1. Parties, scope and roles
This Data Processing Agreement ("DPA") forms part of the Formglide Terms of Service between the Customer that holds the Formglide account and DIGITALIZER LTD, trading as Formglide, company number 15267581, registered office 2nd Floor, Unicorn House, Station Close, Potters Bar, Hertfordshire, EN6 1TL, United Kingdom ("Formglide"). It applies to personal data that Formglide processes on the Customer's behalf in providing the Service ("Customer Personal Data"). It takes effect when the Customer accepts the Terms; no separate signature is needed.
Roles. The Customer is the controller of Customer Personal Data and Formglide is its processor. Where the Customer is itself a processor for a client (for example, an agency running forms in a Client Workspace for a client who decides how the data is used), Formglide is the Customer's sub-processor. The Customer confirms that it has its client's authority to use Formglide on these terms, and passes on its client's instructions through its own use of the Service. Formglide does not take instructions directly from the Customer's clients and will refer any it receives to the Customer.
Formglide's own processing. Formglide is a controller, not a processor, for account administration, billing and support, and for the security and abuse-prevention processing it carries out for its own purposes: bot checks, rate limits, the automated phishing check at publish, handling abuse reports, and taking down forms or suspending Workspaces. That processing is described in the Privacy Policy and is outside this DPA. It does not allow Formglide to use Customer Personal Data for marketing or profiling.
Data protection law means the UK GDPR, the Data Protection Act 2018, the EU GDPR where it applies, and other laws that apply to this processing. Terms such as controller, processor, personal data and personal data breach have the meanings given in that law.
2. Details of the processing
- Subject matter: personal data collected through forms the Customer publishes with the Service, and the related features the Customer sets up.
- Duration: while the Customer uses the Service, plus the return and deletion period in section 10.
- Nature: hosting, storage, transmission, display, analysis for features the Customer turns on, email delivery of notifications and tickets, ticket check-in, export, sending data to integrations the Customer sets up, and deletion.
- Purpose: letting the Customer collect, view, analyse and export responses, issue and check in event tickets, and use the features it configures.
Data subjects: Respondents to the Customer's forms, including Ticket Holders; people named in responses, where a form asks about them; and the Customer's Members, where they appear in operational records such as ticket check-ins.
Categories of personal data:
| Category | What it includes |
|---|---|
| Answers | Whatever the Customer's forms ask, including partial answers where the Customer turns on partial capture, and uploaded files |
| Submission details | Page address, referring page, campaign (UTM) parameters, hidden-field values, device label, browser user agent, A/B version shown, the Respondent's tracking choice where asked, and Meta and Google Analytics browser identifiers where those tools run on the form |
| Network data | The Respondent's IP address, used at submission for rate limits and the bot check and stored only as a one-way hash with the response |
| Form events | A random respondent key and the views, steps and submissions recorded against it |
| Tickets | Holder name and email, tier, ticket code, status, check-in time and the Member who checked it in |
| Integration output | Answers and submission details sent to integrations the Customer sets up, as described in the Privacy Policy |
Special category data. The Customer must not collect special category or criminal offence data without Formglide's prior written agreement. If such data is collected anyway, it remains protected by this DPA.
3. Instructions and confidentiality
Formglide processes Customer Personal Data only on the Customer's documented instructions, including about international transfers. The Customer's instructions are this DPA, the Terms, and the Customer's settings and use of the Service. If the law requires Formglide to process Customer Personal Data in another way, Formglide will tell the Customer first, unless the law prohibits that.
Formglide will tell the Customer promptly if, in its opinion, an instruction breaks data protection law, and may decline to follow that instruction until it is resolved.
Everyone Formglide authorises to process Customer Personal Data is bound by confidentiality and has access only as needed. Formglide will not sell Customer Personal Data, use it for its own marketing or profiling, or combine it across customers for unrelated purposes.
4. The Customer's responsibilities
The Customer will:
- have a lawful basis for the processing, and give Respondents clear information about who it is and how it uses their data before they answer, including on white-labelled forms;
- tell Respondents before they start if partial capture is on, and explain that ticket links work for anyone who has them;
- obtain any consent its tracking requires. Hosted forms show Respondents a consent banner before the Customer's Meta or Google tracking runs; if the Customer turns the banner off, obtaining consent is its responsibility;
- have its own arrangements with the integrations it sets up, which receive data as its recipients, not as Formglide's sub-processors;
- decide who has access to its Workspaces (all Members of a Workspace can see its forms, responses, files, tickets and integration settings, and Members of an agency Workspace can see its Client Workspaces), and remove access when it is no longer needed.
5. Help with rights requests and compliance
Formglide will help the Customer, as far as reasonably possible, to respond to Respondents exercising their data protection rights. If Formglide receives a request about Customer Personal Data, it will pass it to the Customer without undue delay and will not respond itself unless the Customer authorises it or the law requires it. The Customer can export responses as CSV and delete responses itself; where the export does not include data the Customer needs, such as uploaded files, Formglide will help.
Formglide will also help the Customer with its obligations on security, breach notification, data protection impact assessments and consultation with regulators, taking into account the nature of the processing and the information available to Formglide.
6. Security
Formglide will put in place and maintain appropriate technical and organisational measures to protect Customer Personal Data, taking into account the risks, the nature of the data and the state of the art. The current measures are listed in Schedule 2. Formglide may update them, but will not reduce the overall level of protection. Formglide holds no security certification such as ISO 27001 or SOC 2.
