Privacy

Forge Privacy Policy

Effective Date: 14 September 2026

Always Forge Ltd (“Forge”, “we”, “us” or “our”) respects your privacy and is committed to protecting personal information.

This Privacy Policy explains how we collect, use, disclose, store and protect personal information when you visit our website, create or use a Forge account, interact with us or connect third-party platforms such as CRM systems to Forge.

Always Forge Ltd is registered in England and Wales under company number 16240186, with its registered office at 86–90 Paul Street, London EC2A 4NE, United Kingdom.

For privacy enquiries, contact privacy@alwaysforge.com.

01

Our Role Under Data Protection Law

Depending on the circumstances, Forge may act as either a data controller or data processor.

Forge generally acts as a data controller when processing information about our customers, prospective customers, website visitors and account holders for our own legitimate business purposes.

Where Forge processes personal information contained in a customer’s CRM or other connected systems on that customer’s instructions, Forge generally acts as a data processor, and the customer remains the data controller.

Our customers are responsible for ensuring they have an appropriate lawful basis for providing personal information to Forge for processing.

02

Information We Collect

Account and User Information

When you register for or use Forge, we may collect:

  • Name
  • Business email address
  • Company name
  • Job title or role
  • Account credentials and authentication information
  • Subscription and account information
  • Communications with Forge
  • Information about how you interact with the Services

CRM and Integration Data

Where a customer connects Forge to a CRM or other third-party platform, Forge may process information available through that integration according to the permissions granted by the customer.

This may include:

  • CRM users
  • Contacts and leads
  • Companies or accounts
  • Opportunities and deals
  • Sales activities
  • Tasks
  • Notes
  • Pipeline and stage information
  • Sales performance information
  • Goals and attainment data
  • Other CRM information necessary to provide requested Forge functionality

The exact information accessed depends on the connected platform, permissions granted and Forge features used.

Supported integrations may include services such as Pipedrive, Salesforce and HubSpot.

Training and Coaching Content

Customers may provide Forge with materials for sales training and coaching, including documents, videos, recordings, links and other resources.

Forge may process this content to provide features such as AI-generated quizzes, summaries, coaching content and assessments.

Technical and Usage Information

We may automatically collect:

  • IP address
  • Device and browser information
  • Login information
  • Timestamps
  • Application usage
  • Diagnostic information
  • Security events
  • Application logs

Website Information

When you visit our website, we may collect information through cookies and similar technologies.

This may include device information, browser information, pages visited and interactions with the website.

Where required by law, non-essential cookies will only be used with your consent.

03

How We Use Information

We may use personal information to:

  • Provide and operate Forge
  • Authenticate users and manage accounts
  • Connect Forge with authorised CRM platforms
  • Analyse sales performance and CRM information
  • Generate reports, summaries and insights
  • Provide AI-powered coaching and recommendations
  • Prepare information for one-to-one meetings
  • Track goals and performance
  • Generate training materials and quizzes
  • Provide customer support
  • Communicate about the Services
  • Secure, maintain and troubleshoot the platform
  • Detect misuse, fraud and security threats
  • Improve Forge’s functionality and user experience
  • Comply with legal obligations
  • Establish, exercise or defend legal claims
04

Artificial Intelligence and Customer Data

Forge uses artificial intelligence technologies to provide features such as sales insights, summaries, coaching recommendations, goal recommendations, quiz generation and performance analysis.

Customer Data may be processed by AI systems where necessary to provide these features.

Forge does not use Customer CRM Data to train general-purpose AI models or models for other customers.

Where Forge uses third-party AI infrastructure or model providers to deliver AI functionality, we seek to use appropriate contractual and technical protections concerning the processing of customer information.

AI-generated outputs are intended to assist users and should be subject to appropriate human review.

05

Legal Bases for Processing

Where UK GDPR or EU GDPR applies and Forge acts as a controller, we may process personal information on one or more of the following legal bases:

  • Contract — where processing is necessary to provide Services you or your organisation have requested.
  • Legitimate Interests — where processing is reasonably necessary to operate, secure, support and improve our business and Services, provided those interests are not overridden by your rights.
  • Consent — where we ask you to consent to specific processing, such as certain marketing communications or cookies.
  • Legal Obligation — where processing is necessary to comply with applicable law.

