Legal
Data Processing Addendum
Template · Effective Date: August 22, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and is incorporated by reference. It applies when Forreast processes personal data on behalf of a client who is a controller or processor under GDPR. To execute a signed DPA, contact legal@forreast.com.
1. Roles and Scope
The client (“Controller”) engages Forreast (“Processor”) to process personal data on the Controller’s behalf for the provision of strategic intelligence research and the Vizier platform. The categories of data subjects, types of personal data, and processing purposes are described in the Terms of Service and the Controller’s instructions.
2. Processing Instructions
Forreast will process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required by EU or member state law. Forreast will inform the Controller if it cannot comply with an instruction, in which case the Controller may suspend or terminate the service.
3. Confidentiality of Processing Personnel
Forreast ensures that personnel authorized to process personal data are subject to confidentiality obligations or are under an appropriate statutory obligation of confidentiality. Access is granted on a need-to-know basis and is revoked promptly upon role change or departure.
4. Security Measures
Forreast implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit (TLS 1.3) and at rest (AES-256)
- Multi-factor authentication for all administrative access
- Network segmentation and least-privilege access controls
- Regular security assessments and penetration testing
- Incident response plan with defined escalation procedures
- Backups with tested recovery procedures
- Data isolation between clients (no cross-tenant data leakage)
These measures take into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons (Art. 32).
5. Sub-processors
Forreast uses the following categories of sub-processors:
- Cloud infrastructure (hosting and compute)
- DNS and content delivery
- Payment processing (Wise — billing data only)
- Email delivery infrastructure
Forreast enters into written agreements with all sub-processors imposing data protection obligations no less protective than this DPA. Forreast remains liable for the performance of its sub-processors. The Controller will be notified of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object (Art. 28(2)).
6. Data Subject Rights
Forreast assists the Controller in responding to data subject requests by providing the technical and organizational means necessary for the fulfillment of the Controller’s obligation to respond (Art. 28(3)(e)). Forreast forwards any data subject request received directly to the Controller without responding to the request itself.
7. Breach Notification
Forreast will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data. The notification will include the nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed. Forreast will provide ongoing updates as further information becomes available (Art. 33).
8. Data Protection Impact Assessment
Forreast assists the Controller in conducting data protection impact assessments, providing relevant information about the processing, to the extent required (Art. 35).
9. Return or Deletion
Upon termination of services, Forreast will, at the choice of the Controller, return or delete all personal data processed on behalf of the Controller and delete existing copies, unless EU or member state law requires storage. Return or deletion occurs within ninety (90) days of termination (Art. 28(3)(g)).
10. Audit Rights
The Controller may audit Forreast’s compliance with this DPA, subject to reasonable notice (at least 30 days) and confidentiality obligations. Forreast will make available all information necessary to demonstrate compliance and contribute to audits conducted by the Controller or a third-party auditor mandated by the Controller (not competitively affiliated with Forreast) (Art. 28(3)(h)).
11. International Transfers
Where personal data is transferred outside the EEA, Forreast relies on Standard Contractual Clauses (SCCs) as approved by the European Commission (Implementing Decision (EU) 2021/914). Supplementary measures, as appropriate, are implemented based on the results of transfer impact assessments.
12. Governing Law
This DPA is governed by the same governing law as the Terms of Service (State of Delaware, USA) and is subject to the jurisdiction of the supervisory authority of the Controller’s main establishment for GDPR enforcement purposes.
Forreast · forreast.com · legal@forreast.com · dpo@forreast.com
