Privacy Policy

Last updated: 2026-04-10

1. Data Controller

IndustryForge is operated by Kumiko GmbH. References to "we", "us", or "IndustryForge" in this policy refer to that entity as the data controller responsible for your personal data.

For data protection enquiries, contact us via the Contact page.

2. What Data We Collect

We collect and process the following categories of personal data:

  • Account details: your name and email address, collected at registration and used to identify your account.
  • Uploaded CAD files and technical documents: files you submit for manufacturing coordination, including metadata such as file name, size, and upload timestamp.
  • Quote requests: manufacturing parameters and requirements you specify when requesting quotes.
  • Audit trail: timestamped records of actions taken on the platform (uploads, status changes, approvals, and authentication events such as sign-ins and refused sign-in attempts) required for manufacturing traceability.
  • Authentication data: hashed passwords, two-factor authentication secrets (if enrolled), and session tokens. We never store plaintext passwords.
  • Contact messages: messages you submit via the contact form, including name, email, and message content.

3. Why We Process Your Data

We process your personal data for the following purposes:

  • Providing the IndustryForge coordination platform and managing your account.
  • Processing manufacturing job requests and generating quotes.
  • Maintaining an audit trail for EU-sovereign defense manufacturing traceability requirements.
  • Sending transactional emails (account verification, password reset, order notifications).
  • Complying with applicable legal obligations.

4. Legal Basis

Our processing of your personal data is based on the following legal grounds under GDPR:

  • Article 6(1)(b) -- Contract: processing necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract.
  • Article 6(1)(c) -- Legal obligation: processing necessary for compliance with a legal obligation to which we are subject, including manufacturing audit and traceability requirements.
  • Article 6(1)(f) -- Legitimate interests: processing necessary for the purpose of our legitimate interests in maintaining platform security, preventing fraud, and defending against legal claims.

5. Data Retention

  • Account data is retained for as long as your account remains active. Upon account deletion, personal data is removed within 30 days, subject to the exceptions below. Accounts that are not verified within 30 days after the verification link expires are deleted automatically.
  • Uploaded CAD files and technical documents are retained for as long as the associated job and account exist and are removed upon account deletion. Technical data subject to statutory export-control recordkeeping obligations may be retained beyond account deletion to the extent required by law.
  • Audit logs serve defense-manufacturing traceability and are kept in an append-only record: entries are not deleted. When your account is erased, references to your account are removed from these entries and a minimal deletion record (an opaque account identifier and timestamp, kept as proof of erasure and for backup-restore reconciliation) is written; the entries themselves are retained.
  • Authentication records: sign-ins, sign-outs, password resets you complete and two-factor changes are recorded in the same append-only audit trail, as timestamped events with an outcome code, and are part of the data you can export from your profile page. Records of refused sign-in attempts against your account and of requests for a reset link sent to your address are kept the same way but are not attributed to you (anyone can type your address), so they are held for security purposes and are available on request rather than in the self-service export. These records never contain your password, a reset token or a one-time code. Platform administrators can see this history for your account; it is retained like every other audit entry.
  • Operational event records: the platform keeps an internal append-only log of operational events (for example, a quote being issued or a job being placed) for traceability and service improvement. These records contain business values, not personal profiles; references to your account are removed upon erasure, while the operational record itself is retained.
  • Backups: encrypted database backups are kept on a rolling basis and overwritten in rotation. Data deleted from the live system persists in backups until the rotation cycle completes. If a backup is ever restored after a system failure, we re-apply erasure requests fulfilled since that backup was taken.
  • Contact messages are forwarded to our support mailbox and are not stored in the platform database; retention is governed by our mailbox practices.

6. Your Rights

Under GDPR you have the following rights with respect to your personal data:

  • Right of access: you may request a copy of the personal data we hold about you.
  • Right to rectification: you may correct inaccurate data via your profile page.
  • Right to erasure: you may request deletion of your account and associated data via your profile page. Records subject to statutory retention obligations (the append-only audit trail and operational event records with personal references removed, and technical data under export-control recordkeeping) are exempt to that extent.
  • Right to data portability: you may export your data in machine-readable format via /profile/export.
  • Right to object: you may object to processing based on legitimate interests. Contact us via the contact page.

7. Third Parties

We share your data with the following third-party processors, each under a data-processing agreement:

  • Anthropic (Claude API): used for AI-assisted generation of quality-assurance documentation (AS9102 first-article inspection forms), triggered by our staff. Part and inspection data entered for that purpose is transmitted to Anthropic's API. Under Anthropic's commercial terms, API data is not used to train Anthropic models unless a customer explicitly opts in; we have not opted in. AI-generated forms are drafts that go through a human review and approval step in our workflow before release.
  • SMTP provider: used for transactional email delivery (account verification, password reset, order notifications). Only your email address and the content of transactional messages are shared.

We do not sell your personal data to any third party. We do not use tracking, advertising, or analytics third parties.

8. Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Passwords are stored using bcrypt with a cost factor designed to resist brute-force attacks.
  • Session cookies are issued with HttpOnly, Secure, and SameSite=Strict attributes.
  • A Content Security Policy (CSP) is applied to all responses to mitigate cross-site scripting.
  • All administrative accounts are required to enrol in two-factor authentication.
  • All significant actions are recorded in an immutable audit log.

9. Contact

For any data protection enquiry or to exercise your rights, please use our contact page. You also have the right to lodge a complaint with your national data protection supervisory authority.

Last updated: 2026-04-10