Legal & Regulatory Compliance
Chronological compliance schedule detailing data retention, handling lifecycle, client rights, and security audit protocols governing all BuildLogicForge engagements.
Privacy Policy
1.1 Data Controller Identification
BuildLogicForge, registered at 108 Boulevard de Clichy, 75018 Paris, France, acts as the data controller for all personal information collected through our digital platforms, consultation consoles, and client engagement workflows. All data processing activities comply with Regulation (EU) 2016/679 (General Data Protection Regulation).
1.2 Categories of Personal Data Collected
We collect the following categories of personal data through our service interfaces:
- Contact identifiers: full name, business email address, telephone number
- Organizational metadata: company name, job title, industry sector
- Technical telemetry: IP address, browser type, session timestamps (collected via encrypted cookies)
- Project scope data: infrastructure descriptions, threat assessments, security requirements
1.3 Data Retention Schedule
Personal data is retained for the minimum duration necessary to fulfill its stated purpose:
- Active client data: Duration of engagement plus 24 months post-termination
- Prospective client inquiries: 12 months from last communication
- Technical telemetry: 90 days rolling window, anonymized thereafter
- Financial transaction records: 7 years (regulatory tax compliance requirement)
1.4 Data Subject Rights
Under the GDPR, you hold the following rights regarding your personal data: right of access (Art. 15), right to rectification (Art. 16), right to erasure (Art. 17), right to restriction of processing (Art. 18), right to data portability (Art. 20), and right to object (Art. 21). To exercise any of these rights, contact our Data Protection Officer at [email protected].
1.5 International Data Transfers
All personal data is processed and stored within European Union data centers. Where cross-border transfer is necessary for service delivery, we rely on EU Standard Contractual Clauses (SCCs) and ensure equivalent protection levels as mandated by the European Data Protection Board.
Terms of Service
2.1 Scope of Services
BuildLogicForge provides cybersecurity services including vulnerability scanning, penetration testing, cryptographic key management, intrusion detection, incident response, compliance auditing, firewall architecture, and managed security operations. All services are delivered in accordance with the specific Statement of Work (SOW) executed between BuildLogicForge and the Client.
2.2 Service Level Agreements
Clients enrolled in active maintenance retainers receive a 99.99% uptime availability guarantee and a priority 2-hour technical response window. Emergency incident response engagements are triaged within 4 hours of initial notification. SLA metrics are calculated on a calendar-month basis and documented in each client's service dashboard.
2.3 Intellectual Property Transfer
Upon complete settlement of all agreed commercial invoices, BuildLogicForge assigns all worldwide intellectual property rights in client-specific security deliverables, custom configurations, and remediation documentation directly to the Client. BuildLogicForge retains ownership of proprietary scanning tools, methodologies, and threat intelligence frameworks.
2.4 Confidentiality & Non-Disclosure
BuildLogicForge maintains strict confidentiality regarding all client infrastructure details, vulnerability findings, and security configurations. All staff and contractors are bound by enforceable non-disclosure agreements. Confidentiality obligations survive termination of the service agreement for a period of 5 years.
2.5 Limitation of Liability
BuildLogicForge's aggregate liability under any engagement shall not exceed the total fees paid by the Client for the specific service giving rise to the claim. BuildLogicForge shall not be liable for indirect, consequential, or incidental damages, including lost profits, data loss, or business interruption resulting from third-party actions beyond our operational control.
Refund & Reimbursement Policy
4.1 Pre-Engagement Cancellation
Clients may cancel a pending engagement and receive a full refund of any advance deposit provided written notice is received at least 72 hours before the scheduled engagement start date. Cancellations received within 72 hours of the start date are subject to a 25% administrative processing fee.
4.2 In-Progress Service Termination
If a client terminates an active engagement after work has commenced, BuildLogicForge will issue a pro-rata refund for any undelivered service components, calculated based on the percentage of the Statement of Work completed at the time of termination. Deliverables produced up to the termination date remain the Client's property upon settlement of applicable fees.
4.3 Service Dissatisfaction Remedy
If a client believes the delivered service materially deviates from the agreed Statement of Work, they may submit a written dispute within 14 calendar days of delivery. BuildLogicForge will conduct an independent quality review within 5 business days. If the service is found to be materially deficient, BuildLogicForge will either remedy the deficiency at no additional cost or issue a partial refund proportional to the affected deliverables.
4.4 Monthly Retainer Cancellation
Monthly managed security operations retainers may be cancelled with 30 days' written notice. No refund is issued for the current billing period in which cancellation is submitted. All client infrastructure data and access credentials will be securely exported and transferred within 10 business days of termination.
4.5 Refund Processing
All approved refunds are processed within 14 business days to the original payment method. Refund inquiries should be directed to [email protected] with the subject line "Refund Request" and the corresponding invoice reference number.
Security Audits & Data Handling Lifecycle
5.1 Internal Security Audit Schedule
BuildLogicForge conducts quarterly internal security audits covering infrastructure integrity, access control reviews, encryption key rotation verification, and vulnerability assessment of our own operational systems. Annual third-party penetration tests are performed by independent certified assessors.
5.2 Data Handling Lifecycle
Client data follows a strict handling lifecycle: encrypted ingestion at rest (AES-256) and in transit (TLS 1.3), access-controlled processing environments, immutable audit logging, and cryptographic destruction upon retention expiry. All data handling procedures are documented and reviewed bi-annually.
5.3 Breach Notification Protocol
In the event of a personal data breach, BuildLogicForge will notify the relevant Supervisory Authority within 72 hours as required by Article 33 GDPR. Affected data subjects will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 GDPR.
BuildLogicForge
108 Boulevard de Clichy, 75018 Paris, France
Last Revised: September 2026 // All policies governed by EU regulatory framework