Privacy Policy
Effective date: May 28, 2026
Last updated: July 10, 2026
1. Introduction
This Privacy Policy explains how Simplyxity Ltd ("SimplyForms", "we", "our", or "us") collects, uses, shares, retains, and protects personal data when you use the SimplyForms form-building platform, our website at https://simplyforms.dev, and any related services (together, the "Service").
SimplyForms is built for business and developer users. The Service is not designed for regulated high-risk processing (for example, health, payment-card numbers, or children's data) and you must not collect such information through your forms unless you have a separate written agreement with us — see section 12.
2. Who We Are
- Legal entity: Simplyxity Ltd
- Company number: 16938823 (registered in England and Wales)
- Registered office: Office 16349, 182-184 High Street North, East Ham, London, England, E6 2JA
- ICO registration: ZC083885 (UK Information Commissioner's Office)
- Privacy contact: privacy@simplyforms.dev
- Data Protection point of contact: dpo@simplyforms.dev
The dpo@ mailbox follows industry contact-address convention; Simplyxity Ltd has not appointed a statutory Data Protection Officer under UK GDPR Article 37 because the conditions in Article 37(1) do not apply to our processing.
3. Our Role: Controller vs Processor
SimplyForms operates in two distinct data-protection roles, and your rights and our obligations depend on which role applies to the data in question.
- Controller— we determine the purposes and means of processing for: your account profile and authentication data, billing and tax records, support tickets and feedback you send us, marketing and product communications to account holders, security logs, and audit data we generate while operating the Service.
- Processor— we process on behalf of our customers for: the content of form submissions and uploaded files collected by our customers' forms, and the recipient addresses of customer-configured notification emails. This includes submissions made on a SimplyForms-hosted form page (at
simplyforms.dev/f/…), where we operate the public form page on the customer's behalf: the customer remains the controller and a footer on each hosted page identifies them. For that data, our customer is the controller; we follow their documented instructions. See our Data Processing Agreement.
4. Information We Collect
We collect the following categories of personal data:
- Account profile: first name, last name, email address, and account identifiers.
- Authentication & security:password hash (we never see your plaintext password — hashing is performed by our auth provider), TOTP multi-factor authentication factors, hashed recovery codes, and short-lived re-auth and step-up tokens.
- Forms & form configuration: form names, field definitions, email recipients, spam-protection configuration, webhook URLs and secrets.
- AI form-generation prompts:where you use the AI form-generation feature in the dashboard, the free-text design description you type (maximum 1,000 characters) is sent to Google's Vertex AI service to draft a field schema. We store only the SHA-256 hash of the trimmed prompt and the generation timestamp in your form configuration; the plaintext prompt is never persisted by us. We also count the tokens consumed by each generation against your plan's monthly AI quota. This category covers only the design prompt you type — it does notinclude any data submitted by end users through your forms (see “Submissions” below).
- Submissions (end-user data):the content of submissions sent to your forms by your end users, stored encrypted at rest. These are collected either on your own site (where you embed the form) or on a SimplyForms-hosted form page we operate on your behalf — in both cases, as to this data, we act as processor on your behalf.
- Spam-protection / CAPTCHA verification:when a form has a CAPTCHA enabled, the CAPTCHA response token generated in the end user's browser is sent to our backend, which forwards it (and, for Cloudflare Turnstile, Google reCAPTCHA, and hCaptcha, the end user's IP address) to the selected provider's verification endpoint to confirm the submission is not automated. Friendly Captcha receives only the token, not the IP. We do not send your form's field content to any CAPTCHA provider. See section 6 and the Sub-processors page.
- Abuse reports:where someone uses the “Report this form” link on a SimplyForms-hosted form, we collect the report message they write, an optional contact email if they choose to provide one, and the reporter's IP address and user-agent for abuse triage and to deter false reports.
- Uploaded files: files attached to submissions, feedback, or support tickets, stored in Supabase Storage. We do not inspect the contents of uploaded files.
- Team & collaboration: team membership, role assignments, invitation tokens, and notification-email verification status.
- Webhook delivery logs: the request body, signature, status, and attempt history for each webhook delivery attempt. Retained for 30 days.
- Support tickets & feedback: the email address, subject, message, impact level, and any attachments you send via support or feedback channels.
- Billing data: Stripe customer identifier, subscription identifier, subscription status, and the billing address and tax ID you enter at checkout. Card numbers are held by Stripe; we never see them.
- Device, IP & log data:IP address, user-agent string, request timestamps, and high-level error traces. Captured at limited surfaces — login throttling, Turnstile spam protection, the contact form, and error monitoring.
- Aggregate site analytics:on our public marketing site — page views, referrers, anonymised browser, operating system and device type, and the country derived from your IP address at the moment of the request (the IP is processed at request time and then discarded). Our analytics is cookieless: there is no persistent identifier and no individual is profiled.
- Audit logs: action, actor, timestamp, and minimal metadata for sensitive operations on customer data and admin authentication events.
