Forge Digital · Crafting Your Vision
Data Processing Agreement
Version  1.0
Date  27 July 2026

Parties

This Data Processing Agreement (the "DPA"), entered into pursuant to Article 28 of Regulation (EU) 2016/679 (the "GDPR"), forms an integral annex to the Master Services and Subscription Agreement (the "MSA") between: The Controller: the business that accepted the MSA during onboarding, identified by the VAT-registered legal entity captured through the onboarding form and verified through the VIES service (hereinafter the "Controller" or "you"); and The Processor: Forge Digital EOOD, trading as Cars by Forge Digital, with registered office at ul. Aleksandar Stamboliiski N 5-B, flr. 8, office 60, 6000 Stara Zagora, Bulgaria, VAT BG208556549, EIK/UIC 208556549. Data-protection contact: Jonas Van Gavere, Managing Director, info@forgedigital.io (hereinafter the "Processor" or "Forge Digital"). The Controller and the Processor are each a "Party" and together the "Parties".

1 Definitions and roles

Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given to them in the GDPR. The GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. Capitalised terms used in this DPA and not defined here have the meaning given to them in the MSA. For the purposes of the MSA and this DPA, the Controller acts as the data controller and Forge Digital acts as the data processor in respect of the personal data processed by Forge Digital on the Controller's behalf in connection with the Website and related services (the "Controller Personal Data"). Personal data that Forge Digital processes about the Controller itself, its administrator users and its billing (for example, the Controller's administrator email and billing information) is processed by Forge Digital as an independent controller and is governed by Forge Digital's own privacy policy, not by this DPA.

2 Subject matter, duration, nature and purpose

This DPA governs the processing of Controller Personal Data carried out by Forge Digital on behalf of the Controller in connection with the MSA. The subject matter, duration, nature and purpose of the processing, the types of Controller Personal Data concerned and the categories of data subjects are set out in Annex 1. This DPA takes effect on the date the Controller accepts it and remains in force for as long as Forge Digital processes Controller Personal Data on the Controller's behalf. That period corresponds to the term of the MSA, extended for the Grace Period and for any additional period reasonably required for the return or deletion of Controller Personal Data in accordance with Section 10.

3 Processor obligations

Forge Digital shall, in relation to the Controller Personal Data:

4 Security of processing

Forge Digital implements the technical and organisational measures set out in Annex 3 to ensure a level of security appropriate to the risk. Those measures take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Forge Digital may update the measures from time to time, provided that the overall level of security is not reduced.

5 Sub-processing

5.1 General written authorisation

The Controller grants Forge Digital a general written authorisation, within the meaning of Article 28(2) GDPR, to engage the sub-processors described in Annex 2 for the processing activities described in that annex. Annex 2 identifies each sub-processor by its function and by its region of processing; the full list, naming each sub-processor and its legal entity, is available to the Controller at any time on request from support@forgedigital.io.

5.2 Notice of new sub-processors

Where Forge Digital intends to add or replace a sub-processor, it shall inform the Controller of the intended change in advance, identifying the function, the legal entity and the region of processing of the incoming sub-processor, and giving the Controller the opportunity to object on reasonable data-protection grounds within thirty (30) days of the notice. If the Controller does not object within that period, the change is deemed accepted. The current full list of sub-processors, naming each one, is available to the Controller at any time on request from support@forgedigital.io.

5.3 Objection

If the Controller reasonably objects to a new or replacement sub-processor on data-protection grounds, the Parties shall discuss the objection in good faith. If the Parties cannot resolve the objection, the Controller may cancel the affected services with effect from a date determined by the Controller, in which case Forge Digital shall refund any prepaid Fees for the period after cancellation. This is the Controller's sole and exclusive remedy for an unresolved objection.

5.4 Flow-down of obligations

Forge Digital imposes on every sub-processor, by way of a contract or other legal act under Union or Member State law, the same data-protection obligations as set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data-protection obligations, Forge Digital remains fully liable to the Controller for the performance of that sub-processor's obligations.

6 International transfers

6.1 Primary location

Controller Personal Data is processed within the European Union / European Economic Area (EU/EEA). The database and file storage provider hosts the data in Frankfurt, Germany, and the application hosting provider serves the Website from its Frankfurt region.

