Data Processing Agreement
Last updated: August 2, 2026
This agreement applies whenever you use CardForge to process personal data for which you are the controller. It takes effect when you create an account and needs no signature. If your organisation requires a countersigned copy, write to hello@getcardforge.dev.
1. Roles
You are the controller: you decide what personal data enters the service and why. We are the processor: we act only on your instructions, and using the product is how you give them.
2. Scope
Subject matter: providing the service you subscribed to. Duration: as long as your account exists. Nature and purpose: the operations the product performs on your input. Categories of data subjects and of personal data: whatever you choose to send — we do not control that, which is why the next section matters.
3. Your obligations
You warrant that you have a lawful basis for the data you send, and that sending it to us is compatible with the notice you gave your own data subjects. Send only what the service needs. Where the product offers test or redacted modes, prefer them.
4. Our obligations
- Process personal data only on your documented instructions.
- Bind everyone with access to confidentiality.
- Apply the security measures in section 6.
- Assist you with data subject requests, and with your own DPIA where relevant.
- Delete or return the data when the account ends — see section 8.
- Make available the information you need to demonstrate compliance.
5. Sub-processors
You give general authorisation for the sub-processors below. We will tell you before adding or replacing one, and you may object on reasonable data-protection grounds. This table is generated from the same source as the privacy policy, so the two cannot disagree.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Application hosting and page delivery | EU (deploy region) and United States |
| Upstash | Database holding accounts, keys and product data | EU |
| Stripe | Payments and subscription management | EU and United States |
| Brevo | Transactional email (welcome, API key, alerts) | EU (France) |
| Sentry | Application error reporting | EU (.de ingestion host) |
| Vercel BotID | Bot protection on public forms | EU and United States |
| Google Analytics 4 | Aggregate visit statistics | United States |
| Vercel Analytics and Speed Insights | Page performance metrics | EU and United States |
6. Security
Encryption in transit (TLS) and at rest. API keys are stored only as a hash, never in clear text. Access to production data is limited to what operating the service requires. Errors are reported to our monitoring without personal data attached.
7. Breach notification
If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any case within 48 hours, with what we know and what we are doing about it. That leaves you time inside your own 72-hour deadline under Art. 33.
8. Deletion
On request, or when your account closes, we delete your personal data. Write to hello@getcardforge.dev and we act within 30 days. Backups age out on their own schedule and are never written back.
9. International transfers
Some sub-processors operate outside the EEA — the table in section 5 says which. Those transfers rely on the European Commission’s Standard Contractual Clauses, which each of those vendors has in place.
10. Audit
We answer reasonable written questions about this agreement and provide the documentation we hold. For an on-site audit, write to us and we will agree scope and timing.