DevtechForge AI
Platform
Overview Agents Context engine Human in the loop Connectors
Pricing
Services
Forward Deployed Engineers R&D as a Service Ecosystem Enablement
Who we serve
Software vendors Distributors Telcos Cloud and managed service providers
Company
About Devtech Case studies Leadership Careers Contact
Request early access
Request early access
PlatformOverviewAgentsContext engineHuman in the loopConnectors
Pricing
ServicesForward Deployed EngineersR&D as a ServiceEcosystem Enablement
Who we serveSoftware vendorsDistributorsTelcosCloud and managed service providers
CompanyAbout DevtechCase studiesLeadershipCareersContact
Legal

Devtech Forge AI Data Processing Agreement

Last updated: September 23 2026

This Data Processing Agreement, including its Schedules (the "DPA"), forms part of the Devtech Forge AI Terms and Conditions or other written agreement between Devtech Limited and Customer governing Customer's use of the Forge AI platform (the "Agreement"). It applies whenever Devtech processes Personal Data on Customer's behalf in connection with the Service.

Parties:

Devtech Limited, a company registered in England and Wales (registration number 08409744) with its registered office at 25 Old Broad Street, London, EC2N 1HN, United Kingdom ("Devtech" or "Processor"); and

the Customer identified in the Agreement ("Customer" or "Controller").

1. Definitions

1.1 In this DPA:

"Contractual Safeguards" means (i) where the EU GDPR applies, the SCCs, and (ii) where the UK GDPR applies, the SCCs as amended by the UK Addendum.

"Data Protection Legislation" means all applicable laws and regulations governing the processing of Personal Data, including the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, and, where applicable, US State Privacy Laws.

"EU GDPR" means Regulation (EU) 2016/679 (the General Data Protection Regulation).

"Personal Data" means personal data contained in Customer Data (as defined in the Agreement) that Devtech processes on Customer's behalf in providing the Service.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

"Restricted Transfer" means a transfer of Personal Data that would be unlawful under the EU GDPR or the UK GDPR (as applicable) in the absence of an adequacy decision or regulations, the Contractual Safeguards, or another lawful transfer mechanism.

"SCCs" means the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.

"Sub-processor" means any processor engaged by Devtech to process Personal Data on Customer's behalf in connection with the Service.

"UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under s119A of the Data Protection Act 2018.

"UK GDPR" has the meaning given in section 3 of the UK Data Protection Act 2018.

"US State Privacy Laws" means US state laws governing personal information applicable to the processing under this DPA, including the California Consumer Privacy Act as amended (CCPA).

1.2 The terms "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in Data Protection Legislation. Terms defined in the Agreement have the same meaning in this DPA.

2. Scope, Roles, and Precedence

2.1 This DPA applies to Devtech's processing of Personal Data on Customer's behalf in providing the Service. The subject matter, nature, purpose, and duration of the processing, the types of Personal Data, and the categories of data subjects are set out in Schedule 1.

2.2 As between the parties, Customer is the controller and Devtech is the processor. Where Customer itself acts as a processor for a third-party controller, Devtech acts as Customer's sub-processor, Customer warrants that its instructions to Devtech are consistent with the instructions of that controller, and references to "Controller" in this DPA are read accordingly.

2.3 Devtech acts as an independent controller, not as Customer's processor, in respect of: (a) account, billing, and contact data of Customer's personnel needed to administer the commercial relationship; (b) technical and usage data described in the Agreement (excluding the content of Customer Data); and (c) processing required to comply with Devtech's own legal obligations, including fraud and abuse prevention. Devtech will comply with Data Protection Legislation in respect of such processing and process such personal data in accordance with its Privacy Policy.

2.4 In the event of conflict, the order of precedence for matters relating to the processing of Personal Data is: (1) the Contractual Safeguards; (2) this DPA; (3) the Agreement.

2.5 The Customer will ensure that it is entitled to transfer the Personal Data to Devtech so that Devtech may lawfully use, process and transfer the Personal Data for the duration and purposes of the Agreement.