6.2 Sub-processor transfers

Where a sub-processor engaged in accordance with Section 5 is established outside the EEA, or where Controller Personal Data is otherwise transferred outside the EEA, such transfer takes place only subject to the safeguards required under Chapter V GDPR, being (as applicable):

6.3 Transfer impact assessments

Forge Digital documents, for each sub-processor to which Controller Personal Data may be transferred outside the EEA, the transfer mechanism relied upon and, where applicable, a short transfer impact assessment. Those records are available to the Controller on request.

7 Personal data breach

Forge Digital notifies the Controller without undue delay, and in any event no later than seventy-two (72) hours, after becoming aware of a personal data breach affecting Controller Personal Data. The notification includes, insofar as the information is available to Forge Digital at the time, the information referred to in Article 33(3) GDPR, namely:

Where information cannot be provided at the same time, it is provided in phases without undue further delay. Forge Digital provides reasonable further assistance to the Controller in meeting the Controller's own obligations under Articles 33 and 34 GDPR.

8 Data-subject rights

Where Forge Digital receives a request from a data subject seeking to exercise rights under the GDPR (such as access, rectification, erasure, restriction, data portability or objection) in relation to Controller Personal Data, Forge Digital forwards that request to the Controller without undue delay and, unless prohibited from doing so, without responding to the request itself. Forge Digital assists the Controller in responding to such requests as described in Section 3.

9 Audits

Forge Digital makes available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller. The Controller may exercise this audit right once per calendar year on reasonable prior written notice of at least thirty (30) days, and additionally without such notice period following a confirmed personal data breach affecting Controller Personal Data. Audits are conducted during normal business hours, in a manner that minimises disruption to Forge Digital's operations, and subject to reasonable confidentiality undertakings by the Controller and its auditor in respect of Forge Digital's business information and the personal data of Forge Digital's other clients. Where Forge Digital holds current third-party certifications, audit reports or security assessments relevant to the processing covered by this DPA, it may satisfy the Controller's audit request, in whole or in part, by providing such documentation. Each Party bears its own costs of an audit, save that if an audit reveals a material breach by Forge Digital of this DPA, Forge Digital shall reimburse the Controller's reasonable auditor fees.

10 Return and deletion

10.1 On termination

Upon termination or expiry of the MSA, or upon earlier written request by the Controller, Forge Digital shall, at the Controller's choice, delete or return to the Controller all Controller Personal Data processed on its behalf, and delete existing copies held by Forge Digital, subject to Sections 10.2 and 10.3.

10.2 90-day recovery window

The Parties acknowledge that the Platform retains Controller Personal Data during a ninety (90) day Grace Period following termination in order to make it possible for the Controller to reinstate the subscription and recover its data. During the Grace Period, Controller Personal Data is held in a suspended state, is not actively processed and is not accessible to any party other than Forge Digital's authorised personnel for the strict purposes of maintaining the recovery capability. This retention is a documented instruction from the Controller for the purposes of Article 28(3)(g) GDPR: by accepting this DPA, the Controller instructs Forge Digital to retain Controller Personal Data for the Grace Period and to delete it thereafter.

10.3 After the Grace Period

At the end of the Grace Period, Forge Digital permanently deletes Controller Personal Data from the Platform, save for the limited records identified in Section 14.4 of the MSA (invoices and accounting records, contract-version acceptance log, redacted send log with recipient email addresses of the Controller's inbox and administrators only, and retention offer history). Forge Digital continues to protect those records in accordance with this DPA for as long as they are retained.

11 Liability and governing law

The statutory liability regime of the GDPR applies to each Party in respect of its processing of personal data. Subject to the foregoing, this DPA is governed by Bulgarian law and any dispute arising out of or in connection with it falls within the exclusive jurisdiction of the courts of Stara Zagora, Bulgaria, consistent with Section 22 of the MSA (which includes the one-way carve-out for Forge Digital). In the event of any conflict between this DPA and the MSA on matters of data protection, this DPA prevails. This DPA forms an integral annex to the MSA; the remaining terms of the MSA continue unaffected.

12 Acceptance

This DPA is entered into electronically. By clicking "Accept" during onboarding, the Controller agrees to be bound by it and no handwritten signature is required. Forge Digital records the acceptance, the identifier and version of this DPA, the exact date and time, a hashed IP address, and the language in which this DPA was displayed.

