Last updated: September 23 2026
This Privacy Policy explains how Devtech Limited ("Devtech", "we", "us") collects and uses personal data when you visit our website, sign up for or use the Devtech Forge AI platform (“Platform”), or otherwise deal with us in connection with Forge AI.
Devtech Limited is the controller of the personal data described in this Notice. We are a company registered in England and Wales (registration number 08409744) with our registered office at 25 Old Broad Street, London, EC2N 1HN, United Kingdom.
This Notice covers personal data we process as a controller: information about people who visit our website, create and administer a Forge AI account, pay for the service, contact us, or receive our marketing.
This Notice does not cover personal data contained in the content that a customer connects to or processes through the Forge AI platform (for example data drawn from a customer's Jira, GitHub, or Slack). We process that content on the customer's behalf as a processor, and it is governed by our Data Processing Agreement with that customer, not by this Notice. If your personal data is in a customer's Forge AI instance and you want to exercise your rights, please contact that customer (the controller); we will assist them as required.
Forge AI is a business service and is not directed at children under 13 years old.
You will always have the right to lodge a complaint with a supervisory body. The relevant authority in the UK (where we are based) is the Information Commissioner’s Office (www.ico.org.uk). If you do have a complaint, we would appreciate the chance to deal with your concerns before you approach the ICO, so please do contact us in the first instance if possible, at the email address above. If you are based in another jurisdiction, you may have additional rights or ability to refer matters to an alternative supervisory body.
Our Platform may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Platform, we encourage you to read the privacy policy of every website you visit.
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
The type of data we collect, use, store and transfer will depend on the way you interact with us and the relationship we have with you. We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Account and identity data. When you sign up, we collect your name, business email address, the company you represent, your role, account credentials, and the data residency region you select.
Billing data. To take payment we collect your company billing details and VAT identification number. Card payments are collected and processed by our payment provider, Stripe; we do not store full card numbers, and we receive only limited details such as the card brand, expiry, and last four digits.
Usage and technical data. When you use the website or the service we collect technical data such as IP address, device and browser information, log data, and information about how you interact with the service, including through cookies and similar technologies (see Cookies below).
Communications and support data. If you contact us, request a demo, or raise a support request, we collect the content of your communications and related metadata.
Marketing data. If you subscribe to our newsletter or product updates, or engage with our marketing, we collect your contact details and your marketing preferences and engagement.
We collect this data directly from you, from your use of the service, and from cookies and analytics on our website. We do not buy or enrich prospect lists, and we do not combine your data with personal data purchased from third parties.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
We do not knowingly collect any Special Category of Personal Data about you. This includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, health information or genetic and biometric data. We also do not collect criminal conviction or offences data.
Keeping data up to date
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us. You can do this by logging into your account on our Platform and updating certain information or contacting us directly to update on your behalf.
If you fail to provide personal data
Where we need to collect personal data by law or contractual terms, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time.
We use different methods to collect data from and about you. The main way we will collect your personal data is through your direct interactions with us, but we will also collect data through automated technologies and third parties or other publicly available sources.
We will only use your personal data when the law allows us to. This includes UK data protection rules (under the UK GDPR and Data Protection Act 2018) and other applicable laws in countries where we collect and process information.
We will not collect and use your personal data without letting you know. Most commonly, we will use your personal data in the following circumstances:
Principles of processing
We will not process personal data in a way that is incompatible with the purposes for which it has been collected or subsequently authorised by you. We also will not collect any personal data that is not needed for the mentioned purposes.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Purposes for which we will use your personal data
We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the tables below.
| Purpose | Type of data | Lawful basis (UK/EU GDPR) |
|---|---|---|
| Creating and administering your account; providing the service; support | Account and identity data. Usage and technical data. Communications and support data. | Performance of a contract, or our legitimate interest in administering our relationship with the business customer you represent |
| Taking payment; issuing invoices | Account and identity data. Billing data. | Performance of a contract |
| Keeping accounting and tax records | Account and identity data. Billing data. | Compliance with a legal obligation |
| Securing the service; preventing fraud and abuse (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) | Account and identity data. Usage and technical data. Communications and support data. | Our legitimate interest in keeping the service and our customers safe, running our business, and providing administration and IT services |
| Sending service and administrative messages (e.g. billing, security, changes to terms) | Account and identity data. Communications and support data. | Performance of a contract, or our legitimate interest in operating the service (to keep our records updated and to study how users use our Platform and services to enable us to develop our relationships and grow our business). It may also be necessary to comply with a legal obligation. |
| Sending newsletters and product marketing to prospects | Account and identity data. Marketing data. | Your consent |
| Sending marketing about similar Forge AI products to existing customers | Account and identity data. Usage and technical data. Communications and support data. Marketing data. | Our legitimate interest (to develop our services and grow our business, with an opt-out in every message) |
| Website analytics and advertising measurement (Google Analytics, LinkedIn) | Usage and technical data. | Your consent (via the cookie banner) |
| Handling your data protection requests; complying with law | Account and identity data. Usage and technical data. Communications and support data. Marketing data. | Compliance with a legal obligation |
| Improving our website and service (aggregated, non-content analytics) | Usage and technical data. | Our legitimate interest in improving what we offer (to keep our Platform updated and relevant, to develop our business and to inform our marketing strategy) |
Where we rely on legitimate interests, you can ask us for our assessment of how we have balanced those interests against your rights.
