Privacy Policy
Draft pending legal review. Placeholders in [brackets] will be completed before this document takes effect.
Last updated 30 September 2026
This notice describes what Beesworx Groupe (Pty) Ltd (Reg. No. 2024/800456/07) ("Beesworx", "we") collects about you as a user of the Forge platform itself: account holders, org members, people who request beta access, and visitors to the website, dashboard and signup pages. It does not cover personal information that tenants process about their own end users inside applications they deploy on the platform. That processing is governed by the tenant's own privacy notice, and Beesworx's role there is described in the Data Processing Agreement.
Beesworx is the responsible party (POPIA) for the personal information described in this notice.
1. What we collect
| Category | Examples | Source |
|---|---|---|
| Beta access requests | E-mail address, first and last name, company, and what you want to run on Forge | You, through the beta request form (hosted on Buzzz) |
| Account information | Name, e-mail address, organisation membership and role, org invite records (invitee e-mail, inviter, role) | You, at signup or invite |
| Identity data | Identity record (credentials hash, verification status, MFA enrolment state), session records (including IP address and user agent) | Our self-hosted identity service (Ory Kratos) |
| Authentication events | Login and logout, password reset, MFA enrolment, session tokens | Identity service and Forge session handling |
| Terms and policy acceptance | Which version of the Terms, AUP and Privacy Policy you accepted, when, and your IP address and browser user agent at the time (only where acceptance recording is turned on) | You, at signup |
| Audit logs | Action taken, acting identity, target resource, timestamp, and action details, for administrative and lifecycle actions (not every action is currently audited) | Administrative and lifecycle actions through the API, CLI, MCP server and dashboard |
| Usage metering | CPU time, memory, network bytes, disk usage, build time, and LLM gateway request counts, token counts and cost, per org | Container runtime sampling; the LLM gateway |
| Request logs | HTTP method, path (for API, MCP and gateway routes), status, size, latency, and a request ID | Every request through the API |
| Application logs | Your deployed application's stdout and stderr, and platform component logs | Container log collection (only where the operator runs the monitoring stack) |
| Billing information | Your e-mail, organisation name and ID, and plan data (and, where usage billing applies, usage data) sent to our billing provider (RevEx, Beesworx's own billing product); invoices; a flag showing whether a payment method is on file. Card and debit-order collection runs through RevEx's hosted checkout and payment rail (PayFast), which holds your card or bank details directly; Forge never receives them | Billing integration |
| Support communications | Content of support tickets and e-mails you send us | You |
| Dashboard AI assistant | Messages you send the in-dashboard chat assistant, and the results of the actions it takes on your behalf (which can include rows from your own databases, environment settings and logs) | You, via the chat panel (only where the assistant is enabled) |
| Cookies and local storage | Session state, active-org selection; a captcha widget's token and cookies where signup captcha is enabled | Your browser |
We do not intentionally collect special personal information (POPIA section 26 data, e.g. health, biometric, or religious or political information) about platform users. MFA enrolment status is an account-security flag, not special personal information, and is collected as part of authentication. We do not use analytics or advertising trackers on the website or dashboard.
2. Why we collect it (purpose and lawful basis)
- Providing the Service: authenticating you, enforcing your org's permissions, billing your org, and operating the infrastructure you provision. (Contract performance.)
- AI assistant and build helpers: answering what you ask the dashboard assistant, generating a Dockerfile for a repository deployed without one, and diagnosing a failed deploy. Your prompts and the results of the actions the assistant takes go to OpenRouter (United States) and the model provider it routes to, a cross-border transfer (section 4) [ATTORNEY TO CONFIRM THE s72 BASIS]. (Contract performance; you choose to use these features.)
- Beta access: contacting you about your request and onboarding your team. (Your request; legitimate interest.)
- Security and abuse prevention: audit logs, request logs and, where enabled, mining detection exist to detect and respond to compromised accounts, abuse, and attacks against the platform or other tenants. (Legitimate interest and legal obligation.)
- Support: responding to tickets you raise.
- Legal compliance: retaining records required by law (e.g. financial records, security incident records).
