MightyForms is now part of FormBuilder.AnnouncementMightyForms login
MightyForms is now part of FormBuilder.AnnouncementMightyForms login

Data Processing Agreement

Standard Contractual Terms for Data Processing under GDPR

Note: This Data Processing Agreement ("DPA") is automatically incorporated into the Terms of Service for all business customers processing personal data through FormBuilder.

1. Definitions

Controller: The entity that determines the purposes and means of processing personal data

Processor: FormBuilder, processing personal data on behalf of the Controller

Data Subject: An identified or identifiable natural person

Personal Data: Any information relating to a Data Subject

Processing: Any operation performed on Personal Data

2. Scope and Roles

2.1 This DPA applies when Customer (Controller) uses FormBuilder services (Processor) to process Personal Data.

2.2 The parties acknowledge that:

  • Customer is the Controller of Personal Data
  • FormBuilder is the Processor acting on Customer's behalf
  • FormBuilder shall process Personal Data only per Customer's documented instructions

3. Processing Details

Nature and Purpose:

Form creation, data collection, storage, and management services

Duration:

For the duration of the Customer's subscription

Types of Personal Data:

  • Contact information (names, emails, phone numbers)
  • Form response data as determined by Customer
  • IP addresses and technical identifiers
  • Any other data Customer collects via forms

Categories of Data Subjects:

  • Customer's end users
  • Customer's employees
  • Customer's clients/customers
  • Other individuals as determined by Customer

4. Processor Obligations

FormBuilder shall:

  • Process Personal Data only on documented instructions from Customer
  • Ensure persons authorized to process Personal Data are bound by confidentiality
  • Implement appropriate technical and organizational measures
  • Assist Customer in responding to data subject requests
  • Assist Customer in ensuring compliance with Articles 32-36 GDPR
  • Delete or return all Personal Data after services end
  • Make available information necessary to demonstrate compliance
  • Notify Customer of any legally required disclosure of Personal Data

5. Technical and Organizational Measures

Access Control

Multi-factor authentication, role-based access, secure passwords

Data Encryption

TLS 1.3 in transit, AES-256 at rest

System Security

Firewalls, intrusion detection, regular security updates

Incident Management

24/7 monitoring, incident response procedures, breach notification

Physical Security

Cloudflare infrastructure with independently audited security controls

Backup and Recovery

Regular backups, disaster recovery procedures, data redundancy

6. Sub-processors

6.1 Customer authorizes FormBuilder to engage sub-processors listed at formbuilder.com/subprocessors

6.2 FormBuilder shall:

  • Impose data protection obligations on sub-processors
  • Remain liable for sub-processor compliance
  • Notify Customer of sub-processor changes with 30 days notice

7. International Transfers

7.1 FormBuilder may transfer Personal Data outside the EEA only with:

  • EU Standard Contractual Clauses
  • Adequacy decision by the European Commission
  • Other valid transfer mechanism under GDPR

7.2 Primary data processing occurs in US data centers with appropriate safeguards.

8. Data Subject Rights

8.1 FormBuilder shall assist Customer in fulfilling data subject requests for:

  • Access to personal data
  • Rectification or erasure
  • Restriction of processing
  • Data portability
  • Objection to processing

8.2 FormBuilder shall forward data subject requests to Customer without undue delay.

9. Security Breach Notification

9.1 FormBuilder shall notify Customer without undue delay after becoming aware of a personal data breach.

9.2 Notification shall include:

  • Nature of the breach
  • Categories and number of data subjects affected
  • Categories and number of records affected
  • Likely consequences
  • Measures taken or proposed

10. Audit Rights

10.1 FormBuilder shall make available information necessary to demonstrate compliance.

10.2 Customer may exercise audit rights through:

  • Annual SOC 2 Type II reports
  • ISO 27001 certification
  • Security questionnaires
  • On-site audits (with 30 days notice and reasonable scope)

11. Data Return and Deletion

11.1 Upon termination, FormBuilder shall, at Customer's choice:

  • Return all Personal Data in standard format
  • Delete all Personal Data and certify deletion

11.2 Data export available for 30 days post-termination.

12. Liability and Indemnification

12.1 Liability shall be as set forth in the Terms of Service.

12.2 Each party shall indemnify the other against damages arising from their breach of GDPR.

13. Contact Information

Data Protection Officer:

Email: [email protected]

Response time: Within 48 hours

Effective Date: August 19, 2026

This DPA is incorporated by reference into the FormBuilder Terms of Service.

We use necessary cookies to run FormBuilder and optional analytics cookies to understand site usage. You can accept analytics cookies or keep only necessary cookies.