Annex to Article 28 GDPR — Agreement between the Client (Controller) and Form-it (Processor)
This document is an annex to Form-it's Terms of Service and governs, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR), the processing of personal data that Ático Estudio Gráfico, S.L. (Tax ID B13530050, hereinafter the "Processor" or "Form-it") carries out on behalf of the Client who subscribes to an account on the platform (hereinafter the "Controller"), in its capacity as data controller for the personal data of Respondents who answer the Client's forms.
The Controller expressly accepts this annex, together with the Terms of Service and Privacy Policy, via the acceptance checkbox they must tick when registering their Form-it account, before being able to access the dashboard.
This agreement remains in effect for as long as the Controller keeps their Form-it account active, and for the subsequent period necessary to comply with the data-retention or deletion obligations set out in Section 9.
The Processor will process Respondents' personal data solely to provide the Service contracted by the Controller: receiving, processing (including conversational interpretation via AI models in Chat mode), storing, and making available to the Controller the responses to their forms. Processing continues for as long as the Controller retains those responses in their account.
The data subjects are the Respondents who answer the Controller's forms. The type of personal data processed depends entirely on the fields the Controller configures in each form (for example: name, email, phone, free text, attached files or images). The Controller alone decides what data is requested, and is responsible for not collecting special categories of data (Article 9 GDPR) without the enhanced legal basis the Regulation requires.
The Processor undertakes to:
The Controller gives general authorisation for the Processor to engage the following sub-processors, necessary to provide the Service. The Processor will inform the Controller of any change to this list with reasonable advance notice, giving them the opportunity to object:
Some of the sub-processors listed in Section 6 are established outside the European Economic Area. Where this involves an international data transfer, the Processor undertakes that such transfer will be covered by a valid mechanism under Chapter V GDPR (such as the Standard Contractual Clauses approved by the European Commission, or a current adequacy decision for the destination country).
The Processor applies, among others, the following measures: encryption of communications (HTTPS/TLS), encryption of API keys the Controller configures for their own AI provider, access control based on individual authentication, and row-level security (RLS) policies in the database that prevent one Client from accessing another's data.
When the Controller closes their account, or at their express request, the Processor will delete the personal data processed on their behalf, unless a legal rule requires its retention for a specific period, in which case the Processor will keep it blocked during that period and delete it at its end.
The Processor will make available to the Controller the information reasonably necessary to demonstrate compliance with its obligations, and will allow audits, including inspections, requested by the Controller with reasonable advance notice, within what is reasonable for a platform of this size.