Data Processing Agreement

Article 28 GDPR DPA governing our processing of personal data on your behalf.

Effective date: May 28, 2026

Last updated: June 25, 2026

1. Introduction & Auto-Incorporation

This Data Processing Agreement ("DPA") is entered into between Simplyxity Ltd ("SimplyForms", "we", or "Processor") and the customer that has accepted our Terms of Service("Customer", "you", or "Controller"). This DPA supplements and forms part of the Terms of Service.

This DPA applies automatically and without separate signature whenever you use the SimplyForms Service to process personal data of natural persons (your end users) to which UK GDPR, EU GDPR, or comparable data-protection law applies. No purchase-order or counter-signed document is required.

If you require a counter-signed copy of this DPA for procurement purposes, contact dpo@simplyforms.dev with your company details.

2. Definitions

Capitalised terms not defined here have the meaning given in the Terms of Service or UK/EU GDPR. In particular:

  • "Applicable Data Protection Law" means the UK GDPR and Data Protection Act 2018, the EU GDPR (Regulation 2016/679), and any other privacy or data-protection law that applies to the processing.
  • "Customer Personal Data" means personal data we process on the Customer's behalf through the Service, including form Submission contents, file uploads, and notification recipient details.
  • "Data Subject" has the meaning given in Applicable Data Protection Law.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • "Sub-Processor" means any third party engaged by us to process Customer Personal Data on the Customer's behalf.
  • "Standard Contractual Clauses" or "SCCs" means the European Commission's Standard Contractual Clauses adopted under Implementing Decision (EU) 2021/914, Module Two (controller to processor).
  • "UK Addendum" means the UK International Data Transfer Addendum to the EU SCCs issued by the UK ICO.

3. Subject Matter, Duration & Roles

  • Subject matter: our processing of Customer Personal Data to provide the SimplyForms Service.
  • Duration: for as long as the Terms of Service are in force, plus any post-termination period required for return or deletion under section 12.
  • Nature and purpose: see Annex A.
  • Roles: the Customer is the Controller of Customer Personal Data; SimplyForms is the Processor. SimplyForms is the Controller for its own account, billing, support, and security data, governed by the Privacy Policy.

4. Processor Obligations & Documented Instructions

We will:

  • process Customer Personal Data only on the Customer's documented instructions, including the configuration choices you make in the dashboard and the operations described in the Terms of Service and this DPA;
  • inform you if we believe a Customer instruction infringes Applicable Data Protection Law;
  • not process Customer Personal Data for our own purposes, for advertising, for analytics about the Customer's end users, or for training AI/ML models. For the avoidance of doubt: (i) the AI form-generation feature processes only the design prompt typed by the Customer's authorised user in the dashboard, which is not Customer Personal Data submitted through Forms; (ii) where that feature is used, the prompt is transmitted to our AI Sub-Processor (Google, via Vertex AI) under the Google Cloud Data Processing Addendum, which contractually prohibits Google from using the prompt to train or improve its generally-available models; and (iii) we never transmit Submission content to any AI Sub-Processor.

5. Confidentiality

We ensure that personnel authorised to process Customer Personal Data are bound by a contractual or statutory obligation of confidentiality, are trained on data protection, and access Customer Personal Data only on a need-to-know basis.

6. Security Measures

We implement the technical and organisational measures set out in Annex B, including AES-256-GCM envelope encryption of Submission payloads at rest, TLS in transit, mandatory MFA for staff, rate-limited and throttled authentication, and append-only audit logging. We may update these measures over time provided the level of protection is not materially reduced.

7. Sub-Processors

You provide general authorisation for us to engage Sub-Processors. The current list is published at /legal/subprocessors.

We will give at least 30 days' prior notice of any intended addition or replacement of a Sub-Processor by updating the public list and by emailing Account owners where the change affects their use of the Service. You may object on reasonable data-protection grounds during the notice period by writing to dpo@simplyforms.dev. If we cannot accommodate your objection, you may terminate the affected portion of the Service.

We will impose written contracts on each Sub-Processor with data-protection obligations substantially equivalent to those in this DPA. We remain liable to the Customer for the performance of our Sub-Processors' obligations.

Some Sub-Processors are engaged conditionally rather than for every Customer. In particular, the third-party CAPTCHA providers (Google reCAPTCHA, hCaptcha, and Friendly Captcha) listed on the Sub-processors pageare engaged only for a Customer who selects that provider for a Form's spam protection, using the Customer's own provider keys; we transmit the verification request on the Customer's instruction. Where you do not enable such a provider, it processes none of your Customer Personal Data.

