01
This applies automatically
You do not need to email us for a countersigned copy. By using WebForms to process personal data, this agreement is in force between you (the controller) and WebForms (the processor), and it forms part of the Terms of Service.
If your procurement process requires a signed document on your own paper, email help@webforms.to and we will work through it.
02
Roles
You decide what your forms collect and why, so you are the controller. We act only on your documented instructions, so we are the processor. Your configuration in the dashboard, plus these terms, constitute those instructions.
We will tell you if we believe an instruction breaches GDPR or UK GDPR rather than quietly carrying it out.
03
Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Receiving, filtering, storing, and forwarding form submissions |
| Duration | For as long as your account is open, plus the deletion window in clause 9 |
| Nature and purpose | Collection, storage, spam classification, and transmission to destinations you configure - including evaluating any routing rules you define, which decide which destinations receive a given submission |
| Categories of data subject | People who submit your forms, and your own account users |
| Categories of personal data | Whatever fields your form defines, typically name, email, message. Plus technical metadata: IP address, user agent, referring page, and time to complete |
| Special category data | Not permitted without prior written agreement. See the Acceptable Use Policy |
04
Confidentiality
Everyone with access to personal data processed under this agreement is bound by confidentiality obligations. Access is limited to people who need it to operate or support the service, and is logged.
05
Security measures
Our technical and organisational measures under Article 32 include:
- TLS encryption for all data in transit, with HSTS enforced
- Encryption at rest for database storage and backups
- Passwords hashed with a memory-hard algorithm; API secrets stored hashed, never in plaintext
- HMAC-signed webhook payloads so your endpoint can verify origin and integrity
- Network isolation: the database and queue listen only on loopback and are not reachable from the internet
- Rate limiting and multi-layer spam filtering at the ingest edge
- Least-privilege access control, reviewed periodically
- Automated retention enforcement, so data is deleted on schedule rather than on request
06
Subprocessors
You give general authorisation for the subprocessors below. Each is bound by data protection terms no less protective than these.
| Subprocessor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server and database hosting | Germany |
| Cloudflare, Inc. | DNS, TLS termination, DDoS mitigation, email delivery | Global edge network |
| Polar Software | Subscription billing (account and billing data only) | EU / US |
We will give at least 30 days notice before adding or replacing a subprocessor. If you object on reasonable data protection grounds, tell us within those 30 days and we will either propose an alternative or you may terminate the affected service and receive a refund of the unused prepaid term.
07
International transfers
Customer data is stored on servers in Germany, within the EEA. For the routine operation of the service, personal data does not leave the EEA.
Where a subprocessor processes data outside the EEA, that transfer relies on an adequacy decision or on Standard Contractual Clauses together with supplementary measures. For UK controllers, the UK International Data Transfer Addendum applies.
08
Assistance with your obligations
Taking account of the nature of processing, we will help you:
- Respond to data subject requests. The dashboard lets you search, export, and delete any submission yourself, which covers access, rectification, erasure, and portability without waiting on us. If a request reaches us directly, we forward it to you rather than acting on it ourselves
- Carry out data protection impact assessments by providing the information about our processing that you reasonably need
- Meet your breach notification duties, as in clause 10
09
Retention, return, and deletion
Submissions are deleted automatically once they exceed your plan's retention window, enforced by a scheduled job:
- Free - 30 days
- Pro - 180 days
- Agency - 365 days
Delivery records are purged together with their submission, because they contain a copy of the submitted payload. Uploaded files are deleted 30 days after upload, ahead of the submission they belong to.
On termination you may export your data through the dashboard or API. We delete customer personal data from live systems within 30 days of account closure. Encrypted backups are retained on a rolling 35 day cycle and are then overwritten, so data can persist in backup for up to that period after live deletion. It is not restored to production except during disaster recovery.
10
Breach notification
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and within 72 hours, with the nature of the breach, the categories and approximate number of records involved, the likely consequences, and the measures taken.
Where we do not have full detail within 72 hours, we send what we have and follow up. We will not delay telling you while we complete an investigation.
11
Audits
On reasonable written request, and no more than once a year unless a regulator requires otherwise, we will make available the information necessary to demonstrate compliance with Article 28, and cooperate with an audit conducted by you or an independent auditor you appoint.
Audits must be scheduled in advance, respect the confidentiality of other customers, and not disrupt the service.
12
Liability and precedence
Liability under this agreement is subject to the limitations in the Terms of Service. If this agreement conflicts with those terms on a matter of data protection, this agreement takes precedence.
Data protection questions: help@webforms.to