Data Processing Agreement

Version: 1.0

Last Updated: 2026-08-03

1. Introduction and Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service betweenStaticForm ("we", "us", the "Processor") and you, the customer using the Service (the "Customer", the "Controller"). It applies whenever personal data of your form respondents ("Customer Data") is submitted through forms you operate with the Service.

This DPA implements the requirements of Article 28 of the General Data Protection Regulation (GDPR) and applies automatically to all Customers; no signature is required. If you require a countersigned copy for your records, contact us at support@staticform.app.

2. Roles of the Parties

  • You (the Customer) are the Controller of Customer Data: you decide which fields your forms contain, why the data is collected, and how long it is kept.
  • StaticForm is the Processor of Customer Data: we store and process form submissions only to provide the Service to you.
  • For account data (your email address, billing details, and usage data), StaticFormacts as an independent Controller as described in our Privacy Policy. That processing is not covered by this DPA.

3. Details of Processing

3.1 Subject Matter and Duration

The subject matter of the processing is the collection, storage, and delivery of form submissions on behalf of the Customer. Processing lasts for the duration of the Customer's use of the Service, until submissions or the account are deleted.

3.2 Nature and Purpose

  • Receiving form submissions via the Service's endpoints
  • Storing submissions and uploaded files
  • Spam and abuse filtering
  • Delivering submissions to destinations configured by the Customer (email, webhooks, Slack, Discord, Google Sheets, Notion, and similar integrations)

3.3 Categories of Data Subjects

Individuals who submit data through the Customer's forms (for example website visitors, customers, applicants, or employees of the Customer).

3.4 Categories of Personal Data

The Customer determines the categories of personal data through the design of their forms. This may include contact details, identification data, and any other information the Customer chooses to collect, as well as IP addresses and request metadata processed for spam prevention.

4. Special Categories of Data and National Identification Numbers

The Service may be used to collect special categories of personal data (Article 9 GDPR) or national identification numbers only if the Customer has a valid legal basis to do so.

  • National identification numbers are subject to additional rules under the national law of many Member States and may only be processed where that law permits it. It is the Customer's responsibility to verify the rules that apply to its processing.
  • The Customer warrants that it has verified and documented its legal basis before collecting such data through the Service, and will perform a Data Protection Impact Assessment (DPIA) where required by Article 35 GDPR.
  • The Customer must configure its forms and integrations appropriately for such data, for example by not forwarding sensitive fields to third-party integrations that are not covered by the Customer's own processing agreements.
  • We may suspend processing and notify the Customer if we become aware that such data is being collected in apparent violation of applicable law.

5. Processing on Documented Instructions

We process Customer Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do otherwise by EU or Member State law. In that case, we will inform the Customer of the legal requirement before processing, unless the law prohibits this. The Customer's instructions consist of the Terms of Service, this DPA, and the configuration choices the Customer makes in the Service (form fields, retention settings, and submit actions).

We will immediately inform the Customer if, in our opinion, an instruction infringes the GDPR or other applicable data protection provisions.

6. Confidentiality

We ensure that all persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Customer Data is restricted to personnel who need it to operate and support the Service.

7. Security of Processing

Taking into account the state of the art and the nature of the data processed, we implement appropriate technical and organisational measures as required by Article 32 GDPR, including:

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of stored files and backups at rest
  • Authentication and role-based access controls, including for form collaboration
  • Audit logging of system activities
  • Network isolation between application components
  • Regular security assessments and dependency updates
  • Spam and abuse filtering to reject malicious traffic before storage

The Customer is responsible for the security of its own systems and integrations, including the destinations to which it forwards submissions and the protection of its API keys and account credentials.

8. Sub-processors

The Customer grants us general authorisation to engage sub-processors for the operation of the Service. We currently use the following categories of sub-processors:

  • Hosting and infrastructure: cloud infrastructure providers hosting our application and database within the European Economic Area (EEA)
  • Object storage: S3-compatible storage providers for uploaded files
  • Email delivery: Amazon Web Services (Amazon SES) for delivering email submit actions
  • Spam protection: Cloudflare (Turnstile) for bot and abuse detection

Integrations that the Customer itself enables (such as Google Sheets, Notion, Slack, Discord, webhooks, or the Customer's own SMTP server) are destinations chosen by the Customer, not our sub-processors; the Customer is responsible for its own agreements with those providers.

We impose data protection obligations on our sub-processors that are no less protective than those in this DPA, and we remain fully liable to the Customer for their performance. An up-to-date list of sub-processors is available on request via support@staticform.app. We will give the Customer at least 30 days' notice of intended additions or replacements, during which the Customer may object on reasonable data protection grounds. If no resolution is found, the Customer may terminate the affected part of the Service.

9. International Data Transfers

Customer Data is stored within the EEA. Where a sub-processor processes personal data outside the EEA (for example email delivery via Amazon SES), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented where necessary by additional measures.

10. Assistance with Data Subject Rights

Taking into account the nature of the processing, we assist the Customer with appropriate technical and organisational measures in fulfilling the Customer's obligation to respond to data subject requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, and objection). In practice, the Customer can search, export, and delete individual submissions directly through the Service. If a data subject contacts us directly about data processed on the Customer's behalf, we will forward the request to the Customer without undue delay and will not respond substantively unless legally required.

11. Personal Data Breach Notification

We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent known:

  • The nature of the breach, including categories and approximate numbers of data subjects and records concerned
  • The likely consequences of the breach
  • The measures taken or proposed to address and mitigate the breach
  • A contact point for further information

The Customer, as Controller, remains responsible for notifying its supervisory authority and affected data subjects where required by Articles 33 and 34 GDPR. We will reasonably assist the Customer with these obligations.

12. Data Protection Impact Assessments

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, where these relate to processing performed by the Service.

13. Deletion and Return of Data

  • The Customer can delete individual submissions, forms, or its entire account at any time through the Service; deletion is permanent.
  • The Customer can export submissions through the Service before deletion.
  • Upon termination of the Service, we delete all Customer Data in accordance with the retention terms in our Privacy Policy, unless EU or Member State law requires further storage.

14. Audits

We will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits require at least 30 days' written notice, may occur at most once per year (unless a supervisory authority requires otherwise or following a personal data breach), must not unreasonably disrupt our operations, and are at the Customer's expense. We may first satisfy an audit request by providing relevant documentation of our security measures.

15. Liability, Term, and Precedence

  • The limitations of liability in the Terms of Service apply to this DPA.
  • This DPA takes effect when the Customer first uses the Service to process personal data and remains in force as long as we process Customer Data.
  • In case of conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.
  • This DPA is governed by the same law as the Terms of Service.

16. Contact

Questions about this DPA, sub-processor lists, or requests for a countersigned copy can be directed to:

  • Email: support@staticform.app