Back to Form-it

Data Processing Agreement

Annex to Article 28 GDPR — Agreement between the Client (Controller) and Form-it (Processor)

1. Purpose and Parties

This document is an annex to Form-it's Terms of Service and governs, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR), the processing of personal data that Ático Estudio Gráfico, S.L. (Tax ID B13530050, hereinafter the "Processor" or "Form-it") carries out on behalf of the Client who subscribes to an account on the platform (hereinafter the "Controller"), in its capacity as data controller for the personal data of Respondents who answer the Client's forms.

The Controller expressly accepts this annex, together with the Terms of Service and Privacy Policy, via the acceptance checkbox they must tick when registering their Form-it account, before being able to access the dashboard.

2. Duration

This agreement remains in effect for as long as the Controller keeps their Form-it account active, and for the subsequent period necessary to comply with the data-retention or deletion obligations set out in Section 9.

3. Nature, Purpose and Duration of Processing

The Processor will process Respondents' personal data solely to provide the Service contracted by the Controller: receiving, processing (including conversational interpretation via AI models in Chat mode), storing, and making available to the Controller the responses to their forms. Processing continues for as long as the Controller retains those responses in their account.

4. Type of Data and Categories of Data Subjects

The data subjects are the Respondents who answer the Controller's forms. The type of personal data processed depends entirely on the fields the Controller configures in each form (for example: name, email, phone, free text, attached files or images). The Controller alone decides what data is requested, and is responsible for not collecting special categories of data (Article 9 GDPR) without the enhanced legal basis the Regulation requires.

5. Processor's Obligations

The Processor undertakes to:

  • Process personal data only on the Controller's documented instructions (as reflected in their form configuration), except where otherwise required by law.
  • Ensure that persons authorised to process the data are bound by confidentiality.
  • Adopt the technical and organisational security measures required by Article 32 GDPR (encryption in transit, access control, and the measures described in Section 8).
  • Not engage another processor without the Controller's prior, specific or general authorisation, in accordance with Section 6.
  • Assist the Controller, as far as possible, in responding to requests to exercise data subjects' rights.
  • Notify the Controller without undue delay of any personal data breach it becomes aware of.
  • Make available to the Controller the information necessary to demonstrate compliance with these obligations.
  • Delete or return the data at the end of the provision of the Service, in accordance with Section 9.

6. Sub-processors

The Controller gives general authorisation for the Processor to engage the following sub-processors, necessary to provide the Service. The Processor will inform the Controller of any change to this list with reasonable advance notice, giving them the opportunity to object:

  • Supabase, Inc. — database and storage for attached files.
  • Vercel Inc. — application hosting.
  • Clerk, Inc. — authentication for the Controller's accounts.
  • Resend — sending the Service's notifications and transactional emails.
  • OpenAI, L.L.C. — AI conversational processing (the platform's default provider).
  • Anthropic, PBC and Google LLC — AI conversational processing, only when the Controller expressly configures their own API key with one of these providers ("BYOK") instead of the default provider.

7. International Transfers

Some of the sub-processors listed in Section 6 are established outside the European Economic Area. Where this involves an international data transfer, the Processor undertakes that such transfer will be covered by a valid mechanism under Chapter V GDPR (such as the Standard Contractual Clauses approved by the European Commission, or a current adequacy decision for the destination country).

8. Security Measures

The Processor applies, among others, the following measures: encryption of communications (HTTPS/TLS), encryption of API keys the Controller configures for their own AI provider, access control based on individual authentication, and row-level security (RLS) policies in the database that prevent one Client from accessing another's data.

9. Data at the End of the Provision of the Service

When the Controller closes their account, or at their express request, the Processor will delete the personal data processed on their behalf, unless a legal rule requires its retention for a specific period, in which case the Processor will keep it blocked during that period and delete it at its end.

10. Audits

The Processor will make available to the Controller the information reasonably necessary to demonstrate compliance with its obligations, and will allow audits, including inspections, requested by the Controller with reasonable advance notice, within what is reasonable for a platform of this size.