Data Processing Addendum
GDPR Article 28 compliant. Our standard DPA covers data processing across London, Manchester, Dublin, Berlin, and Frankfurt.
Reference: F-DPA-2025
Version 1.0
Data Processing Addendum
GDPR ARTICLE 28 COMPLIANCE • EU DATA PROTECTION
London (LON) • Manchester (MAN) • Dublin (DUB) • Berlin (BER) • Frankfurt (FRA)
Effective Date: January 1, 2026
This Data Processing Addendum ("DPA") forms part of the Master Service Agreement between Forge.io Pty Ltd ("Data Processor") and the Customer identified in the applicable order form ("Data Controller").
1. Definitions and Interpretation
Terms used in this DPA shall have the meanings set forth in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). "Personal Data", "Processing", "Data Subject", and "Supervisory Authority" shall have the same meaning as in Articles 4 of the GDPR.
2. Scope and Purpose of Processing
The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by Union or Member State law.
3. Data Residency Guarantee
Sovereign Data Boundaries
Personal Data processed under this DPA shall remain exclusively within the European Economic Area (EEA) at all times. Forge.io's infrastructure enforces data residency at the network level—data cannot traverse paths that would route it outside your designated region.
4. Security Measures (Article 32)
- Encryption of Personal Data in transit and at rest using AES-256 and TLS 1.3;
- Hardware-isolated compute environments (Firecracker MicroVMs) ensuring workload segregation;
- Continuous monitoring and logging of all access to Personal Data;
- Regular testing and evaluation of security measures through third-party audits.
5. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligation to respond to requests for exercising the Data Subject's rights, including the right of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection.
Authorized Signature
FORGE.IO PTY LTD (Data Processor)
Authorized Signature
DATA CONTROLLER
Forge.io Pty Ltd • Sovereign Developer Cloud
Page 1 of 1 (Template)