Annex 1 Details of the processing

Subject matter

The hosting of the Controller's Website and the transmission of website inquiries submitted by visitors to the Controller, as further described in the MSA.

Duration

For the term of the MSA between the Parties, extended for the Grace Period and thereafter for any period necessary for the return or deletion of Controller Personal Data in accordance with Section 10 of this DPA.

Nature and purpose of the processing

Types of personal data

Categories of data subjects

Special categories of data

None. The processing does not involve special categories of personal data within the meaning of Article 9 GDPR or personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR. The Controller shall not submit, and shall ensure that Website visitors are not invited to submit, special-category data through the Website's inquiry or contact forms.

Annex 2 Sub-processors

The Controller authorises Forge Digital to engage the following sub-processors in connection with the processing described in Annex 1. Each sub-processor is described here by its function and by its region of processing; the full list, naming each sub-processor and its legal entity, is available to the Controller at any time on request from support@forgedigital.io. Forge Digital gives the Controller advance notice of any intended addition or replacement of a sub-processor, so that the Controller may object, and may update this list from time to time in accordance with Section 5 of this DPA.

Sub-processorPurposeLocation of processingTransfer safeguard
The database and file storage providerDatabase, authentication and file storage (single-tenant per Controller).EU (Frankfurt, Germany)Art. 28 DPA. EU processing; SCCs available where sub-processing occurs outside the EEA.
The application hosting providerApplication hosting, CDN, and cookieless web analytics.EU (Frankfurt, Germany)Art. 28 DPA. EU processing; SCCs available where sub-processing occurs outside the EEA.
The transactional email providerTransactional and inquiry email delivery (SPF/DKIM/DMARC configured).EU regionArt. 28 DPA. EU processing; SCCs where applicable.
The bot protection and DNS providerBot protection on public forms and authoritative DNS (DNSSEC enabled).Global anycast; DNS only, not proxying site traffic.Art. 28 DPA + EU-US DPF certification.
The mapping providerMap embed on Website contact pages. The provider receives the visitor's IP address when the map loads.Ireland, through the provider's EU entity, with onward transfer to the US.EU-US DPF (the provider is certified). SCCs where DPF is unavailable.
The automatic translation serviceMachine translation of Controller-written vehicle text into the other public Website languages.US (with EU inference where available)EU-US DPF (the provider is certified) + SCCs. Transfer impact assessment on file.
The image processing serviceAI-assisted image generation (homepage artwork) and background removal on vehicle photographs, on Controller instruction. May incidentally process personal data present in supplied photographs.USSCCs + supplementary technical measures. Transfer impact assessment on file. Data not used to train the provider's models.
The vehicle data look-up serviceVIN look-up used by the Controller to pre-fill vehicle listings. Vehicle data only, not personal data.EUArt. 28 DPA where personal data is processed; otherwise not applicable.
The public-data retrieval servicePeriodic reading of the Controller's public marketplace rating (once per month). Public data only, no personal data of Website visitors.GlobalSCCs where applicable.
The domain registrarDomain registration on behalf of the Controller. The Controller's registrant details (name, address, VAT and contact) reach the registrar and appear in the public WHOIS record.EUArt. 28 DPA. The Controller is the registrant and its details appear in WHOIS; this is disclosed at onboarding.

Note on the payment processor

The payment processor, acting through its US entity and its Irish entity, provides card payment and invoicing services in respect of Forge Digital's billing of the Controller. In respect of that processing, Forge Digital is the controller and the payment processor is a separate controller under its own privacy notice. This processing is not carried out on behalf of the Controller and is therefore outside the scope of this DPA. It is described in Forge Digital's own privacy policy, and the identity of the payment processor is available on request from support@forgedigital.io.

Note on third-party API calls

Third-party API calls made in connection with a Website are routed through Forge Digital's own control plane rather than made directly from the Controller's Website. Consequently, the Controller's Website holds no third-party API credentials. Legally, each such provider remains a sub-processor of Forge Digital and is listed above.

Annex 3 Technical and organisational measures (Article 32 GDPR)

Forge Digital implements and maintains the following technical and organisational measures, as they exist from time to time. Forge Digital may update these measures provided that the overall level of security is not reduced.

Encryption and transport security

Access control

Data protection at rest

Backups and continuity

Auditing and logging

Network and infrastructure

Development and operations

Sub-processors and confidentiality

End of Data Processing Agreement.