Data processing agreement
This agreement is part of the terms of service and applies whenever your forms collect personal data about other people. It sets out how Forms, run by Shaheer Malik (“we”), processes that data on your behalf. It is written to meet Article 28 of the GDPR and the UK GDPR, and it applies to every account without anything to sign. If your organisation needs a countersigned copy, email me@shaheermalik.com.
Roles
For the answers people give in your forms (“respondent data”), you are the controller and we are the processor. You decide what to ask, why, and how long to keep it. For your own account details (your email, billing, sign-in activity), we are the controller, as described in the privacy policy.
What we process, and why
We process respondent data only to provide Forms: storing responses and uploaded files, showing them to you and your team, running the logic, emails, webhooks and integrations you set up, producing exports, and (if you turn it on) the AI analyses described below. We do not use respondent data to train AI models, build profiles, or for any purpose of our own.
Your instructions
Your instructions are the settings you choose in the product: what each form collects, who can see results, which integrations are connected, whether AI insights are on, retention periods, and when you delete responses or your account. We process respondent data only on those instructions, unless the law requires otherwise, in which case we tell you first where we can.
Sub-processors
We use these providers to run the service. Each is bound by terms that are at least as protective as this agreement.
- Cloudflare, Inc. — hosting, database, file storage, queues, DNS, bot protection and custom domains. Data is stored in Cloudflare’s global network, with primary storage in Western Europe.
- Unitpost and Resend — transactional email (alerts to you, and confirmation emails to respondents when you turn them on).
- OpenAI — only when you enable AI features: form building from your descriptions, Smart Insights over responses, transcripts of voice and video answers, and Filo’s follow-up questions. Requests are sent with storage turned off, so OpenAI does not retain them beyond the request, and contact details are excluded from analyses.
- Google — only when you connect Google Sheets or Drive, to write responses and files to your own account.
- Stripe — only when you add a payment question; card details go to your own Stripe account and never reach us.
- Composio — only when you connect a destination such as Slack, Notion or HubSpot; it holds the authorisation for that destination and relays the response you choose to send.
- Expo (push notifications) — only for the iPhone and Android app, carrying the title and preview of a notification to your phone.
- Sentry — error reports from the service, with personal data removed before sending.
- Polar and RevenueCat — billing for your account (controller data, not respondent data).
We’ll update this list before adding a sub-processor that handles respondent data. If you object to a change, you can export your data and close your account.
Security
Respondent data is encrypted in transit (TLS) and at rest. Access inside the service is limited to your account and the teammates you invite, with roles you control. Secrets such as connected-service tokens are encrypted with a key held outside the database. Uploads are scanned for type and size and served with headers that stop them running as code. Sign-in supports two-factor authentication. We keep nightly backups for 30 days, and operational logs for up to 7 days without response content.
Confidentiality
Only the operator of the service can access stored data, and only to run, support or debug the service, or when you ask for help. We do not look at respondent data otherwise.
Helping you meet your obligations
Respondents’ rights requests (access, correction, erasure) can be handled directly in Results: search, open and delete any response, including its files. Exports (CSV, Excel, JSON) give you a portable copy. Per-form retention periods delete responses automatically. If you need help with a request or an impact assessment, email us.
Breach notification
If we become aware of a personal data breach affecting respondent data, we will tell you without undue delay and within 48 hours of confirming it, with what we know about the nature of the breach, the data involved, the likely consequences and what we are doing about it.
International transfers
Primary storage is in Western Europe. Where a sub-processor processes data outside the UK or EEA, transfers rely on adequacy decisions or standard contractual clauses that the sub-processor has in place.
Retention and deletion
Respondent data stays until you delete it, until a retention period you set removes it, or until you delete your account, at which point responses, files and backups copies are removed within 30 days. Data in connected services (your Google Sheet, your Slack workspace) is yours and is unaffected by deletion here.
Audit
We will answer reasonable written questions about how we meet this agreement, and make available the information needed to show compliance. Where an on-site audit is required by law, we will agree a scope and timing in advance.
Contact
Questions about this agreement or data protection: me@shaheermalik.com.