Data Processing Addendum
Version 1.0 · Effective July 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between All Web Forms ("Processor") and the customer ("Controller") and applies whenever the Processor processes personal data on behalf of the Controller under EU GDPR, UK GDPR, or equivalent legislation.
1. Scope and roles
The Controller determines the purposes and means of processing personal data submitted through forms it operates. The Processor processes that data solely to provide the service and only on documented instructions from the Controller (as reflected in the Terms and this DPA).
2. Nature of processing
- Subject matter: hosted form building, submission collection, delivery, and reporting.
- Duration: for the term of the Controller's account plus deletion within 30 days of termination.
- Categories of data: whatever the Controller collects through its forms (contact details, free-text answers, uploads, and — if the Controller enables HIPAA mode — health-related information).
- Categories of data subjects: the Controller's respondents and end users.
3. Processor obligations
- Process personal data only on documented instructions from the Controller.
- Ensure personnel with access to personal data are bound by confidentiality.
- Implement appropriate technical and organizational measures (Article 32) — see our Trust center for the current control set.
- Assist the Controller with data subject requests (access, deletion, portability, restriction, objection) using the tools exposed at /account and via info@allwebforms.com.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
4. Subprocessors
The Controller authorizes the Processor to use the subprocessors listed at /subprocessors. We give reasonable prior notice of changes.
5. International transfers
Where personal data is transferred outside the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum.
6. Deletion
On termination, or on written request, the Processor deletes all personal data within 30 days, except where retention is required by law. Backups are overwritten on their normal rotation cycle.
7. Audits
The Controller may audit compliance with this DPA once per year by reviewing our latest third-party security reports (available on request under NDA) or through a written questionnaire.
8. Contact
Data protection contact: info@allwebforms.com.
This DPA is provided as a self-serve template. To countersign a version for your records, email info@allwebforms.com.