Sign inGuideTermsPrivacySubprocessorsDPA

Data processing agreement

High-level summary of how Phantom Forge Labs processes personal data on behalf of enterprise customers using Forge. This page is not an executable Data Processing Agreement. A full DPA (and SCCs where applicable) is provided as a commercial exhibit and must be executed before production processing under contract.

  • Processor processes personal data only to provide the Service and support, on Controller instructions.
  • Subprocessors are listed at /legal/subprocessors.
  • Security measures include authenticated access, tenant-scoped data isolation, role-based authorization, audit logging, and TLS for hosted traffic per industry practice.
  • Where the order form includes AI SaaS Forge-operated delivery (Inference API and/or Managed agents) and the organization enables Forge model learning, Processor may process scrubbed AI SaaS product signal to improve Forge-operated models, subject to the executed DPA and workspace settings. Build-tier releases are out of that learning path by default.
  • International transfers and subprocessors are addressed in your executed DPA and applicable SCCs.

Optional Forge-operated inference

When the order form includes AI SaaS Inference API and/or Managed agents, Processor may host inference behind Forge aliases. Prompts and completions on that path are processed to provide the Service. API key reveal, rotate, provision, smoke, and try-chat are limited to authenticated organization owners and administrators and are recorded on the AI Release audit timeline. Retention, subprocessors, and region for that SKU are defined in the executed DPA exhibit — not this summary. Build-tier customer-cloud inference stays in the customer account.

Contact

legal@phantomforgelabs.com