Privacy Policy

Effective date: May 28, 2026

Last updated: July 10, 2026

1. Introduction

This Privacy Policy explains how Simplyxity Ltd ("SimplyForms", "we", "our", or "us") collects, uses, shares, retains, and protects personal data when you use the SimplyForms form-building platform, our website at https://simplyforms.dev, and any related services (together, the "Service").

SimplyForms is built for business and developer users. The Service is not designed for regulated high-risk processing (for example, health, payment-card numbers, or children's data) and you must not collect such information through your forms unless you have a separate written agreement with us — see section 12.

2. Who We Are

  • Legal entity: Simplyxity Ltd
  • Company number: 16938823 (registered in England and Wales)
  • Registered office: Office 16349, 182-184 High Street North, East Ham, London, England, E6 2JA
  • ICO registration: ZC083885 (UK Information Commissioner's Office)
  • Privacy contact: privacy@simplyforms.dev
  • Data Protection point of contact: dpo@simplyforms.dev

The dpo@ mailbox follows industry contact-address convention; Simplyxity Ltd has not appointed a statutory Data Protection Officer under UK GDPR Article 37 because the conditions in Article 37(1) do not apply to our processing.

3. Our Role: Controller vs Processor

SimplyForms operates in two distinct data-protection roles, and your rights and our obligations depend on which role applies to the data in question.

  • Controller— we determine the purposes and means of processing for: your account profile and authentication data, billing and tax records, support tickets and feedback you send us, marketing and product communications to account holders, security logs, and audit data we generate while operating the Service.
  • Processor— we process on behalf of our customers for: the content of form submissions and uploaded files collected by our customers' forms, and the recipient addresses of customer-configured notification emails. This includes submissions made on a SimplyForms-hosted form page (at simplyforms.dev/f/…), where we operate the public form page on the customer's behalf: the customer remains the controller and a footer on each hosted page identifies them. For that data, our customer is the controller; we follow their documented instructions. See our Data Processing Agreement.

4. Information We Collect

We collect the following categories of personal data:

  • Account profile: first name, last name, email address, and account identifiers.
  • Authentication & security:password hash (we never see your plaintext password — hashing is performed by our auth provider), TOTP multi-factor authentication factors, hashed recovery codes, and short-lived re-auth and step-up tokens.
  • Forms & form configuration: form names, field definitions, email recipients, spam-protection configuration, webhook URLs and secrets.
  • AI form-generation prompts:where you use the AI form-generation feature in the dashboard, the free-text design description you type (maximum 1,000 characters) is sent to Google's Vertex AI service to draft a field schema. We store only the SHA-256 hash of the trimmed prompt and the generation timestamp in your form configuration; the plaintext prompt is never persisted by us. We also count the tokens consumed by each generation against your plan's monthly AI quota. This category covers only the design prompt you type — it does notinclude any data submitted by end users through your forms (see “Submissions” below).
  • Submissions (end-user data):the content of submissions sent to your forms by your end users, stored encrypted at rest. These are collected either on your own site (where you embed the form) or on a SimplyForms-hosted form page we operate on your behalf — in both cases, as to this data, we act as processor on your behalf.
  • Spam-protection / CAPTCHA verification:when a form has a CAPTCHA enabled, the CAPTCHA response token generated in the end user's browser is sent to our backend, which forwards it (and, for Cloudflare Turnstile, Google reCAPTCHA, and hCaptcha, the end user's IP address) to the selected provider's verification endpoint to confirm the submission is not automated. Friendly Captcha receives only the token, not the IP. We do not send your form's field content to any CAPTCHA provider. See section 6 and the Sub-processors page.
  • Abuse reports:where someone uses the “Report this form” link on a SimplyForms-hosted form, we collect the report message they write, an optional contact email if they choose to provide one, and the reporter's IP address and user-agent for abuse triage and to deter false reports.
  • Uploaded files: files attached to submissions, feedback, or support tickets, stored in Supabase Storage. We do not inspect the contents of uploaded files.
  • Team & collaboration: team membership, role assignments, invitation tokens, and notification-email verification status.
  • Webhook delivery logs: the request body, signature, status, and attempt history for each webhook delivery attempt. Retained for 30 days.
  • Support tickets & feedback: the email address, subject, message, impact level, and any attachments you send via support or feedback channels.
  • Billing data: Stripe customer identifier, subscription identifier, subscription status, and the billing address and tax ID you enter at checkout. Card numbers are held by Stripe; we never see them.
  • Device, IP & log data:IP address, user-agent string, request timestamps, and high-level error traces. Captured at limited surfaces — login throttling, Turnstile spam protection, the contact form, and error monitoring.
  • Aggregate site analytics:on our public marketing site — page views, referrers, anonymised browser, operating system and device type, and the country derived from your IP address at the moment of the request (the IP is processed at request time and then discarded). Our analytics is cookieless: there is no persistent identifier and no individual is profiled.
  • Audit logs: action, actor, timestamp, and minimal metadata for sensitive operations on customer data and admin authentication events.