7. Sub-processors
The Customer gives Formglide general authorisation to use the sub-processors listed in Schedule 1. Formglide will bind each sub-processor to data protection obligations equivalent to those in this DPA and remains responsible to the Customer for their performance.
Formglide will email the Customer's owners at least 30 days before a new sub-processor starts processing Customer Personal Data, saying who it is, what it will do and where. The Customer may object on reasonable data protection grounds during that time. If we cannot find a reasonable solution together, the Customer may end the affected service before the change takes effect, with a refund of prepaid fees for the unused period and help with return or deletion of its data.
8. International transfers
Formglide's application servers and primary database are in Frankfurt, Germany. Formglide's sub-processors are based outside the UK, and some of their processing, such as request routing, security services, email delivery and support, can take place in other countries, including the United States. Where Customer Personal Data is transferred outside the UK, the transfer is covered by those providers' standard data protection terms. The Customer can ask Formglide for more information about these safeguards.
9. Personal data breaches
Formglide will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Formglide will not delay a first notice to collect every detail. The notice goes to the Customer's account owners by email and will describe, as far as known, what happened, the categories and approximate number of people and records affected, the likely consequences, what Formglide has done or will do about it, and who to contact. Formglide will give further information as it becomes available, preserve relevant evidence and help the Customer with any notifications it must make. The Customer decides whether to notify regulators and individuals, unless the law requires Formglide to do so.
10. Return and deletion
During the Service. The Customer can export responses as CSV and delete responses, forms, Workspaces and its account at any time. A deletion made by the Customer is an instruction to delete straight away, and the data cannot be recovered. Uploaded files are stored separately from the database and are removed by a separate clean-up process.
When the Service ends. If Formglide ends or closes the Customer's account (rather than the Customer deleting it), the Customer can ask Formglide for an export of Customer Personal Data for 30 days after closure. Where the Customer cannot sign in, for example because its Workspace is suspended, Formglide will provide the export on request, unless that would be unlawful or create a security risk, in which case Formglide will arrange a safe alternative where it can. Formglide then deletes Customer Personal Data from its active systems within 30 days, unless the law requires it to keep some of it, in which case Formglide will tell the Customer where it lawfully can, keep only what is required and use it only for that purpose.
Copies outside Formglide's systems. Deleted data can remain in Formglide's database provider's backups for a short period until those backups expire, during which it is not used. Emails already delivered and data already sent to integrations the Customer set up are outside Formglide's control. On request, Formglide will confirm when deletion is complete.
11. Information and audits
Formglide will make available the information reasonably needed to show that it meets its obligations under this DPA, and will allow and contribute to audits, including inspections by the Customer or an independent auditor it appoints. Formglide may first answer with written information where that is enough. Inspections need 30 days' notice and may take place no more than once a year, except after a personal data breach, where a regulator requires it, or where there is a genuine concern about compliance. Auditors must keep information confidential and must not compromise other customers' data or the security of the Service. Each party bears its own costs of an audit.
12. Liability and precedence
Each party's liability under this DPA is subject to the limits in section 16 of the Terms, including the separate limit for data protection claims. Nothing limits individuals' rights or regulators' powers under data protection law. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. Changes to this DPA follow the change process in the Terms.
Schedule 1: Sub-processors
| Sub-processor | What it does | Location |
|---|---|---|
| Vercel | Hosting: runs the Service's server code, through which all Customer Personal Data passes | Server code runs in Frankfurt, Germany. Static files and request routing use Vercel's global network |
| Neon | Database: stores all Customer Personal Data except uploaded files | Amazon Web Services, Frankfurt, Germany |
| Cloudflare | File storage (R2) for uploaded files; the Turnstile bot check on hosted forms; domain name service | R2 has a Western Europe location preference, which is not a guarantee that files stay in Europe. Turnstile and DNS run on Cloudflare's global network |
| Resend | Email delivery, including response notifications and event tickets, which can contain answers and ticket details | Provider based in the United States |
| Google Workspace | Formglide's email. Receives Customer Personal Data only where it is included in a message to Formglide, such as a support request | Google's global infrastructure |
Stripe handles Formglide's subscription billing. It receives billing details about the Customer, which Formglide processes as controller under its Privacy Policy. It receives no Customer Personal Data from forms, because payments inside forms are not currently offered.
Schedule 2: Security measures
- The Service's application servers and primary database run in Frankfurt, Germany. All traffic to the Service uses HTTPS.
- Passwords are stored only as hashes. In production, session cookies are Secure, HttpOnly and SameSite=Lax.
- Access to Workspace data is checked on the server.
- Account holders must verify their email address before they can publish forms, invite teammates or send notification and ticket emails. Response notification emails can only go to Members of the Workspace.
- Uploaded files go directly to storage using signed upload links that expire after 15 minutes and are limited by size and file type. Downloads are available only to signed-in Workspace Members, through links that expire after 5 minutes and always download rather than open.
- Invitation links are stored only as one-way hashes. Ticket links use long random tokens. Outgoing webhooks are signed with HMAC-SHA256.
- Cloudflare Turnstile checks for bots on hosted forms, sign-up, sign-in, password reset and the report page. Form submissions and uploads are rate-limited by IP address, and sign-up, sign-in and password reset are rate-limited through the database. These measures reduce automated abuse; they are not guarantees.
- Formglide administrator access is limited to named accounts. Viewing an account as its user, changing a plan, deleting an account, and moderation actions are logged with the administrator's identity and the time.
- Published forms are checked automatically for signs of phishing, and every hosted form carries a "Report abuse" link.
- Payment card details are collected only by Stripe.