The data controller for the processing described in this policy is Forge Digital EOOD (едноличнo дружество с ограничена отговорност), trading as Cars by Forge Digital, with its registered office at ul. Aleksandar Stamboliiski N 5-B, flr. 8, office 60, 6000 Stara Zagora, Bulgaria. Our VAT number is BG208556549 and our EIK/UIC (Bulgarian commercial register) number is 208556549. You can contact us by email at info@forgedigital.io, or by writing to us at the address above. Our data-protection contact is Jonas Van Gavere, Managing Director. You can reach the data-protection contact at info@forgedigital.io. We are not required to appoint a Data Protection Officer under Article 37 GDPR because our processing does not meet the thresholds that trigger that obligation. Should we choose to appoint one voluntarily in the future, we will update this policy.
When our online payment is not yet open in your country and you leave your email address so we can tell you when it opens, we collect the email address you provide. If you also tick the optional marketing box ("Also email me occasional news about Cars by Forge Digital"), we collect the fact that you consented to receive marketing. Important note about email addresses collected before 27 July 2026: the funnel did not carry a marketing consent tick before that date. Email addresses collected before 27 July 2026 are recorded as "never asked" and we do not use them for marketing. If you gave us your address before that date and would like to receive news about Cars by Forge Digital, please email us at info@forgedigital.io to opt in.
When you become a paying customer, our onboarding flow captures:
Payment is taken through the hosted checkout of our payment processor. The payment processor collects your billing address, your VAT number and your card details, and passes back to us the information we need to issue an invoice and to know that you have paid. We do not see or store your full card number. The payment processor processes card data as an independent controller under its own privacy notice. We identify this provider by name on request at support@forgedigital.io.
Console access uses a eight-digit code sent to an authorised email address. We record the fact that a code was issued, that it was used (or expired), and the time. We do not store passwords, because there are none. We keep an internal log of administrative actions taken in the Console for security and audit purposes.
When you send us a support request or otherwise contact us, we process the contact details you use, the content of your message and any information you volunteer, in order to respond to you.
Our own website uses a privacy-friendly, cookieless analytics tool provided by our application hosting provider that does not place any cookies on your device, does not build a personal profile, and provides us only with aggregated statistics. Because no non-essential cookies are set, no cookie banner is required. We identify this provider by name on request at support@forgedigital.io.
We do not knowingly collect special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences (Article 10 GDPR). Please do not send us such data through our forms, chats or emails.
We process personal data for the following purposes, each on a specific legal basis under the GDPR:
| Purpose | Data used | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| To provide the Platform and perform our contract with you | Onboarding data, admin login email addresses, one-time login codes, payment details, support communications, Console usage logs. | (b) performance of a contract to which you are party, or in order to take steps at your request prior to entering into a contract. |
| To bill you and comply with tax and accounting law | Business name and legal entity, VAT number, billing address, invoice records. | (c) compliance with a legal obligation to which we are subject (in particular Bulgarian VAT, tax and accounting law); and (f) our legitimate interest in maintaining accurate financial records. |
| To keep our platform and our funnel safe from spam and abuse | Technical data, salted hashed IP addresses, security events, form-submission timestamps. | (f) our legitimate interest in security and abuse prevention; we consider this proportionate and expected. |
| To improve our platform and understand aggregate usage | Aggregated, non-identifying analytics from our application hosting provider's cookieless web analytics; anonymised usage patterns. | (f) our legitimate interest in improving our service. |
| To respond to your support requests and general contact | Your contact details and the content of your message. | (b) pre-contractual or contractual, as applicable; or (f) our legitimate interest in serving prospects and answering enquiries. |
| To send you occasional marketing about Cars by Forge Digital | The email address on our marketing list and your engagement with those emails. | (a) your consent, given by ticking the optional marketing box. You can withdraw consent at any time. |
| To defend legal claims and enforce our rights | Whatever data is relevant to the specific claim or matter. | (f) our legitimate interest in defending or enforcing our rights and obligations. |
Where a processing is based on our legitimate interest, we have balanced our interest against your rights and freedoms and concluded that the processing is necessary and proportionate. You may object to processing based on legitimate interest as described in Section 8.
We do not carry out any automated decision-making that produces legal effects concerning you or that significantly affects you in a similar way, within the meaning of Article 22 GDPR. VIES verification of a VAT number and the automated fraud checks carried out by our payment processor at payment (which we identify by name on request at support@forgedigital.io) are not "automated decision-making" of that kind: they are eligibility checks based on public data or on your card issuer's risk signals, and their outcome does not on its own decide whether we contract with you.
