Forecraft

Data Processing Addendum

Last updated: June 9, 2026

Contents

  1. Introduction and Context
  2. 1. Definitions
  3. 2. Scope and Purpose of Processing
  4. 3. Processor Obligations
  5. 4. Sub-Processors
  6. 5. Data Subject Rights
  7. 6. Security Measures
  8. 7. Audit Rights
  9. 8. International Transfers
  10. 9. Term and Termination
  11. 10. Contact
Terms of ServicePrivacy PolicySecurity

Introduction and Context

Fractional CFOs and CPA firms using Forecraft upload their clients’ financial data to the Service. In this relationship:

  • The Forecraft customer (fractional CFO or firm) is the data controller— they determine the purpose and means of processing their clients’ data.
  • Forecraft is the data processor — it processes data on behalf of and under the instructions of the controller.
  • The SMB clients whose financial data is uploaded are the data subjects (to the extent their data constitutes personal data under applicable law).

Under GDPR (Article 28) and various state privacy laws, a written Data Processing Addendum between controller and processor is required. This document serves as that agreement, supplementing the Terms of Service.

1. Definitions

Controller
The Forecraft customer (fractional CFO, CPA firm, or other entity) who determines the purpose and means of processing Personal Data through Forecraft.
Processor
Forecraft, which processes Personal Data on the Controller’s behalf.
Data Subject
The identified or identifiable natural person whose Personal Data is processed. In the context of Forecraft, this may include business owners and principals whose names or identifiable financial information appears in uploaded data.
Personal Data
Any information relating to an identified or identifiable natural person as defined under applicable data protection law (including GDPR Article 4(1) and CCPA).
Processing
Any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
Sub-Processor
A third-party service provider engaged by Forecraft to assist in processing Personal Data on behalf of the Controller.
GDPR
The EU General Data Protection Regulation (2016/679) and, where applicable, the UK GDPR.

2. Scope and Purpose of Processing

Subject matter

The processing of Personal Data that may be contained in financial files uploaded to Forecraft by the Controller.

Purpose

To provide the Forecraft Service: generating monthly close packs, variance analysis, AI-assisted narrative, and management pack exports. Forecraft processes Personal Data solely to fulfill this purpose and in accordance with the Controller’s instructions.

Nature of processing

Storage, computation (variance analysis), transmission to sub-processors for AI narrative generation (Anthropic), and generation of output documents.

Categories of Personal Data

Business financial data, which may include names of business owners or officers, transaction descriptions, account names, and other data that may be associated with identifiable individuals.

Duration

For the term of the Controller’s subscription to Forecraft, plus 30 days following termination for data export, after which Personal Data is permanently deleted.

3. Processor Obligations

Forecraft, as Processor, agrees to:

  • Process only on instructions. Process Personal Data only on the documented instructions of the Controller (which are set out in the Terms of Service and this DPA), unless required to do so by applicable law.
  • Ensure confidentiality. Ensure that all personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.
  • Implement security measures. Implement appropriate technical and organizational security measures as described in Section 6.
  • Engage sub-processors appropriately. Use sub-processors only as listed in Section 4, under equivalent data protection obligations.
  • Assist with Data Subject rights. Provide reasonable assistance to the Controller in responding to Data Subject requests as described in Section 5.
  • Assist with security obligations. Assist the Controller in ensuring compliance with GDPR Articles 32–36 (security, breach notification, data protection impact assessments, prior consultation with supervisory authority).
  • Delete or return data. At the choice of the Controller, delete or return all Personal Data on termination of the service. Data is permanently deleted 30 days after account termination.
  • Provide audit information. Make available information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 7.
  • Notify of breaches.Notify the Controller without undue delay (and no later than 72 hours where feasible) upon becoming aware of a personal data breach affecting Controller’s data.
  • Not use data for own purposes.Not process Personal Data for Forecraft’s own purposes, including not using it to train AI models or for any purpose other than providing the Service.