5. How We Use Information & Lawful Bases
We rely on the following lawful bases under the UK GDPR and EU GDPR:
- Performance of a contract— to provide the Service to you, authenticate you, process submissions on your behalf, send service emails, take payment, provide support, and to operate the AI form-generation feature on your request (which includes transmitting your design prompt to our AI sub-processor, Google Vertex AI, and storing the returned field schema in your form configuration).
- Legitimate interests— to keep the Service secure and prevent abuse (login throttling, CAPTCHA bot protection, abuse reports, audit logs), to monitor errors so we can fix them, to understand how our marketing site is used through cookieless, aggregate analytics that do not identify individuals, to communicate product changes, and to protect our legal rights. We have balanced these interests against your rights and freedoms.
- Legal obligation— to retain billing and tax records, respond to lawful information requests, and comply with applicable law.
- Consent— for any optional communication or feature that asks you to opt in (you can withdraw consent at any time).
We do not sell personal data. We do not use customer submission content(the data your end users submit through your forms) for advertising, analytics, or AI/model training. The AI form-generation feature processes only the design prompt you type into the AI modal — it never sees submission content — and we send that prompt to Google Vertex AI solely to draft the field list you request. We use Vertex AI rather than the consumer Gemini endpoint precisely because Vertex AI is covered by the Google Cloud Data Processing Addendum, under which Google is contractually prohibited from using the data we send for training or improving its generally-available models. Our cookieless site analytics measures only aggregate marketing-site usage and never accesses submission content or AI prompts.
Where you enable a third-party CAPTCHA provider (Google reCAPTCHA, hCaptcha, or Friendly Captcha) on a form you embed on your own site, we transmit the verification request to that provider on your instruction, acting as your processor for that step. As the controller of your end users' data, you are responsible for the lawful basis and for disclosing that provider in your own privacy notice. On SimplyForms-hosted form pages and our own auth flows, only the platform Cloudflare Turnstile is used, on our own legitimate-interest basis.
Google user data (Google Sheets integration).If you connect your Google account to a form, SimplyForms requests Google's drive.file permission — the narrowest available scope, which lets us see and edit only spreadsheets SimplyForms itself creates, never anything else in your Google Drive. We use that access for exactly one purpose: creating the destination spreadsheet you name and appending a row for each form submission. The OAuth credential Google issues is stored encrypted (AES-256-GCM) on our backend, is never exposed to the browser, and is deleted when you disconnect the integration. We do not read, share, sell, or transfer Google user data to anyone, and we do not use it for advertising or to train AI models. You can revoke SimplyForms' access at any time from your Google account's third-party access settings, which immediately stops all spreadsheet writes. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. International Transfers
We primarily host data in the European Union and the United Kingdom. Some sub-processors (notably error monitoring, transactional email, and marketing-site analytics providers) may process data in the United States or other jurisdictions outside the UK/EEA.
Where personal data is transferred outside the UK or EEA, we rely on:
- Adequacy decisions by the European Commission or the UK Government where they apply.
- The European Commission's Standard Contractual Clauses (SCCs) (Module Two: controller to processor) and the UK's International Data Transfer Addendum to those SCCs (or the UK IDTA where appropriate).
- Supplementary measures including encryption in transit, at rest, and minimisation of transferred data.
Our marketing-site analytics provider (Umami Software, Inc., United States) is engaged under its Data Processing Agreement on the basis described above, and receives only the aggregate, non-identifying measurements described in section 4 — no submission content and no persistent identifier.
Our AI form-generation sub-processor (Google, via Vertex AI) processes prompts in the European Union — we pin the Vertex region to europe-west2(London) so AI prompts you send through the dashboard do not leave the EU/UK as part of normal processing. The Google Cloud Data Processing Addendum incorporates the European Commission's SCCs and the UK Addendum and governs any onward transfer Google itself performs.
The optional CAPTCHA providers you may enable on your own forms differ in transfer footprint. Google reCAPTCHA (Google LLC) and hCaptcha (Intuition Machines, Inc.) verify in the United States; both are covered by the SCCs and UK Addendum (Google via the Google Cloud Data Processing Addendum; hCaptcha via its DPA, which also relies on the EU–US and UK–US Data Privacy Framework). Friendly Captcha (Friendly Captcha GmbH) verifies in the European Union and is the EU-resident, cookieless option, so selecting it keeps CAPTCHA verification within the EU. These providers are engaged only for forms where you select them.
8. Data Security
We apply security measures appropriate to the risk:
- All network traffic is served over TLS.
- Form submission payloads are envelope-encrypted at rest with AES-256-GCM. Each team holds its own data encryption key, which is itself wrapped under a server-held key encryption key in Google Cloud Secret Manager. Raw database access — including by SimplyForms engineers with operational database credentials — returns ciphertext only.
- Passwords are stored only as salted hashes by our authentication provider.
- Multi-factor authentication (TOTP) is available to all customers and mandatory for SimplyForms staff with admin access.
- Sensitive account actions (password change, email change, MFA disable, billing changes) require a fresh re-authentication within a short window.
- We rate-limit login attempts per account and per IP, and protect public flows with Cloudflare Turnstile.
