LEGAL
Privacy Policy
Last updated: June 5, 2026
1. Who we are
Forzza ("we", "us", "Forzza") is operated by Lamacorn SASU, registered at 42 bis Avenue de Moutille, 33360 Cenac, France.
For any privacy question, contact us at hello@forzza.ai.
2. What data we collect
2.1 Account data
When you sign up we collect your email, password (hashed), and the timestamp of account creation. If you sign up with Google, we also receive your name and profile picture from Google.
2.2 Workspace & product data
You provide:
- Your company website URL (we scrape it once via Cloudflare to build your ICP).
- Your ideal customer profile (ICP), value proposition, and campaign settings.
- Past email/LinkedIn messages you paste to train your Voice Profile.
- Knowledge documents (PDFs, links) you upload to inform message drafting.
2.3 Third-party account data via Unipile
When you connect LinkedIn or Gmail through Unipile, we store OAuth tokens (encrypted at rest) and the metadata Unipile returns: account name, profile URL, connection list, conversation history, and incoming events (post reactions, invitations, DMs). We do not store your LinkedIn or Gmail password — Unipile manages authentication on our behalf.
2.4 Prospect data
Forzza retrieves public LinkedIn profile data of prospects you target (name, headline, current company, public posts). For each prospect, we may also crawl their public company website via Cloudflare to generate personalized messages. This data is processed in your workspace context only.
2.5 Billing data
Subscription and payment data is handled by Polar.sh, our Merchant of Record. We receive customer ID, subscription status, and event metadata — never your card details. See Polar's Privacy Policy.
2.6 Technical & analytics data
We collect server logs (IP address, user-agent, request path), error reports, and product analytics events (page views, button clicks, feature usage). These are used to keep the service running and improve the product.
3. Why we process your data (legal basis)
- Contract performance — to provide the service you signed up for (account, workspace, message drafting, sending).
- Legitimate interest — to keep the service running, prevent fraud, monitor for abuse, and improve the product through aggregated analytics.
- Legal obligation — to meet tax, accounting, and consumer protection requirements.
- Consent — for non-essential cookies and any marketing communications you opt into. You can withdraw consent at any time.
4. Who we share your data with
We use the following sub-processors:
- Supabase (database, authentication) — hosted in the EU.
- Vercel (application hosting, serverless functions) — hosted in the EU and US.
- Polar.sh (Merchant of Record for billing) — hosted in the EU and US.
- Unipile (LinkedIn and Gmail integration) — hosted in France.
- Resend (transactional emails) — hosted in the US.
- Cloudflare (website crawling for ICP and prospect personalization) — global edge network.
- Anthropic (Claude API for AI message drafting). Anthropic does not train models on your data per their API terms.
- OpenAI (GPT-4o fallback). Same no-training commitment per API terms.
- Sentry / PostHog (error monitoring and product analytics) — EU hosting where available.
We never sell your data. We share data only with the sub-processors above and only to the extent needed to provide the service.
5. International transfers
Some sub-processors host data outside the European Economic Area (EEA). For those transfers we rely on Standard Contractual Clauses (SCCs) and the applicable adequacy decisions where they exist.
6. How long we keep your data
- Active accounts: as long as your account exists.
- After account deletion: workspace data is deleted within 30 days; billing records are retained for the legally required duration (up to 10 years for tax purposes).
- Server logs: 90 days.
- Backups: rolling 30 days.
7. Your GDPR rights
If you are in the EU/EEA, UK, or Switzerland you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Request deletion of your data (right to be forgotten).
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time (where consent is the legal basis).
- Lodge a complaint with your local data protection authority (in France: CNIL).
To exercise any of these rights, email hello@forzza.ai. We will respond within 30 days.
8. Cookies
We use cookies for:
- Authentication (essential) — to keep you signed in. Cannot be disabled.
- Theme preference (essential) — to remember light/dark mode.
- Product analytics (non-essential) — to understand how the product is used. Only set if you accept via the cookie banner.
You can manage your preferences at any time by clearing your browser cookies for this site.
9. Security
We use industry-standard encryption (TLS in transit, AES-256 at rest for Supabase, encrypted token storage in Supabase Vault for OAuth credentials), principle of least privilege, and row-level security in our database. No system is 100% secure — if we discover a breach affecting you we will notify you within 72 hours per GDPR Article 33.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated via email and a banner in the app. The "Last updated" date at the top reflects the latest revision.
11. Contact
Questions, requests, or concerns: hello@forzza.ai