Fohrkast

Fohrkast self-compliance

Privacy Policy

How Fohrkast handles account, billing, support, scan, consent, and website-compliance data.

Effective date
19 June 2026
Template version
fohrkast-privacy-2026-06-19

Summary

This page provides general information about Fohrkast's own operations. It is not legal advice.

Fohrkast is a controller for its own users, account data, billing data, product telemetry, support requests, and public website scans that Fohrkast decides to run.

Fohrkast is a processor when a customer uses Shield, Site, or related tools to handle end-user consent records and hosted compliance documents for that customer.

Personal Data We Process

Account and organisation details such as name, business email, company name, role, and authentication identifiers.

Billing and tax metadata handled through Stripe, including customer identifiers, subscription status, invoices, VAT details, and payment status. Fohrkast does not store full card numbers.

Support and DSAR details that a person gives us when asking for help or exercising a data protection right.

Shield consent records such as consent state, policy version, timestamp, domain, and technical proof fields needed to show consent history.

Radar scan data about public websites, including URLs, detected compliance signals, public company identifiers, and non-personal technical evidence.

Purposes And Lawful Bases

We process account, subscription, and product data to provide the service and perform our contract with customers.

We process billing, tax, fraud-prevention, security, and accounting data to comply with legal obligations and protect legitimate interests.

We process support, DSAR, and operational messages to respond to requests and run the service.

We process public website scan data for legitimate interests in providing a compliance scanning and claim workflow, subject to suppression and opt-out controls.

AI Processing

Fohrkast uses vetted templates for generated legal documents. AI fills customer-specific details into those templates and stores template version and legal source citations.

Before sending prompts to an AI provider, Fohrkast minimises and redacts personal data where it is not needed for the task.

AI output is general information, not legal advice. Customers remain responsible for reviewing their own published materials.

International Transfers

Fohrkast keeps personal data in EU-hosted Supabase and Vercel regions where the product controls allow it.

Some sub-processors may process limited data outside the EEA. Fohrkast documents data processing agreements, standard contractual clauses, and transfer safeguards for its AI and billing providers where relevant.

Retention

Account, subscription, and audit records are kept while the account is active and then for the period needed for tax, security, dispute, and legal purposes.

Consent proof logs are kept for the customer retention period configured in Shield, unless deletion is required earlier.

DSAR requests are kept long enough to verify completion, prevent duplicate handling, and meet accountability duties.

Your Rights

People in the EEA and UK can ask for access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where applicable.

Use the DSAR page to submit a data-subject request. We may need to verify identity before acting on a request.

People can also complain to the Irish Data Protection Commission or their local supervisory authority.