ForreastForreast

Legal

GDPR Notice

Effective Date: August 22, 2026

Overview

This notice provides additional information to individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”). It supplements our Privacy Policy.

1. Data Controller

Forreast, 1207 Delaware Ave, Wilmington, DE 19806, USA, is the data controller. Contact: privacy@forreast.com.

2. Data Protection Officer

Forreast has appointed a Data Protection Officer reachable at dpo@forreast.com for all issues related to the processing of your personal data under GDPR.

3. Categories of Personal Data Processed

  • Identification data (name, email, phone, organization)
  • Professional data (job title, company, industry)
  • Communication data (Signal messages, emails, form submissions)
  • Usage data (Vizier portal activity, report access logs)
  • Billing data (invoice reference, payment confirmation)

4. Purposes and Legal Basis

PurposeLegal Basis (Art. 6)
Service delivery (reports, alerts, Vizier portal)Contract (Art. 6(1)(b))
Lead management and CRMLegitimate interest (Art. 6(1)(f))
Newsletter and briefingsConsent (Art. 6(1)(a))
Security, fraud prevention, server logsLegitimate interest (Art. 6(1)(f))
Tax and regulatory complianceLegal obligation (Art. 6(1)(c))

5. Recipients of Data

  • Wise (payment processor — billing name and invoice reference only)
  • Cloud infrastructure providers under Data Processing Agreements
  • Legal and tax advisors when necessary
  • Public authorities when legally required

6. International Transfers

Personal data may be transferred outside the EEA to the United States. For such transfers, Forreast relies on Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision (EU) 2021/914) and implements supplementary measures where appropriate. A copy of the SCCs is available on request to dpo@forreast.com.

7. Retention Periods

  • Active client data: duration of engagement + 90 days
  • CRM leads: 36 months from last contact
  • Newsletter: until unsubscribe + 30 days
  • Server logs: 30 days

8. Your GDPR Rights

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure / “right to be forgotten” (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Right to withdraw consent (Art. 7(3))
  • Right to lodge a complaint with a supervisory authority (Art. 77)

To exercise these rights, contact dpo@forreast.com or privacy@forreast.com. We respond within 30 days (Art. 12(3)).

9. Automated Decision-Making

Forreast does not engage in automated decision-making that produces legal or similarly significant effects on individuals (Art. 22). Our AI-powered research reports are advisory outputs for professional decision-makers, not automated decisions about data subjects.

10. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, Forreast will notify the competent supervisory authority within 72 hours of becoming aware of the breach (Art. 33) and affected data subjects without undue delay if the risk is high (Art. 34).


Forreast · forreast.com · dpo@forreast.com