01Who we are
Forgeon Technologies is a governance, risk and compliance (GRC) consultancy. We advise organisations on GRC strategy, enterprise and cyber risk, audit and controls, privacy and third-party risk, and we implement and support GRC platforms including Archer IRM.
Forgeon Technologies is a trade name of MiraiNext. For the purposes of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025, we are the Data Fiduciary for personal data collected through this website, and you are the Data Principal.
02What this policy covers
This policy explains what personal data we collect through forgeontech.com, why we collect it, who else handles it, and the rights you have over it.
It does not cover personal data we process on behalf of a client during a consulting engagement. Where a client engages us and we handle personal data belonging to that client’s employees, customers or suppliers, the client is the Data Fiduciary and we act as a Data Processor under the terms of the agreement signed with that client. That agreement, not this policy, governs how such data is handled.
03The personal data we collect
We have deliberately kept this website minimal. There is no account to create, no newsletter, no advertising and no tracking. In practice we collect personal data in exactly one place, plus what any web server necessarily sees.
Data you give us through the enquiry form
| Field | Required | Why we need it |
|---|---|---|
| Name | Yes | To know who we are replying to and address you properly. |
| Email address | Yes | To send you a reply. This is our primary means of responding. |
| Phone number | No | Only if you would prefer we call. Leave it blank and we will not. |
| Your message | Yes | To understand what you need and give you a useful first answer. |
You choose what goes into the message field. Please do not include sensitive personal data — financial account details, government identifiers, health information, passwords or credentials — in an enquiry. If a matter requires that kind of detail, we will agree a secure channel with you first.
If your browser has no mail application configured and the form falls back to opening your own email client, the message is composed on your device and sent from your own mailbox. In that case we receive it as an ordinary email and never through this website at all.
Data collected automatically by our infrastructure
Like any website, ours is served by a hosting provider that necessarily sees the connection in order to deliver the page. Our host, Cloudflare, processes your IP address, the time of the request, the page requested, and your browser's user-agent string. This is used to serve the site, apply security protections and guard against abuse. We do not use it to build any profile of you, and we do not combine it with anything else.
Fonts on this site are loaded from Google Fonts. When your browser fetches them, Google receives your IP address and the request. We have no control over that connection, and Google's own privacy terms apply to it. See section 6.
What we do not collect
- We do not run analytics of any kind — no Google Analytics, no page-view counters, no heatmaps, no session recording.
- We do not use advertising or remarketing pixels.
- We do not buy, rent or scrape contact data, and we do not send unsolicited marketing.
- We do not ask for, and have no use for, financial or identity documents through this website.
04Why we use your data, and on what basis
We use the personal data from the enquiry form for one purpose only: to read your enquiry and respond to it, including any follow-up correspondence about a possible engagement.
Under the DPDP Act our basis is your consent, given when you choose to fill in and submit the form. Submitting the form is entirely voluntary — you can email us directly instead, and you can read every word of this site without giving us anything.
If we go on to work together, further processing will be governed by the engagement agreement we sign with you rather than by this consent.
We will not use your enquiry to send you marketing you did not ask for, and we will not pass your details to anyone for their own marketing.
06Who else processes your data
We keep this list short on purpose. These are the only third parties involved in running this website:
| Provider | What it does | What it sees |
|---|---|---|
| Cloudflare | Hosts and delivers the website | Your IP address, request time, page requested, user-agent |
| Web3Forms | Delivers the enquiry form to our inbox | The contents of the form you submit |
| Google Fonts | Serves the typefaces the page is set in | Your IP address and the font request |
| Our email provider | Receives and stores our business mail | Your enquiry, as an email, and our correspondence with you |
Some of these providers operate infrastructure outside India, so your data may be processed on servers in other countries. The DPDP Act permits transfer of personal data outside India except to territories the Central Government restricts by notification; we will comply with any such restriction that applies to us.
Beyond these, we share personal data only where we are legally obliged to — for example in response to a valid order from a court, regulator or law enforcement agency. We do not sell personal data. We have never done so and have no intention of doing so.
