# formbase Docs — Legal

# Legal overview

Index of formbase legal documents

## Legal overview

The agreements that govern your use of formbase, how we handle personal data, and the terms we apply when we process data on your behalf.

> ℹ️ **Last updated: 23 May 2026**
> <div>
>     <p>
>       The Service is operated by <strong>Formbase AS</strong>, a Norwegian limited company with organisation number 937 921 217 and
>       registered office in Oslo, Norway.
>     </p>
>   </div>

<h2 id="documents">Documents</h2>

The three documents below form the legal framework for using formbase.

<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Terms of Service](/legal/terms-of-service) — Rules governing your access to and use of formbase.
  - [Privacy Policy](/legal/privacy-policy) — What personal data we collect, why, and the choices you have.
  - [Data Processing Agreement](/legal/dpa) — Terms under which formbase processes personal data on your behalf, with the subprocessor list and security measures.
</div>

<h2 id="contact">Contact</h2>

- **General, legal, and security questions** — <a href="mailto:support@formbase.so">support@formbase.so</a>

<h2 id="governing-law">Governing law</h2>

Norwegian law governs the Terms of Service and the Data Processing Agreement. The parties agree that the Oslo District Court (Oslo tingrett) has jurisdiction to settle any dispute, subject to the mandatory consumer protections described in the Terms of Service.

<h2 id="changes">Changes</h2>

When we make a material change to any of these documents, we update the "Last updated" date at the top of that document and notify account holders by email or in-product notice at least thirty (30) days before it takes effect.

<h2 id="next-steps">Next steps</h2>
<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Plans and pricing](/subscription-billing/plans-pricing) — Free, Pro, and Business tiers, AI credits, and billing through Polar.
  - [Get started](/getting-started/introduction) — Set up your workspace and publish your first form.
</div>


# Terms of Service

Terms governing your use of formbase

## Terms of Service

The rules that govern your access to and use of formbase, our website, applications, APIs, and integrations.

> ℹ️ **Last updated: 7 October 2026**
> <div>
>     <p>
>       These Terms apply to everyone who creates an account or uses formbase. Read them carefully. If you have questions, contact us at{' '}
>       <a href="mailto:support@formbase.so">support@formbase.so</a>.
>     </p>
>   </div>

<h2 id="acceptance">1. Acceptance of Terms</h2>
These Terms of Service ("Terms") govern your access to and use of formbase, operated by Formbase AS, a Norwegian limited company with
organisation number 937 921 217 and registered office in Oslo, Norway ("formbase", "we", "us"), including our website, applications, APIs,
integrations, and related services (collectively, the "Service"). By creating an account or accessing the Service, you agree to be bound by
these Terms.

If you are using the Service on behalf of an organisation, you represent that you have authority to bind that organisation to these Terms, and "you" refers to both you personally and that organisation.

If you do not agree to these Terms, you must not create an account or use the Service. Your continued use of the Service following any updates to these Terms constitutes acceptance of the revised version.

These Terms incorporate by reference our Privacy Policy, Data Processing Agreement (where applicable), and any product-specific terms presented to you within the Service.

<h2 id="definitions">2. Definitions</h2>
For the purposes of these Terms, capitalized terms have the meanings set out below:

- **Service** means the formbase platform and all features made available through it, including the form builder, hosted forms, dashboards, integrations, AI features, and APIs.
- **User** means any individual who accesses or uses the Service in an Account capacity, whether as a workspace owner or member. Respondents are not Users — see [Section 6](#acceptable-use).
- **Customer** means a User who holds the formbase Account under which the Service is used; for individual accounts this is you, for business accounts this is the organisation you act on behalf of.
- **Account** means the personal record created when you register for the Service, identified by a unique email address.
- **Workspace** means a separately addressable environment within the Service in which forms, submissions, members, and settings are organised.
- **Form** means any survey, questionnaire, application, checkout, or other interactive document created and published through the Service.
- **Submission** means a response, entry, file upload, payment, or other data record collected through a Form.
- **Subscription** means a recurring paid plan that unlocks features or capacity on your Account.
- **Content** means any text, media, file, configuration, response, code, prompt, or other material that you, your collaborators, or your respondents create, upload, transmit, or store through the Service.
- **Your Content** means the Content that belongs to your account, as described in [Section 8](#user-content).
- **AI Features** means any functionality of the Service that uses machine learning or large language models to generate, transform, summarize, route, or otherwise process Content on your behalf.
- **Respondent** means a person who submits a response to a Form, whether or not they hold an Account.

<h2 id="eligibility">3. Eligibility</h2>
To use the Service, you must be at least thirteen (13) years old and have the legal capacity to enter into a binding contract under the laws
of your jurisdiction. Where the law that applies to you sets a higher minimum age for consenting to online services or to the processing of
your personal data, you must meet that higher age. If you are below the age of majority in your country, you confirm that a parent or legal
guardian has authorised your use of the Service.

You may not use the Service if you are barred from doing so under applicable laws, including export controls and sanctions administered by Norway, the European Union, the United Nations, the United Kingdom, or the United States. You confirm that you are not located in, ordinarily resident in, or organised under the laws of a country or territory subject to comprehensive sanctions, and that you are not listed on any restricted-party or denied-persons list.

We may, at our discretion, refuse, suspend, or terminate access where we reasonably believe these eligibility requirements are not met.

<h2 id="account-security">4. Account Registration and Security</h2>
To access most features of the Service, you must register an Account. When you register, you agree to provide accurate, current, and
complete information, and to keep that information up to date.

Each Account is intended for a single human individual. You may not share login credentials, transfer your Account to another person, or allow multiple people to operate under the same Account (including through a shared inbox or alias). For team use, each team member must register their own Account and you may invite them to your Workspace under their own Accounts.

You are responsible for safeguarding your credentials and for any actions taken under your Account, whether or not authorised by you. The Service does not use passwords of its own; you sign in through a magic link sent to your email address or through Google OAuth. You may also try formbase without registering through a temporary anonymous guest session; guest sessions are temporary and do not persist data.

Notify formbase without undue delay if you become aware of any unauthorised access, suspected compromise, or other security incident involving your Account; you can also reach us at <a href="mailto:support@formbase.so">support@formbase.so</a>. To the extent permitted by applicable law, we are not liable for losses resulting from your failure to protect your credentials or to notify us promptly.

<h2 id="workspaces">5. Workspaces and Team Accounts</h2>
The Service is organised around Workspaces. The individual who creates a Workspace is its initial owner and is treated as the primary
account holder for ownership of Content and administrative decisions affecting that Workspace.

Workspace owners may invite additional members to a Workspace. Workspace roles are currently limited to owner and member; owners administer the Workspace and its billing-relevant configuration, and members can access forms, submissions, and integrations to the extent permitted by the Workspace's settings, as described in the Service's documentation and as updated from time to time.

