Data Processing Agreement
Version 1.0 · Effective Aug 15, 2026
This Data Processing Agreement ("DPA") forms part of the FormNX Terms & Conditions (the "Agreement") between The Web Fosters, a firm based in India, GSTIN 21AVVPA3897K1Z3, operating the FormNX service ("FormNX", "we", "us", the "Processor") and the customer accepting the Agreement (the "Customer", the "Controller").
This DPA is pre-signed by FormNX and takes effect automatically for any Customer that requires it, on the Customer's acceptance of the Agreement. Countersignature is welcome for the Customer's own records but is not required for this DPA to be binding. This DPA applies where FormNX processes personal data on the Customer's behalf and the processing is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, Canada's PIPEDA, Quebec's Law 25, or US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA (together, "Data Protection Laws").
1. Roles and Scope
The Customer is the controller of the personal data contained in form responses collected through forms the Customer creates ("Customer Data"). FormNX is the processor of Customer Data and processes it only to provide the services described in the Agreement. The details of the processing are set out in Annex I.
For the personal data the Customer provides to FormNX as an account holder (registration and billing information), FormNX is an independent controller, as described in our Privacy Policy; that processing is outside the scope of this DPA.
2. Processing on Instructions
FormNX will process Customer Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law that applies to FormNX — in which case FormNX will inform the Customer of that legal requirement before processing, unless the law prohibits this. The Agreement, this DPA, and the Customer's configuration and use of the services (including the integrations the Customer chooses to enable) constitute the Customer's complete documented instructions. FormNX will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
3. Confidentiality
FormNX ensures that every person it authorises to process Customer Data is bound by a contractual or statutory duty of confidentiality, and that access to Customer Data is limited to the personnel who need it to operate and support the service.
4. Security
FormNX implements and maintains the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as required by Article 32 GDPR. FormNX may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.
5. Sub-processors
The Customer grants FormNX general authorisation to engage the sub-processors listed in Annex III. FormNX will impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
When FormNX engages a new sub-processor, it will be added to the sub-processor list referenced in Annex III. The Customer may object to a new sub-processor on reasonable data-protection grounds within 30 days of the list being updated by writing to [email protected]. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected services and receive a pro-rata refund of any prepaid fees for the remaining term.
6. Assistance to the Customer
Taking into account the nature of the processing, FormNX will assist the Customer with appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligations to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). The service provides self-serve tools for exporting and deleting form responses. If a data subject contacts FormNX directly about Customer Data, FormNX will forward the request to the Customer without undue delay and will not respond to it substantively except on the Customer's instructions or where legally required.
FormNX will further assist the Customer, taking into account the nature of the processing and the information available to FormNX, in ensuring compliance with the Customer's obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation).
7. Personal Data Breach Notification
FormNX will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. FormNX will provide reasonable cooperation so the Customer can meet its own notification deadlines to authorities and data subjects.
8. Deletion and Return
The Customer can export and delete Customer Data at any time using the tools in the service. Upon termination of the Agreement, or upon the Customer's written request, FormNX will delete Customer Data from live systems within 30 days and from backups within a further 30 days, unless law applicable to FormNX requires longer storage. Deletion timelines are also published in our Privacy Policy.
9. Audits and Information
FormNX will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including written responses to reasonable security and compliance questionnaires, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits beyond written questionnaires: no more than once in any 12-month period, on at least 30 days' written notice, during normal business hours, at the Customer's cost, without access to other customers' data, and subject to reasonable confidentiality obligations.
10. International Transfers
Customer Data is stored in the European Union (see Annex I). FormNX is based in India, and some sub-processors operate from countries without an adequacy decision, so remote access to or transfer of Customer Data outside the EEA, the UK or Canada may occur in the course of providing the services.
Where a transfer of Customer Data from the EEA to a third country without an adequacy decision takes place, the parties agree that the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference, completed as follows: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorisation, 30 days); Clause 11 optional language not included; Clause 17 Option 1 — the law of Ireland; Clause 18 — the courts of Ireland. Annexes I and II of the SCCs are deemed completed with Annexes I and II of this DPA. For transfers from the UK, the UK International Data Transfer Addendum to the EU SCCs applies, completed with the information in this DPA. For Customers subject to PIPEDA or Quebec's Law 25, FormNX provides, through this DPA and its Annexes, protection comparable to that required by those laws, and will provide reasonable assistance with the Customer's transfer impact assessments.
If the SCCs apply, they prevail over any conflicting provision of this DPA or the Agreement.
