FForgeLeads

Data Processing Policy

This internal Policy defines the procedures for processing and deleting personal data within ForgeLeads, published as required by Art. 18.1(1) of Russian Federal Law 152-ФЗ and aligned with GDPR Art. 32.

1. Responsible Person

The person responsible for organizing personal-data processing is Борисов Николай Владимирович (contact: njoy13@inbox.ru).

2. Data Categories and Retention

CategoryRetentionBasis
Email and user identifierUntil account deletion + 30 daysContract performance
Payment data (no card numbers)5 yearsTax and accounting law
Activity logs and session tokens180 daysSecurity and incident investigation
Lead data in CRMUntil account deletion + 30 daysContract performance
BackupsUp to 90 daysDisaster recovery
Authentication cookiesSession or 7 daysService functionality
Analytics cookies (PostHog)Up to 12 monthsUser consent

3. Erasure on User Request

  1. The data subject sends an erasure request to njoy13@inbox.ru with the subject "GDPR Request — Erasure".
  2. The operator confirms receipt within 3 business days and verifies identity (request must come from the registration email).
  3. Data is erased within 30 calendar days of request.
  4. Data is removed from active database; backup copies are purged on rotation (up to 90 days).
  5. The operator confirms completion to the data subject.

4. Erasure on Account Deletion

When a user deletes their account via the Service interface:

  • account is deactivated immediately;
  • data is purged from the active database within 30 days (grace period for accidental deletion recovery);
  • backup data is purged on rotation (up to 90 days);
  • payment data is retained for 5 years in anonymized form for tax purposes.

5. Security Measures

5.1. Technical

  • TLS 1.3 in transit;
  • AES-256 at rest (provided by database vendor);
  • Salted password hashing (bcrypt);
  • Row-Level Security in the database;
  • Two-factor authentication for admin access;
  • Automated audit logging;
  • Regular dependency updates.

5.2. Organizational

  • Designated data protection responsible (see § 1);
  • Strict access limitation;
  • Data Processing Agreements with sub-processors;
  • Annual internal review.

6. Cross-Border Data Transfer

Personal data is transferred outside the Russian Federation for the operation of the Service. Such transfers occur on the basis of the data subject's explicit written consent (Article 12 of Russian Federal Law 152-FZ), captured at registration via a dedicated checkbox in the sign-up form (/signup).

Consent text: "I consent to the cross-border transfer of my personal data to Ireland (Supabase EU), the United States (Stripe, Anthropic, Vercel) and Singapore for the operation of the service".

Recipient countries and legal bases:

  • Ireland(Amazon Data Services Ireland Limited via Supabase Inc. infrastructure) — primary personal data storage. Ireland is listed by Roskomnadzor (Order No. 274 of 15 March 2013) as a country providing adequate protection of data subjects' rights.
  • United States(Stripe Inc., Anthropic PBC, Vercel Inc.) — international payment processing, AI processing of de-identified text, web application CDN delivery. The United States is not listed as a country providing adequate protection — transfer is performed under the data subject's written consent.
  • Singapore(Supabase Inc. — hosting platform corporate entity) — management of the operator's account on the hosting platform. Transfer is performed under the data subject's written consent.

The data subject may withdraw consent to cross-border transfer at any time by emailing the controller (see § 1). Withdrawal of consent terminates the provision of the Service. The consent timestamp is recorded in the profiles.transborder_consent_given_at database column.

7. Incident Response

  1. Incident identification and containment within 24 hours.
  2. Regulator notification (Roskomnadzor / EU DPA) within 72 hours.
  3. Affected-subject notification within 72 hours by email.
  4. Root-cause investigation and remediation within 30 days.
  5. Incident documentation.

8. Policy Updates

This Policy is reviewed at least annually. The current version is published at /legal/data-processing-policy.

Effective: 2026-07-15.

Last updated: