Legal

Data Processing Agreement

Last updated: 9 August 2026

This DPA applies to every account automatically. You do not need to sign or return anything — print this page for your records if your compliance process requires a copy.

1. Scope and acceptance

This Data Processing Agreement ("DPA") forms part of the HelloForms Terms of Service and applies automatically to every account that processes personal data through the service. No signature is required: by using HelloForms to collect form responses you accept this DPA as the data processing terms between you (the "Controller") and HelloForms (the "Processor").

2. Roles of the parties

You decide which questions your forms ask, who may respond, how long responses are kept and where they are sent. You are therefore the controller of submission data. We process that data only to provide the service on your instructions. For your own account data — your name, email, plan and billing records — we act as controller and our Privacy Policy applies.

3. Subject matter, duration and purpose

Subject matter: hosting a form builder, rendering published forms, storing responses, sending notification and reminder emails, and exporting reports. Duration: for as long as your account is active, plus the deletion window in section 10. Purpose: providing the service and its support, security and billing functions.

4. Categories of data and data subjects

Data subjects are the people who complete your forms, plus the users you invite into your workspace. Categories of personal data are whatever your forms collect — commonly names, email addresses, phone numbers, addresses, free-text answers, uploaded files — together with technical data such as IP address, timestamp and user agent captured for abuse prevention. You must not use the service to collect special-category or payment card data unless you have your own lawful basis and appropriate safeguards for doing so.

5. Processor obligations

We process personal data only on your documented instructions, and we will tell you if an instruction appears to breach applicable data protection law. Our personnel are bound by confidentiality, access is limited to those who need it to operate or support the service, and we do not use your submission data to train models or to target advertising.

6. Security measures

Technical and organisational measures include: encryption in transit; encryption at rest for the managed database and file storage; row-level security so no account can read another account's records; hashed passwords; role-based access control with a separate privileged-role table; audit logging of administrative actions; least-privilege service credentials held only server side; rate limiting and abuse detection; automated backups; and dependency and configuration security scanning.

7. Sub-processors

You give general authorisation for us to use sub-processors to run the service: a managed cloud platform providing database, authentication and object storage; a payment provider for subscription billing; and an email delivery provider for transactional, notification and reminder messages. Each is bound by written terms no less protective than this DPA. We will give notice of any new or replacement sub-processor and you may object on reasonable data protection grounds, in which case you may terminate the affected part of the service.

8. Assisting you

We will help you respond to data subject requests, complete data protection impact assessments and answer regulator enquiries. Where a respondent contacts us directly about a form you own, we will refer them to you rather than acting on their data ourselves. Your workspace includes self-service export and deletion tools for submissions so most requests can be handled without contacting us.

9. Personal data breach

We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data, describing the nature of the breach, the categories and approximate volume of records concerned, the likely consequences and the measures taken or proposed.

10. Return and deletion

You can export or delete submissions at any time from your workspace. On termination, or on your written request, we delete your personal data within 30 days, except where we are required to retain records to comply with law — for example billing records kept for tax purposes. Backups age out on their normal rotation schedule.

11. International transfers

Where personal data is transferred outside the UK or the EEA, we rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses with each recipient, together with a transfer risk assessment and the supplementary measures described in section 6.

12. Audits

On reasonable written notice, and no more than once a year unless required by a regulator, we will make available the information needed to demonstrate compliance with this DPA, including our security documentation and the results of our latest security scans.

13. Contact and changes

Requests under this DPA, including sub-processor objections and audit requests, go to hello@helloforms.net. If we update the DPA we will revise the date below and, for material changes, notify account owners by email.

See also our Privacy Policy, Cookie Policy and Terms of Service.