Data Processing Agreement
Last updated: August 24, 2026
This Data Processing Agreement ("DPA") is part of the Terms of Service between you ("Customer", "Controller") and nisuform ("nisuform", "Processor", "we"). It sets out the obligations of both parties whenever nisuform processes personal data on the Customer's behalf through the Service, in particular form Submissions. By using the Service, the Customer accepts this DPA. It takes precedence over the Terms of Service in case of conflict on data processing matters.
nisuform is GDPR friendly: this DPA, including the Standard Contractual Clauses referenced in Section 10, applies automatically to every customer at no additional cost, with no signature required.
1. Definitions
- "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority": as defined in applicable Data Protection Law.
- "Data Protection Law": the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act ("CCPA"), and other applicable data protection laws.
- "Submissions": personal data collected through forms created by the Customer and processed through the Service.
- "Subprocessor": any third party engaged by nisuform to process Personal Data on behalf of the Customer.
2. Roles and Scope of Processing
The Customer acts as Controller (or, where required, as a processor on behalf of its own customer) and nisuform acts as Processor. The parties acknowledge that the CCPA terms in Section 10 apply in parallel where relevant. The subject matter, duration, nature, and purpose of the Processing are:
- Subject matter: receipt, storage, transmission, and display of Submissions on the Customer's behalf.
- Duration: the term of the Customer's subscription, plus the retention period in Section 8.
- Purpose: providing the Service, including submission storage, email notifications to addresses the Customer configures, spam filtering, and account management.
- Categories of Data Subjects: respondents who complete the Customer's forms, and the Customer's authorized users.
- Categories of Personal Data: as configured by the Customer, typically names, email addresses, message content, and technical metadata such as timestamps and originating page.
nisuform processes Personal Data only on the Customer's documented instructions, including as set out in this DPA and the Terms, unless required by law. If nisuform believes an instruction infringes Data Protection Law, it will inform the Customer without undue delay. The Customer is responsible for ensuring its forms and notices provide any lawful basis and disclosures required for its collection of Submissions.
3. Confidentiality
nisuform ensures that all personnel authorized to process Personal Data are bound by confidentiality obligations and receive appropriate data protection training, and that they access Personal Data only as necessary to perform their duties.
4. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, nisuform maintains appropriate technical and organizational measures, including:
- Encryption of Personal Data in transit (TLS) and at rest.
- Access controls with least privilege, unique credentials, and multi-factor authentication for administrative access.
- Encrypted, regularly tested backups.
- Logging and monitoring of systems handling Personal Data.
- Vulnerability management and prompt application of security patches.
- Segregation of Customer data in multi-tenant infrastructure with row-level authorization.
5. Subprocessors
The Customer authorizes the following Subprocessors as of the date of this DPA:
- Supabase, Inc. (database, authentication, and application hosting).
- Resend, Inc. (transactional email delivery).
- Cloudflare, Inc. (object storage and content delivery).
- Polar Software Inc. (subscription billing and merchant of record).
nisuform will impose data protection obligations on Subprocessors equivalent to this DPA and remains fully liable for their performance. nisuform will notify the Customer of any intended new or replacement Subprocessor at least 14 days before it begins processing, giving the Customer the opportunity to object on reasonable data protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected subscription with a pro-rata refund of prepaid fees.
6. Data Subject Rights
Taking into account the nature of the Processing, nisuform assists the Customer in fulfilling its obligations to respond to requests from Data Subjects to exercise their rights (access, rectification, erasure, restriction, portability, and objection) by providing self-service tools to view, correct, export, and delete Submissions through the Service. Where the Customer cannot fulfill a request via the Service, nisuform will provide reasonable assistance at the Customer's expense.
7. Security Incidents
nisuform notifies the Customer without undue delay, and no later than 48 hours after becoming aware of a Personal Data breach affecting the Customer's data. Notifications are sent to the Customer's account email and include, to the extent known: the nature of the breach, categories and approximate numbers of Data Subjects and records affected, likely consequences, and measures taken or proposed. nisuform provides further information as it becomes available and reasonably cooperates with the Customer's investigation. nisuform does not notify Supervisory Authorities or Data Subjects on the Customer's behalf unless instructed.
8. Return and Deletion
The Customer may export or delete Submissions at any time through the Service. Upon the end of the provision of services, nisuform deletes the Customer's Submissions within 30 days, except where Union or Member State law requires storage, in which case the data is kept only as long and as broadly as required and remains protected under this DPA. Backups are purged on a rolling basis within a further 90 days.
9. Audits and Assistance
nisuform makes available information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures and responses to reasonable questionnaires. Where the Customer's regulatory requirements cannot be met by these means, the Customer may, no more than once per year and with 30 days' notice, conduct a remote audit of the controls relevant to the Service; any on-site audit is limited to exceptional circumstances where remote means are insufficient. The Customer bears its own audit costs.
nisuform also assists the Customer with data protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of the Processing and the information available to nisuform.
10. International Transfers
nisuform may transfer and process Personal Data in the United States and other countries where nisuform or its Subprocessors operate. Where such transfers are subject to Data Protection Law, they are made under: an adequacy decision; the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor) or Module Three (Processor to Processor) as applicable, with Annexes I to III completed as set out in this DPA; the UK International Data Transfer Addendum; or the Swiss Federal Data Protection Authority's adapted clauses, as relevant. For CCPA purposes, nisuform certifies that it understands and will comply with the restrictions and obligations of a service provider and will not sell or share personal data, or retain, use, or disclose it outside the direct business relationship between the parties.
11. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, except that those limits do not apply to the Customer's payment obligations or to either party's liability arising from its violation of Data Protection Law to the extent such limits are prohibited by Data Protection Law.
12. Term
This DPA takes effect when the Customer first accepts the Terms of Service or uses the Service, and remains in effect until nisuform no longer processes Personal Data on the Customer's behalf, subject to Section 8.
13. Contact
Questions about this DPA, or requests to execute a signed copy for your records, can be sent to privacy@nisuform.com.