1. Introduction
This Privacy Policy explains how Forum Fortress collects, uses, stores, protects, and deletes personal data when you use our websites, APIs, plugins, software, and related services (the Services).
We are committed to handling personal data in accordance with the UK GDPR, EU GDPR, and other applicable data protection laws.
Where we process data on behalf of customers using our anti-spam and moderation tools, we generally act as a data processor. Where we collect data directly for our own business purposes (such as contact enquiries, support, or account administration), we act as a data controller.
2. Who We Are
Forum Fortress is a privacy-conscious anti-spam and abuse prevention service designed to help online communities reduce spam, fraud, and malicious activity while minimising unnecessary data collection.
For privacy enquiries or data rights requests, please use our privacy request form.
Marscastle Ltd trading as Forum Fortress
Registered in England and Wales.
Registered Office: Suite 37, 15 Montpellier Road, Torquay TQ1 1DL.
Company Registration No. 15029091.
Information Commissioner's Office Registration No. ZC192565.
3. What Personal Data We Process
Depending on how the Services are used, we may process the following categories of personal data.
A. Network and Device Data
- IP address (IPv4 / IPv6)
- Derived subnet information
- ASN / network provider data
- Approximate country or region
- Browser / device metadata
- User-Agent strings
- Referrer information
B. Online Account Identifiers
- Username or forum handle
- Email address
- Site or account identifiers
- Activation codes or API credentials
C. Content and Behavioural Data
- Submitted text content for spam or abuse checks
- Reports of suspicious activity
- Registration attempt metadata
- Signature text or profile fields supplied by customer systems
- URLs or links submitted for analysis
- Moderation outcomes and risk events
D. Derived / Pseudonymous Data
- Hashed usernames
- Hashed email addresses
- Hashed identifiers
- IP subnet reputation signals
- Content fingerprints
- Reputation scores
- Pattern or campaign indicators
E. Website Communications
If you contact us or join the service:
- Name
- Email address
- Message content
- IP address
- Browser metadata
- Referrer
- Website URL (if supplied)
4. How We Use Personal Data
We use personal data for the following purposes:
Security and Abuse Prevention - To detect, block, investigate, and reduce spam, fraud, coordinated abuse, and malicious automation.
Service Delivery - To operate APIs, plugins, accounts, activations, support systems, and customer functionality.
Communications - To respond to enquiries, support requests, and business contact submissions.
Service Improvement - To maintain reliability and improve detection using appropriately minimised information. Customer Personal Data processed as processor is handled on documented instructions; separately determined abuse-prevention processing is described below.
Legal Compliance - To comply with legal obligations, enforce terms, and protect our legitimate interests.
5. Legal Bases for Processing
Where GDPR applies, we rely on one or more of the following lawful bases:
Legitimate Interests - Preventing abuse, securing systems, improving services, and operating our business responsibly.
Contract - Where processing is necessary to provide requested services to customers.
Consent - Where legally required, such as optional marketing communications.
Legal Obligation - Where processing is required by law.
6. Privacy by Design
We aim to reduce unnecessary personal data use wherever practical.
Pseudonymisation - Where suitable, usernames and email addresses may be converted into keyed cryptographic hashes.
Data Minimisation - We aim to retain only the information reasonably required to provide the service and combat abuse.
Link Reduction - Where appropriate, URLs may be reduced to domain or hostname level for analysis.
Limited Decision Logging - Decision records may contain summarised metadata rather than full raw content where possible.
7. Retention of Data
We use different retention periods depending on the type of data and operational need.
Raw event data - Raw IP addresses, email addresses, usernames, user-agent values, submitted content, links and other event details are retained for no more than five (5) days. Allowed events are then completely deleted and create no retained abuse intelligence. Blocked or other qualifying adverse events may retain the decision outcome, reason codes, signal classifications and non-raw technical metadata for the active customer account, but raw identifiers are removed.
Regional edge records - Live request records held at regional edge nodes are normally removed after successful transfer to the UK control plane. Temporary retry or delivery queues remain subject to the five-day raw-data limit above.
Shared abuse-prevention signals - Signals are retained independently and only where customer, site, event, content and cross-identifier attribution has been removed. We do not maintain a queryable cross-forum identity graph or historical email-to-IP relationship. Signals present together in a new request may be combined for that request; that does not establish a stored historical association.
