend. Sending our transactional email.
- Google Workspace. Our own email, including [email protected].
The full list, with what each one sees and where, is on the DPA page. We may also share data where the law requires it, or with a buyer if our business is sold (with this policy still applying). We never sell personal data.
International transfers
In short Unforged is hosted in London. Where a vendor processes data outside the UK or EU, safeguards apply.
Unforged is hosted by Amazon Web Services in London (eu-west-2). Some of our vendors may process personal data outside the UK and the EU. Where they do, we rely on an adequacy decision or appropriate safeguards where applicable, such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses. Ask us for details.
How long we keep it
In short As long as we need it, and no longer. The periods are below.
- Account data is kept while your account is open. When your account closes we delete your organisation’s records (settings, keys and check history). Stored files — documents, reference images and result files — are deleted when you ask us to (email [email protected]), unless law requires us to keep them. Billing and audit records are kept. Your user record at our sign-in provider (WorkOS) is deleted when you ask us to.
- The audit log is kept for 400 days, then deleted.
- Server logs are kept for 30 days, then deleted.
- Billing records (usage records and invoices) are kept after an account closes, for as long as tax and accounting law requires.
- Support emails and contact-form requests are kept while we need them to deal with your request. Ask us and we will delete yours, unless we must keep it.
- Customer data follows each customer’s own history-retention setting (90 days by default, from 30 minutes to 10 years, or indefinitely); reference signatures are kept until the customer deletes them.
- Database backups are kept for 7 days, so deleted data leaves them within 7 days.
Your rights
In short You can ask to see, correct, delete or move your data, object to how we use it, and complain to a regulator.
Under the UK GDPR and the EU GDPR you have the right to:
- get a copy of your personal data;
- have it corrected if it is wrong;
- have it deleted, or its use restricted, in some cases;
- receive it in a portable form, or have it sent to someone else, in some cases;
- object to our use of it where we rely on legitimate interests;
- withdraw consent at any time, where we rely on consent.
Email [email protected] to use any of these. We will reply within one month, and may ask you to confirm who you are. You can also complain to the Information Commissioner’s Office (ico.org.uk) in the UK, or to your data protection authority in the EU; we would be grateful for the chance to put things right first.
Children
In short Unforged is not for anyone under 18.
Unforged is a business service and is not meant for anyone under 18. We do not knowingly collect personal data from children as controller.
Changes to this policy
In short We update this page when things change, and tell account holders about important changes.
When this policy changes, we update this page and its date and version. We tell account holders about important changes by email or in the dashboard.
Contact us
In short Privacy questions and requests go to [email protected].
Email [email protected], or write to GitGlue Ltd, 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE.