Skip to content

Legal

Privacy Policy

What we collect, why we are allowed to, how long we keep it, and how you get it back or get rid of it.

Last updated: 2026-08-09 [email protected]

01 Who we are

ForgeIT L.P. provides software engineering, DevOps and ERP services, and develops the ManagoStores suite along with our own products. We are registered in Greece.

For anything in this policy, write to [email protected].

02 Scope

This policy covers personal data we process on this website and in our own products and services — including the ManagoStores web application and its React Native companion app (together, the "Services").

Where we build or operate software for a client, that client is normally the controller of the data inside it and we act as their processor under a separate agreement. This policy then covers our own relationship with you, not theirs.

03 What we collect

We keep this list short on purpose.

  • Contact data — your name, email, company and message, when you use our contact form or email us.
  • Account data — name, email, roles and permissions, when you use one of our applications.
  • Usage data — pages viewed, actions, timestamps, IP address and device or browser information, from server logs kept for security and performance.
  • Cookies — strictly necessary cookies for the site to work. We run no third-party analytics on this website.
  • Mobile app — barcode scan input, camera permission for scanning, and crash diagnostics where you have enabled them.

04 Legal bases (GDPR Article 6)

  • Contract, Art. 6(1)(b) — providing the Services to you or your organisation.
  • Legitimate interests, Art. 6(1)(f) — security, abuse prevention, and improving the Services.
  • Consent, Art. 6(1)(a) — anything optional. You may withdraw it at any time.
  • Legal obligation, Art. 6(1)(c) — tax, accounting and compliance records.

05 How we use it

  • To provide and maintain the Services, including roles, permissions and support.
  • To answer the enquiries and proposals you send us.
  • To keep our systems secure — audit logs, rate limiting, abuse detection.
  • To understand performance and fix what is slow.

06 Cookies

This website sets strictly necessary cookies only — the session and security cookies without which it cannot function. There is no advertising cookie, no tracking pixel and no third-party analytics script, which is why you are not being shown a consent banner.

If that ever changes, this clause changes with it and you will be asked first.

07 Sharing and processors

We share personal data only with the processors we genuinely need, each under a GDPR-compliant agreement:

  • Hosting and infrastructure providers.
  • Transactional email delivery.
  • Payment processing, where a product of ours is paid for.
  • We do not sell personal data, and we do not share it for advertising.

08 International transfers

We prefer EU hosting and use it wherever we reasonably can. Where data does leave the EEA, we rely on a lawful transfer mechanism such as the Standard Contractual Clauses and satisfy ourselves that the protection travels with it.

09 Retention

We keep personal data only as long as it is needed for the purpose it was collected for, plus whatever a contract or the law requires. Server logs are short-lived unless they are needed for a security investigation.

10 Security

Access control, least privilege, encryption in transit, audited administrative actions, and dependency updates as a routine rather than an emergency. No system is perfectly secure; we treat that as a reason to keep working rather than a disclaimer.

11 Your rights

You may ask for access, rectification, erasure, restriction or portability, and you may object to processing. Where processing rests on consent, you may withdraw it at any time without giving a reason.

Write to [email protected]. You also have the right to complain to the Hellenic Data Protection Authority (www.dpa.gr).

If your data sits inside an application we operate for a client, that client is the controller — we will tell you who to ask, and we will help them answer.

12 Children

Our Services are not directed at children under 16 and we do not knowingly process their personal data. Where one of our products has a different, stated age gate, that product's own terms say so.

13 Changes

We may update this policy. The current version and its date are always at the top of this page; a change that affects your rights will be stated plainly rather than slipped in.

14 Contact

ForgeIT L.P. — [email protected].

Questions about this document? Write to [email protected].