3. Retention
| Data | Retention |
|---|---|
| Beta access requests | [BETA REQUEST RETENTION PERIOD, OWNER TO CONFIRM] |
| Account and identity data | For the life of the account. There is no self-service account-deletion flow today; deleting your organisation does not delete your underlying login identity. Contact forge@beesworx.co.za to request deletion. |
| Terms and policy acceptance record | Tied to your organisation and deleted when the organisation is deleted. [ATTORNEY TO ADVISE: this can remove the record that would evidence a dispute.] |
| Audit logs | Not currently pruned. Kept after the organisation is deleted, with personal details scrubbed (see the Data Processing Agreement). [AUDIT LOG RETENTION PERIOD, OWNER TO SET] |
| LLM usage and usage-metering records | Kept for the life of the organisation and deleted with it. [METERING RETENTION PERIOD, OWNER TO SET] |
| Request logs and application logs | Where the operator runs the monitoring stack, held for 14 days. Without it, held only as long as the underlying container's local log file exists (no fixed period). |
| Database and app backups (your data, not this notice's subject; noted for completeness) | Where scheduled backups are enabled, scheduled backups are kept for 7 days, including any off-host copy. Manual backups are kept until you delete them. Deleting a backup, or your organisation, deletes the off-host copy too. |
| Support communications | [SUPPORT RETENTION PERIOD] |
4. Where your information is processed and cross-border transfers
Beesworx's own infrastructure for Forge is hosted at Virtarix, in a data centre in South Africa. Several processors we use to operate the platform are located outside South Africa. See the sub-operator list for the full list and the POPIA section 72 basis for each transfer, including: RevEx, our billing product (hosted in Germany); Resend (platform e-mail, United States); Buzzz (hosted in Germany), with Amazon SES, for tenant application e-mail and for the beta request form; OpenRouter (United States) and the provider it routes to for the AI model behind the dashboard assistant and build helpers (on forgeserver.app these requests pass through Beesworx's own LLM gateway, hosted in Germany, which records the model, token counts and cost but not the content); LLM providers registered on the platform (reached when your own application calls the LLM gateway, or when the RAG feature processes documents you upload to it; the LLM gateway is not enabled on forgeserver.app); GitHub or another git host (only if you connect a repository); Google Fonts (loaded by every visitor to the website, dashboard and signup pages); and Cloudflare Turnstile or hCaptcha (only if signup captcha is enabled; receives your IP address as part of verifying you are not a bot).
Every hostname on the platform, including your own custom domains, is submitted to a public certificate authority for a TLS certificate and becomes visible in public Certificate Transparency logs. This is standard practice for any HTTPS site and discloses only the hostname, not its content or your personal information.
5. Who we share it with
- Sub-operators listed in the sub-operator list, strictly to operate the Service.
- Law enforcement or regulators, where legally compelled.
- We do not sell personal information.
6. Your rights
Under POPIA, you may request access to, correction of, or deletion of your personal information, and may object to certain processing. Contact forge@beesworx.co.za to exercise these rights; the PAIA Manual explains how to request records. You may also lodge a complaint with the Information Regulator (South Africa).
7. Security
Personal information is protected by the measures described in the Security Statement and the Data Processing Agreement: encryption of credentials, secrets and backup files, org-scoped access control, a network egress boundary, and a sandboxed container runtime for tenant workloads. Platform administrators can technically access account and tenant data directly (e.g. to provide support); this is restricted by policy, not by a technical barrier on every such path (see the Data Processing Agreement for an honest statement of that limitation). No system is perfectly secure; see the Security Statement for how to report a concern.
A few other third-party addresses are contacted automatically by platform infrastructure but do not receive your personal information: container image registries (Docker Hub, ghcr.io, quay.io) when pulling images, a public IP lookup service for the host's own address (dynamic DNS, where used), and the k3s installer when provisioning a managed Kubernetes cluster you request.
8. Contact
E-mail forge@beesworx.co.za. We have not yet designated an Information Officer; until we do, requests to this address are handled by the head of Beesworx as the law provides. Our postal address and full contact details are in the PAIA Manual.