GDPR Compliance

Your data protection rights matter to us. Learn how InspectForge complies with the General Data Protection Regulation.

Our Commitment to Data Protection

INSPECT FORGE LLC is committed to protecting your personal data and respecting your privacy rights. As a company serving customers in the European Union and worldwide, we comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

This page explains your rights under GDPR and how we protect your personal information.

Last Updated: December 7, 2025

Your Data Protection Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this information in a structured, commonly used, and machine-readable format.

Right to Rectification

You have the right to request correction of any inaccurate or incomplete personal data we hold about you. You can update most of your information directly in your account settings.

Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data in certain circumstances, including:

  • • The data is no longer necessary for the purpose it was collected
  • • You withdraw consent and there is no other legal basis for processing
  • • You object to processing and there are no overriding legitimate grounds
  • • The data has been unlawfully processed

Right to Restrict Processing

You have the right to request restriction of processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to Object

You have the right to object to processing of your personal data in certain circumstances, including:

  • • Processing based on legitimate interests
  • • Direct marketing (including profiling)
  • • Processing for scientific or historical research purposes

Right to Withdraw Consent

Where we process your personal data based on consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you live, work, or where an alleged infringement of data protection law occurred.

How We Protect Your Data

Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption: All data is encrypted in transit (TLS/SSL) and at rest (AES-256)
  • Access Controls: Role-based access control with multi-factor authentication
  • Regular Audits: Security assessments and penetration testing
  • Data Minimization: We only collect and retain data necessary for our services
  • Employee Training: Regular privacy and security training for all staff
  • Incident Response: Documented procedures for data breach notification

Legal Basis for Processing

We process your personal data only when we have a legal basis to do so:

Contract Performance

Processing is necessary to provide our inspection management services to you under our Terms of Service.

Consent

You have given clear consent for us to process your personal data for specific purposes (e.g., marketing communications, cookies).

Legitimate Interests

Processing is necessary for our legitimate interests (e.g., fraud prevention, service improvement) where not overridden by your data protection rights.

Legal Obligation

Processing is necessary to comply with our legal obligations (e.g., tax reporting, law enforcement requests).

Data We Collect

Account Information

  • • Name, email address, phone number
  • • Company name and business details
  • • Billing and payment information
  • • Account credentials (encrypted)

Inspection Data

  • • Property addresses and inspection details
  • • Client information (when provided by you)
  • • Inspection reports, photos, and notes
  • • Digital signatures

Usage Information

  • • Log data and device information
  • • IP address and browser type
  • • Pages viewed and features used
  • • Cookies and similar technologies

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • •Active Accounts: Data is retained while your account is active and for 30 days after cancellation
  • •Inspection Reports: Retained for 7 years to comply with professional record-keeping requirements
  • •Financial Records: Retained for 7 years to comply with tax and accounting regulations
  • •Marketing Data: Retained until you unsubscribe or request deletion
  • •Log Data: Retained for 90 days for security and troubleshooting purposes

International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:

  • • We use cloud providers with GDPR-compliant data processing agreements
  • • Data is stored in secure data centers with appropriate certifications
  • • We implement Standard Contractual Clauses (SCCs) where applicable
  • • All transfers comply with GDPR Chapter V requirements

Third-Party Data Processors

We work with trusted third-party service providers who process data on our behalf. All processors are bound by Data Processing Agreements (DPAs) and are required to comply with GDPR:

Cloud Infrastructure: Microsoft Azure (data hosting and storage)
Payment Processing: Stripe (payment and billing)
Email Services: Resend (transactional emails)
Analytics: Google Analytics (website usage, anonymized)
AI Processing: OpenAI, L.L.C. (photo analysis, in-app AI assistance, audio transcription, template and document generation)
AI Processing: Anthropic PBC (AI-assisted report writing and narrative generation)

How AI Processing Works

InspectForge's AI features — collectively branded MI6 — are built on our own inspection logic, prompts and workflows, running on commercial AI models licensed from the providers listed above. When you use an AI feature, the relevant content (for example an inspection photo, an item comment, or an audio recording you upload) is transmitted to that provider solely to generate the response returned to you.

Not used for model training: Neither provider uses data submitted through their commercial APIs to train or improve their models. This is a contractual commitment in their enterprise terms, not an account setting.
Limited retention: Providers may retain submitted content for a limited period for safety and abuse monitoring, in accordance with their published terms, after which it is deleted.
Organization isolation: AI features operate only on your own organization's data. Content belonging to one organization is never used as context for another.
Human review: AI output is a draft. Inspectors review and approve AI-generated content before it is delivered to a client. No automated decision producing legal or similarly significant effects is made about you.

Both AI providers are established in the United States. Transfers to them are covered by the safeguards described in the International Data Transfers section above. If you would prefer that your organization's account not use AI processing, contact us at [email protected] and we can discuss the options available to you.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us:

Data Protection Officer: [email protected]

Response Time

We will respond to your request within 30 days of receipt. In complex cases, we may extend this by an additional 60 days and will inform you of the extension.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • • Notify the relevant supervisory authority within 72 hours of becoming aware
  • • Notify affected individuals without undue delay if there is a high risk
  • • Provide information about the nature of the breach and remedial actions
  • • Document all breaches and our response actions

Children's Privacy

INSPECT FORGE LLC is not intended for use by individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16 without parental consent, we will take steps to delete that information.

Updates to This Page

We may update this GDPR compliance page from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by email or through our service. The "Last Updated" date at the top of this page indicates when it was last revised.

Questions About Your Data?

Our privacy team is here to help. Contact us with any questions about your data protection rights.