3. Processing Instructions

3.1 Devtech will process Personal Data only on Customer's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by law to which Devtech is subject; in that case Devtech will inform Customer of the legal requirement before processing, unless that law prohibits doing so on important grounds of public interest. Devtech will only process Personal Data to the extent necessary to perform its obligations under the Agreement and shall not process any Personal Data for any other purpose.

3.2 Customer's instructions are: the Agreement, this DPA, Customer's configuration of the Service (including the Connected Services Customer connects, the permissions Customer grants, and the instructions Customer and its users give to Agents), and any further documented instructions agreed by the parties.

3.3 Devtech will promptly notify Customer if, in Devtech's opinion, an instruction infringes Data Protection Legislation. Devtech may suspend the affected processing (other than secure storage) until Customer issues revised instructions.

3.4 Devtech will disclose Personal Data to a government authority or other third party only where necessary to comply with law or a binding order of a governmental body, and will, unless legally prohibited, notify Customer before such disclosure and limit the disclosure to the minimum required.

3.5 Third-party model providers. Where Customer configures the Service to use a third-party model provider under the Agreement, Customer thereby instructs Devtech to transmit the relevant Personal Data to that provider. The provider is engaged by Customer, is not a Sub-processor of Devtech, and Customer is responsible for establishing its own lawful basis and processing terms with that provider.

4. No Training on Personal Data

4.1 Devtech will not use Personal Data, or Customer Data generally, to train, fine-tune, or improve machine learning models, whether Devtech's own or third parties'. Inference performed on Devtech's self-hosted models processes Personal Data transiently to generate Output and does not retain it in the models.

5. Confidentiality of Personnel

5.1 Devtech will ensure that persons authorised to process Personal Data are bound by contractual or statutory obligations of confidentiality, are granted access only to the extent necessary to provide, secure, and support the Service, and receive appropriate data protection training.

6. Security

6.1 Devtech will implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, unauthorised or unlawful processing, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as required by Article 32 of the EU GDPR and UK GDPR. The measures currently implemented are described in Schedule 3.

6.2 Devtech may update the measures in Schedule 3 from time to time, provided the update does not materially reduce the overall level of protection.

7. Sub-processors

7.1 Customer provides a general authorisation for Devtech to engage Sub-processors. The Sub-processors currently engaged and authorised are listed in Schedule 2.

7.2 Devtech will give Customer at least 30 days' written notice (by email or in-Service notice) before adding or replacing a Sub-processor. Customer may object on reasonable data protection grounds within that period, in which case the parties will discuss in good faith an alternative. If no alternative is found within 30 days of the objection, Customer may terminate the affected subscription with a pro-rata refund of prepaid unused Fees, as its sole remedy.

7.3 Devtech will impose on each Sub-processor, by written agreement, data protection obligations providing at least the same level of protection as this DPA, to the extent applicable to the services the Sub-processor provides, and remains fully liable to Customer for the performance of each Sub-processor's obligations.

7.4 Upon request, Devtech will provide Customer with the information it reasonably can about Sub-processor agreements, subject to redaction of confidential or commercially sensitive terms.

8. Data Subject Rights and Complaints

8.1 Devtech will promptly notify Customer if it receives a request from a data subject relating to Personal Data, any complaint, notice or communication that relates directly or indirectly to the processing of the Personal Data or to either party's compliance with the Data Protection Legislation, and will not respond to the request except on Customer's documented instructions or as required by law.

8.2 Taking into account the nature of the processing, Devtech will assist Customer by appropriate technical and organisational measures and providing such information to the Customer as the Customer may reasonably require, insofar as this is possible, in fulfilling Customer's obligation to respond to data subject requests. Where the Service provides functionality enabling Customer to action a request itself (for example, deleting or exporting content), Devtech may fulfil its assistance obligation by making that functionality available. Devtech may charge a commercially reasonable fee for assistance that exceeds what the Service's functionality provides, except where the need for assistance arises from Devtech's breach of this DPA.

9. Personal Data Breach

9.1 Devtech will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach. The notification will, to the extent then known: describe the nature of the breach, the categories and approximate numbers of data subjects and records concerned; give a contact point for further information; describe the likely consequences; and describe the measures taken or proposed to address the breach and mitigate its effects. Information may be provided in phases as it becomes available.