If you are invited to a Workspace, you acknowledge that the Workspace owner controls the configuration of that Workspace and may have visibility into, and authority over, the Forms, Submissions, and activity occurring within it. Your use of a Workspace is additionally subject to any internal policies set by its owner, provided they do not conflict with these Terms.

A Workspace is intended to support a single team or organisation collaborating together. The paid features that extend to the members of a Pro-owned Workspace are provided for that collaboration. They are not a means to give the paid features of the Service to unrelated individuals, to multiple distinct organisations, or to the general public under a single Subscription. formbase may apply fair-use limits to the number of members in a Workspace and reserves the right to require separate Subscriptions where a single Workspace, or a set of Workspaces under one Account, is used to extend paid features beyond a single team or organisation.

Workspace ownership does not currently transfer through a self-service flow.

formbase is not a party to any agreement between Workspace owners and their members or Respondents, and is not responsible for resolving disputes among them.

<h2 id="acceptable-use">6. Acceptable Use Policy</h2>
You may use formbase to build, publish, and manage forms for lawful purposes that comply with these Terms and any laws applicable to you and
to the people you collect information from. Typical permitted uses include customer feedback, lead capture, surveys, registrations,
applications, internal workflows, payment collection through supported processors, and similar form-driven activities.

You are solely responsible for the forms you publish, the questions you ask, the data you collect, the files respondents upload, and how you store, share, or act on that information. If you collect personal data, you act as the data controller for that data and must provide respondents with any notices, choices, and legal bases required under applicable privacy laws.

formbase is a general-purpose form builder and is **not designed, certified, or warranted for use with regulated sensitive data**. formbase does not currently offer any certification, business associate agreement, or written authorisation for regulated data use cases — no such arrangement can be obtained by email request alone. Unless we have explicitly agreed otherwise with you in a separate written agreement signed by an authorised representative of formbase, you must not use formbase to collect, store, or process:

- Protected Health Information (PHI) subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA) or equivalent health-data regimes;
- Cardholder data subject to PCI DSS, except through the Payment field — Stripe collects and processes all card data directly; formbase receives only non-sensitive references such as the last four digits;
- Government-issued identifiers used as primary identity proofing (such as full social security numbers, national ID images) unless you have implemented your own additional safeguards;
- Information about minors below the age of consent under applicable law, including data subject to the U.S. Children's Online Privacy Protection Act (COPPA), unless you have obtained verified parental or guardian consent and have your own compliant workflow;
- Any other category of data for which your applicable laws require a specific certification, contract, or technical measure that formbase has not undertaken in writing.

If your use case involves any of the above, you are responsible for assessing fitness yourself, putting any additional safeguards in place, and seeking written confirmation from formbase before proceeding.

Respondents are not Users of formbase. Your relationship with respondents is governed by your own terms and privacy practices. You are responsible for handling their data and any disputes that arise from your forms.

Electronic signatures collected through formbase's Signature field are not qualified or advanced electronic signatures under the EU eIDAS Regulation. They may not satisfy the heightened evidentiary requirements for document types that require a qualified signature under applicable law. You are responsible for assessing whether signatures collected through formbase meet the legal requirements for your specific use case and jurisdiction.

<h2 id="prohibited-uses">7. Prohibited Uses</h2>
You must not use formbase, and must not allow anyone else to use your account, to do any of the following:

- Publish, transmit, or solicit content that is illegal under the laws that apply to you or to your respondents.
- Harass, threaten, defame, or incite violence against any person or group.
- Send spam, unsolicited bulk messages, or use formbase to drive traffic to deceptive destinations.
- Conduct phishing, credential harvesting, or any form of social engineering.
- Distribute malware, viruses, ransomware, or links to malicious software.
- Scrape, crawl, or harvest data from formbase or its users by automated means, except through documented APIs within published rate limits.
- Circumvent or attempt to circumvent submission limits, plan restrictions, paywalls, rate limits, branding restrictions, or other technical controls.
- Infringe any copyright, trademark, patent, trade secret, publicity, or other intellectual property right.
- Upload, request, or generate child sexual abuse material (CSAM) or content that sexually exploits or endangers minors. Where we become aware of such content we are required by law to report it to the relevant authorities (for users in Norway, Kripos; we may also forward reports to organizations such as NCMEC (CyberTipline) where appropriate) and we will do so.
- Commit fraud, run deceptive schemes, or misrepresent your identity, affiliation, or the purpose of your forms.
- Create fake accounts, abuse guest sessions, use multiple accounts or sessions to evade limits or bans, or sell, rent, or transfer accounts to others.
- Share, resell, or redistribute the paid features of the Service in breach of the Workspace fair-use rules in [Section 5](#workspaces).
- Use formbase AI Features to generate, refine, or distribute content that is illegal, harmful, hateful, sexually explicit involving minors, or that would otherwise violate these Terms.
- Abuse payment-enabled forms, including processing test or stolen card data, laundering funds, or collecting payments for goods or services you cannot lawfully provide.
- Interfere with the integrity, security, or performance of formbase, including by probing, load testing without permission, or attempting to gain unauthorised access to any account, system, or data.

We may update the list of prohibited uses as new patterns of abuse emerge.

<h2 id="user-content">8. Your Content and Ownership</h2>
You retain all rights you already have in the content you bring to formbase. This includes the forms you build, the questions and copy you
write, the media and files you upload, the submissions your respondents send you, and any data you import or sync through integrations
("Your Content").

To operate the Service for you, you grant formbase a worldwide, non-exclusive, royalty-free licence to host, store, copy, transmit, display, render, process, back up, and otherwise use Your Content solely as needed to provide, secure, and support the Service for your account, and to improve the Service through aggregated and de-identified analytics that do not contain personal data. This licence covers the technical operations required to run formbase, such as serving forms to respondents, delivering email and webhook notifications, running integrations you enable, generating previews and analytics for you, and maintaining backups.

If you use AI Features, you grant the additional permissions needed for those features to function, including sending the relevant inputs to the AI provider that powers AI Features on your behalf. The provider details, data-handling, and no-training commitments for AI Features are described in [Section 16](#ai).

This licence lasts only as long as Your Content is on formbase, and ends when you or we delete it, subject to short retention windows in backups and logs and to any obligation we have to retain records under applicable law. You are responsible for ensuring you have the rights needed to grant this licence for everything you upload, including any third-party content and any personal data of respondents.

formbase, the formbase brand, the Service, its software, and all related materials we provide remain our property or the property of our licensors. Nothing in these Terms transfers ownership of the Service to you.

<h2 id="moderation">9. Content Moderation and Reporting</h2>
We have the right, but not the obligation, to review content on formbase. We do not pre-screen forms or submissions, and you should not rely
on us to do so.