4. Sub-Processors

The Controller hereby grants general authorization for Forecraft to engage the following sub-processors. Forecraft will ensure each sub-processor is bound by equivalent data protection obligations.

Sub-processorRoleData locationEU transfer mechanismPrivacy policy
Vercel Inc.Hosting & infrastructureUnited StatesSCCPrivacy policy →
Neon Inc.Database (PostgreSQL)United StatesSCCPrivacy policy →
Anthropic PBCAI narrative generationUnited StatesSCCPrivacy policy →
Stripe Inc.Payment processingUnited StatesSCCPrivacy policy →
Upstash Inc.Rate limiting & cachingUnited StatesSCCPrivacy policy →
Resend Inc.Transactional emailUnited StatesSCCPrivacy policy →

SCC = Standard Contractual Clauses (EU Commission Decision 2021/914). UK transfers comply with the UK International Data Transfer Agreement (IDTA).

Forecraft will notify the Controller of any intended addition or replacement of sub-processors with at least 30 days’ notice. The Controller may object to a new sub-processor within that period; if the parties cannot resolve the objection, the Controller may terminate the Service.

5. Data Subject Rights

Forecraft will assist the Controller in responding to Data Subject requests for access, correction, deletion, restriction, objection, and data portability. To submit a request, the Controller should contact privacy@forecraft.tech.

Forecraft will assist within the timeframes required by applicable law (30 days for GDPR, 45 days for CCPA). Where technically feasible, Forecraft will provide the Controller with self-service tools to export or delete workspace data.

6. Security Measures

Forecraft implements the following technical and organizational measures to protect Personal Data:

Technical measures

  • Encryption in transit: TLS 1.3 for all data transmission.
  • Encryption at rest: AES-256 in the database layer (Neon).
  • Password security: bcrypt hashing (cost factor 12); passwords never stored in plain text.
  • Integration tokens: OAuth tokens for QuickBooks/Xero encrypted at rest.
  • Access control: workspace isolation enforced at the application layer; each workspace requires verified session authentication.
  • Authentication: multi-factor authentication (TOTP) available for all accounts; brute-force protection via per-IP rate limiting.
  • Dependency management: automated vulnerability scanning and dependency updates.

Organizational measures

  • Access to production systems restricted to personnel with a legitimate need.
  • Incident response procedures for detecting, containing, and notifying of breaches.
  • Regular internal security reviews.

For more detail, see our Security page.

7. Audit Rights

The Controller may audit Forecraft’s compliance with this DPA no more than once per calendar year, with at least 30 days’ written notice. Audits must be conducted during business hours, at the Controller’s expense, and in a manner that minimizes disruption to Forecraft’s operations.

In lieu of a direct audit, Forecraft may satisfy audit requests by providing relevant third-party audit reports (e.g., SOC 2 reports, penetration test summaries) where available.

8. International Transfers

Forecraft’s infrastructure is located in the United States. Transfers of Personal Data from the EEA or UK to the United States are made in reliance on:

International transfers from the EEA and UK are conducted under Standard Contractual Clauses (EU Commission Decision 2021/914). UK transfers comply with the UK IDTA. Upon request, a copy of the applicable SCCs or IDTA will be provided.

9. Term and Termination

This DPA remains in effect for as long as Forecraft processes Personal Data on behalf of the Controller under the Terms of Service. It terminates automatically upon termination of the Terms of Service. Provisions that by their nature should survive termination (including confidentiality, deletion obligations, and audit rights) will survive.

10. Contact

To request a signed version of this DPA, to report a concern, or to exercise any rights under this agreement:

legal@forecraft.tech
⚠️ ACTION NEEDED: Add your registered business address here before going live with paying customers.

Last updated: June 9, 2026


This DPA supplements our Terms of Service. See also: Privacy Policy · Security · Plain-English Data Guide

Terms of ServicePrivacy PolicySecurityBack to home