8. Assistance to Customer

Taking into account the nature of the processing, we will:

  • provide reasonable assistance, through appropriate technical and organisational measures, for the Customer to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection);
  • support the Customer in carrying out data-protection impact assessments and prior consultations under Articles 35 and 36 GDPR, where required and within the limits of information available to us;
  • where End Users contact SimplyForms directly with a Data Subject request, refer them to the relevant Customer.

9. Personal Data Breach Notification

We will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event, where reasonably practicable, within 72 hours. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. We will cooperate with the Customer to enable the Customer to comply with its own breach-notification obligations.

10. International Transfers

Where we transfer Customer Personal Data to a country outside the UK or EEA that has not received an adequacy decision, we rely on the EU Standard Contractual Clauses (Module Two: controller to processor) and, for UK personal data, the UK International Data Transfer Addendum, which are incorporated into this DPA by reference.

For the AI form-generation feature (Google, via Vertex AI), prompts are processed in the European Union: the Vertex AI region is pinned to europe-west2 (London) as part of normal processing. Where Google itself performs any onward transfer, the Google Cloud Data Processing Addendum (incorporated by reference into our contract with Google) provides for the EU SCCs and the UK Addendum as the operative transfer mechanism. See /legal/subprocessors for the live processing-location entry.

Where the Customer selects a non-platform CAPTCHA provider for a Form's spam protection, the transfer footprint depends on the provider. Google reCAPTCHA and hCaptchaverify in the United States; that transfer is covered by the EU SCCs and the UK Addendum (Google reCAPTCHA under the Google Cloud Data Processing Addendum; hCaptcha under its own DPA, which additionally relies on the EU–US and UK–US Data Privacy Framework). Friendly Captcha verifies in the European Union, so no transfer outside the UK/EEA arises when it is selected. Each entry, with its processing location, is on the Sub-processors page.

For the SCCs and UK Addendum:

  • the Customer is the data exporter and SimplyForms is the data importer;
  • Clause 7 (docking clause) is included;
  • Clause 9 option 2 applies (general written authorisation for Sub-Processors), with the notice period set out in section 7;
  • Clause 11 redress option is not selected;
  • Clause 17 (governing law) and Clause 18 (jurisdiction) are governed by the law of Ireland;
  • the Annexes to the SCCs are populated by Annex A and Annex B of this DPA, with the Customer and SimplyForms' details from the Terms of Service.

11. Audits & Inspections

We will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR, ordinarily in the form of:

  • this DPA, our published security and sub-processor documentation, and our incident-response runbooks where relevant; and
  • responses to reasonable written security questionnaires.

Where the above is not sufficient and the Customer is required by Applicable Data Protection Law to perform an audit, the Customer may conduct an on-site audit on no less than 30 days' prior written notice, during normal business hours, no more than once in any twelve-month period (except following a Personal Data Breach), at the Customer's cost and subject to confidentiality undertakings. The Customer will minimise disruption to our operations and other customers.

12. Return & Deletion of Personal Data

On termination or expiry of the Service, the Customer may export Customer Personal Data using the in-product CSV/JSON export tools. After the export window closes, or on Customer instruction, we will delete Customer Personal Data from the live Service. The Customer's account deletion triggers immediate deletion of teams, workspaces, forms, Submissions, and uploaded files.

We are not required to delete data we are required by law to retain (for example, billing and tax records), nor minimal audit-log rows retained for security and legal compliance for up to 24 months. Disaster-recovery backups roll off automatically on a short rolling schedule and are not customer-accessible.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits a party's liability to Data Subjects under Applicable Data Protection Law.

14. Order of Precedence

In the event of a conflict, the following order of precedence applies: (a) the SCCs and UK Addendum incorporated under section 10, (b) this DPA, (c) the Terms of Service, (d) any other agreement between the parties.

15. Changes to This DPA

We may update this DPA from time to time. Material changes that affect Customer rights or obligations will be notified at least 30 days in advance. The current version is always published at simplyforms.dev/dpa.

16. Contact

Data-protection enquiries and DPA-related notices: dpo@simplyforms.dev. Postal address: Simplyxity Ltd, Office 16349, 182-184 High Street North, East Ham, London, England, E6 2JA.

