Legal
Privacy Policy
Effective 2026-05-21 · Last updated 2026-05-21
What we collect, why, where it lives, and the rights you have over it.
1. Who's the data controller
Forge Workflow Holdings Limited (England), registered company 17283129, address 172 Stafford Street, Wolverhampton, England, WV1 1NA. Privacy contact: privacy@clientnest365.com.
2. What we collect
2.1 Account data
- Your name, email, and password (hashed) when you sign up.
- Your billing details (handled by our PCI-compliant payment processor; we never see your card number).
- Optional: company name, VAT ID, phone number.
2.2 Workspace content
- The files, messages, invoices, and approval objects you create in the portal.
- Metadata about your activity in the workspace (audit log: who did what, when).
2.3 Technical data
- IP address, browser, and device for security and abuse prevention.
- Server logs (kept 14 days) for incident response.
2.4 What we don't collect
- We don't run an analytics tracker on the site by default.
- We don't fingerprint browsers.
- We don't use your content to train AI models.
3. Why we collect it (legal bases under GDPR)
- Contract (Art. 6(1)(b)) for everything required to operate your account and deliver the service.
- Legitimate interest (Art. 6(1)(f)) for security logging and fraud prevention.
- Consent (Art. 6(1)(a)) for any optional analytics or marketing, where applicable. At present we don't run either.
4. Where your data lives
Database and authenticated session data are hosted in the EU. Files are stored in the EU. Transactional email is delivered by a provider that may process data in the US (see sections 5 and 6). Payment processing is handled by a PCI-compliant payment processor.
5. Sub-processors (third parties we share data with to operate the service)
We share personal data with the following categories of recipient, and only as far as each one needs it to run the service:
- Database and application hosting: account data, workspace content, and authenticated sessions (EU).
- File storage: files uploaded to your workspace (EU).
- Transactional email delivery: account, invite, and notification emails. This provider may process data in the US, with the safeguards described in section 6.
- Payment processing: PCI-compliant card processing. Card numbers never touch our systems.
- AI inference: runs the in-portal assistant. Content passed to the model isn't used to train future models.
The current list of named sub-processors is available on request from privacy@clientnest365.com and is provided to every customer under our Data Processing Agreement. We update it whenever we add or change a sub-processor. Account owners are emailed at least 30 days before a new sub-processor goes live.
6. International transfers
Where data leaves the EU (e.g. when the payment processor or the email delivery provider processes your data in the US), we rely on Standard Contractual Clauses (SCCs), together with the UK International Data Transfer Addendum for data covered by UK GDPR, and Data Processing Agreements with each sub-processor.
7. Your rights
You can ask us to:
- Show you what data we hold about you.
- Correct anything that's wrong.
- Delete your workspace and the personal data in it (right to erasure).
- Export your data in a portable format.
- Object to or restrict processing in certain circumstances.
Most of these you can do from your workspace settings. For anything else, email privacy@clientnest365.com. We reply within 30 days.
8. CCPA notice (California residents)
We don't sell personal information. You have the same data-access and deletion rights described in section 7 under the CCPA. Email privacy@clientnest365.com for a CCPA request.
9. Retention
- Active workspace data: kept while your account is open.
- Closed workspaces: permanently deleted 30 days after closure, except where retention is required by law.
- Server logs: 14 days.
- Billing records: 7 years (tax / accounting requirements).
10. Security
Files are stored privately behind short-lived signed download URLs. Each workspace's data is isolated from every other workspace. Connections are TLS-encrypted in transit. Files are encrypted at rest.
11. Children
ClientNest365 isn't intended for anyone under 18.
12. Changes
If we update this policy in a way that materially affects you, we'll email account holders before it takes effect.
13. Contact
Privacy questions: privacy@clientnest365.com. Postal: 172 Stafford Street, Wolverhampton, England, WV1 1NA.
Questions about this policy? Email privacy@clientnest365.com. This policy is published in plain English by Forge Workflow Holdings Limited.