Contact and Business Enquiries - Contact form submissions may be retained for as long as reasonably necessary to respond, maintain correspondence records, or manage legitimate business enquiries.
8. Hosting, Regional Processing and Backups
Core hosting and regional processing
Forum Fortress's control plane, primary databases and authoritative live service data are hosted on infrastructure located in the United Kingdom.
Forum administrators can choose whether live protection checks use the Global API or are locked to Forum Fortress edge servers in the United Kingdom, European Union, or United States. Global routing is the recommended option for maximum speed and resilience. A UK-, EU-, or US-only setting is intended to help with privacy and data-residency requirements: live check data is processed and the automated decision is made in the selected area.
If a forum is locked to a region, Forum Fortress does not use the Global API for that live check unless the administrator explicitly enables global emergency fallback. With that fallback enabled, a regional outage may result in processing outside the selected area. Bootstrap, portal access, account management, and central service administration continue through the UK control plane.
Logged decisions are stored in the central control system in the United Kingdom. Raw personally identifiable fields in those records are retained for no more than five (5) days and then replaced with one-way hashes. Non-raw outcomes, reason codes, and technical metadata may remain under the retention rules in this Policy. Temporary regional queues and edge-held request records remain subject to the same raw-data limit.
Because the Global API, optional fallback, and selected third-party providers may involve locations outside the United Kingdom, we do not claim that all processing takes place in the United Kingdom. A strict regional setting applies to live protection checks, not to every Service function.
Backups
Encrypted backups may temporarily contain historical copies of data pending normal backup rotation cycles.
Backup data is maintained for disaster recovery, resilience, and service continuity purposes only. It is access-restricted and is not routinely used for profiling, moderation decisions, or day-to-day operational analysis.
Vultr automatic backups are normally retained for approximately 14 days, and deleted data may remain in the overall backup rotation for up to 60 days. Marscastle also controls an offline UK backup. An additional encrypted backup is stored in Backblaze B2 EU Central (Amsterdam).
If a disaster restoration is required, completed deletion instructions are reapplied before normal service resumes.
9. Automated Decision Making
Our systems may automatically classify events such as registrations, posts, or reports into outcomes such as:
- allow;
- block; or
- reject where supported by the connected forum software.
These decisions are based on risk signals such as reputation, behavioural patterns, submitted indicators, and network intelligence.
Customers remain responsible for configuring how their forum software applies allowed or blocked outcomes.
AI-assisted support
We use configured ElevenLabs AI agents for AI-assisted portal chat, ticket and telephone support. Caller CLI may be included in the telephone-support workflow. The Forum Fortress control plane remains authoritative for verification, account context, decision-log access, knowledge grounding and support actions. Support transcripts and interaction metadata are retained under the configured Forum Fortress support-retention policy; provider-side retention and processing follow the active ElevenLabs account and service terms.
Telephone support
Support calls are recorded locally on Forum Fortress FusionPBX. Recordings are normally deleted after 30 days; transcripts and call metadata may remain for the account lifetime. A recording may be held longer for a documented complaint, dispute, security incident or legal requirement. AAISP carries call audio and routing metadata. No voicemail is enabled.
Transactional email and billing
MXroute is used for essential verification, reset, login, security and generic support-reply notifications. Support-response bodies and forum-user data are not sent in routine email. Customers enter payment details directly into Stripe; Forum Fortress does not store complete card details, and Stripe receives billing/subscription references rather than forum-user data or decision logs.
10. Sharing of Data
We do not sell personal data.
We may share data only where reasonably necessary with:
- hosting and infrastructure providers;
- technical service providers;
- security and fraud-prevention partners;
- professional advisers;
- regulators or law enforcement where legally required; and
- customers where we process data on their behalf.
Data Processing Addendum
Where Forum Fortress processes personal data on behalf of a forum, the Forum Fortress Standard Data Processing Addendum forms part of the service agreement. It is available on every plan and does not require a separate wizard before installation or protection starts. You can create a named acceptance record and download an acceptance certificate from the Privacy section of the portal.