9.2 Devtech will cooperate with Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach. Devtech's notification of or response to a Personal Data Breach is not an acknowledgement of fault or liability.

9.3 Unsuccessful attempts (such as port scans, failed log-in attempts, or denial-of-service attacks that do not result in access to Personal Data) are not Personal Data Breaches and do not require notification.

10. DPIAs and Consultation

10.1 Taking into account the nature of the processing and the information available to it, Devtech will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, to the extent required of Customer by Data Protection Legislation and related to the Service. Devtech may charge a commercially reasonable fee for assistance beyond providing existing documentation.

11. Data Residency and International Transfers

11.1 Residency. Devtech will host Customer Data in the data residency region selected by Customer at signup and will not change the hosting region without Customer's consent.

11.2 Devtech personnel may access Personal Data remotely from the locations identified in Schedule 1 for support, operations, and security purposes. Such access is subject to the measures in Schedule 3 and, where it constitutes a Restricted Transfer, to Section 11.3.

11.3 Restricted Transfers. Neither party will make a Restricted Transfer except in compliance with Data Protection Legislation. Devtech (and any subprocessor) must not transfer or otherwise process the Personal Data outside the UK or EEA without obtaining the Customer's prior written consent. Where such consent is granted, Devtech may only make a Restricted Transfer under the following conditions:

11.3.1 Devtech is processing the Personal Data in a territory which is subject to adequacy regulations under the Data Protection Legislation that the territory provides adequate protection for the privacy rights of individuals; or

11.3.2 where a Restricted Transfer between the parties requires safeguards:

(a) where the EU GDPR applies, the SCCs (Module Two: controller to processor, or Module Three: processor to processor, as applicable) are incorporated into this DPA by reference, with Customer as data exporter and Devtech as data importer; Clause 7 (docking) is not used; the option in Clause 9(a) is general written authorisation with the 30-day notice period in Section 7.2; the option in Clause 11(a) is not used; the governing law under Clause 17 and the forum under Clause 18 are Ireland; Annexes I and II are completed by Schedules 1, 2, and 3 of this DPA;

(b) where the UK GDPR applies, the SCCs as described in (a) apply as amended by the UK Addendum, which is deemed executed and completed with the information in Schedules 1, 2, and 3; the UK Addendum is governed by the laws of England and Wales; and

(c) transfers to Devtech's Sub-processors are protected by equivalent safeguards imposed under Section 7.3; or

11.3.3 the transfer otherwise complies with the Data Protection Legislation for the reasons notified by Devtech from time to time.

11.4 If a lawful transfer mechanism relied on under this Section is invalidated or amended, the parties will cooperate in good faith to implement a replacement mechanism without delay.

12. Return and Deletion of Personal Data

12.1 During the subscription, Customer may export Customer Data using the Service's functionality.

12.2 Following expiry or termination of the subscription, Devtech retains Customer Data for the 30-day retention window described in the Agreement, during which Customer may export its data or reactivate its subscription.

12.3 Unless the subscription is reactivated, Devtech will delete all Personal Data (including all copies in live systems) promptly after the end of the 30-day window, except where retention is required by law, regulation, or government or regulatory body, in which case Devtech will notify the Customer in writing of that retention requirement, giving details of the documents, materials or Personal Data that it must retain, the legal basis for retention, and establishing a specific timeline for deletion or destruction once the retention requirement ends. Copies in encrypted backups are deleted in the ordinary course of Devtech's 30-day rolling backup cycle and in any event within 30 days of deletion from live systems; backups remain protected by the measures in Schedule 3 until purged.

12.4 On Customer's written request, Devtech will certify deletion in writing.

13. Audits and Compliance Information

13.1 Devtech will keep detailed, accurate and up-to-date written records regarding any processing of the Personal Data to demonstrate its compliance with this DPA, including but not limited to, the access, control and security of the Personal Data, the processing purposes, categories of processing, any transfers of personal data outside the UK or EEA to a third country or international organisation and related safeguards, the information reasonably required to evidence whether data protection tests or other forms of transfer risk assessment required for transfers of data under Data Protection Legislation have been considered and met, and a general description of the technical and organisational security measures referred to in Clause 6. On Customer's reasonable request, Devtech will make available documentation and information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant security audits, certifications, and penetration test results.