Annex A: Processing Details

  • Nature of processing: hosting, storage, transmission, display, deletion, export, and backup of Customer Personal Data; operating SimplyForms-hosted public form pages on the Customer's behalf where the Customer enables hosted delivery; spam-protection (CAPTCHA) verification with the provider the Customer selects; transactional email notifications to recipients you configure; webhook delivery to endpoints you configure.
  • Purpose of processing: providing the SimplyForms Service to the Customer.
  • Duration of processing: for the term of the Terms of Service plus the period necessary for return or deletion under section 12.
  • Categories of Data Subjects: the Customer's end users who submit data through Forms; the Customer's team members who hold accounts; recipients of Customer-configured notification emails.
  • Categories of Personal Data: data the Customer chooses to collect via its Forms (typically contact details such as name and email, free-text messages, and file uploads); team-member account data; notification-recipient email addresses; technical metadata (IP, user-agent, timestamps) captured for security purposes.
  • Special categories: not anticipated; prohibited by the Terms of Service unless separately agreed in writing.
  • Frequency of processing: continuous for as long as the Customer uses the Service.
  • Storage location: primarily European Union and United Kingdom. Some sub-processors process data in the United States or other jurisdictions — see /legal/subprocessors.
  • AI form-generation processing:where a Customer's authorised user invokes the AI form-generation feature in the dashboard, the free-text design prompt typed by that user (maximum 1,000 characters) is transmitted to the AI Sub-Processor (Google, via Vertex AI region europe-west2) solely to draft the requested field schema. SimplyForms persists only a SHA-256 hash of the trimmed prompt and the generation timestamp; the plaintext prompt is not stored. Per-Team token-count usage is retained for quota and billing accounting. No End User submission content is transmitted to the AI Sub-Processor.
  • Spam-protection (CAPTCHA) verification:where the Customer enables a CAPTCHA on a Form, the End User's CAPTCHA response token — and, for Cloudflare Turnstile, Google reCAPTCHA, and hCaptcha, the End User's IP address — is transmitted to the selected provider's verification endpoint solely to confirm the submission is not automated. Friendly Captcha receives only the token, not the IP. No Form field content is transmitted to any CAPTCHA provider. The three optional providers (Google reCAPTCHA, hCaptcha, Friendly Captcha) are engaged only when the Customer selects them, using the Customer's own provider keys, and are listed on the Sub-processors page.
  • Abuse-report processing:where a member of the public uses the “Report this form” link on a SimplyForms-hosted Form, SimplyForms processes the report message, an optional reporter email, and the reporter's IP address and user-agent for abuse triage. This is SimplyForms' own controller-side processing for platform integrity, not processing on the Customer's instruction.

Annex B: Technical & Organisational Measures

  • Encryption in transit: TLS 1.2+ on all customer-facing and inter-service network traffic.
  • Encryption at rest: Submission payloads are envelope-encrypted with AES-256-GCM. Each team holds its own data encryption key (DEK); each DEK is wrapped under a server-held key encryption key (KEK) held in Google Cloud Secret Manager. Raw database access returns ciphertext only.
  • Authentication & access control: password authentication backed by industry-standard hashing; mandatory TOTP MFA for SimplyForms staff with admin access; least-privilege role assignments; mandatory step-up reauth on every SuperAdmin action.
  • Network controls: Cloud Run private ingress where appropriate; HTTP-Origin and OIDC verification on internal service-to-service calls; rate limiting per account and per IP; Cloudflare Turnstile on public auth and form flows.
  • Audit logging: append-only audit log for sensitive operations on customer data and for admin authentication events.
  • Monitoring & error tracking: Sentry configured to scrub Submission bodies, authentication headers, and credentials before events leave the system.
  • AI Sub-Processor isolation:Submission content is never transmitted to AI Sub-Processors. The AI form-generation feature processes only the design prompt typed by the Customer's authorised user, and that prompt is transmitted under the Google Cloud Data Processing Addendum's contractual no-training instruction. SimplyForms does not persist the plaintext prompt; only a SHA-256 hash and metadata are retained. Backend logging, exception capture, and Sentry events are configured so that the raw prompt cannot leak into observability surfaces.
  • Backups: managed daily scheduled backups with a 7-day rolling retention window for disaster-recovery purposes; backups are not customer-accessible and are not used to restore individual accounts.
  • Vulnerability management: automated dependency scanning; security patches applied promptly.
  • Personnel: contractual confidentiality, data-protection training, and need-to-know access.
  • Incident response: documented runbooks for encryption-key incidents, breach response, and data-loss scenarios.