1. Incorporation and precedence
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service between you, acting on behalf of the organisation that holds a Team subscription (the "Controller"), and Forkbench (the "Processor"). It applies from the date your organisation's Team subscription begins, automatically and without further signature, for as long as the Processor processes personal data on the Controller's behalf under the Terms. Capitalised terms not defined here have the meaning given to them in the Terms or the Privacy Policy. If your organisation needs a copy counter-signed by both parties, write to [email protected].
Where this DPA conflicts with the Terms on a question of personal-data processing, this DPA governs; on everything else, the Terms govern.
2. Definitions
"GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Controller", "Processor", "Data Subject" and "Personal Data Breach" have the meanings given in GDPR art. 4. "Standard Contractual Clauses" or "SCCs" means the controller-to-processor clauses adopted by the European Commission (and, for transfers from the UK, the UK International Data Transfer Addendum), as amended or replaced from time to time. "Sub-processor" means another processor engaged by the Processor to process Personal Data on the Controller's behalf.
3. Subject matter and duration
The Processor processes Personal Data on the Controller's behalf for the purpose of providing the Service described in the Terms to the Controller's organisation and its members. Processing lasts for the term of the Controller's Team subscription and continues only as long as needed to comply with Section 14 (Deletion and return) after it ends.
4. Nature and purpose of processing
The Processor processes Personal Data to: create and administer member accounts and organisation membership; synchronise Notebooks content and Thread/board material, which is encrypted on a member's own device under a key the Processor does not hold; relay Talk messages between the web and a member's paired Mac; let an agent use a Vault credential without disclosing its value; and, where the organisation has enabled it, enrol members' Macs into the organisation, apply the organisation's server-set policy to them, and record an organisation-wide access log of which credential or note name — never a value or a note's content — was used, by roughly whom, and when, so that an organisation admin can read and export it. Section 10 of the Terms and the security page (/security) describe the mechanism and its limits in full.
5. Categories of data subjects and categories of personal data
Data subjects: the individuals the Controller adds as members of its organisation (typically its employees or contractors), and, incidentally, any individual whose personal data a member chooses to include in a note, a Talk message, or a Vault entry — content the Processor cannot read (Section 10).
Categories of personal data processed on the Controller's instructions:
- Account and membership data — name, email address, sign-in method, role, and invitation/join timestamps.
- Device data — a device's name, platform, enrolment and release timestamps, and (for Talk) app version and online status.
- Access-log data — a resource's kind (note or credential) and name, the acting member, the device, and a timestamp. Never a secret's value or a note's body.
- Talk conversation content — the parsed messages, instructions and agent replies a member sends or receives while a conversation is live, which the Processor's servers can read in order to relay them (Section 8 of the Privacy Policy).
- Billing contact data — the name and email of whoever the Controller nominates to receive invoices, shared with the payment sub-processor.
- End-to-end encrypted content — Notebooks, Vault entries, and Thread/board material. This is Personal Data the Processor stores and transmits as ciphertext under keys held on members' own devices; the Processor cannot decrypt, read, or search it.
6. Processor obligations
The Processor shall:
- Process Personal Data only on the Controller's documented instructions — which, for this Service, means the Terms, this DPA, and the Controller's own configuration of the organisation's policy — including regarding international transfers, unless required to do otherwise by EU or member-state law, in which case the Processor will inform the Controller before processing, unless that law prohibits it on important grounds of public interest.
- Ensure that anyone authorised to process Personal Data is bound by an obligation of confidentiality (Section 7).
- Implement the security measures described in Section 10.
- Respect the conditions on engaging Sub-processors described in Section 8.
- Assist the Controller with Data Subject requests, as described in Section 12.
- Assist the Controller in meeting its obligations under GDPR art. 32-36, taking into account the nature of processing and the information available to the Processor, including this DPA and the security page.
- At the Controller's choice, delete or return Personal Data on termination, as described in Section 14.
- Make available to the Controller the information necessary to demonstrate compliance with this Section, and allow for and contribute to audits as described in Section 13.
- Inform the Controller promptly if, in the Processor's opinion, an instruction it receives infringes GDPR or another EU or member-state data-protection provision.
7. Controller obligations
The Controller shall: have a lawful basis for any Personal Data it submits, or instructs the Processor to process, on its behalf; comply with its own obligations as a controller under GDPR, including any transparency obligation to its members and any other data subject; ensure its instructions to the Processor are lawful; and remain responsible for the content its members choose to place in notes, Talk messages, or Vault entries, which the Processor cannot inspect and therefore cannot vet on the Controller's behalf.
8. Confidentiality
The Processor ensures that any person it authorises to process Personal Data — including its own personnel — is under a contractual or statutory obligation of confidentiality.
