Forbear

Privacy Policy

Forbear

Last updated: 27 June 2026 · Version 1.0

1. Who we are and what this policy covers

Forbear (“Forbear”, “we”, “us”) uses AI extraction models to read creditor correspondence attached to files in a firm's existing CRM, extracts settlement terms, and writes the accepted result back into that CRM.

Registered at 1010 Wisconsin Ave NW, Suite 620, Washington, DC 20007.

This policy explains how we handle personal data in two distinct capacities, which are governed by different rules:

Whose dataOur roleGoverned by
Part AWebsite visitors, prospects, people who contact usController — we decide why and howThis policy
Part BConsumer records held in the firm's CRMProcessor — we act only on the customer’s documented instructionsThis policy and the Data Processing Agreement signed with that customer

Where the Data Processing Agreement (“DPA”) and this policy conflict in respect of Part B, the DPA governs.

Part A — When we are the controller

This part covers personal data we collect for our own purposes: running our website, responding to access requests, and communicating with prospective and existing customers.

A.1 What we collect

Information you give us. When you submit the access request form we collect your first name, last name, work email address and company name, together with the fact that you agreed to be contacted. If you email us or talk to us during evaluation or onboarding, we hold the content of that correspondence and any business contact details in it.

Information collected automatically. Our web server records the IP address the request came from, the user agent string, the pages requested, referring URL and timestamp. These logs exist to keep the site available and secure.

We do not knowingly collect special categories of personal data under Article 9 GDPR in this part, and the form should not be used to send us any.

A.2 Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Responding to an access request and evaluating fitForm submissions, correspondenceArt. 6(1)(b) — steps at your request prior to a contract
Administering a customer relationship, billing, supportContact details, correspondenceArt. 6(1)(b) — performance of a contract
Site availability, security, abuse preventionServer logsArt. 6(1)(f) — legitimate interest in operating a secure service
Direct outreach to business contacts about the serviceWork email, companyArt. 6(1)(f) — legitimate interest in B2B marketing, subject to your right to object at any time
Meeting tax, accounting and legal obligationsBilling and contract recordsArt. 6(1)(c) — legal obligation

Where we rely on legitimate interest, we have assessed that interest against your rights and are able to provide the assessment on request.

A.3 How long we keep it

A.4 Your rights

If you are in the EEA or UK you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent is the basis. You may exercise any of these by writing to [email protected]. We answer within one month.

You also have the right to complain to a supervisory authority. If you are in the EEA you may complain to the authority in your country of residence or workplace; our EU representative is identified in section 5.

Part B — When we are the processor

The firm is the controller of every consumer record involved. Forbear processes those records on the firm's written instructions and holds no consumer record of its own.

B.1 What we process, and why it is personal data

What Forbear reads, and what it does with it.

Forbear does not read consumer communications, payment instruments, or any field the firm has not mapped in the connection settings.

B.2 What we do with it

Region. Extraction models run on Microsoft Azure in East US. Document intake, the review queue, source documents and the search index run on AWS in us-east-1. No document is copied outside the United States.

Model providers. Documents are read by Azure OpenAI and parsed by Azure AI Document Intelligence in East US, under zero-retention terms: Microsoft does not store the documents or use them to train any model. Documents that match a creditor rule are extracted without a model call.

Write scope. Forbear writes only to the fields named in the connection settings, only after a named user accepts, and every write carries the source document and the accepting user.

Deletion. Deleting a connection deletes the extraction store for that firm within thirty days. Values already written into the firm's CRM belong to the firm and are untouched.

B.3 Models, inference and training

Where inference runs. Extraction models run on Microsoft Azure in East US: Azure OpenAI reads unstructured creditor correspondence and Azure AI Document Intelligence parses letters, faxes and portal screenshots, both under zero-retention terms. Documents that match a creditor rule are extracted without a model call. Document intake, the review queue and source documents stay on AWS in us-east-1, and nothing is processed outside the United States.

Training. No firm's documents train a general model, and Azure OpenAI keeps none of what Forbear sends it and trains on none of it. Accepted and corrected extraction pairs are retained as a labeled corpus, detached from firm and consumer identifiers, and used only to fit Forbear's own extraction models on Azure Machine Learning. A firm may opt out in connection settings.

Human review. The model proposes and never writes. Below the confidence floor an extraction goes to a named reviewer with the source page beside it, and nothing reaches the CRM until that person accepts it.

B.4 Where the data sits

Microsoft Azure, East US: Azure OpenAI and Azure AI Document Intelligence for reading documents, Azure Machine Learning for training Forbear's extraction models on the labeled corpus, and Azure Blob Storage for the write record and the labeled corpus.

Amazon Web Services, us-east-1: EC2 for document intake, the review queue and embedding runs, and S3 for source documents and the search index.

The firm's own CRM, wherever the firm hosts it, for every value Forbear writes back.

B.5 Retention, deletion, and the limits of deletion

Source documents are held for the life of the connection and deleted within thirty days of its removal.

Labeled extraction pairs are kept after a connection ends, detached from the firm and from any consumer identifier.

Audit records of writes are kept for seven years, because a written settlement figure is a record the firm may have to account for.

B.6 Requests from individuals whose data we process

Requests from a consumer go to the firm, which is the controller. Forbear will assist the firm in locating and deleting anything it holds within ten business days of the firm's instruction.

Common provisions

5. International transfers

Forbear is incorporated in the United States and serves customers established in the EEA. Personal data transferred outside the EEA is protected by the European Commission’s Standard Contractual Clauses, together with a transfer impact assessment and the supplementary technical measures described in our security documentation. A copy of the clauses is available on request.

EU representative (Article 27 GDPR)

6. Security

We maintain measures appropriate to the risk, including encryption in transit and at rest, credentials scoped to the minimum necessary, access control on the principle of least privilege, isolation of each customer’s data, and audit logging of access to production systems.

We notify affected customers of a personal data breach without undue delay and, in any event, within 36 hours of becoming aware of it, with the information they need to meet their own notification duties.

7. Children

The service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.

8. Changes to this policy

We may update this policy. Material changes are notified to customers by email at least 30 days before they take effect, and the version number and date at the top of this page are updated in every case.

9. Contact

Privacy enquiries and general: [email protected]
Postal: Forbear, 1010 Wisconsin Ave NW, Suite 620, Washington, DC 20007

← Back

Your request has been received.

Expect a message from Forbear. It goes to the address you gave.