13.2 Devtech holds ISO/IEC 27001 certification and has completed a SOC 2 Type II examination, and will ensure that an audit of its technical and organisational measures continues to be carried out at least annually against a recognised standard. Devtech will provide Customer, on request, with a confidential summary of the most recent results and evidence of remediation of critical findings.

13.3 If the information provided under Sections 13.1 and 13.2 is not sufficient to demonstrate compliance, and Customer has documented grounds to believe Devtech is not complying with this DPA, Customer (or an independent auditor on its behalf that is not a competitor of Devtech) may audit Devtech's compliance, limited to the systems and processes relevant to the Service, on at least 30 days' written notice, during business hours, no more than once per calendar year (except following a Personal Data Breach or where required by a supervisory authority), subject to Devtech's confidentiality and security requirements. Each party bears its own costs of an audit.

14. US State Privacy Laws

14.1 To the extent US State Privacy Laws apply to Personal Data, Devtech acts as Customer's "service provider" or "processor" (as defined in those laws). Devtech will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than providing the Service or as otherwise permitted by those laws; or (c) combine Personal Data with personal information from other sources except as permitted for service providers. Devtech will notify Customer if it determines it can no longer meet its obligations under US State Privacy Laws, and Customer may take reasonable steps to stop and remediate unauthorised use of Personal Data.

15. Liability

15.1 Each party's liability arising out of or in connection with this DPA (including the Contractual Safeguards) is subject to the limitations and exclusions of liability in the Agreement, provided that nothing in this Section limits: (a) a party's liability to data subjects under the third-party beneficiary provisions of the Contractual Safeguards; or (b) any liability that cannot be limited under Data Protection Legislation.

16. General

16.1 This DPA takes effect when the Agreement takes effect and terminates automatically on the later of (a) termination or expiry of the Agreement and (b) completion of the deletion obligations in Section 12.

16.2 If Data Protection Legislation changes in a way that requires variation of this DPA or the Contractual Safeguards, the parties will negotiate in good faith the necessary variations.

16.3 Amendments to this DPA must be in writing and agreed by both parties, except that Devtech may update Schedule 2 in accordance with Section 7 and Schedule 3 in accordance with Section 6.2.

16.4 If any provision of this DPA is or becomes invalid, the remaining provisions are unaffected.

16.5 This DPA is governed by the law governing the Agreement, save that the SCCs are governed by the laws of Ireland and the UK Addendum by the laws of England and Wales, as set out in Section 11.3.

Schedule 1: Details of Processing

Controller (data exporter): Customer, as identified in the Agreement. Contact details as provided at signup.

Processor (data importer): Devtech Limited, 25 Old Broad Street, London, EC2N 1HN, United Kingdom. Contact: privacy@devtechforge.ai.

Subject matter of the processing: provision of the Forge AI platform: a hosted service that connects to Customer's third-party systems, indexes and makes searchable the data held in them, and provides AI Agents that read that data, generate content and code, and take actions in Connected Services as configured by Customer.

Nature of the processing: collection (ingestion from Connected Services at Customer's direction), storage, indexing and vectorisation, retrieval, analysis and inference (including by Devtech's self-hosted machine learning models), display to Customer's authorised users, transmission (including to Connected Services when Agents act, and to third-party model providers only where Customer configures them), deletion.

Purpose of the processing: providing, securing, and supporting the Service for Customer in accordance with the Agreement.

Duration of the processing: the term of the Agreement plus the 30-day post-termination retention window, followed by deletion in accordance with Section 12.

Types of Personal Data: identification and contact data (names, email addresses, usernames, avatars); professional data (roles, team memberships); user-generated content from Connected Services that may contain any personal data included in it by Customer's users (issue and ticket text, commit messages and code authorship metadata, chat messages, documentation, support conversations, alert and log data); Service account data (user profiles, authentication identifiers); prompts and instructions given to Agents and the resulting Output.

Sensitive Personal Data: the parties do not anticipate the processing of special categories of personal data. Customer must not use the Service to process special category data unless the parties have agreed additional safeguards in writing. Devtech does not require special category data to provide the Service.

