Data Processing Addendum
Effective Date: September 5, 2026 · Last Updated: September 5, 2026
For organizations, not individual accounts.
This Data Processing Addendum ("DPA") applies only if your organization uses the Service under an Organization Plan (defined in our Terms of Service, Section 4). It describes how Forzara processes your program's participant data on your organization's behalf, and it's incorporated into the Terms of Service by reference, the same way our Privacy Policy is, so there's no separate document to sign. If you're an individual using Forzara on your own, this page doesn't apply to you; see our Privacy Policy instead.
1. Roles of the Parties
For personal information your organization submits to, or has its authorized staff enter into, the Service about a participant your organization enrolls, your organization is the business (or, if applicable under your jurisdiction's law, the controller), and Forzara acts as a service provider or processor, processing that data only to provide the Service, only under your organization's instructions as given through your organization's use of the Service and this DPA, and not for Forzara's own independent purpose.
2. Subject Matter, Duration, and Nature of Processing
Processing under this DPA covers the participant data described in our Privacy Policy (Sections 2 and 5) and, if applicable to your organization's use of the Service, our Health Data Privacy Policy: milestone status and any short note a participant attaches, coach visibility into that status, AI-assisted document generation (processed in memory only and never written to persistent storage, see Section 1 of our Security page), and, if your organization uses them, CSBG/grant-reporting worksheet fields. Processing lasts for the term of your organization's Organization Plan agreement, plus any period afterward needed to comply with law, resolve a dispute, or satisfy a recordkeeping requirement described in our Privacy Policy or Health Data Privacy Policy.
3. Categories of Data Subjects and Personal Information
Data subjects are the participants your organization enrolls, and your organization's own authorized staff. Categories of personal information are exactly those already disclosed in our Privacy Policy's Section 2 (and, where applicable, our Health Data Privacy Policy's Section 1); this DPA doesn't expand what's collected, it describes how what's already disclosed is handled on your organization's behalf.
4. Subprocessors
Forzara uses a small number of subprocessors to provide the Service, the same ones already listed in our Privacy Policy's Section 10:
- Google Gemini (paid API tier), for real time AI-assisted document generation and form guidance. Inputs and outputs are never stored by Forzara, and Google's paid API terms exclude this data from training or improving their models.
- Our payment processor, for subscription billing. We never receive or store full payment card numbers.
- Our email delivery and hosting infrastructure providers.
- Our SMS provider, only if your organization's staff or its participants choose to enable two factor login.
If we add a new subprocessor that materially changes how your organization's data is processed, we'll update this page and its "Last Updated" date, the same notice process described in Section 9 below. Contact us using Section 10 if your organization has questions about a specific subprocessor.
5. Security Measures
Forzara applies the technical and organizational measures described in full on our Security page, summarized here rather than duplicated so the two pages can't drift out of sync: encryption in transit (HTTPS/HSTS) and at rest for the specific fields that call for it, bcrypt password hashing checked against known-breached passwords, a strict nonced Content-Security-Policy, rate limiting against automated and abusive traffic, optional SMS-based two factor login, and a minimization-first design where document content is never written to persistent storage in the first place. Our TLS configuration and security headers are independently scanned and rated (Qualys SSL Labs, Mozilla HTTP Observatory); current results and re-scan links are on the Security page.
6. Breach Notification
If Forzara confirms a breach involving your organization's participant data, we will notify your organization without unreasonable delay, consistent with the notification standard set by applicable state breach-notification laws, and provide the information reasonably available to us about the scope of the incident so your organization can meet its own notification obligations to participants or regulators. We don't commit to a fixed number of hours here because no such fixed number exists in how we actually operate today; "without unreasonable delay" is the real standard, not a marketing number.
7. Assistance with Data Subject Requests
If a participant your organization enrolled submits a verified request to access, correct, or delete their personal information, Forzara will assist your organization in responding to the extent required by applicable law and to the extent the request relates to data we process on your organization's behalf. Participants can also reach us directly through Support or Delete Account for the same rights described in our Privacy Policy.
8. Return or Deletion of Data on Termination
Document content and detailed tool inputs are never stored in the first place, so there's nothing to return or delete there by design. For the account and milestone data that is stored, our standard retention and deletion practices, described in our Privacy Policy's Section 6, apply when your organization's Organization Plan ends, subject to the CSBG/grant-reporting recordkeeping exception already described in our Health Data Privacy Policy's Section 7, where applicable.
9. Changes to This Addendum
If we change what's described here, we'll update this page and its "Last Updated" date, and for a material change, provide notice the same way described in our Terms of Service's Section 15.
10. Liability and Contact
Liability arising out of or related to this DPA is subject to the same Organization Plan limitation of liability described in our Terms of Service, Section 12; this DPA does not create a separate or additional liability cap. Questions about this DPA: