Privacy Policy
Effective date: July 27, 2026 · Last updated: July 28, 2026
1. Who this policy covers
This Privacy Policy applies to FORA (the "Service"), operated by FORA Field Solutions ("FORA," "we," "us"). FORA is provided to companies on a business-to-business basis. Each company that subscribes (a "Customer") controls its own workers', supervisors', and administrators' access via company login codes or an individual roster of names and PINs.
If you are a worker, supervisor, or admin using FORA through your employer's account, your employer is the data controller for the information you submit, and this policy describes how FORA, as processor/service provider, handles that data on your employer's behalf. Questions about your specific employer's use of FORA should first go to your employer.
2. Information we collect
2.1 Account & roster information
- Company name, contact name, email address, phone number, and business address, collected during onboarding.
- Company login code(s), or — for companies using individual roster login — each worker's and supervisor's name and 4-digit PIN.
- Role (worker, supervisor, admin) and plan tier (Basic or Advanced).
2.2 Content you submit
- Standard operating procedures (SOPs) and equipment or site lists uploaded by a company.
- Voice recordings and/or text descriptions of tasks, incidents, or near misses, submitted to generate Field Level Hazard Assessments (FLHAs), toolbox talks, incident reports, near miss reports, equipment inspections, daily reports, monthly site inspections, and custom documents.
- Any information a worker or supervisor types or dictates into a form, including descriptions of workplace events, which may in some cases describe an injury or health-related incident.
- Photos or attachments, where a form supports them.
2.3 Usage & technical information
- Log data such as login timestamps, IP address, browser/device type, and pages or actions taken in the app.
- Session tokens used to keep you signed in and to authorize each request against our servers.
- Master-code login activity, which is logged for security and audit purposes.
2.4 Payment information
Subscription payments are handled by Stripe, our payment processor. We do not receive or store full payment card numbers — Stripe collects and processes that information directly under its own privacy policy.
3. How we use information
- To provide the Service: authenticate logins, generate AI-assisted safety documents, store and display submissions, and power the Supervisor Dashboard and Admin Panel.
- To cross-reference task descriptions against a company's own uploaded SOPs and equipment so that generated documents reflect that company's actual procedures.
- To operate, maintain, and secure the Service, including detecting misuse of login codes and auditing master-code access.
- To communicate with Customers about their account, billing, onboarding, and support.
- To improve the Service, including understanding which document types and features are used.
- To comply with legal obligations and enforce our Terms of Use.
We do not sell personal information, and we do not use Customer or User content to serve third-party advertising.
4. AI processing
When a worker or supervisor generates a document (for example, an FLHA), the task description and relevant excerpts of the company's SOPs are sent to Anthropic's Claude API to produce the hazards, controls, PPE, and compliance suggestions returned to the user. This transmission is limited to what's needed to generate that specific document. Anthropic processes this data as our sub-processor and under its own data-handling terms for API customers; it is not used to train Anthropic's foundation models under those terms.
5. Who we share information with
We share information only as needed to run the Service, with the following categories of service providers ("sub-processors"):
- Supabase — database hosting and file storage for all Customer and User data.
- Vercel — application hosting and the serverless functions that process every request.
- Anthropic — AI processing of task descriptions and SOP excerpts to generate documents, as described in Section 4.
- Stripe — payment processing for subscription billing.
Within a Customer's own account, submissions are visible to that Customer's supervisors and admins as intended by the Service's design (e.g., the Supervisor Dashboard). Data is walled off between companies: one Customer's data, forms, and users are isolated from every other Customer's.
We may also disclose information if required by law, to protect the rights, property, or safety of FORA, our Customers, or others, or in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections.
6. Data security
- Every request to our serverless functions is checked against a signed, server-verified session before it can touch any data.
- Row Level Security is enabled on every database table as a deny-by-default backstop — there are no bypass policies, so direct access with a public key is refused.
- Login codes and PINs are used to authenticate Users; Customers are responsible for managing their own roster and code confidentiality, and can deactivate a person's access immediately from the Admin Panel.
- Master-code logins (used for administrative support) are logged and auditable.
No method of transmission or storage is 100% secure. We work to protect information using the measures above, but cannot guarantee absolute security.
If we become aware of a breach of security safeguards involving personal information under our control that creates a real risk of significant harm, we will notify affected Customers and any regulator to whom notification is legally required (including, where applicable, the Office of the Privacy Commissioner of Canada and/or the Information and Privacy Commissioner of Alberta) without unreasonable delay, and will provide the information reasonably necessary for the Customer to notify its own affected individuals where the Customer is responsible for doing so.
7. Data retention
We retain Customer and User data for as long as a Customer's account is active, and for a reasonable period afterward to allow for account recovery, comply with legal or safety record-keeping obligations, resolve disputes, and enforce agreements. A Customer may request deletion of its account data by contacting us; some information may be retained where required by law or legitimate business record-keeping needs (for example, incident and near-miss records that a Customer is independently obligated to retain).
8. Your rights
FORA Field Solutions operates in Alberta, Canada, and handles personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA). Depending on where you or your company are located, other privacy laws (such as the EU/UK GDPR or U.S. state privacy laws) may also give you rights to access, correct, export, or request deletion of personal information, or to object to or restrict certain processing. Because FORA is provided on a business-to-business basis, workers and supervisors should generally direct these requests to their employer (the Customer, who controls the account); Customers and admins can also contact us directly at forafieldsolutions@gmail.com and we will respond within a reasonable time, and in any event within any timeframe required by applicable law.
9. International data transfers
Our service providers (Supabase, Vercel, Anthropic, Stripe) may process and store data in the United States or other countries outside your own. By using the Service, you understand that your information may be transferred to and processed in countries with data protection laws different from those in your jurisdiction.
10. Children's privacy
FORA is a workplace tool intended for use by employees of subscribing companies and is not directed to, or intended for use by, children. We do not knowingly collect personal information from anyone under the minimum working age in their jurisdiction.
11. Cookies & similar technologies
The app uses session storage/tokens necessary to keep you logged in and to authorize your requests. We do not currently use third-party advertising or cross-site tracking cookies within the application itself. Our public marketing site may load fonts from Google Fonts, which can involve a connection to Google's servers.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify Customers. Continued use of the Service after a change becomes effective constitutes acceptance of the revised policy.
13. Contact us
Questions about this Privacy Policy or how your information is handled can be sent to forafieldsolutions@gmail.com.