Legal

Privacy Policy

Last updated 29 September 2026

This policy explains what personal data Forge collects, why, who we share it with, how long we keep it, and your rights.

Who we are. Forge is provided by Rok Enterprises Ltd, trading as Intelligent Operations, a company registered in England and Wales (company number 13757176). Registered office: 3 Rectory Lane, Bleadon, Weston-super-Mare, BS24 0PE. For anything about your data, email ops@intelligentoperations.uk.

Our two roles

For your account, we are the controller. That covers the details of the people who use Forge, billing records, support messages and the launch list. This policy explains how we handle that data.

For what you put in your workspace, such as your customers’, staff’s and suppliers’ details, your business is the controller and we process it on your behalf. That is covered by our Data Processing Addendum. If you are a member of the public whose details are held in a business’s Forge workspace, or who filled in a form a business shared, please contact that business about your data.

What we collect

  • Account details: your name, email address, username and role. Your email address and a password are needed to create an account. We store a scrambled (hashed) version of your password, never the password itself. If a colleague added you to their workspace, we got your name and email address from them.
  • Billing details: the business name and address, the number of seats, and payment and invoice records. Card payments are processed by our payment provider. We never see or store your full card number.
  • Activity records: a record of actions taken in each workspace, such as who created or changed something, when, and whether it worked. This includes actions your connected AI assistant takes for you.
  • Security records: for sensitive actions, such as changes to accounts, logins, invitations and access, we keep a tamper-proof record of who did what, in which workspace, and the result. It doesn’t contain your documents or records.
  • Technical data: our servers log requests, which can include your IP address and browser type. If something goes wrong, we send an error report to our error-monitoring provider with request content removed.
  • Support messages: anything you send us when you ask for help.
  • Launch list: your email address, if you ask us to tell you when Forge opens.

Cookies

Forge uses one essential cookie, forge_session, to keep you signed in. It can’t be read by scripts on the page and is only sent over secure connections. If you fill in a form that a business has shared publicly, Forge also sets forge_public_respondent, which remembers your answers on that device for up to a year so you don’t lose them. Both cookies are strictly necessary. We don’t use advertising or analytics cookies.

Services you connect

  • Your AI assistant. When you connect an AI assistant such as ChatGPT or Claude, what you ask it and what Forge returns pass through that assistant’s provider, under your own agreement with them.
  • Google Drive and Dropbox. You can choose to keep your workspace files in your own Google Drive or Dropbox. If you connect Google Drive, Forge asks for access to your Drive files and your email address, and uses them only to store and read your workspace files. For Dropbox, Forge uses its own app folder in your Dropbox. You can disconnect either at any time.

We don’t read your email or calendar. Forge’s use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

Why we use your data

  • To provide Forge under our contract with you: running your account, taking payment, sending account emails such as invitations and password resets, and giving support.
  • For our legitimate interests: keeping Forge secure, detecting and investigating misuse (including keeping security records), fixing faults and improving the service. We keep this to what is necessary.
  • To meet legal obligations: for example, keeping tax and accounting records.
  • With your consent: emailing you about the launch. You can unsubscribe at any time.

We don’t sell your data, we don’t use it for advertising, and we don’t use your workspace content to train AI models.

Who we share it with

We use these providers to run Forge. Each one is bound by a contract to protect the data and use it only for the service they provide to us.

DigitalOceanHosting, databases and file storage (London), and a backup copy of stored files (Frankfurt, Germany)
Amazon Web ServicesEncrypted backups and the security record (London)
ResendSending account emails, such as invitations and password resets (USA)
SentryError monitoring, with request content removed (USA/EU)
GoogleOur business email, including support messages you send us (USA/EU)
Our payment providerTaking card payments. We will name them here before paid subscriptions start.

We may also share data where the law requires it, or to protect the rights and safety of Forge, our customers or others.

Where your data is kept

Your data is mainly stored in the United Kingdom. A backup copy of stored files is kept in the European Union, and some providers above are based in the USA. Where data leaves the UK, we rely on UK adequacy regulations or the UK International Data Transfer Addendum, as set out in each provider’s data protection terms.

How long we keep it

Account and workspace dataWhile you have access. After access ends, you can read and export it for 30 days, and we delete it 60 days after access ends, with 14 days’ warning. Full details are in our Terms.
Database backupsEncrypted, and deleted automatically after 35 days.
File backupsEncrypted copies are removed by a clean-up process once nothing in Forge refers to them any more. This can take longer than 60 days after access ends, and earlier versions of files can stay in our encrypted backups until we remove them manually.
Activity recordsUp to 400 days for actions taken through connected AI assistants, and up to 90 days for actions in the web app.
Security recordsSeven years. They are locked so they can’t be changed or deleted early.
Billing recordsSix years after the end of the financial year they relate to, as required for tax.
Server logsApplication logs are kept for 14 days. System logs are overwritten automatically when they reach a size limit, which can take several months.
Launch listUntil you unsubscribe or ask us to remove you.

We only use backups to recover Forge after a failure. If we restore a backup that contains data we had already deleted, we delete it again.

How we protect it

Each workspace’s records are kept in a separate database, and access is checked on every request. All connections to Forge are encrypted. Passwords are stored hashed and connection tokens are stored encrypted. Backups are encrypted before they leave our server, and only named people can access our servers, using SSH keys with password login turned off.

Your rights

You can ask us for a copy of your personal data, and ask us to correct it, delete it, restrict or object to how we use it, or send it to you in a portable format. Where we rely on your consent, you can withdraw it at any time. Email ops@intelligentoperations.uk and we will reply within one month.

If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first.

Children

Forge is a business service and isn’t intended for anyone under 18.

Changes to this policy

We will update this policy when how we handle data changes. The date at the top shows the latest version. For significant changes, we will email workspace owners before they take effect.