1. Who we are

Forgina ("we", "us") provides workplace software to organisations in industry. Our products are licensed to organisations, not to individual consumers, and they have no public sign-up. You can only use them with an account created for you by your employer or the organisation operating your site.

Questions about this policy or about your personal data: privacy@forgina.com

2. Our role

Your employer (the organisation that licensed the product) decides which personnel receive accounts, which records are created, which optional modules are switched on, and how long data is kept. Under the GDPR and the Turkish Personal Data Protection Law (KVKK), that organisation is the data controller and Forgina acts as a data processor on its documented instructions.

Practically, this means: if you want to see, correct, or delete data about you, contact your employer first. We will support them in responding, and you can always write to us at the address above.

We act as a controller only for the narrow set of data we need to run the service itself, such as security and abuse-prevention records on sign-in.

3. Data we process

What is processed depends on the product, on the modules your organisation has chosen to switch on, and on the permissions you grant. Not every category below applies to every product or every user.

Account and identity data — provided by your organisation, not by you: name, work email address, job title, department, assigned role, any authorisations recorded for you, and your language preference.

Authentication and session data — your password (stored only as a salted hash by our authentication provider; we never see it) and session tokens, held in the device's protected credential storage and not written to cloud backups.

Device and technical data — a device registration identifier generated randomly on your device, the platform, the application version and the operating-system version. The identifier binds an account to a single device; it is not a hardware serial number, not an advertising identifier, and cannot be used to recognise you in any other application.

Records and content you create — the entries, records, forms, confirmations and files you create or upload in the products, together with the identity of the acting user, the server time of the action and the time reported by your device. Many of these serve as evidence and are held as append-only records that cannot be edited or deleted from the application by any user, including administrators.

Data obtained through device permissions — where you grant a permission listed in section 4, the data that permission provides, for the purposes described in this policy.

Notification tokens — a push token issued by Apple or Google, the platform and the environment, used solely to deliver notifications to you. Tokens reported as invalid are deleted automatically.

Usage and diagnostic data — in some products, a limited record of application usage and stability: the account and organisation, the type of event, application and operating-system version, session duration, and crash diagnostics on some platforms.

Security records — the email address used in a sign-in attempt, failed attempt counts and any resulting lockout.

Special categories of data — depending on the modules your organisation chooses to use, a product may process data that qualifies as a special category under Article 9 of the GDPR and Article 6 of the KVKK. Where that is the case, your organisation determines the purpose and the legal basis, access is restricted to the users it specifically authorises, and the data is used only for the purposes it has defined.

4. Device permissions

Depending on the product, the modules your organisation has enabled and the task you are carrying out, an application may ask for the following device permissions:

Each permission is requested only at the point where it is needed, and only for the purposes described in this policy. Declining one never blocks the rest of the application, and you can withdraw any of them at any time in your device settings.

Four points are worth stating plainly:

5. Why we process it, and on what legal basis

We process personal data in order to provide the products to your organisation, to record actions taken in them, to deliver notifications, to secure accounts and prevent misuse, and to keep the service reliable and available.

The legal bases are performance of the contract with your organisation, the legal obligations your organisation is subject to, the legitimate interests of your organisation and of ourselves in providing and securing the service, and, where a processing activity requires it, your consent. Where processing may be necessary to protect someone's life or physical integrity, we also rely on vital interests.

6. What we do not do

Our iOS applications contain no third-party analytics, advertising, attribution or crash-reporting components. Our Android application uses Google Firebase for notification delivery, usage measurement and crash reporting; the Firebase components also declare access to the Android advertising identifier. We do not use that identifier for advertising and we build no advertising or marketing profiles from it.

7. Service providers

We use the following providers to operate our products. They process data on our instructions under written agreements and may not use it for their own purposes.

8. Disclosures to public authorities

Where your organisation is legally required to report certain records to a public authority, a product may transmit those records to that authority on your organisation's behalf. Your organisation decides whether and when this happens, and remains the controller for it.

We will otherwise disclose personal data to an authority only where we are legally compelled to do so.

9. International transfers

Server-side functions of our web management panels are configured to run in the European Union (Frankfurt). Our providers may otherwise process data in facilities inside and outside the European Economic Area. Where data leaves the EEA, transfers are covered by the providers' standard contractual clauses. The hosting regions applicable to your organisation's deployment are available on request.

10. How long data is kept

Records that serve as evidence are retained for as long as your organisation's licence is active and for the retention period your organisation is required or chooses to apply. They are not deleted when an individual account is deactivated, because that would destroy the record of who did what.

Account records are kept while your account exists. When your organisation deactivates or deletes your account, access ends immediately, including on any device already signed in.

Notification tokens are removed when they stop being valid. Security records are kept only as long as needed for security purposes.

11. Security

We protect data with encryption in transit, tenant isolation enforced at the database level so one organisation can never read another's records, storage of credentials and session tokens in the device's protected credential storage, additional validation of the connection between our applications and our servers, binding of accounts to a single device, and immediate termination of sessions when an account is deactivated. Permission and validation rules are enforced on the server, not only in the application.

No system is perfectly secure, but we treat the records our customers entrust to us as high-value data and design accordingly.

12. Your rights

Subject to applicable law, you have the right to request access to your personal data, correction of inaccurate data, erasure, restriction of or objection to processing, and data portability, and to lodge a complaint with a supervisory authority — in Türkiye, the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).

Because your organisation is the controller, please direct requests to them first; they can act on most of them directly in the management panel. If you contact us at privacy@forgina.com, we will forward your request to the relevant organisation and assist them in responding.

Erasure rights are limited where a record must be retained as evidence or to meet a legal obligation.

13. Children

Our products are workplace applications intended for adult personnel. They are not directed to children and we do not knowingly collect data from anyone under 18.

14. Changes to this policy

If we change this policy we will update the effective date above and, where the change is significant, notify the organisations that license our products. Continued use after a change indicates the updated policy applies.

15. Contact

Forgina
Email: privacy@forgina.com

← Back to forgina.com