Where Forge acts as a processor, we process personal information on the instructions of the relevant customer/data controller.

06

How We Share Information

We may disclose information to trusted service providers that assist us in operating Forge, including providers of:

  • Cloud infrastructure and hosting
  • Database and storage services
  • Authentication and security
  • AI and machine-learning infrastructure
  • Analytics and monitoring
  • Email and communications
  • Customer support
  • Payment processing

These providers may process information only as necessary to provide their services to Forge and subject to appropriate contractual protections.

We may also disclose information where required by law, regulation, court order or other valid legal process.

Information may be disclosed in connection with a merger, acquisition, financing, restructuring or sale of all or part of our business, subject to appropriate confidentiality and data protection requirements.

Forge does not sell Customer Data.

07

Third-Party Integrations

When you connect Forge to a third-party service, such as Pipedrive, Salesforce or HubSpot, information may pass between Forge and that service.

Access is governed by the permissions authorised by the customer and the APIs and authentication mechanisms provided by the relevant platform.

Third-party services operate under their own privacy policies and terms.

Customers can revoke Forge’s access through supported integration controls or through the relevant third-party platform.

08

International Data Transfers

Forge and some of our service providers may process information outside the United Kingdom or European Economic Area.

Where personal information is transferred internationally, we take appropriate steps designed to ensure an adequate level of protection in accordance with applicable data protection law.

Depending on the circumstances, these safeguards may include:

  • UK adequacy regulations
  • European Commission adequacy decisions
  • Approved Standard Contractual Clauses
  • The UK International Data Transfer Agreement
  • The UK Addendum
  • Other legally recognised safeguards
09

Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected.

This includes providing the Services, meeting contractual requirements, complying with legal obligations, resolving disputes and enforcing agreements.

Retention periods may vary depending on the nature of the information and the customer’s configuration.

When a customer terminates its Forge account or requests deletion, Customer Data will be deleted or returned in accordance with applicable contractual obligations, legal requirements and technical retention processes.

Backups may retain information for a limited period before being securely overwritten or deleted.

10

Disconnecting CRM Integrations

Customers may disconnect supported CRM integrations.

Once an integration is disconnected, Forge will no longer be authorised to retrieve new information from that CRM through the disconnected connection.

Previously processed information may remain within Forge for the applicable retention period or until deletion is requested, subject to contractual, technical and legal requirements.

Customers can contact privacy@alwaysforge.com regarding deletion of information associated with an integration.

11

Security

We implement reasonable technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Measures may include:

  • Access controls
  • Authentication
  • Encryption
  • Logging
  • Infrastructure security
  • Restricted employee access
  • Security monitoring

No online system can guarantee absolute security.

12

Your Data Protection Rights

Depending on your location and applicable law, you may have rights concerning your personal information.

Under UK GDPR and, where applicable, EU GDPR, these may include the right to:

  • Access personal information
  • Correct inaccurate information
  • Request deletion
  • Restrict processing
  • Object to certain processing
  • Receive certain information in a portable format
  • Withdraw consent where processing relies on consent
  • Lodge a complaint with a relevant supervisory authority

Where Forge processes information solely on behalf of a customer, we may refer your request to that customer because the customer is responsible for responding as data controller.

To exercise rights relating to information for which Forge is controller, contact: privacy@alwaysforge.com

UK individuals also have the right to complain to the Information Commissioner’s Office (ICO).

13

Marketing Communications

We may send business users information about Forge products, features and services where permitted by law.

You can opt out of marketing emails at any time using the unsubscribe mechanism included in the communication or by contacting us.

We may still send essential service communications relating to your account, security or use of Forge.

14

Cookies

Our website may use essential cookies necessary for security, authentication and website functionality.

We may also use analytics or other non-essential cookies to understand website usage and improve our Services.

Where required, visitors will be given appropriate choices regarding non-essential cookies.

Additional information may be provided through a separate Cookie Policy or cookie-management interface.

15

Children’s Privacy

Forge is a business service and is not intended for children.

We do not knowingly offer the Services directly to individuals under the age of 16.

16

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our Services, technology, legal requirements or data-processing practices.

Where changes are material, we will take reasonable steps to notify affected users or customers.

The current version will be published on our website with its effective date.

17

Contact Us

For questions, concerns or requests relating to this Privacy Policy or our handling of personal information, contact: