Legal Document

Privacy Policy

How Forfos collects, uses, and protects your personal information — in plain language, with full compliance across AU, UK, EU, and US regulations.

Last updated: April 2, 2026Applies to: AU · UK · EU · US · CA15 sections
GDPR Compliant
UK GDPR Compliant
CCPA / CPRA Compliant
Australian Privacy Act

Plain Language Summary

We collect your name, email, and company info when you contact us or apply for a job. We use it to respond to you and improve our services. We don't sell your data. You can request access, correction, or deletion at any time by emailing hello@forfos.com.

1. Introduction

Forfos Pty Ltd ("Forfos", "we", "us", or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at forfos.com, use our services, or interact with us in any way. We operate across multiple jurisdictions including Australia, the United States, the United Kingdom, Canada, and Singapore. This policy is designed to comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, the EU General Data Protection Regulation (GDPR) 2016/679, and the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA). Please read this policy carefully. If you disagree with its terms, please discontinue use of our site and services. If you have questions, contact us at hello@forfos.com.

2. Information We Collect

2.1 Information You Provide Directly

We collect information you voluntarily provide when you: • Fill out our contact form (name, email address, company name, message) • Submit a job application (name, phone number, email, resume, cover letter, position applied for) • Subscribe to our newsletter or marketing communications • Book a consultation or engage our services • Communicate with us via email, phone, or social media This may include: full name, email address, phone number, company name, job title, billing and payment information, and any other information you choose to provide.

2.2 Information Collected Automatically

When you visit our website, we automatically collect certain technical information including: • IP address and approximate geographic location • Browser type and version • Operating system • Referring URLs and exit pages • Pages viewed and time spent on each page • Device identifiers • Cookie data and similar tracking technologies This information is collected using cookies, web beacons, pixel tags, and similar technologies. See Section 8 (Cookies) for more detail.

2.3 Information from Third Parties

We may receive information about you from third-party sources such as: • Business partners and referral sources • Social media platforms (if you interact with our social profiles) • Analytics providers (e.g., Google Analytics) • Advertising networks • Publicly available sources (e.g., LinkedIn for B2B prospecting) We handle all third-party sourced data in accordance with this policy and applicable law.

3. How We Use Your Information

We use the information we collect for the following purposes: Service Delivery: To provide, operate, and improve our e-commerce operations services; to respond to enquiries and fulfil service requests; to process job applications and communicate with candidates. Business Operations: To manage our client relationships; to send invoices and process payments; to maintain our internal records and business administration. Marketing & Communications: To send you information about our services, case studies, and industry insights (where you have opted in or where we have a legitimate interest); to personalise your experience on our website; to conduct surveys and gather feedback. Legal & Compliance: To comply with applicable laws and regulations; to enforce our terms and agreements; to protect the rights, property, and safety of Forfos, our clients, and others; to respond to legal requests and prevent fraud. Analytics & Improvement: To understand how visitors use our website; to measure the effectiveness of our marketing; to improve our website, services, and user experience. We will only use your personal information for the purposes for which it was collected, or for compatible purposes that you would reasonably expect.

5. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes. We may share your information in the following circumstances: Service Providers: We engage trusted third-party vendors who assist us in operating our website and delivering our services. These include cloud hosting providers, email delivery platforms, CRM software, analytics tools, and payment processors. All service providers are contractually bound to handle your data securely and only for the purposes we specify. Professional Advisors: We may share information with lawyers, accountants, auditors, and insurers where necessary for professional advice or compliance. Business Transfers: If Forfos is involved in a merger, acquisition, asset sale, or restructuring, your information may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy. Legal Requirements: We may disclose your information if required to do so by law, court order, or government authority, or if we believe disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of any person. With Your Consent: We may share your information for any other purpose with your explicit consent. We do not share personal information with third parties for their own direct marketing purposes without your consent.

6. International Data Transfers

Forfos operates globally with team members and infrastructure in Australia, the Philippines, the United States, the United Kingdom, and Canada. As a result, your personal information may be transferred to and processed in countries outside your country of residence. For transfers from the UK or EEA: We ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission or UK Information Commissioner's Office (ICO), adequacy decisions, or other lawful transfer mechanisms. For transfers from Australia: We take reasonable steps to ensure overseas recipients handle your information in a manner consistent with the Australian Privacy Principles. For transfers involving US residents: We comply with applicable US state privacy laws including the CCPA/CPRA. By using our services, you acknowledge that your information may be transferred internationally as described above.

7. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Contact form submissions: Retained for up to 3 years to manage our business relationship and for follow-up purposes. Job applications: Retained for 12 months after the position is filled or the application is closed, unless you consent to longer retention for future opportunities. Client data: Retained for the duration of the engagement plus 7 years to comply with tax and legal obligations. Website analytics data: Typically retained for 26 months in aggregated or anonymised form. Marketing data: Retained until you unsubscribe or withdraw consent, plus a reasonable period thereafter. When your data is no longer required, we will securely delete or anonymise it. You may request earlier deletion — see Section 9 (Your Rights) for details.

8. Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your experience and gather analytics data. Essential Cookies: Necessary for the website to function properly. These cannot be disabled. Analytics Cookies: Help us understand how visitors interact with our website (e.g., Google Analytics). These are only set with your consent where required by law. Marketing Cookies: Used to deliver relevant advertising and track campaign performance. These are only set with your consent. You can control cookies through your browser settings. Most browsers allow you to refuse cookies or delete existing ones. Note that disabling certain cookies may affect website functionality. For UK and EU visitors, we obtain your consent before setting non-essential cookies in accordance with the UK PECR and EU ePrivacy Directive. To opt out of Google Analytics tracking, you can use the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.

9. Your Privacy Rights

Australian Residents (Privacy Act 1988)

Under the Australian Privacy Principles, you have the right to: • Access the personal information we hold about you • Request correction of inaccurate or incomplete information • Make a complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have breached the APPs

UK & EU Residents (UK GDPR / GDPR)

Under UK GDPR and EU GDPR, you have the right to: • Access: Obtain a copy of your personal data • Rectification: Correct inaccurate or incomplete data • Erasure ("Right to be Forgotten"): Request deletion of your data in certain circumstances • Restriction: Request we limit processing of your data • Data Portability: Receive your data in a structured, machine-readable format • Object: Object to processing based on legitimate interests or for direct marketing • Withdraw Consent: Where processing is based on consent, withdraw it at any time • Lodge a Complaint: With the UK ICO (ico.org.uk) or your local EU supervisory authority

California Residents (CCPA / CPRA)

California residents have the right to: • Know: Request disclosure of the categories and specific pieces of personal information we have collected about you • Delete: Request deletion of your personal information (subject to certain exceptions) • Correct: Request correction of inaccurate personal information • Opt-Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioural advertising • Non-Discrimination: We will not discriminate against you for exercising your CCPA rights • Limit Use of Sensitive Personal Information: Where applicable To exercise your California rights, contact us at hello@forfos.com with the subject line "CCPA Request".

10. Exercising Your Rights

To exercise any of the rights described above, please contact us at: Email: hello@forfos.com Subject line: "Privacy Request – [Your Right]" We will respond to your request within: • 30 days for GDPR / UK GDPR requests (extendable by a further 2 months for complex requests) • 45 days for CCPA requests (extendable by a further 45 days) • A reasonable period for Australian Privacy Act requests (generally within 30 days) We may need to verify your identity before processing your request. We will not charge a fee for reasonable requests, but may charge a reasonable fee for manifestly unfounded or excessive requests.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include: • Encryption of data in transit (TLS/SSL) and at rest • Access controls and authentication requirements for our systems • Regular security assessments and staff training • Vendor due diligence for all third-party processors • Incident response procedures However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by applicable law (e.g., within 72 hours under GDPR, or as soon as practicable under the Australian Notifiable Data Breaches scheme).

12. Children's Privacy

Our website and services are not directed to individuals under the age of 16 (or 13 in the United States). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@forfos.com and we will promptly delete such information.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you by email or a prominent notice on our website. We encourage you to review this policy periodically to stay informed about how we protect your information. Your continued use of our website after any changes constitutes your acceptance of the updated policy.

15. Contact Us & Data Controller Details

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: Forfos Pty Ltd Email: hello@forfos.com Phone (AU): +61 494 670 786 Phone (PH): +63 915 694 6540 For UK/EU GDPR enquiries, you may also contact our representative or lodge a complaint with: • UK: Information Commissioner's Office — ico.org.uk • EU: Your local data protection authority For Australian privacy complaints: • Office of the Australian Information Commissioner — oaic.gov.au We take all privacy concerns seriously and will respond promptly to your enquiry.
Back to top

Last updated: April 2, 2026

Have a Privacy Question?

Our team is happy to clarify how we handle your data, process a rights request, or discuss our compliance practices. Reach out any time.

Email Us
Talk with Us