When we become aware of content or behaviour that violates these Terms or applicable law, we may take any action we consider appropriate. This includes removing or disabling forms, files, or submissions, suspending or terminating accounts, withholding payouts on payment forms, preserving records for investigations, and reporting illegal content to the relevant authorities. Where reasonable and lawful, we will tell you what we have done and why.

If you believe content on formbase violates these Terms or your rights, contact us at support@formbase.so with enough information for us to locate and assess it. For copyright and other intellectual property complaints, including notices similar to those provided for under the U.S. Digital Millennium Copyright Act, send your notice to support@formbase.so and include the works concerned, the URLs of the allegedly infringing content, your contact details, and a statement that your complaint is made in good faith. Counter-notices may be sent to the same address.

We may keep records of reports and the actions we take in response. Submitting a knowingly false or abusive report is itself a breach of these Terms. In appropriate circumstances, we terminate the accounts of users who repeatedly infringe the intellectual property rights of others.

formbase does not scan files uploaded by respondents for malware or other harmful content. You are responsible for any files your respondents upload through your forms, and you should not download or open files from untrusted respondents without appropriate precautions.

<h2 id="plans">10. Plans and Subscriptions</h2>
formbase is offered on a free tier and paid Pro and Business tiers. Each plan defines the features and usage limits available to you, and
the current details for every plan are published on the [formbase pricing page](/subscription-billing/plans-pricing).

The free tier lets you build, publish, and collect responses from forms within the limits described on the pricing page. It is intended for personal use, evaluation, and low-volume projects. formbase may apply soft caps, formbase branding on public forms, or feature restrictions to the free tier, and may adjust these from time to time. If you exceed the limits applicable to your plan, formbase may stop accepting new submissions on affected forms, display a limit-reached notice, or notify you by email.

The Pro tier unlocks higher limits, custom domains, custom themes, advanced analytics, and AI Skills. No plan includes AI credits; you purchase them separately as described in [Section 12](#ai-credits). The Business tier builds on Pro and additionally includes respondent email verification, custom data retention schedules, version history, a higher custom-domain allowance, and an optional shared AI credit pool for workspace members. Third-party integrations (webhooks, automation platforms, and similar connections) are available on all plans; Pro unlocks higher submission volumes that make them more practical at scale. You may subscribe to Pro or Business on a monthly or yearly billing cycle. Yearly subscriptions are billed up front for the full term and typically include a discount relative to the monthly price.

Subscriptions are tied to your individual formbase user account, not to a workspace. If you belong to multiple workspaces, your plan entitlements and AI credit balance follow you across all of them. Workspaces themselves are not billed; only users are. When you are the owner of a workspace and your account is on a paid tier, that tier's features (such as custom domains, higher submission limits, and advanced analytics) extend to all members of that workspace; members do not need their own subscription to access those features within your workspace. This member benefit is subject to the fair-use rules in [Section 5](#workspaces). On the free and Pro tiers, AI credits remain personal to each user. On the Business tier, the workspace owner may enable a shared pool, in which case members consume the owner's purchased AI credits while working in that owner's workspaces.

Your subscription renews automatically at the end of each billing cycle using the payment method on file, unless you cancel before the renewal date.

A first Pro subscription on the monthly billing cycle may start with a free trial, whose length is shown at checkout. You provide a payment method at checkout, and nothing is charged during the trial. Unless you cancel before the trial ends, the trial converts into a paid monthly Pro subscription and the first payment is charged when the trial ends. If you cancel during the trial, or the first payment fails, your account moves to the free tier when the trial ends. formbase may limit trials to one per person, account, or payment method, and may change or withdraw the trial offer at any time.

formbase may change the prices, features, or limits of any plan. For changes that affect the price you pay on renewal, or that materially reduce the features or limits available on a paid plan, we will give you reasonable advance notice before the change takes effect. If you do not accept the change, you may cancel your subscription before it renews, and your access will continue under your existing plan until the end of your current billing period.

<h2 id="billing">11. Payment Processing and Billing</h2>
All subscription payments and AI credit purchases on formbase are processed by Polar (polar.sh), our payment provider. Polar acts as the
Merchant of Record for these transactions. This means Polar sells the formbase subscription or credit pack to you, collects payment, issues
the receipt or invoice, and handles applicable taxes on our behalf.

When you subscribe or top up credits, you also agree to Polar's terms of service and privacy policy in addition to these Terms. Your card details, billing address, and other payment information are collected and stored by Polar, not by formbase. formbase receives only the limited transaction data needed to provision your plan and credits and to handle support requests.

Because Polar is the Merchant of Record, Polar determines and charges any value-added tax, goods and services tax, sales tax, or equivalent levy that applies to your purchase based on your billing location. The price displayed at checkout will reflect taxes where required. You are responsible for providing accurate billing and tax information, including any VAT number or business identifier if you are purchasing as a business.

Receipts and, where applicable, tax-compliant invoices are issued by Polar and made available through the billing portal linked from your formbase account. If you need a corrected invoice, contact Polar through the billing portal.

If payment cannot be collected, your account may enter a grace period during which Pro features are progressively restricted, and may ultimately be downgraded to the free tier until the outstanding balance is paid, as described in the [billing documentation](/subscription-billing/upgrading-downgrading#grace-period). You remain responsible for any amounts owed.

<h2 id="ai-credits">12. AI Credits</h2>
Several formbase features, such as AI-assisted form building, AI chat for analysing submissions, and the AI skill picker, consume AI
credits. Credits represent prepaid usage of the underlying AI models that power these features and are not a currency, store of value, or
property right.

No plan includes AI credits. You can purchase credit top-ups from Polar at any time, on any plan. **Purchased credits do not expire** and remain available on your account until they are used.

Different AI operations consume different amounts of credits depending on the model used and the size of the input and output. The current consumption rates are published in the [formbase documentation](/ai/ai-credits-usage) and may be adjusted as model pricing or capabilities change.

Credits are tied to your user account and cannot be transferred, gifted, resold, or exchanged for cash. Purchased top-up credits are not refundable once they are used, except where required by mandatory consumer protection law.

formbase applies fair use protections to AI Features to keep the Service stable and affordable for everyone. We may rate-limit, throttle, or temporarily pause AI operations if we detect automated abuse, attempts to extract model weights or training data, or usage patterns that materially exceed normal interactive use. Fair use thresholds, where defined, are published in the [formbase documentation](/ai/ai-credits-usage). If we suspect fraud or abuse, we may also suspend AI access while we investigate.

<h2 id="cancellation">13. Cancellation, Refunds and Right of Withdrawal</h2>
You can cancel your Pro subscription at any time from your formbase billing settings. When you cancel, your subscription will not renew at
the end of the current billing period. You keep access to Pro features until that period ends, after which your account is moved to the free
tier. Purchased AI credits stay on your account. Your forms, responses, and workspace data remain available subject to the free tier's
limits.

formbase does not offer refunds for unused subscription time, unused AI credits, or partially used billing periods, except where required by mandatory consumer protection law or as provided by the [Data Processing Agreement](/legal/dpa) in the event of termination following a subprocessor objection. This applies whether you cancel mid-cycle, downgrade, stop using the Service, or are downgraded automatically after a failed payment. Where Polar has issued an invoice, any refund decision is also subject to Polar's policies as Merchant of Record.

