Sub-Processors

The current list of sub-processors we engage to operate SimplyForms.

Last updated: June 25, 2026

1. Introduction

We engage the third-party providers listed below as Sub-Processors to operate the SimplyForms Service. Each Sub-Processor is contracted under a written agreement requiring data-protection obligations substantially equivalent to those we accept under our Data Processing Agreement. Each one receives only the data it needs for its specific function.

Most Sub-Processors below are engaged for every Customer (for example, hosting, database, and email). The three optional CAPTCHA providers — Google reCAPTCHA, hCaptcha, and Friendly Captcha— are conditional: we engage them only for a Customer who selects that provider for a specific form’s spam protection, using the Customer’s own provider keys, and only to relay that form’s verification request. Cloudflare Turnstile is the always-on default and is also the only CAPTCHA used on SimplyForms-hosted form pages.

For background on our roles and lawful bases, see the Privacy Policy. We do not use advertising or marketing sub-processors.

2. Current Sub-Processors

Sub-processorPurposeData scopeLocationVendor legal page
SupabaseManaged Postgres database, authentication, and object storage for the customer-facing Service.Account profile, team/workspace data, form configuration, encrypted submission payloads (we hold the keys), uploaded files, audit logs.European Union (Ireland, eu-west-1)Supabase DPA
StripeSubscription billing, embedded checkout, automatic tax calculation, and webhook delivery of billing events.Stripe customer ID, subscription ID, billing address and tax ID, payment method (held by Stripe, not by us).European Union (Stripe Payments Europe Ltd) / United StatesStripe DPA
ResendTransactional email delivery (account verification, team invitations, submission notifications, retention warnings, account-exists checks).Recipient email address, sender identity, and email body (which may contain submission preview data when the customer has configured email notifications).European Union (Ireland, eu-west-1) -- US-incorporated providerResend DPA
SentryApplication error monitoring across web, admin, and backend services.Error stack traces, request URLs, browser/device metadata, IP address. Sentry is configured to scrub request bodies, authentication headers, cookies, and credentials before events leave our systems.United States / European UnionSentry DPA
CloudflareDNS, CDN, and Turnstile bot/abuse protection on public auth and form endpoints. Turnstile is the always-on default spam protection and the only CAPTCHA used on SimplyForms-hosted form pages.IP address, user-agent, request metadata, and Turnstile challenge state for requests that traverse the Cloudflare edge.Global edge networkCloudflare DPA
Google (reCAPTCHA)Bot and abuse verification on a Customer’s embedded form. Conditional: engaged only when the Customer selects Google reCAPTCHA as that form’s spam protection, using the Customer’s own reCAPTCHA keys.The reCAPTCHA response token generated in the end user’s browser, the end user’s IP address, and the pass/fail verification result. We transmit these to Google’s siteverify endpoint on the Customer’s instruction; we send no form field content. Since 2 April 2026 Google processes reCAPTCHA data as a processor under the Google Cloud Data Processing Addendum.United States (Google LLC)Google Cloud DPA
hCaptcha (Intuition Machines, Inc.)Bot and abuse verification on a Customer’s embedded form. Conditional: engaged only when the Customer selects hCaptcha as that form’s spam protection, using the Customer’s own hCaptcha keys.The hCaptcha response token generated in the end user’s browser, the end user’s IP address, and the pass/fail verification result, transmitted to hCaptcha’s siteverify endpoint on the Customer’s instruction; we send no form field content.United States (Intuition Machines, Inc.)hCaptcha DPA
Friendly Captcha (Friendly Captcha GmbH)Bot and abuse verification on a Customer’s embedded form, and the cookieless, EU-resident option. Conditional: engaged only when the Customer selects Friendly Captcha as that form’s spam protection, using the Customer’s own keys.The Friendly Captcha response token generated in the end user’s browser and the pass/fail verification result, transmitted to Friendly Captcha’s siteverify endpoint on the Customer’s instruction. We do not transmit the end user’s IP address to Friendly Captcha, and Friendly Captcha sets no cookies.European Union (Friendly Captcha GmbH, Germany)Friendly Captcha DPA
Google Cloud (Cloud Run + Secret Manager)Application hosting for the web, admin, and backend services, and secure storage of the server-held key-encryption key.All application traffic and logs for the customer-facing Service; wrapped per-team data-encryption keys; the server-held key-encryption key.European UnionGoogle Cloud DPA
UmamiFirst-party cookieless analytics for the public marketing site only.Page views, referrers, anonymised browser/OS/device type, and country derived from IP at request time then discarded. No persistent identifier, no submission content, no cross-site tracking.United StatesUmami DPA
Google (Gemini API via Vertex AI)AI form-generation: drafts a field schema from the design prompt typed by an authorised user in the dashboard AI modal. Engaged via Vertex AI rather than the consumer Google AI Studio endpoint so the relationship is covered by the Google Cloud DPA, under which Google is contractually prohibited from using the data we send for training or improving its generally-available models.Free-text design prompt (max 1,000 characters) typed by the Customer’s authorised user, and the generation’s token-count metadata returned by the model. No End User submission content and no End User personal data are transmitted. Google returns the generated field schema.European Union (Vertex AI region europe-west2, London)Google Cloud DPA

3. Change Notification & Objection

We will publish updates to this list at least 30 days before any new Sub-Processor begins processing personal data for production use. We will also email Account owners where the change affects their use of the Service.

If you object on reasonable data-protection grounds during the notice period, write to dpo@simplyforms.dev. We will work with you in good faith to address the objection. If we cannot reasonably accommodate it, you may terminate the affected portion of the Service in accordance with the DPA.

4. Contact

Questions about our Sub-Processors: dpo@simplyforms.dev. Postal address: Simplyxity Ltd, Office 16349, 182-184 High Street North, East Ham, London, England, E6 2JA.