11. US State Privacy Laws
Where the Customer is subject to the California Consumer Privacy Act as amended by the CPRA, or a similar US state privacy law, FormNX acts as the Customer's "service provider" or "processor" under that law. FormNX will not sell or share Customer Data; will not retain, use or disclose Customer Data for any purpose other than providing the services under the Agreement, or as otherwise permitted by those laws; will not combine Customer Data with personal information received from other sources except as permitted for the business purpose; certifies that it understands and will comply with these restrictions; and will notify the Customer if it determines it can no longer meet its obligations under those laws. The Customer may take the reasonable steps set out in Section 9 to verify that FormNX uses Customer Data consistently with the Customer's obligations.
12. Liability and General
The liability of each party under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws do not permit such limitation. This DPA prevails over the Agreement in case of conflict concerning the processing of Customer Data. This DPA is governed by the law governing the Agreement, except where the SCCs require otherwise. If any provision of this DPA is found unenforceable, the remainder stays in effect.
Annex I — Description of the Processing
| Subject matter | Provision of the FormNX online form building service: hosting forms, collecting, storing and making available form responses and uploaded files on the Customer's behalf. |
|---|---|
| Duration | The term of the Agreement, plus the deletion periods in Section 8. |
| Nature and purpose | Collection, storage, organisation, retrieval, disclosure to the Customer, export, and deletion of form responses submitted to the Customer's forms; delivery of submission notification emails; execution of integrations the Customer enables. |
| Categories of data subjects | Individuals who fill in and submit the Customer's forms ("form responders"), and the Customer's own users of the service. |
| Categories of personal data | Determined by the Customer through the fields the Customer adds to its forms. Typically contact details (name, email, phone), free-text answers, uploaded files, and technical data related to a submission. The Customer is responsible for the lawfulness of the data it chooses to collect. |
| Special categories | Only if and to the extent the Customer chooses to collect them through its forms. FormNX provides per-field encryption for sensitive fields (Annex II) and recommends enabling it for any such data. |
| Frequency | Continuous, for as long as the Customer's forms accept submissions. |
| Storage location | Application and database: DigitalOcean, Frankfurt, Germany. Uploaded files: Backblaze B2, EU Central region. All Customer Data resides in the European Union. |
Annex II — Technical and Organisational Measures
- Encryption in transit — all traffic to and from the service is encrypted using TLS.
- Per-field encryption at rest — form fields marked as sensitive by the Customer are encrypted (AES-256) before storage.
- Password security — account passwords are stored only as irreversible hashes; plain-text passwords are never stored.
- Access control — access to production systems is restricted to personnel who need it to operate and support the service, over authenticated, encrypted channels.
- Data segregation — Customer Data is logically segregated per account; customers can only access their own data.
- Backups — data is backed up daily; backups are stored in the EU and purged on the schedule in Section 8; restores are tested periodically.
- Vulnerability management — systems are kept updated with security patches; dependencies are monitored.
- Breach response — a documented notification commitment as per Section 7 of this DPA.
- Data minimisation tooling — self-serve export and deletion of individual responses, whole forms, or the entire account.
Annex III — Authorised Sub-processors
The current, authoritative list of sub-processors, including what each is used for, where it runs and whether it can access Customer Data, is published and maintained at:
formnx.com/details/docs/resources/gdpr
As of the effective date of this DPA, the sub-processors that process Customer Data are: DigitalOcean LLC (hosting and database — data located in Frankfurt, Germany), Backblaze Inc. (file storage — data located in the EU Central region), and Zoho Corporation (transactional email, including submission notifications — EU data centre). Services the Customer connects itself (for example Google Sheets, the Customer's own Stripe account, email marketing tools, or webhooks) act on the Customer's instructions directly and are not FormNX sub-processors.
Signatures
Pre-signed on behalf of FormNX. This DPA is effective on the Customer's acceptance of the Agreement; the Customer's countersignature below is for the Customer's records only.
The Web Fosters (FormNX)
/s/ Nikhil Agrawal
Nikhil Agrawal, Founder
GSTIN 21AVVPA3897K1Z3
Date: Aug 15, 2026
Customer
Legal entity name: ______________________________
Signature: ______________________________
Name and title: ______________________________
Date: ______________________________
Questions about this DPA: [email protected]
Related
- Terms & Conditions — the agreement this DPA forms part of
- Privacy Policy — what data we collect and how we handle it
- GDPR — data residency, security measures and the live sub-processor list