Legal Center

Legal

ForgeOps Subprocessor List

Version
1.3
Effective
2026-08-25
Last updated
2026-08-25
Reading time
3 min
Content digest
45e59f14…d5ad46fe
Document: ForgeOps Subprocessor List

This page lists the third parties that process Customer Data in connection with the ForgeOps platform. It supplements the ForgeOps Privacy Policy and any Data Processing Addendum between ForgeOps and a customer.

The list is maintained as structured data inside ForgeOps and re-published whenever it changes. Each published version is retained, so a customer can see what the list said on any past date.

Sub-processors engaged by ForgeOps

These providers process Customer Data on ForgeOps' instructions in order to operate the platform. Each is engaged under terms requiring confidentiality and appropriate security.

Vercel Inc.

  • Purpose: Hosting & delivery
  • Data processed: Application hosting and request delivery. Request metadata and application logs; no customer database contents at rest.
  • Processing location: United States

Supabase Inc.

  • Purpose: Database & authentication
  • Data processed: The application database (all Customer Data at rest), user authentication records and password hashes, and object storage for uploaded files.
  • Processing location: United States

Amazon Web Services, Inc. (Simple Email Service)

  • Purpose: Email delivery & receipt
  • Data processed: Outbound transactional email and inbound intake mail, including message bodies, attachments, recipient addresses and delivery outcomes.
  • Processing location: United States

Google LLC (Gemini API)

  • Purpose: AI model processing
  • Data processed: Content submitted to AI features — email text, extracted document content, record descriptions and prompts — when those features are enabled for an organization.
  • Processing location: United States

Fly.io (Fly.io, Inc.)

  • Purpose: Background processing
  • Data processed: CAD geometry extraction. Uploaded STEP/CAD files are processed to produce part and cut-list data.
  • Processing location: United States

Stripe, Inc.

  • Purpose: Payments
  • Data processed: Payment and payout processing for customer invoices, including payer contact details and payment status. Full card numbers are handled by Stripe and are not stored by ForgeOps.
  • Processing location: United States

Customer-authorized integrations

These are connected by the customer through the provider's own consent flow, and reach only the data the customer's authorization grants. A customer can disconnect any of them at any time. They are listed for completeness; ForgeOps does not engage them on the customer's behalf.

Microsoft Corporation (Microsoft 365 / Microsoft Graph)

  • Purpose: Customer-authorized integration
  • Data processed: Mailbox contents and attachments for email intake and sending, and documents stored in OneDrive or SharePoint, limited to the scopes the customer authorizes.
  • Processing location: Per the customer's own Microsoft 365 tenant configuration

Google LLC (Google Drive)

  • Purpose: Customer-authorized integration
  • Data processed: Documents stored in the customer's Google Drive, limited to the scopes the customer authorizes.
  • Processing location: Per the customer's own Google Workspace configuration

Intuit Inc. (QuickBooks Online)

  • Purpose: Customer-authorized integration
  • Data processed: Accounting records synchronized at the customer's direction — customers, vendors, invoices, purchase orders, bills, payments and time activity.
  • Processing location: Per the customer's own QuickBooks company configuration

Changes to this list

ForgeOps may engage a new sub-processor to operate or improve the Service. Where a Data Processing Addendum is in place, the notice and objection process in that addendum applies. Otherwise, changes are published here with a new version number and effective date.

To be notified of changes to this list, contact privacy@forgeops-erp.com.

ForgeOps will give 30 days notice before a new sub-processor begins processing Customer Data, by publishing an updated version of this list with a new effective date. A customer who has asked to be notified at privacy@forgeops-erp.com will also be told directly.

Version history

Superseded versions are retained permanently. Their text is never edited.

  • v1.2Effective 2026-08-25 · superseded 2026-08-25Read v1.2
  • v1.1Effective 2026-08-20 · superseded 2026-08-25Read v1.1
  • v1.0Effective 2026-08-18 · superseded 2026-08-20Read v1.0