If you are a consumer resident in the European Union, the European Economic Area, or Norway, you have a statutory 14-day right to withdraw from a distance contract for digital services, without giving any reason. Because Polar, as Merchant of Record, collects your express prior consent to immediate delivery at checkout — in accordance with Article 16(m) of Directive 2011/83/EU and the Norwegian Right of Cancellation Act (Angrerettloven 2014, LOV-2014-06-20-27) — performance begins when the purchase is completed, and the right of withdrawal is exhausted from that point.

<h2 id="respondent-payments">14. Respondent Payments via Stripe Connect</h2>
formbase lets you add Payment fields to your forms so that respondents can pay you when they submit a response, for example for bookings,
donations, paid registrations, or product orders. These respondent payments are processed through Stripe Connect, and they are separate from
your formbase subscription and AI credit purchases.

To accept respondent payments, you must connect your own Stripe account to formbase. You are solely responsible for creating, verifying, and maintaining that Stripe account, for complying with Stripe's Connected Account Agreement and other applicable Stripe terms, and for meeting any identification, tax, and regulatory requirements Stripe imposes on you.

For respondent payments, you are the merchant of record. formbase is not a party to the transaction between you and your respondent, does not sell your goods or services, does not handle the funds, and does not issue receipts or invoices on your behalf. Funds are processed by Stripe and settled to your connected Stripe account, subject to Stripe's fees, holds, and payout schedule.

As the merchant for these transactions, you are responsible for:

- Describing accurately what the respondent is paying for, including price, currency, and any recurring terms.
- Charging, collecting, reporting, and remitting any applicable taxes on the respondent's payment.
- Honoring the goods, services, or commitments the respondent has paid for.
- Handling refunds, chargebacks, disputes, customer support, and any consumer law obligations toward your respondents.
- Complying with all laws that apply to your business, including anti-money-laundering, sanctions, and sector-specific regulations.

For data protection purposes, Stripe acts as an independent controller for the payment data it processes. formbase's ability to offer respondent payments depends on its ongoing compliance with Stripe's platform agreement; if that relationship changes, the availability of Payment fields may be affected without notice. We are not liable for Stripe's availability, fees, fund holds, account suspensions, or disputes between you and a respondent. You agree to indemnify formbase against claims, losses, and expenses arising from your use of respondent payments, except to the extent caused by our own breach of these Terms.

formbase does not currently charge a platform fee on respondent payments.

<h2 id="availability">15. Service Availability and Modifications</h2>
formbase does not offer a formal service level agreement (SLA). Uptime is best-effort; we cannot guarantee that the Service will be
uninterrupted, error-free, or available at any specific time.

From time to time we will perform maintenance, which may occur without advance notice.

formbase reserves the right to modify, suspend, or discontinue any part of the Service — including individual features, integrations, plans, and limits — at any time, with or without notice, and with or without liability to you, except as required by applicable law. Minor changes, performance improvements, and bug fixes may be deployed at any time.

Some features are clearly labelled as beta, preview, or experimental. These are offered "as is" and may change, break, or be withdrawn without notice. You should not rely on beta features for production workflows or business-critical use, and any data, configurations, or behaviour tied to a beta feature may be reset when the feature graduates or is removed.

<h2 id="ai">16. AI Features and Outputs</h2>
formbase includes AI-powered capabilities, including AI-assisted form building, AI chat for analysing submissions, and the AI skill picker.
These features are powered by AWS Bedrock models, and the providers we use may change over time as we improve quality, latency, and cost.
Any change of AI provider constitutes a new subprocessor and will be notified in accordance with [Section 19](#subprocessors) and the [Data
Processing Agreement](/legal/dpa).

AI outputs are generated probabilistically and can be inaccurate, incomplete, biased, outdated, or misleading. You are responsible for reviewing every AI-generated output before relying on it, publishing it, sending it to respondents, or using it to make decisions. Do not treat AI suggestions as legal, medical, financial, or other professional advice. You remain solely responsible for the forms you publish and any decisions you make based on AI output.

When you use AI Features, the prompts you submit and the relevant context from your account (such as form structure or submission samples you explicitly share with the AI) are sent to Amazon Bedrock for processing. We configure it so that, under the [AWS Service Terms](https://aws.amazon.com/service-terms/) governing Amazon Bedrock, your inputs and outputs are:

- **Not used to train** any AWS or third-party foundation models;
- **Not stored by AWS** after the request is processed, and handled in accordance with the AWS Service Terms and Amazon Bedrock data-protection commitments; and
- Processed in line with the security and data protection commitments described in our [Privacy Policy](/legal/privacy-policy) and [Data Processing Agreement](/legal/dpa).

Where AI processing transfers your data outside the European Economic Area, formbase relies on the safeguards set out in [Section 10 of the Data Processing Agreement](/legal/dpa#international-transfers), including Standard Contractual Clauses adopted under Decision (EU) 2021/914 and, where applicable, the EU–US Data Privacy Framework.

You should not submit personal data, secrets, or other sensitive information through AI Features unless you have a lawful basis to share that information with AWS and have considered the risks. We do not control how AWS responds to lawful government requests directed at it.

The prohibited uses in [Section 7](#prohibited-uses) apply to AI Features. You must not attempt to reverse-engineer the underlying models, extract their weights, or use the AI Features to build a competing product.

<h2 id="integrations">17. Third-Party Integrations</h2>
formbase connects to a range of third-party services so you can route submissions, sync data, and automate workflows. These integrations
include messaging tools, webhook endpoints, automation platforms, spreadsheets, productivity suites, databases, and email providers. This
Section 17 covers only third-party integrations that you optionally enable; the subprocessors formbase relies on to deliver the Service are
described in [Section 19](#subprocessors) and the [Data Processing Agreement](/legal/dpa), and you cannot opt out of them while using the
Service.

Third-party services are operated independently and are not part of formbase. We do not control their availability, pricing, features, terms, privacy practices, or uptime, and we are not responsible for outages, changes, deprecations, or data loss on their side. If a third-party service changes its API or terms in a way that breaks an integration, we cannot guarantee continued functionality.

When you connect a third-party service, you authorise formbase to exchange data with that service on your behalf. You are responsible for reviewing and complying with the terms and acceptable use policies of every service you connect, and for ensuring you have the right to share the data you route through formbase. OAuth permissions you grant remain active until you revoke them, either inside formbase or in the third-party service.

If you use API keys or our MCP server to integrate formbase with your own systems or with AI agents, you are responsible for keeping credentials secret, rotating them when needed, and for all activity performed using those credentials. We may rate-limit, suspend, or revoke API keys and MCP access that show signs of abuse, security risk, or that violate these Terms.

