Legal

Data Processing Addendum

Version 2026-08-12 - Effective for all customers on or after this date

1. Purpose and scope

This Data Processing Addendum (“DPA”) forms part of the FormsDock Terms of Service and applies to the extent that FormsDock processes Personal Data on behalf of the Customer in connection with the Service. Capitalized terms not defined here have the meaning given in the Terms or in the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).

2. Roles

The parties acknowledge that, with respect to Personal Data of the Customer's end users processed through the Service, the Customer is the Controller and FormsDock is the Processor.

3. Processor obligations

FormsDock will:

  • Process Personal Data only on documented instructions from the Customer, including with regard to transfers.
  • Ensure that personnel authorized to process Personal Data are bound by confidentiality.
  • Implement the technical and organizational measures listed in Annex II.
  • Engage subprocessors only with the Customer's general authorization and provide a list at /legal/subprocessors.
  • Assist the Customer in fulfilling its obligations to respond to data subject requests.
  • On the Customer's request, delete or return all Personal Data at the end of the provision of the Service.

4. Subprocessors

The Customer provides general authorization for FormsDock to engage subprocessors. FormsDock will notify the Customer at least 14 days before adding or replacing a subprocessor. The Customer may object on reasonable grounds related to data protection; the parties will work in good faith to resolve the objection.

5. International transfers

FormsDock stores Personal Data in the region selected by the Customer during signup. For transfers from the EEA, UK, or Switzerland to a third country, FormsDock relies on the EU Standard Contractual Clauses (Module 2: Controller to Processor) adopted by the European Commission, which are incorporated by reference. A copy of the executed SCCs is available on request.

6. Security incidents

FormsDock will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a Personal Data Breach affecting the Customer's data. The notice will include the information required by Article 33(3) GDPR to the extent it is available.

7. Annex I - Details of the processing

  • Subject matter. Storage, validation, and forwarding of form submissions.
  • Duration. For the term of the Customer's subscription plus a 30-day deletion window.
  • Nature. Collection, storage, transmission, and deletion of end-user-supplied data.
  • Categories of data. Any personal data the Customer chooses to collect via FormsDock forms.
  • Categories of data subjects. The Customer's end users who submit forms.

8. Annex II - Technical and organizational measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Role-based access control with mandatory WebAuthn for administrative actions.
  • Continuous logging with anomaly detection on the ingest path.
  • Quarterly third-party penetration testing; summary reports available on request.
  • Documented incident response runbook with on-call rotation.

9. How to sign

Paid Customers accept this DPA automatically when they accept the FormsDock Terms of Service. To request a countersigned copy, email dpa@formdock.app from the email address associated with your account.