5. How We Use Information & Lawful Bases

We rely on the following lawful bases under the UK GDPR and EU GDPR:

  • Performance of a contract— to provide the Service to you, authenticate you, process submissions on your behalf, send service emails, take payment, provide support, and to operate the AI form-generation feature on your request (which includes transmitting your design prompt to our AI sub-processor, Google Vertex AI, and storing the returned field schema in your form configuration).
  • Legitimate interests— to keep the Service secure and prevent abuse (login throttling, CAPTCHA bot protection, abuse reports, audit logs), to monitor errors so we can fix them, to understand how our marketing site is used through cookieless, aggregate analytics that do not identify individuals, to communicate product changes, and to protect our legal rights. We have balanced these interests against your rights and freedoms.
  • Legal obligation— to retain billing and tax records, respond to lawful information requests, and comply with applicable law.
  • Consent— for any optional communication or feature that asks you to opt in (you can withdraw consent at any time).

We do not sell personal data. We do not use customer submission content(the data your end users submit through your forms) for advertising, analytics, or AI/model training. The AI form-generation feature processes only the design prompt you type into the AI modal — it never sees submission content — and we send that prompt to Google Vertex AI solely to draft the field list you request. We use Vertex AI rather than the consumer Gemini endpoint precisely because Vertex AI is covered by the Google Cloud Data Processing Addendum, under which Google is contractually prohibited from using the data we send for training or improving its generally-available models. Our cookieless site analytics measures only aggregate marketing-site usage and never accesses submission content or AI prompts.

Where you enable a third-party CAPTCHA provider (Google reCAPTCHA, hCaptcha, or Friendly Captcha) on a form you embed on your own site, we transmit the verification request to that provider on your instruction, acting as your processor for that step. As the controller of your end users' data, you are responsible for the lawful basis and for disclosing that provider in your own privacy notice. On SimplyForms-hosted form pages and our own auth flows, only the platform Cloudflare Turnstile is used, on our own legitimate-interest basis.

Google user data (Google Sheets integration).If you connect your Google account to a form, SimplyForms requests Google's drive.file permission — the narrowest available scope, which lets us see and edit only spreadsheets SimplyForms itself creates, never anything else in your Google Drive. We use that access for exactly one purpose: creating the destination spreadsheet you name and appending a row for each form submission. The OAuth credential Google issues is stored encrypted (AES-256-GCM) on our backend, is never exposed to the browser, and is deleted when you disconnect the integration. We do not read, share, sell, or transfer Google user data to anyone, and we do not use it for advertising or to train AI models. You can revoke SimplyForms' access at any time from your Google account's third-party access settings, which immediately stops all spreadsheet writes. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Sharing & Sub-Processors

We share personal data only with sub-processors that help us operate the Service, under written contracts that require equivalent protections. Each sub-processor receives only the data it needs for its specific function.

The full, current list — with vendor, purpose, data categories, and processing location — is published at /legal/subprocessors. We commit to publishing changes there at least 30 days before a new sub-processor begins processing personal data for production use.

These include Umami, which provides cookieless analytics for our marketing site and receives only aggregate, non-identifying measurements — no submission content and no persistent identifier. See our Cookie Policy for the full analytics detail.

They also include Google (Gemini API via Vertex AI), which drafts field schemas from the design prompt you type into the AI form-generation feature. Google receives only the prompt text and returns the generated schema. We never transmit submission content to Google's AI services. The full disclosure — purpose, data scope, processing location, and the contractual no-training instruction — is on the Sub-processors page.