07Where your data is stored
Enquiries reach us as email and are stored in our business mailbox. Website delivery logs sit with our host. We do not maintain a separate customer database, CRM or mailing list built from website enquiries.
08How long we keep it
- Enquiries that do not lead to an engagement — kept for up to 24 months from our last exchange, so that we have context if you come back to us, then deleted.
- Enquiries that lead to an engagement — retained for the life of the engagement and afterwards for as long as we are required to keep business records under applicable Indian tax, GST and company law.
- Infrastructure logs — retained by our host under their own retention schedule, typically a short rolling window measured in days.
You can ask us to erase your enquiry sooner. See section 10.
09Your rights under the DPDP Act
As a Data Principal you have the following rights over personal data we hold about you:
- Right to access — to ask for a summary of the personal data we hold about you, how we are processing it, and who we have shared it with.
- Right to correction and erasure — to have inaccurate or misleading data corrected, incomplete data completed, and data erased where we no longer need it for the purpose you gave it for.
- Right to withdraw consent — to withdraw your consent at any time, as easily as you gave it. Withdrawal does not make our earlier processing unlawful, but we will stop processing and erase the data unless a law requires us to keep it.
- Right to grievance redressal — to raise a complaint with us about how we have handled your data, and to have it answered.
- Right to nominate — to nominate another individual to exercise these rights on your behalf if you die or become incapacitated.
Exercising any of these rights is free. We will not treat you differently for having asked.
The DPDP Act also asks Data Principals not to make false or frivolous requests, and not to impersonate someone else when making one.
10How to exercise your rights, and how to complain
Write to us at privacy@forgeontech.com with the subject line “DPDP request”, telling us what you would like us to do. Please write from the email address you originally contacted us from, so that we can be confident the request is really yours. If you cannot, we may ask you a question or two to verify your identity — we ask for no more than we need.
We aim to answer within 7 working days. Where a request is complex we will tell you so and keep you updated, and in every case we will resolve it within the 90-day period set by the Digital Personal Data Protection Rules, 2025.
If you are unhappy with how we have handled a request, reply and say so — it will be escalated internally and reviewed afresh.
11Complaining to the Data Protection Board
If you have raised a grievance with us and remain dissatisfied, or we have not responded within the period above, you have the right to complain to the Data Protection Board of India, established under the DPDP Act. Details of how to approach the Board are published by the Ministry of Electronics and Information Technology.
We would much rather hear from you first and put it right ourselves, but that route is yours whether or not you use it.
12How we protect your data
The measures below are proportionate to what we actually hold, which is correspondence rather than bulk personal data:
- The whole site is served over HTTPS, with HTTP Strict Transport Security enforced, so traffic between you and us is encrypted.
- A Content Security Policy and related security headers restrict what the page is allowed to load and connect to.
- Access to our mailbox is limited to the people who need it and protected by multi-factor authentication.
- We minimise by default: the form asks for four fields, and only three are required.
No system is perfectly secure, and we will not claim otherwise. If a personal data breach affecting you occurs, we will notify you and the Data Protection Board as required by the DPDP Act and the 2025 Rules.
13Children
This website is aimed at businesses and the professionals who work in them. It is not directed at children, and we do not knowingly collect personal data of anyone under 18. The DPDP Act requires verifiable parental consent before processing a child's personal data, and we do not process children's data at all. If you believe a child has sent us personal data, tell us and we will delete it.
14Changes to this policy
If we change what we collect or how we use it, we will update this page and change the “last updated” date at the top. Where a change materially affects your rights, we will make that clear rather than quietly editing the text. The version published here is always the one that applies.
15Contact us
Questions about this policy, or about anything we hold on you. Data protection matters reach us fastest at the first address:
- Privacy and data protection — privacy@forgeontech.com
- Anything else — sales@forgeontech.com
- Entity — MiraiNext, trading as Forgeon Technologies
See also our Terms of Service.