Privacy / release 1

Privacy statement

This statement explains in plain language which personal data iForge uses, why, for how long and what control you have. It covers the public website, enquiries, the Founding Cohort and the first iForge release.

Effective
22 August 2026
Version
1.1
Controller
Pracht B.V.
01

1. Controller and contact

Pracht B.V. is the controller for the iForge processing described here. Pracht B.V. is registered with the Dutch Chamber of Commerce under number 82507740 and has VAT ID NL862497437B01. Its registered address is Bollengoed 24, 3882 WH Putten, the Netherlands.

For privacy requests, email maurice@pracht-finance.nl with the subject PRIVACY. This contact route is monitored by the controller.

02

2. Data, purposes and legal bases

iForge applies data minimisation. The public website contains a limited Founding Cohort application form, but no customer account, production intake or connected wearable database.

Website, aggregate measurement and security

IP address, request time, URL, browser/device signals and security events may be processed to deliver and protect the site. iForge also counts page views by day, path and campaign parameters without storing an IP address, cookie or visitor identifier for that count. Basis: legitimate interests in availability, fraud prevention, security and evaluating the effectiveness of the public website.

Enquiries and Founding Cohort

Name, business contact details, message, role, preferences and correspondence are used to answer enquiries, assess fit and take steps before a contract. Basis: pre-contractual steps and, where applicable, legitimate interests in professional follow-up.

Contract and administration

Identity, contact, order, payment, invoice and service records are used to perform the agreement and meet tax and accounting duties. Basis: contract and legal obligation.

Email marketing

Updates are sent only with valid consent or where Dutch electronic-marketing rules permit communication to an existing customer about similar services. Every message contains a simple opt-out.

Marketing measurement

Meta Pixel and LinkedIn Insight Tag remain off unless you give prior marketing consent and the platform, transfer and release checks are approved. Basis: consent.

Programme, coaching and wearable data

These data are not collected through the current public demo. Production processing starts only after the separate onboarding notice, necessity assessment, security controls and, where health data are involved, explicit consent have passed the release gate.

03

3. Health and performance data

Health data and data that reveal health through measurement or inference are special-category data. iForge will process them only for a specific, explained coaching purpose after a separate positive choice that qualifies as explicit consent. Refusing or withdrawing that consent does not affect access to public information and does not create a disadvantage beyond features that objectively require those data.

Health, wearable, coaching, baseline and checkout data are never used for advertising audiences, platform retargeting or customer-list uploads. iForge is not a medical provider and does not use these data to diagnose or treat disease.

04

4. AI, profiling and human review

The AI Coach may organise inputs, identify patterns and propose next actions. Recommendations are bounded, explainable at an appropriate level and subject to human review for consequential coaching decisions. iForge does not currently make decisions based solely on automated processing that produce legal or similarly significant effects. If that changes, the notice and safeguards will be updated before activation.

05

5. Cookies, local storage and platform tags

The site stores the choice ‘necessary only’ or ‘allow marketing measurement’ locally on your device for up to 180 days. Marketing tags do not load before an affirmative choice. Refusal is offered at the same level as acceptance, the site continues to work after refusal, and the Privacy settings control lets you change or withdraw your choice.

Marketing tags are limited to the homepage and Founding Cohort pages. They are excluded from baseline, coach, checkout, data-use, privacy and future intake pages. No server-side tagging, Conversions API or customer-list upload is used in release 1. Platform identifiers alone do not activate tracking; a separate release flag remains required.

06

6. Recipients and processors

Access is limited to people and suppliers that need it for the stated purpose. Categories may include EU hosting and infrastructure, business email and collaboration, payment and accounting providers when checkout is activated, and authorised coaches under confidentiality and data-processing terms.

Meta Platforms Ireland Limited and LinkedIn Ireland Unlimited Company receive event data only if their tags are activated after consent. For the initial collection and transmission through their business tools, platform terms may allocate joint or independent controller roles. iForge does not sell personal data.

07

7. EU processing and international transfers

iForge selects EU-hosted product infrastructure and keeps health, wearable and coaching data away from advertising platforms. Some global communication or advertising suppliers may nevertheless access or transfer limited website or business-contact data outside the EEA. Such a supplier is not activated until the transfer route, roles and safeguards have been documented.

Where a transfer occurs, iForge relies on an applicable adequacy decision, including the EU-U.S. Data Privacy Framework for a certified recipient, or approved contractual safeguards plus a transfer assessment. A general promise of EU-only processing is not used where the provider cannot evidence it.

08

8. Retention

Raw website and security logs are kept for no more than 30 days, unless an identified incident requires a protected copy for up to 12 months. Enquiries and qualified prospect correspondence are kept for up to 12 months after the last meaningful contact. Unsuccessful cohort applications are deleted within 6 months.

Contract, invoice and core accounting records are kept for 7 years, or 10 years where a specific VAT scheme requires it. Programme and coaching data are deleted or irreversibly anonymised within 90 days after the programme ends, unless a legal claim or an explicitly agreed follow-up purpose requires a longer period. Consent evidence is kept for up to 5 years after withdrawal or the last relevant processing. The on-device marketing choice expires after 180 days.

09

9. Security and incidents

iForge uses least-privilege access, multi-factor authentication where available, encryption in transit, controlled production changes, backups, logging and processor review proportionate to the data and risk. Test environments must use synthetic or irreversibly anonymised data. Suspected personal-data breaches are contained, documented and assessed promptly; the Dutch Data Protection Authority and affected people are notified where the GDPR requires it.

10

10. Your rights

You may ask for access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting prior lawful processing. Direct-marketing objections are honoured at any time. We normally respond within one month and may ask for proportionate information to verify identity.

11

11. Complaints, children and changes

Please contact iForge first so we can resolve the issue. You also have the right to complain to the Dutch Data Protection Authority or another competent EEA supervisory authority.

The release 1 offer is intended for adults. iForge does not knowingly collect children’s data through the public website.

Material changes are versioned and dated. Where a change affects consent or an existing purpose, iForge will request a new choice before the new processing starts.

REF

Legal references

This statement is based on the GDPR and current guidance. These links lead to the authoritative or supervisory source.