Legal

Privacy policy

How we collect, use and protect your personal data. Hosted in France, GDPR-compliant, no model training, no resale.

Scroll to read

Last updated: February 2026.

This privacy policy explains how Forge collects, uses, and protects personal data in connection with the use of the platform. Forge's mission is to help business clients improve their teams' performance.

1. Data controller

Personal data processed through Forge is under the responsibility of:

Squarance

Société par actions simplifiée (SAS)

20 boulevard Montmartre, 75009 Paris, France

Contact: dpo@forgelearning.com

Data Protection Officer (DPO)

The Data Protection Officer is Guillaume Blachon.
Contact: dpo@forgelearning.com

2. Personal data processed

In the context of using Forge, personal data is processed for the purposes described below.

Purpose Categories of data Legal basis Retention
Account creation and managementFirst name, last name, professional email, user IDContract performanceDuration of the contract
Authentication and securityIP address, technical logs, authentication and session dataLegitimate interest (security)30 days (logs)
AI conversational serviceInteractions with the coach, conversation historyContract performanceDuration of the contract
Educational activity generationQuestions asked, generated contentContract performanceDuration of the contract
Experience personalisationLanguage, user memory (professional preferences)Contract performanceDuration of the contract
Service improvement (anonymised statistics)Aggregated and anonymised dataLegitimate interestNon-personal anonymised data
Customer supportRelevant identification and usage dataContract performanceDuration necessary for processing

2.1 User memory

The user memory maintained by the coaches:

  • is visible and editable by the user through the interface;
  • is used solely to improve response relevance;
  • can be deleted by the user at any time.

2.2 Educational content imported by the client

Documents, knowledge bases, or training materials imported into Forge are provided under the client's responsibility. By default, these contents are considered professional data, not personal data.

If such content contains personal data:

  • the client remains the data controller;
  • Forge acts as a data processor;
  • data is processed exclusively to provide the service;
  • the security mechanisms described in this policy apply.

Upon client request:

  • content can be exported;
  • content can be deleted;
  • associated indexes and representations are deleted;
  • backups follow the normal retention cycle (maximum 30 days).

3. Purposes of processing

Personal data is processed for the following purposes:

  • provision and operation of the Forge service;
  • security, abuse prevention, and incident detection;
  • product improvement without exploiting client content (aggregated and anonymised statistics);
  • customer support and assistance;
  • compliance with legal and regulatory obligations.

Data is never used for commercial or advertising purposes.

Forge's processing activities rely on:

  • performance of the contract between Forge and its clients;
  • Forge's legitimate interest (security, service improvement);
  • compliance with applicable legal obligations.

5. Hosting and subprocessors

5.1 Hosting

Data is hosted in France by Scaleway (infrastructure and data hosting).

5.2 Logs and monitoring

Log data is hosted in Ireland by Datadog (technical monitoring and application logs, data limited to technical information).

5.3 AI providers

Forge may use AI providers for certain features. In this context:

  • only content data in textual excerpts is transmitted;
  • no directly identifying personal data (name, email, user ID) is transmitted;
  • data is not used to train models;
  • retention is strictly temporary.

The list and details of providers are available on the About your data page.

6. Data transfers outside the European Union

Main data is hosted within the European Union. Some technical subprocessors may be located outside the EU. In such cases:

  • only strictly necessary excerpts are transmitted;
  • no directly identifying data is sent;
  • transfers are governed by Standard Contractual Clauses (SCCs) or equivalent mechanisms;
  • providers contractually commit not to use data for model training.

7. Data retention periods

Data is retained as follows:

  • Account data: duration of the contract;
  • Usage data: duration of the contract;
  • Technical logs: limited duration (about 30 days);
  • After termination: deletion of data (database and imported or generated content) within 3 months.

8. Data security

Forge implements appropriate technical and organisational measures to ensure data security, including:

  • data encryption;
  • access control;
  • logging and traceability;
  • monitoring and incident detection.

These measures are detailed on the About your data page.

9. Rights of data subjects

In accordance with the GDPR, users have the following rights:

  • right of access;
  • right to rectification;
  • right to erasure (some rights can be exercised directly in settings);
  • right to object;
  • right to data portability.

To exercise these rights, users may contact: dpo@forgelearning.com.

10. Cookies and trackers

Forge only uses technical and performance measurement tools (Datadog). Forge does not use any marketing or advertising cookies.

11. Changes to the privacy policy

This policy may be updated to reflect:

  • legal or regulatory developments;
  • changes to the Forge service.

The latest version is always available on the Forge website.

12. Contact

For any questions regarding this policy or data protection: dpo@forgelearning.com.

Last updated: February 2026.

Data Protection Officer: Guillaume Blachon, dpo@forgelearning.com.