Data Processing Agreement

Last updated: March 1, 2025

This Data Processing Agreement ("DPA") forms part of the agreement between Formaya ("Processor", "we", "us") and the customer using our Service ("Controller", "you") for the processing of personal data in connection with the Formaya platform. This DPA applies where and to the extent that Formaya processes personal data on your behalf in the course of providing the Service.

1. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person submitted through forms created on the Service
  • Processing: Any operation performed on Personal Data, including collection, storage, encryption, retrieval, transmission, and deletion
  • Data Subject: The individual whose Personal Data is processed (i.e., form respondents)
  • Sub-processor: A third party engaged by Formaya to process Personal Data on behalf of the Controller

2. Scope and Purpose of Processing

Formaya processes Personal Data solely to provide the Service, which includes:

  • Receiving and storing form responses submitted by Data Subjects
  • Encrypting response data at rest using AES-256-GCM
  • Decrypting and displaying response data to authorized workspace members
  • Generating aggregated analytics (completion rates, field performance, drop-off analysis)
  • Delivering webhook notifications to endpoints configured by the Controller
  • Providing CSV export of response data
  • Storing file uploads submitted through forms
  • Auto-saving partial responses for respondent convenience (48-hour retention)

3. Controller Obligations

As the Controller, you are responsible for:

  • Ensuring you have a lawful basis for collecting Personal Data through your forms
  • Providing appropriate privacy notices to Data Subjects before data collection
  • Obtaining necessary consents where required by applicable law
  • Determining the types of Personal Data collected and the purposes of processing
  • Responding to Data Subject rights requests (access, deletion, portability)
  • Not collecting sensitive or special category data without appropriate safeguards

4. Processor Obligations

Formaya commits to:

  • Process Personal Data only on your documented instructions and for the purposes of providing the Service
  • Ensure personnel authorized to process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures (see Section 5)
  • Assist you in responding to Data Subject rights requests where technically feasible
  • Notify you without undue delay upon becoming aware of a Personal Data breach
  • Delete or return Personal Data upon termination of the Service, at your choice
  • Make available information necessary to demonstrate compliance with this DPA

5. Security Measures

Formaya implements the following technical and organizational measures:

  • Encryption at rest: Form response data encrypted with AES-256-GCM
  • Encryption in transit: All data transmitted over TLS/HTTPS
  • Access control: Role-based access (owner, admin, member) with workspace isolation
  • Authentication: Password hashing (bcrypt, 12 rounds), optional TOTP 2FA, JWT session management
  • API security: Scoped API keys with SHA-256 hashing, rate limiting
  • Webhook security: HMAC-SHA256 payload signing
  • Data minimization: Partial responses auto-expire after 48 hours
  • Audit trail: Webhook delivery logging, API key usage tracking

6. Sub-processors

Formaya uses the following sub-processors:

  • Stripe: Payment processing (billing data only, no form response data)
  • SMTP Provider: Transactional email delivery (email addresses for notifications only)

We will notify you before engaging new sub-processors. You may object to a new sub-processor within 30 days of notification. If we cannot accommodate your objection, you may terminate the Service.

7. Data Transfers

Where Personal Data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses or other approved transfer mechanisms under applicable data protection law.

8. Data Breach Notification

In the event of a Personal Data breach, Formaya will notify you without undue delay (and in any event within 72 hours of becoming aware) with details of the breach, including:

  • The nature of the breach and categories of data affected
  • The approximate number of Data Subjects and records affected
  • The likely consequences of the breach
  • Measures taken or proposed to address and mitigate the breach

9. Data Deletion

Upon termination of your account or at your request, Formaya will delete your Personal Data within 30 days, except where retention is required by applicable law. You may delete individual responses, forms, or export your data at any time through the Service.

10. Duration and Termination

This DPA is effective for the duration of your use of the Service. It terminates automatically when your account is closed. Obligations regarding data deletion and confidentiality survive termination.

11. Contact

For questions about this DPA or to exercise your rights as a Controller, contact us at [email protected].

Formaya — Conversational Form Platform