Back to Legal
LG-06·

Privacy Policy

Introduction

Fortiv ApS (“Fortiv”, “we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights in relation to it.

Fortiv is a Danish company and your data controller under the General Data Protection Regulation (EU) 2016/679 (“GDPR”). Our lead supervisory authority is Datatilsynet, the Danish Data Protection Authority.

If you have any questions about this policy or how we handle your personal data, please contact us at privacy@fortiv.io.

1. Who This Policy Applies To

This policy applies to:

  • Platform users — individuals who use the Fortiv BCMS platform on behalf of a customer organization
  • Website visitors — individuals who visit www.fortiv.io
  • Prospective customers — individuals whose contact details we hold for sales or marketing purposes

If you are using the Fortiv platform on behalf of your employer or organization, your organization is the data controller for the content you upload and manage within the platform. This policy describes how Fortiv processes your personal data as a data processor on your organization’s behalf, as well as in our own capacity as a data controller (e.g. for account management and support).

2. Personal Data We Collect

2.1 Platform Users

When you use the Fortiv platform, we process the following data:

Data TypeExamplesPurpose
Account informationName, work email address, job titleAccount creation and management
Authentication dataHashed passwords, MFA tokens, session dataSecure access to the platform
Usage dataActions taken in the platform, access logs, timestampsSecurity monitoring, audit trails, product improvement
Content you createBusiness continuity plans, risk assessments, incident records, uploaded documentsProviding the service
Support communicationsMessages sent to our support teamResolving your support requests

2.2 Website Visitors

When you visit our website, we may collect:

Data TypeExamplesPurpose
Analytics dataPages visited, time on page, browser type, approximate locationUnderstanding how our website is used
Contact form submissionsName, work email, company, messageResponding to your enquiry
Cookie dataSession identifiers, preference cookiesWebsite functionality and analytics
Visitor identification dataWhen you visit our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your emailIdentifying potential business customers for outbound sales and marketing

2.3 Prospective Customers

If you have expressed interest in Fortiv or been identified as a potential customer, we may hold:

Data TypeExamplesPurpose
Contact detailsName, work email, job title, company nameSales and marketing communications
Engagement historyEmails opened, demos attended, conversationsManaging our sales relationship

3. Legal Bases for Processing

We process your personal data on the following legal bases:

Processing ActivityLegal Basis
Providing the platform and managing your accountPerformance of a contract (Article 6(1)(b))
Responding to support requestsPerformance of a contract (Article 6(1)(b))
Security monitoring and audit loggingLegitimate interests — protecting our systems and customers (Article 6(1)(f))
Sending marketing communications to existing customersLegitimate interests (Article 6(1)(f))
Sending marketing communications to prospective customersLegitimate interests (Article 6(1)(f))
Website analyticsLegitimate interests (Article 6(1)(f))
Compliance with legal obligations (e.g. financial records)Legal obligation (Article 6(1)(c))
Processing based on your consent (e.g. marketing opt-in)Consent (Article 6(1)(a))

Where we rely on legitimate interests, you have the right to object to that processing. See Section 7 for details.

4. How We Use Your Data

We use personal data to:

  • Provide, maintain, and improve the Fortiv platform
  • Manage your account and authenticate your access
  • Respond to support requests and enquiries
  • Send you product updates, security notifications, and service-related communications
  • Send you marketing communications about Fortiv products and services (where permitted)
  • Monitor security and investigate incidents
  • Meet our legal and regulatory obligations
  • Understand how our website and product are used
  • Identify potential business customers who visit our website and reach out with relevant sales communications

We do not sell your personal data to third parties. We do not use your data for automated decision-making that produces legal or similarly significant effects.

5. Data Sharing and Sub-processors

We share personal data only where necessary to deliver our services. The following third parties process personal data on our behalf:

Sub-processorPurposeData Location
Amazon Web ServicesCloud infrastructure hosting all platform dataEU: Frankfurt, Germany (eu-central-1); US: N. Virginia (us-east-1) — region-segregated
AWS BedrockAI inference for platform featuresEU: cross-region; US: us-east-1 (in-region)
ElevenLabsVoice synthesis for platform featuresEU for EU customers; US region for US customers
Logfire (Pydantic)Application observability and monitoringEU for EU customers; US region for US customers
SentryError monitoringEU for EU customers; US region for US customers
PostHogProduct analyticsEU for EU customers; US region for US customers
IntercomCustomer support communicationsEU (Ireland) for EU customers; US region for US customers
TwilioTransactional email/SMS/voiceEU routing for EU customers; US endpoints for US customers
Google WorkspaceInternal email and document managementGlobal (Standard Contractual Clauses)
Google Analytics 4 (Consent Mode v2)Cookieless conversion modeling and website analyticsGlobal (Google servers; data minimized via consent signals)
HubSpotCRM — contact and sales managementEU (Frankfurt) for EU customers; US for US customers
Leadfeeder (by Dealfront)Company-level website visitor identification (no personal data — IP-to-company resolution only)EU (Frankfurt, Germany)

All sub-processors are bound by data processing agreements and meet our security requirements. A full and current list of sub-processors is available upon request at privacy@fortiv.io.

We notify customers at least 30 days before engaging any new sub-processor that processes customer data.

International Transfers

Customer product data is region-segregated: EU customer data is stored within the European Union (AWS eu-central-1, Frankfurt); US customer data is stored in us-east-1 (N. Virginia, US). Customer data does not cross between the EU and US regions. Sub-processors route customer workloads region-specifically (EU-customer data to EU endpoints; US-customer data to US-region endpoints, effective 25 September 2026).

6. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy:

Data TypeRetention Period
Platform account and content dataDuration of your organization’s contract + 30-day export window
Backups of platform data90 days from creation
Security and audit logs12 months
Application logs12 months
Support communications6 months after resolution
Marketing contact dataUntil you unsubscribe or request deletion, or 2 years of inactivity
Financial and contractual records5 years (Danish Bookkeeping Act)

When a customer contract ends, your organization has 30 days to export all data. After this period, all data is permanently deleted within a further 30 days, including backups within 90 days.

7. Your Rights

Under GDPR, you have the following rights in relation to your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you
RectificationAsk us to correct inaccurate or incomplete data
ErasureAsk us to delete your personal data where there is no legitimate reason to continue processing it
PortabilityReceive your data in a structured, machine-readable format (JSON or CSV)
RestrictionAsk us to pause processing of your data in certain circumstances
ObjectionObject to processing based on legitimate interests or for direct marketing
Withdraw consentWhere processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at privacy@fortiv.io. We will respond within 30 days. We may need to verify your identity before acting on your request.

If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with our lead supervisory authority:

Datatilsynet (Danish Data Protection Authority)
Carl Jacobsens Vej 35, 2500 Valby, Denmark
dt@datatilsynet.dk | +45 33 19 32 00
www.datatilsynet.dk

8. Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of all data at rest (AES-256) and in transit (TLS 1.2+)
  • Multi-factor authentication for all administrative access
  • Role-based access controls on a need-to-know basis
  • Continuous security monitoring and intrusion detection
  • Annual third-party penetration testing
  • ISO 27001:2022 certification (audit ready, pending); SOC 2 (in progress)

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify Datatilsynet within 72 hours and affected individuals without undue delay.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify platform users by email or in-app notification, and update the “Last Updated” date at the top of this page. We encourage you to review this policy periodically.

10. Contact Us

For any questions, requests, or concerns regarding this Privacy Policy or your personal data:

Fortiv ApS
Email: privacy@fortiv.io
Website: www.fortiv.io/legal/privacy

Document reference: LG-06 — Privacy Policy. Part of the Fortiv legal framework at fortiv.io/legal.

Learn more

See first-hand what AI-native resilience looks like

Fortiv
© Fortiv 2026Legal and Privacy