Data Protection

Data Processing Agreement

This DPA describes how Flexform processes personal data on your behalf, in compliance with GDPR and applicable data protection laws.

Last Updated: February 19, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Flexform ("Processor," "we," "us") and the customer ("Controller," "you") governing your access to and use of our Services.

This DPA addresses the requirements of Article 28 of the General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws regarding the processing of personal data.

2. Roles of the Parties

You (the Customer)

Act as the Data Controller — you determine the purposes and means of processing personal data collected through forms you create on Flexform.

Flexform

Acts as the Data Processor — we process personal data on your behalf solely to provide, secure, and support the Services.

You are responsible for the accuracy, quality, and lawfulness of the personal data you collect and for establishing an appropriate legal basis for processing (e.g., consent, legitimate interest, contractual necessity).

3. Scope & Nature of Processing

Flexform processes personal data solely to:

1Host and deliver forms created by you.
2Collect and store responses submitted by respondents to your forms.
3Send transactional email notifications (via Amazon SES) related to form submissions.
4Provide analytics and reporting on form responses.
5Provide AI-assisted form creation (via Google Gemini API) when you use AI features.
6Maintain the security, availability, and integrity of the Services.

Data Subjects

  • Form creators (your authorized users)
  • Form respondents

Types of Personal Data

  • Contact information
  • Account & form response data
  • Technical data (IP, device info)

Processing continues for the duration of the agreement. Upon termination, data handling follows Section 9 of this DPA.

4. Processor Obligations

Flexform shall:

1Process personal data only on your documented instructions, unless required by applicable law.
2Ensure that persons authorized to process personal data are bound by appropriate confidentiality obligations.
3Implement appropriate technical and organizational security measures.
4Not engage sub-processors without your prior authorization.
5Assist you in responding to data subject rights requests.
6Notify you of personal data breaches without undue delay.
7Delete or return personal data upon termination.
8Make available information necessary to demonstrate compliance with this DPA.

5. Security Measures

🔐Encryption

HTTPS/TLS in transit, industry-standard encryption at rest

🛡️Access Controls

Role-based access, MFA for admins, least privilege principle

☁️Infrastructure

AWS with multi-availability zone deployment

🔑Authentication

JWT-based with secure token rotation, OAuth 2.0

📊Monitoring

Continuous security monitoring and anomaly detection

✉️Email Security

DKIM, SPF, DMARC for Amazon SES; bounce/complaint handling via SNS

🚨Incident Response

Documented procedures for prompt identification and remediation

6. Sub-processors

You provide general authorization for Flexform to engage sub-processors to assist in providing the Services.

Sub-processorPurpose
Amazon Web Services (AWS)Cloud hosting, email delivery (SES), storage
Google Cloud (Gemini API)AI-assisted form generation
Payment ProcessorSubscription billing

We will provide at least 15 days' advance notice before engaging a new sub-processor. You may object on documented data protection grounds. If we cannot reasonably accommodate your objection, you may terminate the affected Services.

7. Data Subject Rights

Flexform will provide reasonable assistance to you in responding to requests from data subjects exercising their rights under applicable data protection laws, including requests for access, rectification, erasure, restriction, portability, and objection.

If Flexform receives a request directly from a data subject, we will promptly redirect the request to you unless legally required to respond directly.

8. Data Breach Notification

Flexform will notify you of any confirmed personal data breach within 72 hours of becoming aware of the breach. The notification will include:

1A description of the nature of the breach, including the categories and approximate number of data subjects affected.
2The likely consequences of the breach.
3A description of the measures taken or proposed to address the breach and mitigate its effects.

Flexform will take reasonable steps to contain and remediate the breach and will cooperate with your investigation and notification obligations.

9. Data Return & Deletion

Upon termination of the agreement:

30

Data Export Period

Flexform will make your data available for export for 30 days after termination.

90

Permanent Deletion

After the 30-day period, all personal data will be permanently deleted within 90 days, unless retention is required by applicable law.

Backup copies will be deleted in accordance with our standard backup rotation schedule.

10. International Data Transfers

Flexform's Services are hosted in the United States. For personal data originating from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission to ensure an adequate level of data protection.

In such transfers, you act as the data exporter and Flexform acts as the data importer. The SCCs are incorporated by reference into this DPA.

11. Audits & Compliance

Upon reasonable written request (no more than once annually), Flexform will provide documentation demonstrating compliance with this DPA. If on-site audits are required, they must be conducted with at least 15 days' advance notice, during business hours, and at your expense.

12. Liability & Miscellaneous

The liability limitations set forth in the Terms of Service apply to claims arising under this DPA, subject to mandatory provisions of applicable data protection law that cannot be contractually limited.

In the event of a conflict between this DPA and the Terms of Service regarding personal data processing, this DPA shall prevail.

Flexform may update this DPA to comply with changes in applicable data protection laws, with notice to you.

This DPA is governed by the same governing law as the Terms of Service.

13. Contact Us

For questions about this DPA or data processing practices: