Formpost
Log in

Legal

Data Processing Agreement

Last updated 6 August 202614 sections

This agreement covers the personal data Formpost processes on your behalf when your visitors submit your forms. It is written to be read by the person doing your vendor review, so it names our sub-processors, says where data physically sits, and describes what we actually do rather than what sounds reassuring.

01The parties

The processor under this agreement is DocumentMind LLC, registered in Cheyenne, Wyoming, United States, which operates Formpost. The controller is you — the account holder whose forms collect the data.

02Scope and roles

This Data Processing Agreement forms part of the Terms of Service between you and Formpost. It applies whenever we process personal data on your behalf.

For the contents of your form submissions you are the controller and we are the processor: you decide what your form asks for, who it is delivered to, and how long it is kept. For your own account data — your email address, plan and billing records — we are the controller, and the Privacy Policy governs it.

You remain responsible for having a lawful basis to collect what your forms collect, and for telling your visitors how their information will be used.

03What we process

Subject matterReceiving form submissions from your website, filtering them, storing them, and delivering them to the destinations you configure.
DurationFor as long as your account is active, plus the retention period of your plan.
Categories of data subjectsThe visitors who fill in your forms.
Categories of personal dataWhatever fields your form contains — typically name, email address and a message — plus any files attached, and technical metadata collected for abuse prevention: IP address, user agent and referring page.
Special categoriesNone requested by us. If your form asks for special category data, you are responsible for the additional safeguards that requires.

04Our instructions

We process submission data only to provide the service: to deliver it to the address and integrations you configured, to run the spam controls you enabled, to enforce your plan's limits, and to keep it available to you in the dashboard for your retention period.

We do not use submission content to train models, do not build profiles of the people who fill in your forms, and do not sell or share it with anyone beyond the sub-processors listed below and the destinations you yourself configure.

If an instruction from you would in our view breach data protection law, we will tell you rather than carry it out.

05Confidentiality

Access to production systems is limited to people who need it to operate or support the service, and everyone with access is bound by a duty of confidentiality that survives the end of their engagement.

06Security measures

We maintain the following technical and organisational measures. They are described honestly: this is what a small, focused service actually does, not a list copied from a larger company.

  • All traffic is encrypted in transit with TLS. Submissions, attachments and account data are encrypted at rest.
  • The submission endpoint runs as a separate service from the dashboard, exposing no port to the public internet other than through a managed tunnel.
  • Each form's endpoint delivers only to the address that form was configured with. Knowing an endpoint does not grant read access to anything.
  • Access to the database is limited to the application's service credentials; row-level security scopes every dashboard query to the account that owns the data.
  • Rate limiting per IP and per form, plus optional honeypot, captcha, keyword and domain controls that you configure.
  • Automatic backups of the database, retained on a rolling window by our database provider.

07Sub-processors

You give general authorisation for us to engage the sub-processors below. We will update this page before adding or replacing one, and you may object on reasonable data protection grounds — in which case you may terminate the affected part of the service without penalty.

Sub-processorPurposeLocation
SupabaseDatabase and authenticationUnited States
Amazon Web ServicesAttachment storage (S3)United States
ResendDelivering notification emailUnited States
DigitalOceanHosting the submission endpointUnited States
VercelHosting the website and dashboardUnited States
CloudflareDNS, TLS and network protectionGlobal
StripeSubscription payments — account data onlyUnited States

This list is the current one, not an illustrative example. If your review needs to be told when it changes, say so through the contact page and we will add you to the notice.

08International transfers

Processing takes place in the United States. Where you or your visitors are in the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914, module two, controller to processor), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this agreement by reference and prevail over it in the event of conflict.

09Assisting you

The dashboard is built so that most of this needs no request to us: you can search, export and delete submissions yourself, and deleting a form deletes everything attached to it.

Where a data subject contacts us directly about data we hold on your behalf, we will not respond substantively — we will forward it to you, because you are the controller. For anything the dashboard cannot do, and for help with data protection impact assessments or consultations with a supervisory authority, contact us and we will assist within the scope of the service.

10Personal data breach

If we become aware of a breach affecting personal data we process for you, we will notify you without undue delay and in any event within 72 hours of becoming aware, with what we know about the nature of the breach, the categories and rough number of records involved, the likely consequences, and the steps taken. Notifying your own supervisory authority and data subjects, where required, remains your decision as controller.

11Deletion and return

Submissions are deleted automatically at the end of your plan's retention period. You can also delete any submission, or an entire form, at any time — that deletion is immediate and permanent.

When your account is closed we delete submission data within thirty days, except where law requires us to keep something. You can export everything as CSV or JSON before then, or through the submissions API.

PlanSubmissions are kept for
Free30 days
Pro1 year
BusinessUntil you delete them

Notification email we already delivered sits in your own mailbox and is outside our control. Deleting a submission here does not retract it, which matters when you are answering an erasure request.

12Audit

On reasonable written request, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information needed to demonstrate compliance with this agreement. Where an on-site audit is genuinely necessary, we will agree scope and timing with you in advance so it does not disrupt the service or expose other customers' data.

13Order of precedence

Where this agreement conflicts with the Terms of Service, this agreement prevails for matters of personal data processing. Where the Standard Contractual Clauses conflict with either, the Clauses prevail.

14Accepting this agreement

This agreement is effective for every customer from the date at the top of this page — using the service means it applies, and no signature is needed for it to bind us. If your own compliance process requires a counter-signed copy, ask through the contact page and we will send one.