Privacy Policy
Effective date: July 27, 2026 · Last updated: September 30, 2026
1. Who this policy covers
This Privacy Policy applies to FORA (the "Service"), operated by FORA Field Solutions ("FORA," "we," "us"). FORA is provided to companies on a business-to-business basis. Each company that subscribes (a "Customer") controls its own workers' and supervisors' access via company login codes or an individual roster of names and PINs.
If you are a worker or supervisor using FORA through your employer's account, your employer is the data controller for the information you submit, and this policy describes how FORA, as processor/service provider, handles that data on your employer's behalf. Questions about your specific employer's use of FORA should first go to your employer.
2. Information we collect
2.1 Account & roster information
- Company name, contact name, email address, phone number, and business address, collected during onboarding.
- Company login code(s), or (for companies using individual roster login) each person's name and 6-digit PIN. For people who sign in with an authenticator app, we also store an encrypted authenticator key and hashed one-time backup codes.
- Role (worker, supervisor or account owner), job title, department and division tags, default site, and plan tier (Basic or Advanced).
2.2 Content you submit
- Standard operating procedures (SOPs) and equipment or site lists uploaded by a company.
- Voice recordings and/or text descriptions of tasks, incidents, or near misses, submitted to generate Field Level Hazard Assessments (FLHAs), toolbox talks, incident reports, near miss reports, equipment inspections, daily reports, monthly site inspections, and custom documents.
- Any information a worker or supervisor types or dictates into a form, including descriptions of workplace events, which may in some cases describe an injury or health-related incident.
- Photos or attachments, where a form supports them.
2.3 Usage & technical information
- Log data such as login timestamps, IP address, browser/device type, and pages or actions taken in the app.
- Session tokens used to keep you signed in and to authorize each request against our servers.
- Master-code login activity, which is logged for security and audit purposes.
2.4 Payment information
Subscription payments are handled by Stripe, our payment processor. We do not receive or store full payment card numbers. Stripe collects and processes that information directly under its own privacy policy.
3. How we use information
- To provide the Service: authenticate logins, generate AI-assisted safety documents, store and display submissions, and power the Supervisor Dashboard and our internal account-management tools.
- To cross-reference task descriptions against a company's own uploaded SOPs and equipment so that generated documents reflect that company's actual procedures.
- To operate, maintain, and secure the Service, including detecting misuse of login codes and auditing master-code access.
- To communicate with Customers about their account, billing, onboarding, and support.
- To improve the Service, including understanding which document types and features are used.
- To comply with legal obligations and enforce our Terms of Use.
We do not sell personal information, and we do not use Customer or User content to serve third-party advertising.
4. AI processing
When a worker or supervisor generates a document (for example, an FLHA), the task description and relevant excerpts of the company's SOPs are sent to Anthropic's Claude API to produce the hazards, controls, PPE, and compliance suggestions returned to the user. This transmission is limited to what's needed to generate that specific document. Anthropic processes this data as our sub-processor and under its own data-handling terms for API customers; it is not used to train Anthropic's foundation models under those terms.
5. Who we share information with
We share information only as needed to run the Service, with the following categories of service providers ("sub-processors"):
- Supabase: database hosting and file storage for all Customer and User data.
- Vercel: application hosting and the serverless functions that process every request.
- Anthropic: AI processing of task descriptions and SOP excerpts to generate documents, as described in Section 4.
- Stripe: payment processing for subscription billing.
Within a Customer's own account, submissions are visible to that Customer's supervisors as intended by the Service's design (e.g., the Supervisor Dashboard). Data is walled off between companies: one Customer's data, forms, and users are isolated from every other Customer's.
We may also disclose information if required by law, to protect the rights, property, or safety of FORA, our Customers, or others, or in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections.
6. Data security
- Every request to our serverless functions is checked against a signed, server-verified session before it can touch any data.
- Row Level Security is enabled on every database table as a deny-by-default backstop. There are no bypass policies, so direct access with a public key is refused.
- Login codes and PINs are used to authenticate Users; Customers are responsible for managing their own roster and code confidentiality, and can request that FORA deactivate a person's access immediately.
- FORA's own privileged support access (used for account support) requires two-factor authentication in addition to a long, separately-secured code, and every use of it is logged and auditable.
- Privileged actions taken on a Customer's account (such as changes to plan tier, login codes, or company records) are recorded in an internal audit log.
- Files a Customer uploads or a User submits (such as attachments and generated documents) are stored separated by company in our file storage.
No method of transmission or storage is 100% secure. We work to protect information using the measures above, but cannot guarantee absolute security.
If we become aware of a breach of security safeguards involving personal information under our control that creates a real risk of significant harm, we will notify affected Customers and any regulator to whom notification is legally required (including, where applicable, the Office of the Privacy Commissioner of Canada and/or the Information and Privacy Commissioner of Alberta) without unreasonable delay, and will provide the information reasonably necessary for the Customer to notify its own affected individuals where the Customer is responsible for doing so.
7. Data retention
We retain Customer and User data for as long as a Customer's account is active. After a Customer's subscription ends:
- Safety documentation (FLHAs, toolbox talks, equipment inspections, near miss and incident reports, daily reports, monthly site inspections, custom documents), equipment records, and time clock reports are retained for 3 years, so they remain available if needed for a post-termination safety inquiry, audit, or a Customer's own longer regulatory record-keeping obligation.
- Roster/personnel data and company configuration (SOPs, sites, custom fields and forms) are deleted within 90 days.
- Where a Customer's own applicable occupational health and safety regulation requires longer retention of any of the above, we will retain that Customer's data for the longer period on request made before its subscription ends.
A Customer may request earlier deletion of its roster or configuration data at any time; safety documentation subject to the retention period above is not deleted early on request, since that would undermine the recordkeeping purpose it exists for. Some information may still be retained beyond these periods where required by law or to resolve a dispute already in progress.
8. Your rights
FORA Field Solutions operates in Alberta, Canada, and handles personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA). Depending on where you or your company are located, other privacy laws (such as the EU/UK GDPR or U.S. state privacy laws) may also give you rights to access, correct, export, or request deletion of personal information, or to object to or restrict certain processing. Because FORA is provided on a business-to-business basis, workers and supervisors should generally direct these requests to their employer (the Customer, who controls the account); Customers can also contact us directly at forafieldsolutions@gmail.com and we will respond within a reasonable time, and in any event within any timeframe required by applicable law.
9. International data transfers
Our service providers (Supabase, Vercel, Anthropic, Stripe) may process and store data in the United States or other countries outside your own. By using the Service, you understand that your information may be transferred to and processed in countries with data protection laws different from those in your jurisdiction.
10. Children's privacy
FORA is a workplace tool intended for use by employees of subscribing companies and is not directed to, or intended for use by, children. We do not knowingly collect personal information from anyone under the minimum working age in their jurisdiction.
11. Cookies & similar technologies
The app uses session storage/tokens necessary to keep you logged in and to authorize your requests. We do not currently use third-party advertising or cross-site tracking cookies within the application itself. Our public marketing site may load fonts from Google Fonts, which can involve a connection to Google's servers.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify Customers. Continued use of the Service after a change becomes effective constitutes acceptance of the revised policy.
13. Contact us
Questions about this Privacy Policy or how your information is handled can be sent to forafieldsolutions@gmail.com.