<h2 id="export">18. Data Export and Portability</h2>
Your data belongs to you. While your account is active, you can export your forms and submissions at any time in standard formats, including
CSV and Excel (XLSX), directly from the formbase application. There is no limit on how often you can export your own data.

Cancelling a Pro subscription does not delete your data; you keep access on the free tier subject to the free tier's limits. If you **close your account**, the account and its forms and submissions are removed from active systems and remain in our providers' backups only until the corresponding backup window expires, as described in the [Privacy Policy](/legal/privacy-policy). We strongly recommend exporting any data you need before closing your account.

If you are a Workspace owner and you close your account, the Workspace and all its associated forms, submissions, and data will be scheduled for deletion. Members' own accounts are not affected by a Workspace owner closing their account.

<h2 id="privacy">19. Privacy and Data Processing</h2>
How we collect, use, store, and share personal data is described in our [Privacy Policy](/legal/privacy-policy), which forms part of these
Terms by reference.

For data submitted to your forms by respondents, you are the data controller and formbase acts as your data processor. This means you decide what personal data to collect, why, and on what legal basis, and we process that data on your behalf and on your documented instructions. The terms of that processing relationship, including subprocessors, security measures, and international transfers, are set out in our [Data Processing Agreement](/legal/dpa), which applies automatically to customers subject to the GDPR or equivalent regimes.

For data we collect about you as a formbase user, such as your account details, billing information, and usage of the product, formbase is the data controller. We process this data to provide and improve the Service as described in the Privacy Policy.

formbase handles personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Norwegian data protection law. If you have questions about how your data or your respondents' data is handled, or if you need to exercise data subject rights, contact us at <a href="mailto:support@formbase.so">support@formbase.so</a>. In the event of a personal data breach affecting your account, formbase will notify you in accordance with [Section 11 of the Data Processing Agreement](/legal/dpa#breach), which sets out our notification obligations and timelines.

<h3 id="subprocessors">Subprocessors</h3>
formbase relies on a small set of trusted third-party providers ("subprocessors") to deliver the Service. These subprocessors process
personal data on our behalf only as needed to provide their part of the Service, under contracts that require appropriate confidentiality
and security measures. The current core subprocessors include:

- **Convex** — application database and backend.
- **Cloudflare R2** — object storage for file uploads and signatures.
- **Cloudflare** — CDN, DNS, edge security, custom hostnames, and Turnstile bot protection.
- **Polar** — subscription billing and AI credit purchases (Merchant of Record; independent controller for buyer billing data).
- **Stripe** — respondent payment processing via Stripe Connect (independent controller for payment data).
- **Amazon Web Services (AWS)** — Amazon Bedrock for AI Features; Amazon SES for transactional and system emails, including abandoned-response reminders on Pro workspaces.
- **Axiom** — operational logs and monitoring.
- **PostHog** — analytics for our website and account sign-ups.
- **Unsplash** — image search API; selected images are stored in Cloudflare R2 and served from there.

The authoritative list of subprocessors — with data categories and regions — is in our [Data Processing Agreement](/legal/dpa). Changes to subprocessors are handled in accordance with [Section 9 of the Data Processing Agreement](/legal/dpa#subprocessors).

<h2 id="intellectual-property">20. Intellectual Property</h2>
formbase, including its software, source code, user interface, design system, illustrations, documentation, brand name, logos, and other
trademarks, is owned by formbase and protected under Norwegian and international intellectual property laws. All rights not expressly
granted to you in these Terms are reserved.

Subject to your compliance with these Terms, formbase grants you a limited, non-exclusive, non-transferable, non-sublicensable, and revocable licence to access and use the Service for your internal business or personal purposes during the term of your account. This licence does not permit you to copy, modify, reverse engineer, decompile, resell, sublicence, or create derivative works based on the Service, except to the extent such restrictions are prohibited by mandatory law.

You must not remove, obscure, or alter any proprietary notices on the Service, and you must not use formbase's name, logos, or other brand assets except as expressly permitted in writing or as needed to refer to the Service in accordance with applicable law.

Nothing in this Section 20 affects the rights you retain in Your Content, as described in [Section 8](#user-content).

<h2 id="feedback">21. Feedback</h2>
If you choose to send formbase ideas, suggestions, feature requests, bug reports, or any other feedback regarding the Service ("Feedback"),
you agree that such Feedback is non-confidential and that formbase may use, reproduce, modify, distribute, and commercialise the Feedback
for any purpose, without restriction, attribution, or obligation to compensate you. You waive any rights in the Feedback that would prevent
formbase from exercising the foregoing, to the extent permitted by applicable law, including moral rights under the Norwegian Copyright Act
(Åndsverkloven) and equivalent laws in other jurisdictions. You are not required to provide Feedback, and submitting Feedback does not grant
formbase any rights in Your Content beyond those described in [Section 8](#user-content).

<h2 id="termination-by-you">22. Termination by You</h2>
You may cancel your subscription or close your account at any time through your account settings or by contacting
<a href="mailto:support@formbase.so">support@formbase.so</a>. See [Section 13](#cancellation) for cancellation and refund terms and [Section
18](#export) for data handling after closure.

<h2 id="termination-by-formbase">23. Termination and Suspension by formbase</h2>
formbase may suspend or terminate your access to the Service, in whole or in part, at our sole discretion, with or without cause, and with
or without notice, except where mandatory consumer protection law requires otherwise. For consumers on a paid subscription, termination
without cause will not take effect before the end of the current paid billing period, and any prepaid fees for the unused remainder of that
period will be refunded. Reasons may include:

- You materially breach these Terms or any policy incorporated by reference;
- You fail to pay fees when due and the failure is not remedied after reasonable notice;
- Your use of the Service creates a security, legal, or operational risk to formbase, its users, or third parties;
- formbase is required to do so by law, regulation, or a binding order from a competent authority; or
- formbase ceases to offer the Service or a specific feature.

Where the circumstances permit, formbase will give you advance notice of suspension or termination and a reasonable opportunity to cure the issue. In cases involving abuse, illegal activity, security incidents, or risk of harm, formbase may act immediately and without prior notice.

Following termination, formbase will handle your data in accordance with the Privacy Policy. Provisions that by their nature survive termination remain in effect, including [Section 8](#user-content) (Your Content and ownership), [Section 20](#intellectual-property) (intellectual property), [Section 21](#feedback) (feedback), [Section 24](#warranty-disclaimer) (warranty disclaimer), [Section 25](#limitation-of-liability) (limitation of liability), [Section 26](#indemnification) (indemnification), and [Section 27](#governing-law) (governing law and dispute resolution).

