Privacy policy
This page is about data concerning you — your account, your payments, your emails to us. Data inside your forge is a different relationship: there you are the controller and we are your processor, and the data processing agreement governs it.
Who is responsible
The provider's registered name and address are not published here yet. Until they are, this service is not being offered for sale, and the address below is the way to reach whoever is operating it.
Email: support@forgejo.dc-analytic.com
We have not appointed a data protection officer. We are not required to, and saying we had one would be more impressive than true. Privacy questions reach the address above and are answered by a person who can act on them.
What we hold, and why
| Data | Why | Legal basis |
|---|---|---|
| Your email address and a hash of your password | To give you an account and let you sign in | Performance of the contract |
| Two-factor settings and recovery codes | To let you protect the account that can export your source code | Performance of the contract |
| Session records | To keep you signed in | Performance of the contract |
| Your instances: names, plans, state, quotas, usage, backup records | To run the service you bought | Performance of the contract |
| Subscription state from our payment provider, and your billing details held by them | To take payment and to know whether a subscription is paid | Performance of the contract; legal obligation for tax records |
| Emails you send to support, and our replies | To answer you, and to remember what was said | Performance of the contract; our legitimate interest in keeping a record |
| Rate-limit counters keyed by IP address | To stop somebody guessing passwords against the portal | Our legitimate interest in keeping accounts secure |
| Operational logs from the control plane and the portal, which can contain IP addresses | To operate the platform and investigate faults and abuse | Our legitimate interest in a service that works and is not abused |
| An audit record of changes to instances: who did what, and when | To be able to answer what happened to an instance and on whose instruction | Our legitimate interest in accountability |
We never see your card number. Payment details are entered on our payment provider's own pages and stay with them. What reaches us is whether the subscription is paid.
There is no analytics, no advertising, no tracking, and no profiling. We do not sell data and we have nobody to sell it to.
How long we keep it
- Instance data and its backups: 30 days from the moment an instance is suspended — whether for non-payment, on cancellation, or because you asked us to delete it — and then permanently destroyed.
- The retention period above is the same one stated in the terms and the data processing agreement. There is one of it.
- An export archive: 24 hours after it is built, then deleted.
- Your account: for as long as you have one, and for a short period afterwards so that a deletion made in error can be undone. Ask and we delete it sooner.
- Invoices and payment records: as long as tax law requires, which in the EU is generally seven to ten years. We cannot delete these on request, and neither can our payment provider.
- Support email: two years from the last message in a thread.
- Rate-limit counters: minutes to hours. They expire on their own.
- Operational logs: until the host's journal rotates them out. That is bounded by disk space rather than by a fixed number of days, which is an honest description rather than a good one, and we would rather say so than publish a period nothing enforces.
Who else sees it
Only the companies we need to run the service, each doing one job, each under a contract that binds them to it. Every one of them is named, with what they do and where, on the subprocessor page — including the two that are outside the EU and why.
We disclose data to authorities only where we are legally required to, and we will tell you when that happens unless we are forbidden from telling you.
Where your data is
The servers your instance runs on, and the storage both copies of its backups go to, are in the EU — and the companies operating them are European too, which is a stronger statement and the one that matters: a provider with a United States parent can be reached by United States law wherever it keeps the bytes. Two of our suppliers — the email provider and the payment provider — are groups with United States parents, so email metadata and billing data may be processed outside the EU under the European Commission's standard contractual clauses. They are the only two, and they are why we would not make the backups a third. The subprocessor page says exactly which is which; we would rather you know than assume.
One more, because it is invisible and it is on every page of this portal: the portal loads its one JavaScript library from a public content delivery network, which means your browser makes a request to that network's servers and it sees your IP address. That is a dependency we intend to remove by serving the file ourselves, and until we have, it belongs on this page rather than in a footnote.
Cookies
Three, all strictly necessary, none needing consent: a session cookie so that you stay signed in; a cross-site request forgery token so that a form submission is really yours; and a short-lived one carrying a single notice — "you have signed out", "your recovery codes were generated" — across the redirect that shows it to you, which is discarded as soon as it has been read. There are no others: no "remember this device", no preferences, nothing that measures you. There is no cookie banner because there is nothing to ask you about.
Your rights
You can ask us for a copy of your data, for it to be corrected, for it to be deleted, for processing to be restricted, for a portable copy, and you can object to processing we do on the basis of legitimate interests. Email the address at the top. We answer within one month, and if a request is complex enough to need longer we will tell you before the month is up rather than afterwards.
Two of these you can exercise yourself, immediately, without asking: portability — the export in the portal is a complete, machine-readable copy of your instance — and deletion of an instance, which starts the 30 days above.
If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to the data protection authority in the EU country where you live or work, or where the provider is established.
If something goes wrong
If personal data is breached, we notify the competent supervisory authority within 72 hours of becoming aware of it, and we tell affected customers directly where the breach is likely to be a risk to them. We will tell you what happened, what data was involved, and what we have done, rather than the smallest thing we could get away with saying.
Changes
The date at the top of this page is when it last changed. Material changes are emailed to customers at least 30 days before they take effect.