9. Sub-processors
The Controller gives the Processor general authorisation to engage the Sub-processors listed at /subprocessors, which the Processor keeps current. The Processor will: impose data-protection obligations on each Sub-processor that are no less protective than this DPA; remain fully liable to the Controller for a Sub-processor's acts and omissions; and give notice of an intended new Sub-processor by updating that page (and, on request, by email to the Controller's nominated contact) at least 14 days before the change takes effect, during which the Controller may object on reasonable data-protection grounds. If the parties cannot resolve an objection in good faith, either party may terminate the processing the new Sub-processor would have performed.
10. International transfers
Some Sub-processors process Personal Data outside the EEA and the UK, including in the United States; the location of each is stated at /subprocessors. Where the Processor transfers Personal Data outside the EEA or the UK, it relies on the Standard Contractual Clauses (or the UK Addendum) as the transfer safeguard, incorporated into this DPA by reference, and will provide a copy on request.
The Processor does not rely on the EU-US Data Privacy Framework for this purpose. The Framework is not, at the date of this DPA, a safeguard the Processor is willing to build a transfer story on: a June 2026 US Supreme Court ruling on the independence of the Federal Trade Commission has unsettled the institutional footing the Framework's adequacy finding rests on, and a new annulment action is being filed at the Court of Justice of the EU. The Processor will keep this Section current if that changes.
11. Security measures
The Processor implements the technical and organisational measures described on the security page (/security), including: notes, Vault credentials and shared-Thread content encrypted on a member's own device under keys the Processor does not hold; TLS-encrypted transport; hashed passwords and rate-limited authentication; least-privilege access to infrastructure; a credential broker that substitutes a bound secret into an outbound request rather than disclosing its value to an agent; and encrypted, access-controlled backups. The Processor holds no SOC 2, ISO 27001, PCI DSS or HIPAA certification and makes no representation that these measures are impenetrable — the security page states plainly where each of them stops.
12. Personal data breach notification
The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of a confirmed Personal Data Breach affecting Personal Data the Processor processes on the Controller's behalf, at the Controller's nominated contact or, absent one, the organisation owner's account email. The notice will describe, to the extent then known: the nature of the breach; the categories and approximate number of data subjects and records concerned; its likely consequences; and the measures taken or proposed to address it and mitigate its effects. The Processor will update the Controller as material new information becomes available and will reasonably cooperate with the Controller's own obligations under GDPR art. 33 and 34.
13. Assistance with data subject rights
Access, correction, deletion, and portability are self-service for an individual member, from their own account page (Section "Your rights" of the Privacy Policy), and the Processor directs a member who asks it directly to that page. Where the Processor receives a request from a data subject that concerns Personal Data it processes on the Controller's behalf and that self-service route does not cover, it will forward the request to the Controller promptly and will not respond to the data subject directly, other than to confirm it has done so, unless required by law.
14. Audit rights
The Processor will make this DPA, the security page and the sub-processor list available on request, and will respond to one reasonable written security questionnaire from the Controller every 12 months. On at least 30 days' written notice, and no more than once every 12 months — except following a confirmed Personal Data Breach affecting the Controller's data, or at the documented request of a supervisory authority — the Processor will permit the Controller, or an independent third-party auditor the parties agree on and who is bound by confidentiality, to audit the Processor's compliance with this DPA. An audit is conducted during ordinary business hours, must not disrupt the Service for other customers, is at the Controller's expense, and is subject to a scope and confidentiality terms agreed in advance.
15. Deletion and return of data on termination
Within 30 days after the Controller's Team subscription and any renewal ends, and at the Controller's choice made before that point:
- Return. The organisation owner may export the organisation-wide access log as a CSV file from the organisation's admin page, and each member may export their own account data — profile, devices, Thread and note metadata, and their sealed (still-encrypted) notes, Vault entries and Thread content — from their own account page. End-to-end encrypted content is returned exactly as the Processor holds it: sealed. The Processor never held the key, so it cannot supply a plaintext copy; a member recovers plaintext from a Mac they have enrolled, before the account or the organisation is deleted.
- Delete. Absent an export, or after one, Personal Data is deleted following the same schedule the Privacy Policy publishes: the account and its content are erased within 30 days of a deletion request, and an encrypted backup taken before that point still contains a copy until it expires, within 35 days. Billing and tax records survive for the period described in the Privacy Policy's retention table (currently 10 years), because accounting law requires it, and are not returned to or usable by the Controller for any other purpose.
16. Liability
Each party's liability arising out of this DPA is subject to the limitations and exclusions set out in Section 17 (Limitation of liability) of the Terms, except to the extent applicable law prohibits limiting liability for an infringement of GDPR.
17. Contact
Questions about this DPA, or a request under it? Email [email protected]. Report a suspected Personal Data Breach to [email protected].