ForreastForreast

Legal

Privacy Policy

Effective Date: August 22, 2026 · Last Updated: August 22, 2026

1. Data Controller

Forreast (“we”, “us”, or “Forreast”) is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws. For questions about this policy or your data rights, contact privacy@forreast.com.

2. Data We Collect

Information you provide directly:

  • Contact form submissions: name, email, phone, company, and message content
  • Vizier portal account: name, email, organization, and authentication credentials
  • Signal correspondence: messages, shared documents, and attachments sent to the Vizier
  • Application forms (careers, partners, ambassadors, experts): name, email, phone, resume/CV links, and cover notes
  • Newsletter subscriptions: email address only
  • Payment information: billing name, invoice reference, and wire transfer details via Wise (we do not store card numbers)

Information collected automatically:

  • Anonymous analytics via self-hosted Umami (no third-party cookies, no behavioral tracking, no cross-site profiling)
  • Server logs: IP address, user agent, timestamps, and request paths (retained 30 days for security and abuse prevention)
  • Technical data: browser type, device type, and referring URL (anonymized, aggregated)

3. How We Use Your Data

  • Service delivery: generating research reports, alerts, and Vizier portal access
  • Communication: responding to inquiries, delivering reports, and sending intelligence briefings
  • CRM and sales: managing leads, subscriptions, and client relationships (stored in our self-hosted Odoo instance)
  • Security: preventing fraud, abuse, and unauthorized access
  • Legal compliance: meeting obligations under applicable laws and regulations

4. Legal Basis for Processing (GDPR Article 6)

  • Consent: newsletter subscriptions and optional data you provide through forms
  • Contract: processing necessary to deliver the subscription services you requested
  • Legitimate interest: server security, fraud prevention, and service improvement
  • Legal obligation: compliance with tax, financial, and regulatory requirements

5. Data Sharing

We do not sell your data. We share data only with:

  • Payment processor (Wise): billing name and invoice reference for wire transfers
  • Infrastructure providers: hosting, DNS, and email delivery (all under data processing agreements)
  • Legal authorities: when required by law, court order, or to protect our legal rights

We do not use third-party advertising networks, data brokers, or behavioral tracking services. All analytics are self-hosted.

6. Data Retention

  • Active client data: retained for the duration of the engagement plus a 90-day grace period
  • CRM leads: retained for 36 months from last contact, then deleted
  • Newsletter subscribers: retained until unsubscribe, then deleted within 30 days
  • Server logs: retained 30 days
  • Application data: retained per the relevant retention policy for the specific form type

7. Data Security

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is restricted to authorized personnel on a least-privilege basis. Multi-factor authentication is required for all internal administrative systems. Communications over Signal are end-to-end encrypted. See our Security Policy for details.

8. Your Rights

Under GDPR, CCPA/CPRA, and other applicable laws, you have the right to:

  • Access: request a copy of your personal data
  • Rectification: correct inaccurate or incomplete data
  • Erasure: request deletion of your data (“right to be forgotten”)
  • Restriction: limit how we process your data
  • Portability: receive your data in a structured, machine-readable format
  • Objection: object to processing based on legitimate interests
  • Withdraw consent: at any time without affecting prior processing

To exercise any of these rights, contact privacy@forreast.com. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

9. International Data Transfers

Forreast is a US-based company. Data may be processed in the United States and the European Union. For transfers outside the EEA, we rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards as required by GDPR Chapter V.

10. Cookies

We use only essential cookies necessary for the website to function. Our analytics (Umami) are self-hosted and do not use tracking cookies. We do not use third-party advertising or social media tracking cookies. No cookie banner is required because we do not place non-essential cookies.

11. Children’s Privacy

Our services are not directed to individuals under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact privacy@forreast.com and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy. Material changes will be posted on this page with an updated effective date. We will notify active clients by email at least 30 days before material changes take effect.

13. Contact

For privacy questions, data requests, or to exercise your rights: privacy@forreast.com or sovereign@forreast.com.


Forreast · forreast.com · sovereign@forreast.com