Data and project-file privacy

Clear handling
for sensitive project context.

This policy describes how contact details, RFQ requirements, CAD files, service data, and authorized administrator activity are processed across the platform.

PRIVACY / RFQ DATA / PRIVATE FILES

RFQ informationPrivate file storagePrivacy rights

Policy contents

Operational transparency. Legal facts still to confirm.

The processing descriptions reflect the current platform. Operator identity, legal bases, retention periods, transfer terms, and effective dates remain explicitly unconfirmed.

01

Policy scope and contact

  • This policy explains how information is processed when you use the Forgevian website, submit a request for quote, upload files, receive transactional email, or contact us.
  • Privacy enquiries and rights requests may be sent to privacy@forgevian.com.
  • Operator legal identity and registered address: To be confirmed before search indexing is enabled.
02

Information we collect

  • Contact and business information, including name, company, email address, and country.
  • RFQ information, including process interest, material intent, quantity, timeline, project description, consent state, and submission reference.
  • Optional CAD files, drawings, specifications, archives, and other supporting documents accepted by the RFQ workflow.
  • Source and attribution information, such as landing page, current page, referrer, campaign parameters, and Google click identifiers when present.
  • Technical and security information, including request logs, rate-limit data, authentication activity, browser or device information, and security events.
  • For authorized staff, authentication identity, role, status changes, internal notes, and audited file-access events.
03

How we use information

  • To create and maintain an RFQ draft, receive a formal submission, conduct manual engineering review, communicate about requirements, and prepare project-specific quotations.
  • To operate file upload and download controls, authenticate authorized staff, maintain status and audit records, prevent abuse, and investigate operational or security incidents.
  • To send customer confirmations, internal RFQ notifications, authentication messages, and other service communications.
  • To understand website and RFQ-funnel performance where analytics is configured and the applicable consent state permits processing.
  • Applicable legal bases by jurisdiction: To be confirmed before search indexing is enabled.
04

RFQ data

  • RFQ contact details and project requirements are stored so the engineering team can review and manage the enquiry.
  • A submitted RFQ may be assigned a reference code and moved through internal workflow states with status history and notes.
  • RFQ data is not used to provide automatic quotation or automatic CAD analysis in the current platform.
05

CAD and supporting files

  • File upload is optional. Accepted files are restricted by type, individual size, number of files, and total submission size.
  • Files are stored as private objects in Cloudflare R2 and are not assigned a permanent public URL.
  • Authorized staff access files through short-lived signed links created after server-side authentication and permission checks.
  • ZIP files are not unpacked and CAD files are not automatically parsed or rendered by the platform.
  • The current platform does not use a separate malware-scanning provider. Uploaded files should be treated cautiously by authorized recipients.
06

Infrastructure and service providers

  • Vercel provides website hosting, application delivery, and server execution.
  • Supabase provides PostgreSQL data processing, database services, and administrator authentication.
  • Cloudflare R2 provides private object storage for CAD files and supporting documents.
  • Resend provides transactional email delivery for RFQ confirmations and operational notifications.
  • Google Tag Manager and Google Analytics may process consent-permitted website interaction events when production identifiers are configured. Events are designed not to contain names, email addresses, filenames, CAD contents, storage keys, or RFQ reference codes.
  • Confirmed processing regions, subprocessors, and transfer safeguards: To be confirmed before search indexing is enabled.
07

Cookies and browser storage

  • The RFQ workflow uses functional HttpOnly cookies to protect draft access and successful-submission confirmation.
  • The administrator area uses Supabase authentication session storage for authorized staff access.
  • Browser storage may preserve initial landing attribution, current page, campaign information, and analytics-consent preferences without intentionally storing RFQ contact information or CAD content.
  • Analytics storage is denied by default in the application consent configuration and may be updated through the consent mechanism when available.
08

Sharing and disclosure

  • Information may be shared with the service providers listed above only as needed to operate the platform and deliver the relevant service.
  • Information may also be disclosed when required by law, to protect rights or security, to investigate misuse, or in connection with a legitimate organizational transaction subject to appropriate safeguards.
  • Project files are not published as customer work or used as public case content without separate authorization.
09

Retention and deletion

  • RFQ contact and project-data retention: To be confirmed before search indexing is enabled.
  • CAD and supporting-file retention: To be confirmed before search indexing is enabled.
  • Internal notes, status history, and audit-log retention: To be confirmed before search indexing is enabled.
  • Retention may be extended where necessary for an active project, security investigation, dispute, legal obligation, or the establishment, exercise, or defense of legal claims.
10

International processing

  • The service supports global business enquiries, and infrastructure or service providers may process information in countries other than the country where it was submitted.
  • Operator-specific international transfer mechanism and regional disclosures: To be confirmed before search indexing is enabled.
11

Security

  • Controls include private object storage, short-lived signed file links, server-side authorization, role checks, rate limits, audit logging, encrypted network transport, and restricted service credentials.
  • No internet service can guarantee absolute security. Controls and operational procedures are reviewed as the platform evolves.
12

Your privacy rights

  • Depending on location and applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent.
  • Submit a request to privacy@forgevian.com. Identity verification, response periods, available appeals, and regulator details depend on applicable law.
13

Children

  • The platform is designed for business and professional manufacturing enquiries and is not directed to children.
  • Minimum-age wording and jurisdiction-specific requirements: To be confirmed before search indexing is enabled.
14

Policy administration

  • Effective date: To be confirmed before search indexing is enabled.
  • Last updated: To be confirmed before search indexing is enabled.
  • This page will remain excluded from search indexing and the Sitemap until operator details, retention periods, applicable legal bases, and final legal wording are confirmed.