Legal
Privacy
Draft pending legal review. This document sets out the structure and the positions we intend to take, but it has not been reviewed by counsel and is not yet operative. It carries noindex until it is signed off, and the launch gate blocks release while any legal document is unreviewed.
Outstanding before sign-off:
- Identify the data controller: the registered legal entity, its address, and its registration number (FR-60).
- Confirm whether an EU representative or a data protection officer is required, and name them if so.
- Confirm the retention period for enquiry data with whoever owns the sales pipeline.
- List the actual sub-processors once the form handler, analytics, and any CRM are selected.
- Have counsel confirm the CCPA/CPRA position for United States visitors.
Who controls your data
The controller is the RiseForge legal entity identified on the imprint page. That entity is not yet published here, which is one of the items blocking sign-off of this document.
What we collect, and why
When you contact us
The enquiry form collects your name, company, work email, and the description of your project, together with whichever context you arrived with — the service, industry or engagement model page you came from. We use it to answer you and to decide whether we are the right people for the work.
Legal basis: steps taken at your request prior to entering a contract, and our legitimate interest in responding to business enquiries.
When you browse the site
We intend to use privacy-preserving analytics that does not set cookies, does not track individuals across sites, and does not build a profile of you. If that remains true at launch, no consent banner is required and none will be shown. If any component that sets non-essential cookies is later added, consent will be requested first, with rejecting made exactly as easy as accepting.
Who else sees it
Enquiries are handled by RiseForge staff. The form posts to this site’s own handler and the message is delivered by our own mail server, so no third-party form or email processor sits between you and us today. Any processor added later will be listed by name here before this document is signed off; we are not going to publish a vague reference to “trusted partners” in place of a list.
How long we keep it
Enquiries that do not become engagements are deleted after a defined retention period, which is one of the outstanding items above. Records relating to engagements are kept for as long as the contract and the applicable statutory limitation and tax periods require.
Your rights
Where the GDPR applies you have the right to access your data, to have it corrected or deleted, to restrict or object to processing, and to receive it in a portable form. You may also complain to your national supervisory authority. Where United States state privacy laws apply you have comparable rights, including the right to know what has been collected and to have it deleted.
To exercise any of these, write to privacy@riseforge.io. We respond within the statutory period, and in practice sooner.
International transfers
We serve clients across the United States, Canada, the European Union, and the Middle East, so personal data may be transferred between those regions. The transfer mechanisms relied on will be stated here specifically before sign-off.
Changes
When this document changes, the date at the top changes with it and the substantive change is described. The date is set by hand when the text is edited, not generated on each page view.