- All sensitive operations on customer data are recorded in an append-only audit log.
No system can be guaranteed completely secure. If we become aware of a personal-data breach affecting you, we will notify you and the appropriate supervisory authority in accordance with applicable law.
9. Data Retention
We retain personal data only as long as necessary for the purposes set out above:
| Category | Retention |
|---|---|
| Account profile & team data | For the life of the account; permanently deleted on account closure. |
| Form submissions (by plan) | Free: 30 days · Starter: 90 days. Higher-tier plans with longer retention windows will be added here when those plans launch. Plan downgrades trigger a 30-day grace period before the shorter window applies. |
| AI form-generation prompts & metadata | For the life of the generated form: a SHA-256 hash of the prompt, the generation timestamp, and the model name are kept alongside the form configuration. The plaintext prompt is never stored by SimplyForms. Per-team token-count usage is retained indefinitely for quota and billing purposes. Google's retention of the prompt itself is governed by the Google Cloud Data Processing Addendum and is described on the Sub-processors page. |
| Uploaded files | Deleted together with their submission. |
| Webhook delivery logs | 30 days, then permanently purged. |
| Authentication & security audit logs | Up to 24 months for security and legal-compliance purposes (GDPR Art. 6(1)(f) legitimate interests). |
| Support tickets & feedback | Up to 24 months from the last interaction. |
| Billing & tax records | Retained for the period required by UK tax law (currently 6 years). |
| Database backups | Managed by Supabase as daily scheduled backups with a 7-day rolling retention window; older snapshots roll off automatically and are not customer-accessible. |
| Deleted accounts | Account, teams, workspaces, forms, submissions, and uploads are deleted immediately. Minimal audit-log rows (action, actor email, timestamp) are retained for security and legal compliance up to the audit-log retention above. |
We send an email warning approximately seven days before form submissions become eligible for deletion under the plan retention window so that you can export them.
10. Your Rights
If you are an account holder, you have the following rights in relation to your personal data, subject to legal limits:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete personal data; closing your account performs this for most categories.
- Restriction — ask us to suspend certain processing.
- Objection — object to processing based on legitimate interests.
- Portability — receive your data in a structured, machine-readable format. You can export your submissions to CSV or JSON at any time from the dashboard.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email privacy@simplyforms.dev. We will respond within one month and may ask you to verify your identity.
11. Requests From End Users
If you submitted a form built by a SimplyForms customer and want to access, correct, or delete your submission, we are acting as processor on behalf of that customer. This is true whether you submitted on the customer's own website or on a SimplyForms-hosted form page (at simplyforms.dev/f/…) — the customer is the controller in both cases, and the footer on each hosted page identifies them (or links to their privacy notice). Please contact the customer (the site or business that runs the form) directly. We will assist our customer in responding to your request, but we cannot act on it unilaterally.
12. Sensitive & Children's Data
The Service is not designed for processing special-category data under UK or EU GDPR, payment-card numbers (PCI DSS), regulated health information (including HIPAA), criminal-offence data, or personal data of children under 13 (or under 16 in the EEA). Do not collect such information through your forms unless we have signed a separate written agreement with you that specifically permits it.
We may suspend forms or accounts where we reasonably believe — based on the form’s configuration (field labels, form name, recipient settings), file-upload metadata, abuse reports from end users, or other lawful signals available to us without decrypting submission contents— that they are being used to collect such data without authorisation. We do not proactively read encrypted submission payloads to enforce this clause.
13. Staff Access to Submission Data
SimplyForms staff do not access the content of form submissions during normal operations. Our internal admin tools show only metadata (form, timestamp, spam status, flagged reason) by default. Submission payloads — including names, emails, messages, and file uploads — are not visible to staff without going through a justified-access flow.
Access to submission content is restricted to these specific circumstances:
- Abuse investigation — investigating reports of spam, harassment, or platform abuse.
- Legal requests — responding to a subpoena, warrant, or other lawful production order. Requires a separate super-admin reviewer — no self-approval.
- Data subject requests — fulfilling a verified request from an end user, routed through the customer/controller. Also requires a separate super-admin reviewer.
- Customer-authorised debugging — troubleshooting on a customer ticket or email request where the customer has authorised review.
- Security incidents — investigating an active security event affecting the platform.
Every access requires a written justification recorded in our audit log, is limited to a single submission with a 15-minute single-use token, and is reviewable by our security team. We never use submission content for marketing, model training, or analytics. This commitment applies to end-user submission content; the AI form-generation feature operates on the design prompt you type in the dashboard, not on submission content (see sections 4 and 5).
Customers may opt in to email notifications for every such access from Account → Team → Privacy & Notifications.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy here and updating the "Last updated" date. For significant changes affecting your rights, we will also email account holders at least 30 days before the change takes effect.
16. Contact & Complaints
For privacy questions, requests, or complaints, email privacy@simplyforms.dev or write to Simplyxity Ltd, Office 16349, 182-184 High Street North, East Ham, London, England, E6 2JA.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint/ or with your local EU/EEA supervisory authority.