Data Processing Agreement
Standard Contractual Terms for Data Processing under GDPR
Note: This Data Processing Agreement ("DPA") is automatically incorporated into the Terms of Service for all business customers processing personal data through FormBuilder.
1. Definitions
Controller: The entity that determines the purposes and means of processing personal data
Processor: FormBuilder, processing personal data on behalf of the Controller
Data Subject: An identified or identifiable natural person
Personal Data: Any information relating to a Data Subject
Processing: Any operation performed on Personal Data
2. Scope and Roles
2.1 This DPA applies when Customer (Controller) uses FormBuilder services (Processor) to process Personal Data.
2.2 The parties acknowledge that:
- Customer is the Controller of Personal Data
- FormBuilder is the Processor acting on Customer's behalf
- FormBuilder shall process Personal Data only per Customer's documented instructions
3. Processing Details
Nature and Purpose:
Form creation, data collection, storage, and management services
Duration:
For the duration of the Customer's subscription
Types of Personal Data:
- Contact information (names, emails, phone numbers)
- Form response data as determined by Customer
- IP addresses and technical identifiers
- Any other data Customer collects via forms
Categories of Data Subjects:
- Customer's end users
- Customer's employees
- Customer's clients/customers
- Other individuals as determined by Customer
4. Processor Obligations
FormBuilder shall:
- Process Personal Data only on documented instructions from Customer
- Ensure persons authorized to process Personal Data are bound by confidentiality
- Implement appropriate technical and organizational measures
- Assist Customer in responding to data subject requests
- Assist Customer in ensuring compliance with Articles 32-36 GDPR
- Delete or return all Personal Data after services end
- Make available information necessary to demonstrate compliance
- Notify Customer of any legally required disclosure of Personal Data
5. Technical and Organizational Measures
Access Control
Multi-factor authentication, role-based access, secure passwords
Data Encryption
TLS 1.3 in transit, AES-256 at rest
System Security
Firewalls, intrusion detection, regular security updates
Incident Management
24/7 monitoring, incident response procedures, breach notification
Physical Security
Cloudflare infrastructure with independently audited security controls
Backup and Recovery
Regular backups, disaster recovery procedures, data redundancy
6. Sub-processors
6.1 Customer authorizes FormBuilder to engage sub-processors listed at formbuilder.com/subprocessors
6.2 FormBuilder shall:
- Impose data protection obligations on sub-processors
- Remain liable for sub-processor compliance
- Notify Customer of sub-processor changes with 30 days notice
7. International Transfers
7.1 FormBuilder may transfer Personal Data outside the EEA only with:
- EU Standard Contractual Clauses
- Adequacy decision by the European Commission
- Other valid transfer mechanism under GDPR
7.2 Primary data processing occurs in US data centers with appropriate safeguards.
8. Data Subject Rights
8.1 FormBuilder shall assist Customer in fulfilling data subject requests for:
- Access to personal data
- Rectification or erasure
- Restriction of processing
- Data portability
- Objection to processing
8.2 FormBuilder shall forward data subject requests to Customer without undue delay.
9. Security Breach Notification
9.1 FormBuilder shall notify Customer without undue delay after becoming aware of a personal data breach.
9.2 Notification shall include:
- Nature of the breach
- Categories and number of data subjects affected
- Categories and number of records affected
- Likely consequences
- Measures taken or proposed
10. Audit Rights
10.1 FormBuilder shall make available information necessary to demonstrate compliance.
10.2 Customer may exercise audit rights through:
- Annual SOC 2 Type II reports
- ISO 27001 certification
- Security questionnaires
- On-site audits (with 30 days notice and reasonable scope)
11. Data Return and Deletion
11.1 Upon termination, FormBuilder shall, at Customer's choice:
- Return all Personal Data in standard format
- Delete all Personal Data and certify deletion
11.2 Data export available for 30 days post-termination.
12. Liability and Indemnification
12.1 Liability shall be as set forth in the Terms of Service.
12.2 Each party shall indemnify the other against damages arising from their breach of GDPR.
13. Contact Information
Effective Date: August 19, 2026
This DPA is incorporated by reference into the FormBuilder Terms of Service.