<h2 id="warranty-disclaimer">24. Warranty Disclaimer</h2>
To the maximum extent permitted by applicable law, the Service is provided on an "as-is" and "as-available" basis, without warranties of any
kind, whether express, implied, or statutory. formbase specifically disclaims all implied warranties of merchantability, fitness for a
particular purpose, non-infringement, accuracy, reliability, and any warranty arising out of course of dealing or usage of trade.

formbase does not warrant that the Service will be uninterrupted, error-free, secure against all threats, free of viruses or harmful components, or that defects will be corrected. You acknowledge that the Service depends on third-party infrastructure, networks, and services outside formbase's full control.

Nothing in this section limits warranties or rights that cannot be excluded under mandatory Norwegian or EU consumer protection law.

<h2 id="limitation-of-liability">25. Limitation of Liability</h2>
To the maximum extent permitted by applicable law, in no event will formbase be liable for any indirect, incidental, special, consequential,
exemplary, or punitive damages, including loss of profits, revenue, goodwill, data, business opportunities, or anticipated savings, even if
formbase has been advised of the possibility of such damages.

formbase's total aggregate liability arising out of or relating to these Terms or your use of the Service, whether in contract, tort (including negligence), statute, or otherwise, will not exceed (a) for users on a paid plan, the total fees paid for your formbase Subscription and AI credit purchases through Polar as Merchant of Record during the twelve (12) months immediately preceding the event giving rise to the liability; or (b) for users on a free plan, one hundred euros (EUR 100). Any platform fee that formbase may charge on respondent payments is treated as fees paid to formbase for the purposes of calculating the cap in clause (a). The cap in clause (b) does not apply to liability that cannot be limited under mandatory Norwegian or EU consumer protection law, including liability towards a consumer for damage caused by formbase's gross negligence, wilful misconduct, or a personal data breach attributable to formbase, or liability to any data subject under Article 82 GDPR.

formbase is not liable for any failure or delay in performance caused by events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, labour disputes, governmental action, internet or telecommunications failures, power outages, or failures of third-party infrastructure or services ("Force Majeure").

Nothing in this section limits or excludes liability that cannot be limited or excluded under mandatory law, including liability for death or personal injury caused by negligence, fraud, fraudulent misrepresentation, gross negligence, wilful misconduct, or a personal data breach attributable to formbase, or liability owed to you as a consumer under mandatory Norwegian or EU consumer protection law.

<h2 id="indemnification">26. Indemnification</h2>
To the extent permitted by applicable law, you agree to defend, indemnify, and hold harmless formbase and its officers, employees,
contractors, and agents from and against any third-party claims, demands, actions, losses, damages, liabilities, costs, and expenses
(including reasonable legal fees) arising out of or relating to:

- Your Content, including any claim that Your Content infringes third-party rights, violates law, or causes harm to a respondent or other person;
- Your use of the Service in breach of these Terms or applicable law;
- Your violation of any rights of a third party, including privacy, intellectual property, or contractual rights; or
- Your responsibilities as a data controller for submissions you collect through the Service.

This indemnity does not apply to the extent the claim arises from formbase's own negligence, wilful misconduct, or breach of these Terms. If you are a consumer, this section applies only to the extent permitted by mandatory consumer protection law, and nothing in this section limits your statutory rights.

formbase will notify you of any claim for which it seeks indemnification.

<h2 id="governing-law">27. Governing Law and Dispute Resolution</h2>
These Terms and any dispute or claim arising out of or in connection with them, their subject matter, or formation (including
non-contractual disputes or claims) are governed by and construed in accordance with the laws of Norway, without regard to its conflict of
laws principles.

Subject to the mandatory consumer-protection carve-outs in this Section 27, the parties agree that the Oslo District Court (Oslo tingrett) has jurisdiction to settle any dispute arising out of or in connection with these Terms or the Service.

If you are a consumer resident in the European Economic Area, the choice of law and forum above does not deprive you of the protection of mandatory consumer protection laws of the country in which you are habitually resident. You retain the right to bring proceedings against formbase, and may be sued by formbase, only in the courts of the country in which you are habitually resident.

If you are a consumer resident outside the European Economic Area, mandatory consumer protections of the country in which you are habitually resident may also apply, in which case the choice of law and forum above does not override those protections to the extent they cannot lawfully be waived.

Before initiating formal proceedings, you agree to first attempt to resolve any dispute informally by contacting formbase at support@formbase.so.

formbase is not obliged to participate in alternative dispute resolution before a consumer dispute resolution body, but will consider such requests in good faith. If you are a consumer resident in Norway, you may bring a complaint to the **Norwegian Consumer Authority** (Forbrukertilsynet, <a href="https://www.forbrukertilsynet.no">forbrukertilsynet.no</a>) or the **Norwegian Consumer Council** (Forbrukerrådet, <a href="https://www.forbrukerradet.no">forbrukerradet.no</a>). If you are a consumer resident in the European Union, you may also contact the European Commission's consumer redress portal (accessible at <a href="https://consumer-redress.ec.europa.eu">consumer-redress.ec.europa.eu</a>) for guidance on dispute resolution options in your country.

<h2 id="general">28. General Provisions</h2>
<h3 id="changes">Changes to These Terms</h3>
formbase may update these Terms from time to time to reflect changes in the Service, legal or regulatory requirements, or business
practices. For material changes, formbase will give you reasonable advance notice before the changes take effect. Your continued use of the
Service after the effective date constitutes your acceptance of the updated Terms. If you do not agree to the changes, you may terminate
your account before they take effect, as described in [Section 22](#termination-by-you).

<h3 id="entire-agreement">Entire Agreement</h3>
These Terms, together with the Privacy Policy and any other policies or supplemental terms expressly incorporated by reference, constitute
the entire agreement between you and formbase regarding the Service, and supersede any prior or contemporaneous agreements, communications,
or proposals on the same subject matter.

<h3 id="severability">Severability</h3>
If any provision of these Terms is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, that provision will
be enforced to the maximum extent permissible and the remaining provisions will continue in full force and effect.

<h3 id="no-waiver">No Waiver</h3>
formbase's failure to enforce any right or provision of these Terms does not constitute a waiver of that right or provision. Any waiver must
be in writing and signed by an authorised representative of formbase to be effective.

<h3 id="assignment">Assignment</h3>
You may not assign, transfer, or delegate these Terms or any of your rights or obligations under them, in whole or in part, without
formbase's prior written consent. Any attempted assignment in breach of this section is void. formbase may freely assign or transfer these
Terms, in whole or in part, including in connection with a merger, acquisition, reorganisation, sale of assets, or by operation of law,
provided that the assignee is bound by these Terms and your rights under them are not materially diminished. If you are a consumer, formbase
will give you reasonable advance notice before such an assignment takes effect, and you may terminate your account if you do not accept the
assignment.

<h3 id="notices">Notices</h3>
formbase will provide notices to you by email to the address associated with your account, through the Service interface, or by other
reasonable means. You are responsible for keeping your contact information accurate and up to date. You must send legal notices to formbase
by email to support@formbase.so, and such notices are deemed received on the earlier of acknowledgement by formbase or three (3) business
days after sending.