When you connect the Google Sheets integration, Google additionally acts as a conditional recipient on your instruction: we send your form submissions' field values to the Google Sheets API solely to append them to the spreadsheet SimplyForms created in yourGoogle Drive (see “Google user data” in section 5). That spreadsheet lives in your Google account under Google's own terms; disconnecting the integration stops all writes.

Three further providers — Google reCAPTCHA, hCaptcha, and Friendly Captcha— are conditionalsub-processors: we engage them only when you select that provider for a form's spam protection, and only to verify the CAPTCHA token your end user's browser produces (for reCAPTCHA and hCaptcha, also the end user's IP). Each is listed, with its data scope and processing location, on the Sub-processors page.

In addition, we may disclose personal data:

  • To meet legal requirements— when required by law, regulation, or a valid legal process. We will challenge requests that appear unlawful or overbroad where it is reasonable to do so.
  • In a business transfer— in connection with a merger, acquisition, or sale of assets, subject to equivalent privacy commitments.

7. International Transfers

We primarily host data in the European Union and the United Kingdom. Some sub-processors (notably error monitoring, transactional email, and marketing-site analytics providers) may process data in the United States or other jurisdictions outside the UK/EEA.

Where personal data is transferred outside the UK or EEA, we rely on:

  • Adequacy decisions by the European Commission or the UK Government where they apply.
  • The European Commission's Standard Contractual Clauses (SCCs) (Module Two: controller to processor) and the UK's International Data Transfer Addendum to those SCCs (or the UK IDTA where appropriate).
  • Supplementary measures including encryption in transit, at rest, and minimisation of transferred data.

Our marketing-site analytics provider (Umami Software, Inc., United States) is engaged under its Data Processing Agreement on the basis described above, and receives only the aggregate, non-identifying measurements described in section 4 — no submission content and no persistent identifier.

Our AI form-generation sub-processor (Google, via Vertex AI) processes prompts in the European Union — we pin the Vertex region to europe-west2(London) so AI prompts you send through the dashboard do not leave the EU/UK as part of normal processing. The Google Cloud Data Processing Addendum incorporates the European Commission's SCCs and the UK Addendum and governs any onward transfer Google itself performs.

The optional CAPTCHA providers you may enable on your own forms differ in transfer footprint. Google reCAPTCHA (Google LLC) and hCaptcha (Intuition Machines, Inc.) verify in the United States; both are covered by the SCCs and UK Addendum (Google via the Google Cloud Data Processing Addendum; hCaptcha via its DPA, which also relies on the EU–US and UK–US Data Privacy Framework). Friendly Captcha (Friendly Captcha GmbH) verifies in the European Union and is the EU-resident, cookieless option, so selecting it keeps CAPTCHA verification within the EU. These providers are engaged only for forms where you select them.

8. Data Security

We apply security measures appropriate to the risk:

  • All network traffic is served over TLS.
  • Form submission payloads are envelope-encrypted at rest with AES-256-GCM. Each team holds its own data encryption key, which is itself wrapped under a server-held key encryption key in Google Cloud Secret Manager. Raw database access — including by SimplyForms engineers with operational database credentials — returns ciphertext only.
  • Passwords are stored only as salted hashes by our authentication provider.
  • Multi-factor authentication (TOTP) is available to all customers and mandatory for SimplyForms staff with admin access.
  • Sensitive account actions (password change, email change, MFA disable, billing changes) require a fresh re-authentication within a short window.
  • We rate-limit login attempts per account and per IP, and protect public flows with Cloudflare Turnstile.
  • All sensitive operations on customer data are recorded in an append-only audit log.

No system can be guaranteed completely secure. If we become aware of a personal-data breach affecting you, we will notify you and the appropriate supervisory authority in accordance with applicable law.

9. Data Retention

We retain personal data only as long as necessary for the purposes set out above:

