Privacy Policy
Draft pending legal review. Placeholders in [brackets] will be completed before this document takes effect.
Last updated 30 September 2026
This notice describes what [BEESWORX LEGAL NAME] (Reg. No. [BEESWORX REGISTRATION NO.]) ("Beesworx", "we") collects about you as a user of the Forge platform itself: account holders, org members, people who request beta access, and visitors to the website, dashboard and signup pages. It does not cover personal information that tenants process about their own end users inside applications they deploy on the platform. That processing is governed by the tenant's own privacy notice, and Beesworx's role there is described in the Data Processing Agreement. How we handle job applicants' information is described in the Recruitment Privacy Notice.
Beesworx is the responsible party (POPIA) for the personal information described in this notice.
1. What we collect
| Category | Examples | Source |
|---|---|---|
| Beta access requests | E-mail address, first and last name, company, and what you want to run on Forge | You, through the beta request form (hosted on Buzzz) |
| Account information | Name, e-mail address, organisation membership and role, org invite records (invitee e-mail, inviter, role) | You, at signup or invite |
| Identity data | Identity record (credentials hash, verification status, MFA enrolment state), session records (including IP address and user agent) | Our self-hosted identity service (Ory Kratos) |
| Authentication events | Login and logout, password reset, MFA enrolment, session tokens | Identity service and Forge session handling |
| Terms and policy acceptance | Which version of the Terms, AUP and Privacy Policy you accepted, when, and your IP address and browser user agent at the time (only where acceptance recording is turned on) | You, at signup |
| Audit logs | Action taken, acting identity, target resource, timestamp, and action details, for administrative and lifecycle actions (not every action is currently audited) | Administrative and lifecycle actions through the API, CLI, MCP server and dashboard |
| Usage metering | CPU time, memory, network bytes, disk usage, build time, and LLM gateway request counts, token counts and cost, per org | Container runtime sampling; the LLM gateway |
| Request logs | HTTP method, path (for API, MCP and gateway routes), status, size, latency, and a request ID | Every request through the API |
| Application logs | Your deployed application's stdout and stderr, and platform component logs | Container log collection (only where the operator runs the monitoring stack) |
| Billing information | Your e-mail, organisation name and ID, and usage and plan data sent to our billing provider (RevEx, Beesworx's own billing product); invoices; a flag showing whether a payment method is on file. Card and debit-order collection runs through RevEx's hosted checkout and payment rail ([PAYMENT RAIL, e.g. PayFast/Paystack and/or debit order]), which holds your card or bank details directly; Forge never receives them | Billing integration |
| Support communications | Content of support tickets and e-mails you send us | You |
| Dashboard AI assistant | Messages you send the in-dashboard chat assistant, and the results of the actions it takes on your behalf (which can include rows from your own databases, environment settings and logs) | You, via the chat panel (only where the assistant is enabled) |
| Cookies and local storage | Session state, active-org selection; a captcha widget's token and cookies where signup captcha is enabled | Your browser |
We do not intentionally collect special personal information (POPIA section 26 data, e.g. health, biometric, or religious or political information) about platform users. MFA enrolment status is an account-security flag, not special personal information, and is collected as part of authentication. We do not use analytics or advertising trackers on the website or dashboard.
2. Why we collect it (purpose and lawful basis)
- Providing the Service: authenticating you, enforcing your org's permissions, billing your org, and operating the infrastructure you provision. (Contract performance.)
- Beta access: contacting you about your request and onboarding your team. (Your request; legitimate interest.)
- Security and abuse prevention: audit logs, request logs, and mining detection exist to detect and respond to compromised accounts, abuse, and attacks against the platform or other tenants. (Legitimate interest and legal obligation.)
- Support: responding to tickets you raise.
- Legal compliance: retaining records required by law (e.g. financial records, security incident records).
3. Retention
| Data | Retention |
|---|---|
| Beta access requests | [BETA REQUEST RETENTION PERIOD, OWNER TO CONFIRM] |
| Account and identity data | For the life of the account. There is no self-service account-deletion flow today; deleting your organisation does not delete your underlying login identity. Contact [PRIVACY CONTACT] to request deletion. |
| Terms and policy acceptance record | Tied to your organisation and deleted when the organisation is deleted. [ATTORNEY TO ADVISE: this can remove the record that would evidence a dispute.] |
| Audit logs | Not currently pruned. Kept after the organisation is deleted, with personal details scrubbed (see the Data Processing Agreement). [AUDIT LOG RETENTION PERIOD, OWNER TO SET] |
| LLM usage and usage-metering records | Kept for the life of the organisation and deleted with it. [METERING RETENTION PERIOD, OWNER TO SET] |
| Request logs and application logs | Where the operator runs the monitoring stack, held for [LOG RETENTION, the configured period, default 14 days]. Without it, held only as long as the underlying container's local log file exists (no fixed period). |
| Database and app backups (your data, not this notice's subject; noted for completeness) | Where scheduled backups are enabled, scheduled backups are kept for [BACKUP RETENTION, default 7 days], including any off-host copy. Manual backups are kept until you delete them. Deleting a backup, or your organisation, deletes the off-host copy too. |
| Support communications | [SUPPORT RETENTION PERIOD] |
4. Where your information is processed and cross-border transfers
Beesworx's own infrastructure for Forge is hosted at [HOSTING DATA CENTRE NAME AND LOCATION, see the sub-operator list]. Several processors we use to operate the platform are located outside South Africa. See the sub-operator list for the full list and the POPIA section 72 basis for each transfer, including: Resend (platform e-mail, United States); Buzzz, with Amazon SES, for tenant application e-mail and for the beta request form; the AI provider behind the dashboard assistant and build helpers (only where those features are enabled); LLM providers registered on the platform (reached when your own application calls the LLM gateway, or when the RAG feature processes documents you upload to it); GitHub or another git host (only if you connect a repository); Google Fonts (loaded by every visitor to the website, dashboard and signup pages); and Cloudflare Turnstile or hCaptcha (only if signup captcha is enabled; receives your IP address as part of verifying you are not a bot).
Every hostname on the platform, including your own custom domains, is submitted to a public certificate authority for a TLS certificate and becomes visible in public Certificate Transparency logs. This is standard practice for any HTTPS site and discloses only the hostname, not its content or your personal information.
5. Who we share it with
- Sub-operators listed in the sub-operator list, strictly to operate the Service.
- Law enforcement or regulators, where legally compelled.
- We do not sell personal information.
6. Your rights
Under POPIA, you may request access to, correction of, or deletion of your personal information, and may object to certain processing. Contact [PRIVACY CONTACT / INFORMATION OFFICER] to exercise these rights; the PAIA Manual explains how to request records. You may also lodge a complaint with the Information Regulator (South Africa).
7. Security
Personal information is protected by the measures described in the Security Statement and the Data Processing Agreement: encryption of credentials, secrets and backup files, org-scoped access control, a network egress boundary, and a sandboxed container runtime for tenant workloads. Platform administrators can technically access account and tenant data directly (e.g. to provide support); this is restricted by policy, not by a technical barrier on every such path (see the Data Processing Agreement for an honest statement of that limitation). No system is perfectly secure; see the Security Statement for how to report a concern.
A few other third-party addresses are contacted automatically by platform infrastructure but do not receive your personal information: container image registries (Docker Hub, ghcr.io, quay.io) when pulling images, a public IP lookup service for the host's own address (dynamic DNS, where used), and the k3s installer when provisioning a managed Kubernetes cluster you request.
8. Contact
[PRIVACY CONTACT, e.g. privacy@forgeserver.app, or the Information Officer once registered]