Frequency: continuous, for the duration of the subscription (connector synchronisation runs on scheduled intervals).

Categories of data subjects: Customer's employees, contractors, and other authorised users; individuals whose personal data appears in the Connected Services content Customer chooses to connect (which may include Customer's own customers, end users, suppliers, and other third parties).

Hosting location: the data residency region selected by Customer at signup (European Union or United States of America).

Remote access locations (support and operations): United Kingdom (Devtech Limited); United States of America (Devtech International LLC, see Schedule 2). No access from other locations without safeguards under Section 11.3.

Competent supervisory authority: for Customers in the EEA, the supervisory authority of the member state of Customer's establishment; for Customers in the UK, the Information Commissioner.

Schedule 2: Authorised Sub-processors

Devtech International LLC, 95 Third Street, San Francisco, California 94103, United States (Devtech affiliate), purpose: support, operations, and engineering services provided to Devtech Limited, location: United States. Devtech International LLC is certified under the EU-US Data Privacy Framework and the UK Extension to the EU-US Data Privacy Framework; transfers to it are additionally protected by the safeguards in Section 11.3.

velia.net Internetdienste GmbH, Hessen-Homburg-Platz 1, 63452 Hanau, Germany, purpose: hosting of Customer instances and data, including encrypted backups, location: Germany.

Verda Cloud Oy, Lapinlahdenkatu 16, 00180 Helsinki, Finland, purpose: hosting of Customer instances and data, including encrypted backups, location: Finland.

Hosting Sub-processors are engaged per the data residency region selected by Customer. Additional regional hosting providers will be added in accordance with Section 7.2.

Schedule 3: Technical and Organisational Measures

Tenant isolation. Each Customer is provisioned a dedicated instance; Customer Data is segregated per tenant and not commingled across customers.

Agent execution isolation. Agents execute in isolated virtual machines per task run, with access limited to the Customer's own data and the permissions Customer has configured; execution environments are destroyed after use.

Encryption. Personal Data is encrypted in transit (TLS 1.2+) and at rest. Backups are encrypted.

Access control. Role-based access control for Customer users; access permissions within the Service mirror the permissions granted in the Connected Services. Devtech personnel access is role-based, limited to what is necessary for support and operations, protected by multi-factor authentication, and logged.

Credential handling. Connector credentials and tokens are stored encrypted and are not exposed to other tenants or to Agents beyond the scope required.

No training. Machine learning models are self-hosted on Devtech infrastructure and are not trained or fine-tuned on Customer Data (Section 4).

Logging and monitoring. Security-relevant events (authentication, administrative actions, data access by Devtech personnel) are logged; logs are protected against tampering and retained for a defined period.

Vulnerability management and development. Changes are code-reviewed and tested before release; dependencies and images are monitored for vulnerabilities; security patches are applied within defined timeframes.

Backups and resilience. Regular encrypted backups within the Customer's selected region on a 30-day rolling retention cycle; documented restore procedures; deletion aligned with Section 12.3.

Certifications. Devtech holds ISO/IEC 27001 certification and has completed a SOC 2 Type II examination (Section 13.2).

Incident response. A documented incident response process covering detection, escalation, containment, customer notification (Section 9), and post-incident review.

Personnel. Confidentiality agreements with all personnel who may access Personal Data; annual data protection and security training; access revoked promptly on role change or departure.

Physical security. Hosting is in professional data centres maintained by the infrastructure providers listed in Schedule 2, with physical access controls certified to recognised standards; Devtech offices hold no production Personal Data.

Data subject request support. The Service provides search, export, and deletion capabilities enabling Customer to locate and act on individual records (Section 8.2).

DevtechForge AI

Your digital workforce.
Always on, around the clock.

in
Platform
OverviewContext engineConnectorsAgentsHuman in the loopPricing
Services
Forward Deployed EngineersR&D as a ServiceEcosystem Enablement
Who we serve
Software vendorsDistributorsTelcosService providers
Company
About DevtechCase studiesLeadershipCareersContact
© 2026 Devtech Limited. All rights reserved.
Privacy policyTerms and conditionsData processing agreementCookie policyCookie settings