<h3 id="language">Language</h3>
These Terms are written in English, which governs in any conflict with a translation, except where mandatory consumer protection law
requires otherwise.

<h2 id="related">Related documents</h2>

<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Privacy Policy](/legal/privacy-policy) — How we collect, use, and share personal data.
  - [Data Processing Agreement](/legal/dpa) — Terms for processing personal data on your behalf.
  - [Legal overview](/legal/overview) — Index of formbase legal documents.
</div>


# Privacy Policy

How formbase collects, uses, and protects personal data

## Privacy Policy

What personal data formbase collects, why we collect it, how we use it, and the choices you have over your information.

> ℹ️ **Last updated: 7 October 2026**
> <div>
>     <p>
>       This Privacy Policy explains how formbase handles personal data for everyone who visits our website, uses the product, or submits a
>       response to a form built on formbase. If you have any questions, contact us at{' '}
>       <a href="mailto:support@formbase.so">support@formbase.so</a>.
>     </p>
>   </div>

<h2 id="introduction">1. Introduction</h2>
formbase is a form builder. People use it to create surveys, applications, registrations, checkouts, and other interactive documents, and to
collect responses from their audiences. Personal data flows through the Service in two distinct ways: data that formbase collects about its
own users (the people who build forms), and data that respondents submit through forms built by those users.

This Privacy Policy describes both. We have tried to keep it short, plain, and honest. Where a section applies only to one group, we say so. Capitalized terms not defined here have the meanings set out in our [Terms of Service](/legal/terms-of-service). For data protection roles, references to "you" in this policy correspond to the "Customer" (and, under the GDPR, the "Controller") in our [Data Processing Agreement](/legal/dpa).

By using formbase, you acknowledge that we process personal data as described in this policy. If you do not agree, do not use the Service.

<h2 id="who-we-are">2. Who We Are</h2>
The Service is operated by **Formbase AS**, a Norwegian limited company with organisation number 937 921 217 and registered office in Oslo,
Norway ("formbase", "we", "us", "our"). For the personal data we collect about users of the Service — such as your account, billing, and
product usage data — formbase is the data controller.

For the personal data that respondents submit through your forms, **you** (the formbase user who built the form) are the data controller, and formbase acts as your data processor. The terms of that processing relationship are described in the [Data Processing Agreement](/legal/dpa), which applies automatically to customers subject to the GDPR or equivalent regimes. This Privacy Policy still tells respondents what formbase technically does with their data on your behalf, but it does not replace your own privacy notice.

For questions, complaints, or data subject requests, contact us at <a href="mailto:support@formbase.so">support@formbase.so</a>.

<h2 id="scope">3. Scope</h2>
This Privacy Policy covers personal data that formbase collects, uses, or shares when:

- You visit **formbase.so** or any of its subdomains;
- You sign up for, sign in to, or use **the formbase application** at app.formbase.so;
- You **submit a response** to a form that is hosted on formbase or embedded on another website;
- You **contact us** for support, sales, partnerships, or anything else;
- You read or interact with our **marketing emails, social channels, or events**.

It does not cover third-party websites, services, or integrations that we link to or that you choose to connect, even if they are reached from inside formbase. Those services have their own privacy policies, and you should review them.

<h2 id="data-we-collect">4. Personal Data We Collect</h2>
We try to collect only what we need. The categories below describe the personal data we may handle in different parts of the Service.

<h3 id="account-data">Account data</h3>
When you create a formbase account, we collect:

- Your **email address**, used to sign in and receive system messages.
- A **display name and avatar** if you set them, used to identify you to your collaborators.
- Authentication data linked to **sign-in methods** you choose, such as magic-link login, Google sign-in, or anonymous guest sign-in for short-lived guest sessions.
- **Workspace settings** you set up, including workspace name, timezone, and the list of members you have invited.

Your email address is a contractual requirement for using the Service — it is the only data required to register, and without it we cannot create your account. Display name, avatar, and workspace settings are optional.

<h3 id="billing-data">Subscription and billing data</h3>
formbase subscriptions and AI credit purchases are sold through **Polar** (polar.sh), our payment provider and Merchant of Record. Polar
collects and stores your payment details directly. formbase receives only the limited information needed to provision your plan and credits,
including:

- A Polar customer identifier linking your formbase account to your Polar customer record;
- A Polar subscription identifier and the chosen billing interval (monthly or annual);
- Subscription lifecycle timestamps such as the current period end, lapse, and grace-period markers used to apply your plan entitlements;
- Order and credit-top-up identifiers used to provision AI credits.

formbase does not see or store payment card details, tax identifiers, or billing addresses — Polar holds those records directly, and you can access them through the Polar billing portal. Where you accept respondent payments through the Payment field, Stripe collects all card data directly; formbase receives only non-sensitive references such as the last four digits.

<h3 id="form-content">Form content you create</h3>
The forms you build on formbase — including questions, copy, media, conditional logic, and styling — are stored on our infrastructure so we
can display them to respondents and let you edit them later. Form configuration is treated as Your Content under our [Terms of
Service](/legal/terms-of-service).

<h3 id="submission-data">Submission data from respondents</h3>
When someone submits a response to one of your forms, we store on your behalf:

- The **answers and uploads** the respondent provides, exactly as they entered them;
- A **submission timestamp**, the respondent's browser language, the workspace timezone (captured at submit), and identifiers that link the submission to your form;
- **Drafts and partial submissions** saved server-side while the respondent fills the form, plus timestamps used to power abandoned-response reminders (when you enable them);
- **Technical analytics signals** captured for every published form, including approximate country (derived from the respondent's timezone or the Cloudflare edge `CF-IPCountry` header), device type, browser, traffic source, and engagement duration;
- A **respondent-side visitor identifier** used to deduplicate form view and engagement counts — see [Cookies and Similar Storage](#cookies) for details;
- Where you use the Payment field, a reference to the **Stripe payment** the respondent completed (the card data itself is handled by Stripe, not by formbase).

Respondent IP addresses are processed transiently for rate limiting, Cloudflare Turnstile bot protection, and abuse prevention, and are not persisted alongside submissions.

You decide what fields to include and which of these technical signals to capture. You are the data controller for submissions — see [Section 2](#who-we-are) for data protection roles.

Form submissions may include special categories of personal data under Article 9 GDPR — such as health information, political opinions, or biometric data — depending on the questions you ask. As the controller, you are responsible for establishing a valid legal basis under Article 9(2) GDPR before collecting such data and for making any required disclosures to respondents.

