Effective: 2026-07-25

Privacy Policy

This policy explains which information FORALL processes, why it is processed, where it is stored, how long it is retained, and how a person or customer organization can exercise data rights.

Publication control: Deployment must set LEGAL_APPROVAL_REFERENCE to the signed local counsel review. This repository text is not a substitute for jurisdiction-specific approval.

Controller and scope

The contracting FORALL entity is the controller for account, billing, website, and support data. Customer organizations control the visitor and contact content they submit to the service; FORALL processes that content on their instructions.

Data and purposes

  • Account identity, verified email, authentication events, organization membership, and preferences: account delivery, access control, and security.
  • Visitor identifiers, conversations, attachments, tickets, page events, and CRM fields: customer-requested messaging and support operations.
  • Plan, usage, invoices, payment references, and refund records: subscription delivery, accounting, fraud prevention, and legal compliance.
  • Support submissions, delivery failures, IP/security telemetry, and audit events: support, abuse prevention, incident response, and service reliability.

Legal basis and choice

Processing is performed to provide the contracted service, comply with applicable obligations, protect the service, or on consent where required. Marketing and non-essential analytics require an appropriate consent signal and can be declined without disabling core service.

Retention

  • Active tenant content is kept while the service is active.
  • A requested deletion enters the disclosed cooling period, after which active database and object-storage copies are erased unless a legal hold applies.
  • Billing and tax records are retained for the legally required accounting period.
  • Security and audit records are retained for the configured compliance period; backup copies age out under the documented backup rotation and are not restored for ordinary use.

Storage, transfers, and subprocessors

Production configuration identifies the hosting region and approved subprocessors. The current list, service purpose, storage location, and transfer safeguard is published at /subprocessors. Material changes are notified through the contractual channel.

Rights and security

Authorized organization owners can request a machine-readable export or scheduled deletion after re-authentication. Individuals may request access, correction, deletion, restriction, objection, or portability through privacy@forall.ir. We verify identity and route end-user requests to the controlling customer when appropriate. Exports are short-lived, access-controlled, and audited.

Contact and complaints

Contact privacy@forall.ir for the privacy owner or data protection contact. Include the organization name and request type, but never send a password or payment credential. You may complain to the competent supervisory authority where that right applies.

Questions or rights requests: privacy@forall.ir. Support requests can also be submitted through the contact form.