Data storage & location
All data you share with ForgeWorth — including any content we build into your platform portal — is stored in Supabase's London data centre, which runs on Amazon Web Services (AWS) in the eu-west-2 region (London, UK).
Data does not leave the UK for storage purposes. Supabase routes all reads and writes to the configured UK region.
Three providers handle our infrastructure:
| Provider | Role | Location | Certification |
|---|---|---|---|
| Supabase | Database & file storage | 🇬🇧 London, UK | SOC 2 Type 2 |
| Vercel | Platform hosting | 🇬🇧 EU-West | SOC 2 Type 2 |
| Anthropic (AI) | Asset delivery assist | USA — SCC | SCCs; no training on data |
A full sub-processor list is available in our privacy policy and on request.
No. We use Row-Level Security (RLS) on every client data table in our database. RLS is enforced at the database engine level — it's not just application-level filtering. Each client's data is cryptographically isolated: a query from your portal can only return your rows, regardless of what credentials are used.
UK GDPR & compliance
Yes. ForgeWorth (Tino Mutasa t/a ForgeWorth) is registered as a data controller with the UK Information Commissioner's Office (ICO) under the Data Protection Act 2018.
ICO registration number available on request. You can verify any UK ICO registration at ico.org.uk.
Yes — for any engagement involving your business's personal data. We have a standard Article 28 UK GDPR DPA ready to countersign. It covers:
- Subject matter, nature, and purpose of processing
- Your rights as controller; our obligations as processor
- Sub-processor list with locations and compliance basis
- AI processing clause (patient data commitment)
- 72-hour breach notification
- 30-day deletion on termination
- Governing law: England and Wales
For USA-based sub-processors (Anthropic/Calendly), we rely on Standard Contractual Clauses (SCCs) as the Article 46 transfer mechanism under UK GDPR. Supabase's DPA incorporates the UK International Data Transfer Agreement (IDTA).
Primary storage remains in the UK (London, AWS eu-west-2). International transfers are limited to sub-processor relationships, not your data storage.
We respond to all data subject rights requests (access, rectification, erasure, restriction, portability, objection) within one calendar month of receipt, in line with UK GDPR Articles 15–22.
To submit a request: contact@theforgeworth.com with subject line "Data subject request".
AI use & healthcare clients
No — never, without your explicit written consent.
We use Claude (Anthropic) to help build your digital assets — your systems, templates, booking tools, and processes. The AI sees your business information: your services, workflows, pricing, and content. It does not see your patients' personal data.
No. Anthropic's API terms of service explicitly prohibit using API input data to train their models. Data submitted via the API (which is how ForgeWorth interacts with Claude) is not used for model training.
We do not use your data for any purpose other than completing your engagement.
Yes. We regularly work with private clinics, physiotherapy practices, and allied health providers. Our data handling is designed with regulated healthcare in mind:
- No patient data enters AI without written consent
- UK-only storage (London, AWS eu-west-2)
- DPA available for signature before any data is shared
- Data minimisation: we never ask for more than the engagement requires
- Deletion within 30 days of engagement end
We are not a healthcare software provider and do not handle clinical records. We build the business systems around your practice — booking, marketing, CRM, content — not the clinical record itself.
Security controls
Our breach response procedure:
- Supabase notifies ForgeWorth per their DPA obligations
- ForgeWorth assesses the breach within 24 hours
- Client notification within 72 hours of ForgeWorth becoming aware
- ICO notified where legally required (Article 33 UK GDPR — breaches likely to result in risk to individuals)
- Full breach report provided to affected clients within 14 days
We retain engagement data for 24 months after the engagement ends (for warranty and IP support purposes), then delete it. On your request, we can delete earlier.
On offboarding we will: export a full data pack for you, delete your records from our platform, and confirm deletion in writing within 30 days.
You always retain full ownership of all deliverables — these are transferred to you via IP Assignment Deed at handover.
We run a regular security review covering:
- Git history scanning for exposed credentials
- .gitignore enforcement for environment files
- Supabase RLS policy audit
- Dependency vulnerability checks
Our infrastructure providers (Supabase, Vercel) carry SOC 2 Type 2 certification which includes annual third-party security audits. Supabase's full security posture is at supabase.com/security.
Need something in writing?
We can turn around a DPA within 2 working days. Or if you have specific questions not answered here, drop us a line.
Contact us