Back to Legal & Compliance

Data Processing & GDPR Policy

Last updated: 2 July 2026

Our Role

When you use CertForge, your company acts as the Data Controller for client, site, and inspection data you enter, and CertForge (operated by Bright Click Studio) acts as the Data Processor.

Legal Basis for Processing

We process personal data on the basis of contract performance (providing the service you subscribed to), legitimate interest (platform security and improvement), and consent where applicable.

Categories of Data Processed

Company data, user account data, client and site records, inspection and certification data, commercial documents, photographs, attachments, and email communication logs.

Sub-processors

We use trusted third-party providers for hosting, email delivery, and payment processing, all of whom are contractually bound to appropriate data protection standards.

International Transfers

Where data is processed outside the UK/EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses.

Data Subject Rights

Individuals have the right to access, rectify, erase, restrict, or port their personal data, and to object to processing, in accordance with UK GDPR / EU GDPR.

Data Breach Notification

In the event of a data breach affecting personal data, we will notify affected companies and relevant authorities as required by law.

Data Protection Contact

For GDPR-related requests or questions, please use our Contact & Support page.