Help center
Go to home
Go to templates
Go to settings
Go to help center

Data Processing Agreement

The processing terms between a form owner and the operator of this install: roles, instructions, sub-processors, security and deletion.

This agreement covers the personal data that forms built on this install of Tinyform collect from respondents. It sits under the terms at Terms & Conditions and applies whenever an account holder publishes a form that another person fills in.

The parties and their roles

The controller is the account holder who builds a form: they decide what it asks and why.

The processor is the operator of this install: [name, legal form, address, contact]. They store the answers and deliver them to the controller's workspace on the controller's behalf.

Subject matter and duration

The processing is the storing, displaying, exporting, notifying about and deleting of form submissions, together with the files and signatures attached to them. It lasts for as long as the controller holds an account on this install and until the data is deleted under the section on deletion below.

What is processed

  • Data subjects: the people who fill in the controller's forms.
  • Categories: whatever the controller's questions ask for, which may include names, contact details, free text, uploaded files, drawn signatures and, where the controller added the block, the respondent's country. The controller must not ask for special categories of data unless they have a lawful basis for it and tell the operator.
  • Also processed for the controller's benefit, without the controller asking a question: the analytics events behind the Insights tab, which carry a daily-salted hash rather than an address.

Instructions

The processor acts only on the controller's instructions. Those instructions are given through the product itself: publishing or closing a form, setting Submissions data retention, deleting a submission or a form, exporting submissions, turning notifications on, and connecting a webhook or an integration. The processor will not use the data for any other purpose and will tell the controller if an instruction appears to break the law.

The processor's obligations

  • Keep the data confidential and let only people who need it for running the server reach it.
  • Apply the security measures below.
  • Help the controller answer a request from a respondent to see, correct, export or delete their data, where the controller cannot do it alone from the Submissions tab.
  • Tell the controller without undue delay on becoming aware of a breach affecting their data, with what is known about it.
  • Make available what is needed to show these obligations are met, and allow an audit on reasonable notice.
  • Delete or return the data at the end of the agreement.

The controller's obligations

  • Have a lawful basis for every question, and give respondents a privacy notice.
  • Keep their account and workspace membership secure.
  • Use the product's own controls for retention and deletion rather than relying on the processor to act unasked.

Sub-processors

On the default install everything below the product runs on the operator's own server and no other company sees the data. The operator lists here what actually runs on their install and where.

ComponentRoleWhere it runs on the default installThird party involved
PostgresAccounts, forms and answersThis serverNone
Object storageAttachments and signatures, in a private bucketThis server, unless the operator pointed it at a hosted bucket: [provider, region]Only if hosted
ClickHouseAnalytics eventsThis serverNone
Amazon SESEvery email the product sends; it is the one transport this product has[the mail provider or server the operator named, and its country]Yes, if a provider
GeoLite2 databaseThe respondent's country lookupA file on this server's diskNone; no request leaves
StripeBilling, if the operator sells a planStripe's serversYes, if configured
Google reCAPTCHABot protection, if the operator configured it and a form uses the blockGoogle's serversYes, if configured

Services the controller connects themselves, such as a webhook target or an embedded page, are the controller's own sub-processors and are not covered by this agreement. The processor will announce a new sub-processor before engaging it and give the controller a chance to object.

Security measures

  • Transport encryption on every connection, terminated by the reverse proxy.
  • Attachments and signatures in a bucket with no public address, readable only by a workspace member or a link the server signed for a limited time.
  • Passwords stored as hashes; form passwords as salted hashes.
  • Two-factor authentication available to every account.
  • Access to a form's data limited to the members of the workspace that owns it.
  • Daily database backups into a bucket of their own, written with credentials that reach no other bucket and kept thirty days on the default install.
  • The operator states further measures here: [disk encryption, off-site backups, access to the machine].

International transfers

The data is stored where this server is: [country or region]. If any sub-processor above is in another country, the operator names the transfer mechanism here: [mechanism].

Deletion

A submission the controller deletes from the Submissions tab is removed with the files the respondent attached and the signature they drew. A form the controller deletes waits thirty days in the trash and is then removed with everything under it. A retention window set on a form removes each submission once it has aged past the window. When the controller's account is deleted, the processor removes what remains on the schedule in the Privacy notice, apart from copies in backups, which expire on the backup schedule.

Term and acceptance

This agreement runs for as long as the controller holds an account here. The operator states how it is accepted: [by creating an account, or by signature]. It is governed by the same law as the terms.