Because Forge AI is an AI platform, we want to be clear about how your data and AI interact:
- We do not train on your data. We do not use your personal data, prompts, or the content you connect to the service to train, fine-tune, or improve any machine learning model, whether ours or a third party's.
- Where AI processing happens. Forge AI's models are hosted by us on our own infrastructure in the data residency region you select (currently the EEA). Your data is not sent to an external model provider for inference unless you choose to configure one yourself, in which case that provider processes it under your own agreement with them.
- Human access to your content. We do not routinely review the prompts you give to Agents or the content the service processes. Our personnel access that content only where you ask us to (for example to resolve a support request), where necessary to keep the service secure, or where required by law, and always subject to confidentiality. We do not review it to train models or for advertising.
- Outputs may be wrong. AI-generated output can be inaccurate or incomplete. You should review it before relying on it, as explained in our Terms and Conditions.
If you have opted in, or if you are an existing customer and the marketing concerns similar Forge AI products, we may send you marketing emails. You can opt out at any time using the unsubscribe link in any marketing email or by contacting us at privacy@devtechforge.ai. Opting out of marketing does not stop service and administrative messages, which we need to send you to operate your account. We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
Our website uses cookies and similar technologies. Strictly necessary cookies (for example to keep you signed in and to secure the signup flow) are always on. Analytics and advertising cookies - including Google Analytics (provided by Google) and the LinkedIn Insight Tag (provided by LinkedIn) - are only set with your consent, which we collect through the cookie banner shown when you first visit. You can change or withdraw your consent at any time through the cookie settings link on our website. Full details of the cookies we use are set out in our Cookie Policy.
Browser opt-out signals. Where your browser sends a Global Privacy Control (GPC) or similar opt-out signal, we treat it as a request to disable non-essential analytics and advertising cookies for that browser.
We share personal data with the following categories of recipient, under appropriate contracts:
- Payment provider: Stripe, which processes billing and payment data.
- Hosting and infrastructure providers: velia.net Internetdienste GmbH (Germany) and Verda Cloud Oy (Finland), which host the service and our data and such other third parties we may appoint to provide services on our behalf and as our processors, like payment, systems administration, web hosting, marketing and support services.
- Analytics and advertising providers: Google (Google Analytics) and LinkedIn (Insight Tag), where you have consented.
- Our marketing and CRM platform: Microsoft Dynamics 365 and HubSpot, which we use to manage communications and marketing.
- Our group affiliate: Devtech International LLC (United States), which provides support, operations, and engineering services to us.
- Professional advisers and authorities: our accountants, auditors, insurers, and legal advisers, and regulators, courts, or authorities where we are required by law to disclose.
- Authorities: regulatory, government and industry bodies, like ICO, HM Revenue & Customs, fraud prevention organisation or law enforcement bodies who require reporting of processing activities in certain circumstances, especially in the prevention of money laundering and fraud.
- Corporate partners: includes third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
A current list of the sub-processors that process personal data within the Forge AI service is maintained at our sub-processor page.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
We are based in the UK and host customer instances in the EEA (Germany and Finland). Some recipients are outside the UK and EEA, in particular our US affiliate Devtech International LLC and certain analytics and advertising providers. Where we transfer personal data outside the UK or EEA, we protect it using a lawful transfer mechanism, which will be one or more of: the recipient's certification under the EU-US Data Privacy Framework and the UK Extension (Devtech International LLC is certified under both), the UK and EU Standard Contractual Clauses and, where required, the UK Addendum. You can ask us for a copy of the safeguards we use by contacting privacy@devtechforge.ai.
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. Details of retention periods for different aspects of your personal data are set out below. We may keep your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
- Account data: for the life of your account, and for a limited period after closure to handle post-termination matters, then deleted or anonymised.
- Billing, invoicing, and tax records: seven (7) years, to meet UK and EU accounting and tax law.
- Marketing data: until you opt out or withdraw consent, after which we keep a minimal suppression record so we can honour your choice.
- Analytics data: for the retention period configured in our analytics tools.
- Support and other communications: for as long as needed to handle the matter and a reasonable period afterwards.
