Effective 14 September 2026
Privacy Notice
IncidentForge is operated by Vladyslav Verkhusha. This notice explains what personal data is used by the public website, customer portal, licensing and activation service, and how to contact the operator about that data.
Local incident data
Incident records, evidence, reports, analyst content, timelines, findings, recommendations and local AI prompts remain in the customer-controlled IncidentForge deployment unless the customer deliberately exports or transfers them. The public website, billing service and licensing service do not require that content. Do not send incident material through a billing or support message.
Data we use
The service may use the minimum data needed to provide account access and licensing: name, email address, subscription and transaction identifiers, entitlement state, workstation activation metadata, one-time sign-in and session records, security-audit metadata, support correspondence and limited operational logs.
Why we use it
Data is used to deliver purchased access, authenticate customers, issue and verify entitlements, maintain account and security records, respond to support requests, prevent abuse, troubleshoot the service and meet applicable accounting or legal obligations. Where required, processing is based on performance of the customer agreement, legitimate operational and security interests, legal obligations or consent.
Payments and service providers
Paddle acts as Merchant of Record for public IncidentForge purchases and handles checkout, payment details, tax, invoices, subscription billing and eligible refunds under its own notices. IncidentForge does not receive or store complete payment-card details. ADM.Tools provides email hosting and SMTP delivery for portal and support messages. Providers process the data necessary to perform their services and may process it in countries other than the customer’s country under their applicable safeguards.
Email, cookies and analytics
The customer portal may send one-time sign-in links, transaction-related notices and service messages. IncidentForge does not operate a marketing-email program unless a person separately opts in to one in the future. The portal uses essential, HttpOnly, SameSite session cookies. The public website has no advertising or marketing trackers by default.
Retention and security
Account, entitlement, transaction references and security records are retained only while needed to provide the service, protect accounts, resolve disputes and meet applicable legal or accounting obligations. Retention can differ by record type and mandatory requirement. Access controls, data minimization, transactional processing and audit records are used to protect the service, but no system can guarantee absolute security.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection or a portable copy of personal data, and may complain to an appropriate supervisory authority. Some information must be retained where required by law or needed to establish or defend legal claims. Identity may need to be verified before a request is completed.
Contact
For a privacy request, email support@incidentforge.net or call +380 75 110 1196. The data operator is Vladyslav Verkhusha. Do not include incident evidence, report contents, passwords or activation secrets in a privacy request.
Changes to this notice
Material changes will be published on this page with a revised effective date. The version displayed when data is processed applies subject to mandatory law.
