Fornzix Privacy Policy

Privacy Policy

Last Updated: November 8, 2025

1) Who We Are

Fornzix

Website: fornzix.com

Email: info@fornzix.com

For purposes of the EU/UK GDPR, Fornzix is the data controller for personal data described in this Policy unless stated otherwise.

2) Scope

This Policy explains how we collect, use, disclose, and protect information when you use our website, products, and services (the “Services”). It applies to residents of the United States (including California CCPA/CPRA) and the EU/EEA/UK (GDPR).

3) Information We Collect

  • Account information: name (if provided), username, password, email, date of account creation.
  • Payment information: processed by our payment providers (see §7). We receive limited payment metadata such as transaction status and IDs; we do not store full card numbers.
  • Service and support communications: messages you send to us.
  • Technical data (automatic): basic device, browser, and access information (e.g., IP address, timestamps) generated by normal web operations.
  • Uploads or content you submit to the Services (if applicable).

We use session cookies for login/authentication. See §10.

4) How We Use Information

  • Provide, secure, and maintain the Services (including authentication and account management).
  • Process payments and fulfill transactions.
  • Communicate with you about your account, security, and important updates.
  • Provide marketing communications if you opt in or where permitted by law.
  • Comply with legal obligations and enforce terms.

We do not use your information for automated decision-making that produces legal or similarly significant effects.

5) Legal Bases for Processing (GDPR)

  • Contract necessity: to create and manage your account and provide Services you request.
  • Legitimate interests: to secure our Services, prevent fraud, and improve user experience, balanced against your rights.
  • Legal obligation: to meet regulatory, tax, accounting, or court requirements.
  • Consent: for optional marketing where required. You may withdraw consent at any time.

6) Your Choices

  • Account settings: you may update account details.
  • Marketing: you may opt out of marketing emails by using unsubscribe links or contacting us at info@fornzix.com.
  • Cookies: since we only use session cookies required for login, disabling them may prevent sign-in.

7) Sharing and Disclosures

We share information with service providers only to operate the Services:

  • Payments: Stripe and WooCommerce (payment processing). They act as independent controllers or processors for the payment portion as applicable.
  • Hosting/IT and support vendors as needed to run the Services.

We may disclose information to comply with law, protect rights and safety, or in connection with a business transaction (merger, acquisition, or asset sale). We do not sell or share personal information for cross-context behavioral advertising as defined by the CPRA.

8) International Data Transfers

If you are outside the United States, your information may be processed in the U.S. and other countries with different data protection laws. Where required, we use appropriate safeguards (e.g., Standard Contractual Clauses).

9) Data Retention

Fornzix retains personal information only for marketing and login purposes and deletes upon request. If permitted by law, we may retain minimal records necessary to demonstrate compliance or resolve disputes. When we delete, we aim to complete verified deletions within 30 days.

10) Cookies

We use session cookies strictly necessary for authentication and core functionality. We do not use advertising cookies.

11) Security

We employ reasonable technical and organizational measures designed to protect personal information. No method of transmission or storage is completely secure.

12) Your Rights

California (CCPA/CPRA)

California residents have the right to:

  • Know/access the categories and specific pieces of personal information we collected.
  • Delete personal information (subject to legal exceptions).
  • Correct inaccurate personal information.
  • Receive information about disclosures for business purposes.
  • Opt out of sale or sharing (not applicable; we do not sell/share as defined).
  • Limit use/disclosure of sensitive personal information (not applicable as used here).
  • Be free from discrimination for exercising these rights.

Submit requests at info@fornzix.com. We will verify your identity before fulfilling requests. Authorized agents may act on your behalf with proper authorization.

EU/EEA/UK (GDPR)

You have the right to:

  • Access, rectify, or erase your personal data.
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your supervisory authority.

Contact: info@fornzix.com.

13) Children’s Privacy

Our Services are not directed to children. If we learn we collected personal information from a child where parental consent is required, we will delete it.

14) Do Not Track

We do not respond to browser DNT signals due to lack of a common standard.

15) Changes to This Policy

We may update this Policy. Material changes will be noted by updating the “Last Updated” date and, where appropriate, additional notice.

16) Contact

For questions or privacy requests, contact info@fornzix.com

California “Notice at Collection”

We collect the categories below for the business and commercial purposes listed in §4 and share with service providers in §7. We do not sell or share personal information as defined by CPRA.

CPRA Category Examples Retention Disclosed To
Identifiers name (if provided), username, email, IP address While account is active; deleted upon request Hosting/IT, payment processors (limited)
Customer Records account profile basics Same as above Same as above
Commercial Information transaction metadata from processors Same as above Payment processors
Internet/Network Activity basic access logs necessary to run the Service Same as above Hosting/IT
Sensitive PI account password (hashed) While account is active; deleted upon request Hosting/IT (as necessary for authentication)

No profiling with legal or similarly significant effects.