Formpost
Log in

Legal

GDPR

Last updated 6 August 20268 sections

This page is for the person checking whether they can put a Formpost contact form on a site with European visitors. It sets out who is responsible for what, where the data physically goes, and which parts stay yours — including the ones no form backend can take off your hands.

01Who is responsible for what

Under the GDPR you are the controller of the data your forms collect: you chose to put the form on your site, you decided what it asks for, and you decide who sees the answers. Formpost is your processor — we receive submissions, filter them, store them for the period your plan allows, and deliver them where you told us to.

That split matters because most of the obligations land on the controller. We can give you the tools and the paperwork; we cannot give you a lawful basis for collecting what you collect.

02What we provide

  • A Data Processing Agreement that is in force for every account without anyone having to sign anything, incorporating the Standard Contractual Clauses.
  • A published list of every sub-processor, what it handles and where it sits, updated before we add one.
  • Encryption in transit and at rest, and a submission endpoint that can only ever deliver to the address its form was set up for.
  • Self-service export and deletion, so most data subject requests need no ticket to us.
  • Retention that ends on its own — thirty days on Free, a year on Pro, and under your control on Business.
  • Breach notification without undue delay and within 72 hours of us becoming aware.

03Where the data goes

Submissions, attachments and account data are processed in the United States. For data coming from the EEA, the UK or Switzerland that is an international transfer, and we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, incorporated into the DPA.

We do not currently offer EU-only data residency. If your own assessment requires processing to stay inside the EEA, this is the point at which to tell us before you build on it rather than after.

04Handling a data subject request

Someone who filled in your form may ask you for a copy of their data, or to have it deleted. Almost all of it you can do yourself, immediately, without opening a ticket with us:

The requestWhat you doNeed us?
Access or portabilityFind the submission in the dashboard and export it as CSV or JSON, or pull it through the submissions APINo
ErasureDelete the submission — deleting a form takes everything attached to itNo
RectificationYou hold the record, so you amend itNo
Restriction or objectionStop the processing at your end, or delete what the form holdsNo
Anything the above cannot coverAsk through /contact and we will assist within the scope of the serviceYes

Erasure has one edge you should know about: the notification email already sits in your own mailbox, and deleting the submission here does not reach it. Finishing an erasure request usually means deleting it in both places.

05What you still have to do

These are yours as controller, and no form backend can do them for you:

  • Have a lawful basis for what the form collects. For an ordinary contact form that is usually the legitimate interest of replying to someone who chose to write to you — but the form deciding that is yours, not ours.
  • Tell people on the page what you will do with what they send, and link your own privacy notice next to the form.
  • Avoid asking for special category data — health, biometrics, political or religious views, sexual orientation — unless you genuinely need it and can lawfully hold it.
  • Choose a retention period you can justify. A plan's maximum is not automatically the right answer for your form.
  • Keep your own record of processing activities, and run a DPIA if what you collect calls for one. We will help with the parts that concern us.

None of these transfer to us by signing up. A processor can hold the data properly; it cannot supply your lawful basis for collecting it.

06Product controls worth knowing about

Two settings reduce how much data you collect in the first place, which is the cheapest kind of compliance there is.

  • Domain locking refuses submissions posted from anywhere other than the sites you list, so a copy of your form somewhere else stops feeding your database.
  • Spam filtering rejects junk before it is stored, so you are not holding personal data from people who never intended to contact you.

07What we do not claim

There is no such thing as a GDPR certification for a service like this, and any vendor showing you a compliance badge is showing you a graphic. What exists is a set of obligations, a contract that allocates them, and evidence of what a processor actually does — which is what the DPA and the sub-processor list are for.

We also do not currently have a designated representative in the EU under Article 27. If that matters for your assessment, tell us and we will say where we have got to rather than guess.

08The documents

The Data Processing Agreement at /dpa is the binding one — it names the sub-processors, the transfer mechanism, the security measures and the deletion terms. The Privacy Policy at /privacy covers what we do with your own account data, where we are the controller. If your review needs a counter-signed copy of the DPA, ask through the contact page.