Privacy Policy

Our privacy policy and how we use your data

Last updated: 2026-07-30

1. Introduction

This Privacy Policy explains how ForenSync (“we”, “us”) handles personal data when you use the ForenSync platform and websites (the “Service”). We are committed to protecting personal data and to processing it in line with applicable data protection law, including the EU General Data Protection Regulation (GDPR) where it applies.

2. Controller and processor roles

For the account and usage data described below, ForenSync acts as a data controller. For the case content that an organisation and its investigators submit while using the Service, ForenSync acts as a data processor on that organisation’s behalf, and the organisation is the controller. Where we act as a processor, our processing is governed by the agreement in place with the organisation.

3. Personal data we process

  • Account data: name, email address, organisation membership, role, and authentication data (including two-factor authentication factors).
  • Usage data: actions taken in the Service, audit-trail events, device and log information used to operate and secure the platform.
  • Policy acceptance: a record of the policies you accepted during account activation and when.
  • Case content: information an organisation chooses to upload for an investigation. This may include personal data of third parties; the organisation is responsible for the lawfulness of that content.

4. How we use personal data and our legal bases

We process personal data to:

  • provide, secure and support the Service (performance of a contract and our legitimate interests);
  • authenticate users and prevent unauthorised access (legitimate interests and legal obligations);
  • maintain audit trails and records of policy acceptance (legal obligations and legitimate interests); and
  • communicate operational and service messages.

Where we act as a processor of case content, we process it only on documented instructions from the controlling organisation.

5. Sharing and sub-processors

We share personal data with service providers who help us run the Service (for example hosting, database, email and payment providers), who process it on our behalf under appropriate contractual safeguards. We do not sell personal data. A current list of sub-processors is made available to customers.

6. International transfers

Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission’s standard contractual clauses or an adequacy decision.

7. Retention

We retain account and usage data for as long as an account is active and as needed to provide the Service, comply with legal obligations, resolve disputes and enforce agreements. Case content is retained according to the controlling organisation’s instructions.

8. Security

We use technical and organisational measures to protect personal data, including access controls, encryption in transit, row-level data isolation between organisations, optional two-factor authentication, and append-only audit logging. No system is completely secure, but we work to reduce risk and to respond to incidents promptly.

9. Your rights

Subject to applicable law, you may have the right to access, correct, or erase your personal data, to restrict or object to certain processing, and to data portability. The Service provides self-service tools for some of these rights, including account data export and account deletion. Because much case content is controlled by your organisation, some requests are best directed to your organisation administrator.

10. Cookies

We use essential cookies to operate the Service and optional cookies to improve it. You can manage your preferences through the cookie banner. See our Cookie Policy for details.

11. Children

The Service is intended for professional use by authorised investigators and is not directed to children. We do not knowingly create accounts for children.

12. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes we will update the “last updated” date and, where appropriate, ask you to review the revised Policy during activation or sign-in.

13. Contact

For privacy questions or to exercise your rights, contact your organisation administrator or ForenSync through the contact details on our website.