We do not sell your personal data. We do not share it with third parties for their own commercial purposes. To operate our business, we rely on a small number of carefully chosen service providers that act as our processors within the meaning of the GDPR (except for the payment processor, which is a separate controller as explained below). The table below sets out the categories of recipient, what each one does for us, where it is located and the capacity in which it acts, as Article 13(1)(e) GDPR permits. The full list naming each provider, together with the transfer mechanism relied upon for that specific recipient, is available on request from support@forgedigital.io, and we will give you advance notice of any intended addition or replacement of a provider so that you may object. Each processor is bound by a written data-processing agreement that requires them to process your data only on our instructions and to protect it.
| Recipient | What they do for us | Location | Role |
|---|---|---|---|
| The database and file storage provider | Hosts our own funnel and billing database (which contains the data listed in Section 2). | EU (Frankfurt) | Processor |
| The application hosting provider | Hosts our funnel and marketing pages, and provides cookieless web analytics. | EU (Frankfurt) | Processor |
| The transactional email provider | Delivers the transactional emails we send you (login codes, invoices, notices) and any marketing email you have opted in to. | EU region | Processor |
| The bot protection and DNS provider | Provides bot protection on our forms and DNS for our domain forgedigital.io. | Global anycast; DNS only. | Processor |
| The payment processor (its EU entity and its US affiliate) | Takes card payments from you, issues invoices and receipts, and provides fraud protection. | Ireland (billing), US (backend), under EU-US DPF. | Separate controller |
| Our external Bulgarian accounting firm | Receives our invoices and VAT records to prepare our statutory filings. | Bulgaria | Processor |
We may additionally disclose your personal data where we are required to do so by law, by a competent authority, by a court order, or where necessary to protect our rights, our property or the safety of others.
Your personal data is primarily processed within the European Union / European Economic Area. Where a recipient listed in Section 5 processes your data outside the EEA, we rely on one or more of the following safeguards under Chapter V of the GDPR:
We can provide you with a copy of the transfer mechanism relied upon for any specific recipient, and the name of that recipient, on request from support@forgedigital.io.
| Data | Retention |
|---|---|
| Email addresses on our launch list (no marketing consent given) | Kept as "never asked". Not used for marketing. Purged twenty-four (24) months after collection, or immediately on your request. |
| Email addresses on our marketing list (marketing consent given) | Kept while you remain subscribed. Auto-purged twenty-four (24) months after your last positive engagement (opened email or clicked link). Removed immediately on unsubscribe. |
| Onboarding submissions (including brand assets, business details) | Kept for as long as you are our customer, and thereafter for the ninety (90) day recovery grace period. Deleted thereafter, save for the records identified below. |
| Console administrator email addresses and login-code records | Kept for the duration of the account, then purged with the account at the end of the ninety (90) day grace period. |
| Invoices and accounting records | Kept for the statutory retention period under Bulgarian accounting and tax law, being up to ten (10) years for balance-sheet items and annual financial statements, and shorter periods for supporting documents as prescribed by law. |
| Contract-version acceptance log (which document version you accepted, when, in which language) | Kept for as long as reasonably necessary to demonstrate that a specific version of a contractual document was accepted, and for the applicable limitation periods thereafter. |
| Outbound email send log (redacted: recipient email, reference, type, vehicle where applicable, status) | Kept as an append-only immutable log for as long as reasonably necessary for audit, non-repudiation and troubleshooting. |
| Support requests and general correspondence | Kept for as long as necessary to resolve your query and to keep a record of the interaction, typically two (2) years, unless a longer period is necessary to defend legal claims. |
| Data relevant to a specific dispute or legal claim | Kept for the applicable limitation period plus a reasonable margin. |
Under the GDPR you have the following rights in respect of the personal data we hold about you. We will respond to any request to exercise these rights within one (1) month, or, exceptionally, within two (2) further months where the request is complex or where we receive a large volume of requests (in which case we will inform you within the first month).
To exercise any of these rights, please contact us at info@forgedigital.io. We may need to verify your identity before responding, in particular where the request concerns sensitive data or where fulfilling it could affect the rights of others.
You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. As our lead supervisory authority we are subject to the Commission for Personal Data Protection (Комисия за защита на личните данни / КЗЛД / CPDP) in Bulgaria: 2 Prof. Tsvetan Lazarov Blvd, 1592 Sofia, Bulgaria; email kzld@cpdp.bg; website www.cpdp.bg. We would appreciate the opportunity to address any concern you have before you contact the supervisory authority, and we invite you to email us first at info@forgedigital.io.
We take appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access, alteration or destruction, in accordance with Article 32 GDPR. These measures include:
Our business-to-business services are not directed to children. We do not knowingly collect personal data from anyone under the age of sixteen (16). If you become aware that a child has provided us with personal data, please contact us at info@forgedigital.io and we will delete it.
We may update this privacy policy from time to time to reflect changes to our operations, our service providers or applicable law. The version and date at the top of this policy indicate when it was last updated. Where the change is material, we will inform you by email to the address on file (for customers) or by prominent notice on our website (for prospects). Continued use of our services after an update means you have taken notice of it. If you do not agree with an update and are a customer, you may cancel your subscription in accordance with the Master Services and Subscription Agreement.
If you have any question about this privacy policy or about how we process your personal data, please contact us:
End of Privacy Policy.