We may retain and use de-identified or aggregated data (which cannot reasonably be used to identify you) without time limit, for example to understand and improve our website and service. We do not attempt to re-identify such data.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We maintain appropriate technical and organisational measures to protect personal data. Devtech holds ISO/IEC 27001 certification and has completed a SOC 2 Type II examination. More detail on our platform security measures is set out in the DPA.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Depending on where you are and the applicable law, you have rights to: access your personal data; have inaccurate data corrected; have data erased; restrict or object to processing; data portability; and, where we rely on consent, to withdraw it at any time without affecting prior processing. Where the CCPA applies, you also have rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information (we do not sell or share it in that sense).
Under the UK data protection laws, you have certain rights in relation to your personal data. We have set these out in the below:
| Your Right | What it means |
|---|---|
| Right to be informed You have the right to be told how we will use your personal data | We provide this privacy policy to explain how we use your personal data. |
| Right of access You can ask us to receive a copy of your personal data, commonly known as a SAR. | If you ask, we will confirm how we process your personal data and, in certain cases, provide you with a copy of the personal data we hold about you. There are some exemptions where we do not need to provide copies (like communications we have had with our legal advisers), and we can’t give you any personal data about other people or personal data which is linked to ongoing investigations, and we are prevented by law from sharing. |
| Right to rectification You can ask us to correct your personal data if you think it is wrong or complete if it is incomplete | You can have incomplete or inaccurate personal data corrected. Before we update your file, we may need to check the accuracy of the new personal data you have provided, and we will restrict processing while we verify the accuracy. |
| Right to erasure You can ask us to delete personal data in certain circumstances | If we do not have a reason for holding your personal data and continue to use it, if you gave us consent and have now withdrawn that consent, you have objected to us using your personal data or we are using it unlawfully, you can ask us to delete it. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request. |
| Right to restrict processing In certain circumstances, you can ask us to restrict or suspect use of your personal data. | You can ask us to suspend the processing of your personal data in the following scenarios: If you want us to establish the data's accuracy. Where our use of the data is unlawful but you do not want us to erase it. Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims. You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it. |
| Right to object You can object to us processing your personal data for (i) direct marketing or (ii) our own legitimate interests. | If you object to direct marketing, we must stop using your personal data for that reason. If we are using legitimate interest, you can object to us using your personal data. But if there is an overriding reason why we need to use your personal data, we do not need to accept your request to stop and can continue to use your personal data. If you object to us using personal data which we need in order to provide our Services, we may need to close your account as we won’t be able to provide the Services. |
| Right to data portability You can ask us to transfer your personal data to you or another company | We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you. |
To exercise any right, contact privacy@devtechforge.ai. We will respond within the time required by law (generally one month under UK/EU GDPR). We will not discriminate against you for exercising your rights.
No fee usually required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated.
If you have a concern we have not resolved, you can complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EEA you can complain to the supervisory authority where you live or work.
This section provides additional disclosures for residents of California and other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon). It supplements the rest of this Notice.
Categories of personal information we collect. In the 12 months before the date of this Notice we have collected the following categories of personal information (as defined by the California Consumer Privacy Act, "CCPA"):
| CCPA category | Examples we collect |
|---|---|
| Identifiers | Name, business email, account ID, IP address |
| Customer records / commercial information | Company billing details, VAT ID, subscription and transaction history |
| Internet or network activity | Usage and log data, interactions with our website and service |
| Geolocation data | Approximate location derived from IP address; the residency region you select |
| Professional or employment information | Your company and role |
| Audio, electronic, or similar information | The content of your communications with us |
| Sensitive personal information | Account log-in credentials |
Sources, purposes, and disclosures. We collect this information from the sources, and use it for the purposes, described earlier in this Notice. We disclose it for business purposes to the categories of recipient listed under "Who we share your data with" (such as our payment, hosting, marketing, and analytics providers and our group affiliate).
No sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA and similar laws. We do not use or disclose sensitive personal information for purposes that would give you a right to limit that use.
"Shine the Light" (California Civil Code § 1798.83). We do not disclose personal information to third parties for those third parties' own direct marketing purposes.
Your US state privacy rights. Subject to the applicable law and its exceptions, you have the right to: confirm whether we process your personal information and access it; delete it; correct it; obtain a portable copy; and opt out of any "sale," "sharing," or targeted advertising and of certain profiling (we do not carry out these activities). We will not discriminate against you for exercising these rights.
How to exercise them. Submit a request to privacy@devtechforge.ai. We will verify your request by reference to information associated with your account. You may use an authorised agent to act for you, in which case we may require proof of authorisation. Where the applicable law provides an appeal right, you may appeal a decision by replying to our response; if we deny your appeal you may contact your state Attorney General.
Data protection contact: privacy@devtechforge.ai Devtech Limited, 25 Old Broad Street, London, EC2N 1HN, United Kingdom.
Data Protection Officer: dpo@devtechforge.ai
We may update this Notice from time to time. If we make material changes we will take reasonable steps to notify you, for example by email or a notice in the service. The "last updated" date at the top shows when this Notice was last revised.