Privacy Policy
Forbear
1. Who we are and what this policy covers
Forbear (“Forbear”, “we”, “us”) uses AI extraction models to read creditor correspondence attached to files in a firm's existing CRM, extracts settlement terms, and writes the accepted result back into that CRM.
Registered at 1010 Wisconsin Ave NW, Suite 620, Washington, DC 20007.
This policy explains how we handle personal data in two distinct capacities, which are governed by different rules:
| Whose data | Our role | Governed by | |
|---|---|---|---|
| Part A | Website visitors, prospects, people who contact us | Controller — we decide why and how | This policy |
| Part B | Consumer records held in the firm's CRM | Processor — we act only on the customer’s documented instructions | This policy and the Data Processing Agreement signed with that customer |
Where the Data Processing Agreement (“DPA”) and this policy conflict in respect of Part B, the DPA governs.
Part A — When we are the controller
This part covers personal data we collect for our own purposes: running our website, responding to access requests, and communicating with prospective and existing customers.
A.1 What we collect
Information you give us. When you submit the access request form we collect your first name, last name, work email address and company name, together with the fact that you agreed to be contacted. If you email us or talk to us during evaluation or onboarding, we hold the content of that correspondence and any business contact details in it.
Information collected automatically. Our web server records the IP address the request came from, the user agent string, the pages requested, referring URL and timestamp. These logs exist to keep the site available and secure.
We do not knowingly collect special categories of personal data under Article 9 GDPR in this part, and the form should not be used to send us any.
A.2 Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Responding to an access request and evaluating fit | Form submissions, correspondence | Art. 6(1)(b) — steps at your request prior to a contract |
| Administering a customer relationship, billing, support | Contact details, correspondence | Art. 6(1)(b) — performance of a contract |
| Site availability, security, abuse prevention | Server logs | Art. 6(1)(f) — legitimate interest in operating a secure service |
| Direct outreach to business contacts about the service | Work email, company | Art. 6(1)(f) — legitimate interest in B2B marketing, subject to your right to object at any time |
| Meeting tax, accounting and legal obligations | Billing and contract records | Art. 6(1)(c) — legal obligation |
Where we rely on legitimate interest, we have assessed that interest against your rights and are able to provide the assessment on request.
A.3 How long we keep it
- Access requests that do not become customers: 12 months from last contact, then deleted.
- Customer contact and contract records: for the term of the agreement plus 6 years, to meet limitation periods and accounting obligations.
- Server logs: 30 days.
- Records of an objection or opt-out: retained indefinitely, so that we can honour it.
A.4 Your rights
If you are in the EEA or UK you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent where consent is the basis. You may exercise any of these by writing to [email protected]. We answer within one month.
You also have the right to complain to a supervisory authority. If you are in the EEA you may complain to the authority in your country of residence or workplace; our EU representative is identified in section 5.
Part B — When we are the processor
The firm is the controller of every consumer record involved. Forbear processes those records on the firm's written instructions and holds no consumer record of its own.
B.1 What we process, and why it is personal data
What Forbear reads, and what it does with it.
- Creditor correspondence — Documents and notes attached to a file in the connected CRM: letters, portal exports, PDF attachments and typed call notes. These are read in order to extract settlement terms.
- The file fields the extraction targets — Account identifiers, creditor name, balance and existing settlement fields, read so an extraction can be matched to the right file and written back to the right place.
- Negotiator decisions — Which proposed values a named user accepted or corrected, and when.
Forbear does not read consumer communications, payment instruments, or any field the firm has not mapped in the connection settings.
B.2 What we do with it
Region. Extraction models run on Microsoft Azure in East US. Document intake, the review queue, source documents and the search index run on AWS in us-east-1. No document is copied outside the United States.
Model providers. Documents are read by Azure OpenAI and parsed by Azure AI Document Intelligence in East US, under zero-retention terms: Microsoft does not store the documents or use them to train any model. Documents that match a creditor rule are extracted without a model call.
Write scope. Forbear writes only to the fields named in the connection settings, only after a named user accepts, and every write carries the source document and the accepting user.
Deletion. Deleting a connection deletes the extraction store for that firm within thirty days. Values already written into the firm's CRM belong to the firm and are untouched.
B.3 Models, inference and training
Where inference runs. Extraction models run on Microsoft Azure in East US: Azure OpenAI reads unstructured creditor correspondence and Azure AI Document Intelligence parses letters, faxes and portal screenshots, both under zero-retention terms. Documents that match a creditor rule are extracted without a model call. Document intake, the review queue and source documents stay on AWS in us-east-1, and nothing is processed outside the United States.
Training. No firm's documents train a general model, and Azure OpenAI keeps none of what Forbear sends it and trains on none of it. Accepted and corrected extraction pairs are retained as a labeled corpus, detached from firm and consumer identifiers, and used only to fit Forbear's own extraction models on Azure Machine Learning. A firm may opt out in connection settings.
Human review. The model proposes and never writes. Below the confidence floor an extraction goes to a named reviewer with the source page beside it, and nothing reaches the CRM until that person accepts it.
B.4 Where the data sits
Microsoft Azure, East US: Azure OpenAI and Azure AI Document Intelligence for reading documents, Azure Machine Learning for training Forbear's extraction models on the labeled corpus, and Azure Blob Storage for the write record and the labeled corpus.
Amazon Web Services, us-east-1: EC2 for document intake, the review queue and embedding runs, and S3 for source documents and the search index.
The firm's own CRM, wherever the firm hosts it, for every value Forbear writes back.
B.5 Retention, deletion, and the limits of deletion
Source documents are held for the life of the connection and deleted within thirty days of its removal.
Labeled extraction pairs are kept after a connection ends, detached from the firm and from any consumer identifier.
Audit records of writes are kept for seven years, because a written settlement figure is a record the firm may have to account for.
B.6 Requests from individuals whose data we process
Requests from a consumer go to the firm, which is the controller. Forbear will assist the firm in locating and deleting anything it holds within ten business days of the firm's instruction.
Common provisions
5. International transfers
Forbear is incorporated in the United States and serves customers established in the EEA. Personal data transferred outside the EEA is protected by the European Commission’s Standard Contractual Clauses, together with a transfer impact assessment and the supplementary technical measures described in our security documentation. A copy of the clauses is available on request.
EU representative (Article 27 GDPR)
6. Security
We maintain measures appropriate to the risk, including encryption in transit and at rest, credentials scoped to the minimum necessary, access control on the principle of least privilege, isolation of each customer’s data, and audit logging of access to production systems.
We notify affected customers of a personal data breach without undue delay and, in any event, within 36 hours of becoming aware of it, with the information they need to meet their own notification duties.
7. Children
The service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.
8. Changes to this policy
We may update this policy. Material changes are notified to customers by email at least 30 days before they take effect, and the version number and date at the top of this page are updated in every case.
9. Contact
Privacy enquiries and general: [email protected]
Postal: Forbear, 1010 Wisconsin Ave NW, Suite 620, Washington, DC 20007