CategoryRetention
Account profile & team dataFor the life of the account; permanently deleted on account closure.
Form submissions (by plan)Free: 30 days · Starter: 90 days. Higher-tier plans with longer retention windows will be added here when those plans launch. Plan downgrades trigger a 30-day grace period before the shorter window applies.
AI form-generation prompts & metadataFor the life of the generated form: a SHA-256 hash of the prompt, the generation timestamp, and the model name are kept alongside the form configuration. The plaintext prompt is never stored by SimplyForms. Per-team token-count usage is retained indefinitely for quota and billing purposes. Google's retention of the prompt itself is governed by the Google Cloud Data Processing Addendum and is described on the Sub-processors page.
Uploaded filesDeleted together with their submission.
Webhook delivery logs30 days, then permanently purged.
Authentication & security audit logsUp to 24 months for security and legal-compliance purposes (GDPR Art. 6(1)(f) legitimate interests).
Support tickets & feedbackUp to 24 months from the last interaction.
Billing & tax recordsRetained for the period required by UK tax law (currently 6 years).
Database backupsManaged by Supabase as daily scheduled backups with a 7-day rolling retention window; older snapshots roll off automatically and are not customer-accessible.
Deleted accountsAccount, teams, workspaces, forms, submissions, and uploads are deleted immediately. Minimal audit-log rows (action, actor email, timestamp) are retained for security and legal compliance up to the audit-log retention above.

We send an email warning approximately seven days before form submissions become eligible for deletion under the plan retention window so that you can export them.

10. Your Rights

If you are an account holder, you have the following rights in relation to your personal data, subject to legal limits:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — ask us to delete personal data; closing your account performs this for most categories.
  • Restriction — ask us to suspend certain processing.
  • Objection — object to processing based on legitimate interests.
  • Portability — receive your data in a structured, machine-readable format. You can export your submissions to CSV or JSON at any time from the dashboard.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.

To exercise any of these rights, email privacy@simplyforms.dev. We will respond within one month and may ask you to verify your identity.

11. Requests From End Users

If you submitted a form built by a SimplyForms customer and want to access, correct, or delete your submission, we are acting as processor on behalf of that customer. This is true whether you submitted on the customer's own website or on a SimplyForms-hosted form page (at simplyforms.dev/f/…) — the customer is the controller in both cases, and the footer on each hosted page identifies them (or links to their privacy notice). Please contact the customer (the site or business that runs the form) directly. We will assist our customer in responding to your request, but we cannot act on it unilaterally.

12. Sensitive & Children's Data

The Service is not designed for processing special-category data under UK or EU GDPR, payment-card numbers (PCI DSS), regulated health information (including HIPAA), criminal-offence data, or personal data of children under 13 (or under 16 in the EEA). Do not collect such information through your forms unless we have signed a separate written agreement with you that specifically permits it.

We may suspend forms or accounts where we reasonably believe — based on the form’s configuration (field labels, form name, recipient settings), file-upload metadata, abuse reports from end users, or other lawful signals available to us without decrypting submission contents— that they are being used to collect such data without authorisation. We do not proactively read encrypted submission payloads to enforce this clause.

13. Staff Access to Submission Data

SimplyForms staff do not access the content of form submissions during normal operations. Our internal admin tools show only metadata (form, timestamp, spam status, flagged reason) by default. Submission payloads — including names, emails, messages, and file uploads — are not visible to staff without going through a justified-access flow.

Access to submission content is restricted to these specific circumstances:

  • Abuse investigation — investigating reports of spam, harassment, or platform abuse.
  • Legal requests — responding to a subpoena, warrant, or other lawful production order. Requires a separate super-admin reviewer — no self-approval.
  • Data subject requests — fulfilling a verified request from an end user, routed through the customer/controller. Also requires a separate super-admin reviewer.
  • Customer-authorised debugging — troubleshooting on a customer ticket or email request where the customer has authorised review.
  • Security incidents — investigating an active security event affecting the platform.

Every access requires a written justification recorded in our audit log, is limited to a single submission with a 15-minute single-use token, and is reviewable by our security team. We never use submission content for marketing, model training, or analytics. This commitment applies to end-user submission content; the AI form-generation feature operates on the design prompt you type in the dashboard, not on submission content (see sections 4 and 5).

Customers may opt in to email notifications for every such access from Account → Team → Privacy & Notifications.

14. Cookies & Similar Technologies

We use a small set of cookies and similar storage technologies described in our Cookie Policy. We do not use advertising or cross-site tracking cookies and we do not load analytics that set cookies. If we ever introduce non-essential cookies, we will ask for your consent before they are set.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy here and updating the "Last updated" date. For significant changes affecting your rights, we will also email account holders at least 30 days before the change takes effect.

16. Contact & Complaints

For privacy questions, requests, or complaints, email privacy@simplyforms.dev or write to Simplyxity Ltd, Office 16349, 182-184 High Street North, East Ham, London, England, E6 2JA.

If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint/ or with your local EU/EEA supervisory authority.