Current providers
Our versioned provider register distinguishes customer-data subprocessors from other providers. The public register is factual; internal contract-review status is not shown here.
| Provider | Role and purpose | Location/retention note |
|---|---|---|
| Vultr | Processor/subprocessor — UK control-plane hosting, primary databases and application services; regional edge APIs and processing; automatic backups; and selected serverless inference for one-sentence decision summaries. | Forum Fortress’s control plane, primary databases and authoritative live service data are hosted in the United Kingdom. Regional edge nodes operate from selected Vultr locations internationally, close to customer origins. Live edge request records are removed after successful transfer to the UK control plane, subject to temporary delivery retries and applicable backup rotation. Vultr serverless inference receives only the minimum decision/reason information needed for the short summary; raw identifiers and submitted content are excluded. |
| ElevenLabs | Processor/subprocessor for configured AI customer-service conversations — Configured Forum Fortress AI support agents for telephone, web chat and ticket conversation, including provider transcription and agent analysis where enabled. | According to the active ElevenLabs account, service configuration and current subprocessor arrangements. The control plane remains authoritative for verification, account context, entitlements, knowledge grounding and state-changing actions. |
| Backblaze | Processor/subprocessor for encrypted disaster-recovery backups — Encrypted off-site disaster-recovery backup storage using Backblaze B2 EU Central. | B2 EU Central, Amsterdam, Netherlands. Backups are for disaster recovery and restoration, not routine querying or decision-making. |
| Andrews & Arnold / AAISP | Processor for transmitted support-call data and independent controller for own operations — Telephone-number provision, SIP connectivity and support-call carriage. | United Kingdom, subject to ordinary telecommunications routing and interconnection. No AAISP voicemail or deliberately enabled AAISP recording feature is used. |
| ProxyCheck.io | Conditional processor/subprocessor for IP-only network-risk enrichment — Proxy, VPN, hosting and network-risk enrichment for the current IP lookup. | International/provider-operated global CDN infrastructure No customer, site, domain, event, email, username or content metadata is sent. |
| Stripe | Payment processor and independent controller for regulated payment activities — Subscriptions, billing, payments, invoices, refunds, chargebacks and payment-fraud/legal compliance. | According to Stripe's current service and subprocessor arrangements. Payment details are entered directly into Stripe; Forum Fortress does not store complete card details and does not send forum-user data or decision logs. |
| MXroute | Processor for Marscastle-controlled account and essential support communications — Verification, password reset, passwordless login, security/account messages and generic support-reply notifications. | United States Support-response bodies and forum-user/decision data are not sent by routine notification email. |
11. International Transfers
Where data is transferred outside the UK or EEA, we use appropriate safeguards where required. Provider-specific contractual status and transfer details are reviewed in the versioned register; we do not claim that every pending provider agreement has already been signed.
12. Security
We use reasonable technical and organisational safeguards including:
- access controls;
- encryption in transit;
- restricted administrative access;
- pseudonymisation where practical;
- logging and monitoring;
- retention controls; and
- secure hosting practices.
No internet service can guarantee absolute security, but we take protection seriously.
13. Your Rights
Depending on your jurisdiction, you may have rights to:
- request access to your personal data;
- request correction of inaccurate data;
- request deletion of data;
- object to certain processing;
- restrict processing;
- request portability where applicable; and
- complain to a relevant supervisory authority.
Where we act solely as processor for a customer, requests may need to be directed to that customer first.
Use the privacy request form for access, rectification, erasure, objection, restriction, signal review or a data-protection complaint. We acknowledge complaints within 30 days and investigate without undue delay. You may also complain to the UK Information Commissioner's Office.
14. Cookies and Website Technologies
Our website may use essential cookies or similar technologies required for security, session handling, spam prevention, and core functionality.
We do not use unnecessary tracking technologies unless we state otherwise.
15. Children
Our Services are not directed at children under 13 (or any higher minimum age required by local law). We do not knowingly collect personal data from children without lawful basis.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the “Last updated” date.
17. Customer Responsibilities
Customers using Forum Fortress remain responsible for ensuring they have an appropriate lawful basis to submit user data to us and for providing any privacy notices required to their own users.
18. Contact
For privacy enquiries, requests, or complaints, please use the privacy request form.
Marscastle Ltd trading as Forum Fortress
Registered in England and Wales.
Registered Office: Suite 37, 15 Montpellier Road, Torquay TQ1 1DL.
Company Registration No. 15029091.
Information Commissioner's Office Registration No. ZC192565.