Privacy notice
This notice explains how Forzyte, LLC (“Forzyte”, “we”) handles personal data when you use forzyte.com, including the contact form. It is meant to meet the transparency requirements of the EU General Data Protection Regulation (GDPR) for visitors in the European Economic Area and the United Kingdom, and to describe the same practices for visitors elsewhere.
Who is responsible
The data controller is Forzyte, LLC, a United States company. Contact: [email protected].
What we collect
When you send a contact request we store your name, email address, organization name, optional phone number, the services you selected, the time of submission, and a limited network identifier used to prevent abuse. We also store a first-party session cookie named forzyte.sid so the form can be submitted securely and so administrators can sign in. We do not use advertising or analytics cookies. We do not sell contact data.
Why we use it, and the lawful basis
We use contact-form data to respond to your inquiry from [email protected] and to keep an internal record of the request. The lawful basis is Article 6(1)(b) GDPR: steps at your request before a possible engagement. We also rely on Article 6(1)(f) for limited abuse prevention (rate limits and the network identifier) and to protect the security of the form. Our legitimate interest is to run a contact channel that is usable and not easily abused. The session cookie is strictly necessary for that service.
Where it is stored, and transfers
Requests are stored on Forzyte’s server in AWS us-east (United States) and are available only to Forzyte administrators through a signed-in inbox. Public internet access to the origin is limited to a Cloudflare tunnel. If you are in the EEA or UK, sending a request transfers your data to the United States. That transfer is necessary to handle your inquiry. We rely on Amazon Web Services’ published customer agreement, Data Processing Addendum, and Standard Contractual Clauses for infrastructure in the United States, and on Cloudflare’s equivalent terms for the tunnel in front of the site. Forzyte itself is not certified under the EU-U.S. Data Privacy Framework.
How long we keep it
We keep a contact record for 24 months from the time it is received, then delete it, unless a shorter deletion is requested and we have no legal duty to keep it, or a longer legal obligation applies. Administrators can delete a record sooner when follow-up is finished or when you ask us to erase it.
How it is protected
The public site does not expose the inbox. The origin process binds to localhost. Administrators sign in with a password. Contact fields are encrypted at rest on the server. Transport to visitors is HTTPS. We do not send your request by opening your email client; it stays on Forzyte’s server until an administrator follows up from [email protected].
Your rights
If GDPR or UK GDPR applies to you, you may ask us to access the data we hold about a request you submitted, correct it, delete it, restrict how we use it, or receive a copy. You may also object to processing that we carry out on legitimate-interest grounds (the abuse-prevention identifier). Write to [email protected] from the address you used on the form so we can match the record. You may lodge a complaint with your local supervisory authority. We will fulfill a verified access or erasure request without undue delay, and within one month where the GDPR applies.
What we do not do
We do not use the contact form for marketing lists, automated decision-making, or profiling. We do not share inquiry records with third parties for their own purposes. Infrastructure providers (AWS, Cloudflare) process data only to host and deliver the site.