<h3 id="usage-data">Product usage and device data</h3>
When you use the formbase application, we automatically collect:

- **Activity logs** such as which pages you load, what features you use, and when, used to operate the product, debug issues, and understand which features matter.
- **Device and browser data** such as user-agent, screen size, operating system, language, and approximate location derived from IP.
- **IP address**, used to deliver the Service, detect abuse, rate-limit, and meet security obligations.
- **Diagnostic data** such as error reports and performance traces when the application encounters a problem, used to diagnose and fix the issue.

<h3 id="cookies-data">Cookies and similar technologies</h3>
We use cookies and similar storage mechanisms to keep you signed in, remember your workspace and preferences, and secure the application. On
our website, analytics cookies are set only if you accept them. See [Cookies and Similar Storage](#cookies) for details and the choices you
have.

<h3 id="ai-data">AI feature data</h3>
When you use AI Features — such as AI-assisted form building, the AI skill picker, or AI chat for analysing submissions — we process:

- The **prompts** you send to the AI;
- The **context** the feature passes alongside the prompt, such as the structure of the form you are editing or submission data you explicitly share;
- The **outputs** the AI returns;
- **Credit consumption metadata**, so we can show your remaining balance and deduct usage correctly.

These inputs and outputs are sent to Amazon Bedrock to generate the response. We may add or change providers over time and will update this Privacy Policy and the subprocessor list in the [Data Processing Agreement](/legal/dpa) accordingly. See [AI Features](#ai) below for the contractual protections we have in place.

<h3 id="support-data">Support and communications data</h3>
When you email us, fill out a contact form, or chat with us, we keep the contents of the conversation, the contact details you provide, and
any context needed to assist you. Recordings and transcripts of demo calls, if applicable, are stored only with your prior consent.

<h3 id="sources">Where this data comes from</h3>
Most personal data comes directly from you. Some is received from Google (sign-in profile), Polar (billing metadata), Stripe (transaction
references, not card data), or derived from your IP address (approximate country for analytics).

<h2 id="how-we-use">5. How We Use Personal Data</h2>
We use personal data for the following purposes, and only when one of the legal bases in [Section 6](#legal-bases) applies.

We do **not** sell personal data, and we do not share personal data with advertisers or data brokers for advertising purposes. For AI data-handling and no-training commitments, see [Section 13](#ai).

<h2 id="legal-bases">6. Legal Bases for Processing</h2>
If you are in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with a similar regime, we process
personal data only when one of the following legal bases under the GDPR applies:

- **Contract** (Article 6(1)(b)) — providing the Service, managing your account, processing payments, operating AI Features, and providing support.
- **Legitimate interests** (Article 6(1)(f)) — where our interest does not override your rights. Specifically:
  - _Securing the Service_ — our interest in keeping formbase and its users safe from abuse, fraud, and attacks.
  - _Improving the product_ — our interest in understanding how formbase is used so we can make it better, relying on aggregated and de-identified data wherever possible.
  - _Service communications_ — our interest in telling you about changes to features you already use.
  - _Counting website visits_ — our interest in knowing how many people visit our website and which pages they view, measured without cookies as described in [Cookies and Similar Storage](#cookies).
- **Consent** (Article 6(1)(a)) — analytics cookies and session recordings on our website, and optional product data sharing. You can withdraw consent at any time, for example through Cookie settings in the website footer.
- **Legal obligation** (Article 6(1)(c)) — tax, accounting, sanctions, and other legal obligations.
- **Vital interests** (Article 6(1)(d)) — only in rare cases to protect someone's life or physical safety.

Where we rely on legitimate interests, you have the right to object, and we will reconsider on the basis of your specific situation.

<h2 id="sharing">7. How We Share Personal Data</h2>
We share personal data only when one of the following applies.

<h3 id="subprocessors">With subprocessors that help us run formbase</h3>
We rely on a small set of trusted third-party providers to deliver the Service. They process personal data only as needed to provide their
part of the Service, under contracts that require appropriate confidentiality and security measures. The core subprocessors include:

- **Convex** — application database and backend.
- **Cloudflare R2** — object storage for file uploads and signatures.
- **Cloudflare** — CDN, DNS, edge security, custom hostnames, and Turnstile bot protection.
- **Polar** — subscription billing and AI credit purchases (Merchant of Record; independent controller for buyer billing data).
- **Stripe** — respondent payment processing via Stripe Connect (independent controller for payment data).
- **Amazon Web Services (AWS)** — Amazon Bedrock for AI Features; Amazon SES for transactional and system emails, including abandoned-response reminders on Pro workspaces.
- **Axiom** — operational logs and monitoring.
- **PostHog** — analytics for our website and account sign-ups.
- **Unsplash** — image search API; selected images are stored in Cloudflare R2 and served from there.

The authoritative, up-to-date list of subprocessors, along with the categories of data each one processes and the regions in which they operate, is maintained in our [Data Processing Agreement](/legal/dpa).

<h3 id="integrations-share">With integrations you connect</h3>
When you connect a third-party service to formbase — such as a webhook endpoint, automation platform, spreadsheet, messaging tool, or CRM —
you authorise us to send the relevant data to that service on your behalf. We share only what is needed for the integration to work, and the
third party becomes responsible for the data once it receives it under its own terms and privacy policy.

<h3 id="collaborators-share">With your collaborators</h3>
If you invite people to your workspace, they will see your name, email, role, and the forms and submissions they have permission to access.
Workspace owners can change member access and request ownership reassignment through support; the available workspace roles are described in
[Section 5 of the Terms of Service](/legal/terms-of-service#workspaces).

<h3 id="legal-share">For legal and safety reasons</h3>
We may disclose personal data when we believe in good faith that disclosure is necessary to (a) comply with applicable law or a binding
order from a competent authority, (b) enforce our [Terms of Service](/legal/terms-of-service), (c) detect, prevent, or address fraud,
security, or technical issues, or (d) protect the rights, property, or safety of formbase, our users, respondents, or the public.

<h3 id="business-share">In a business transfer</h3>
If formbase is involved in a merger, acquisition, reorganisation, sale of assets, or insolvency, personal data may be transferred to the
relevant counterparties as part of that transaction. Any such transfer will be subject to applicable data protection law.

<h2 id="transfers">8. International Data Transfers</h2>
formbase is based in Norway, and we aim to minimise transfers outside the European Economic Area. Some of our subprocessors are located in,
or transfer data to, jurisdictions outside the EEA, including the United States and the United Kingdom.

When personal data leaves the EEA, we rely on Standard Contractual Clauses (SCCs) adopted under Decision (EU) 2021/914, the UK International Data Transfer Addendum, the Swiss FDPIC addendum, adequacy decisions, or the EU–US Data Privacy Framework (DPF), as applicable. We also apply encryption in transit and at rest, restricted access, and contractual data minimisation. The applicable transfer mechanism for each subprocessor is detailed in our [Data Processing Agreement](/legal/dpa#international-transfers).

<h2 id="retention">9. Data Retention</h2>
We keep personal data only as long as we need it for the purposes described in this policy and as required by law.

- **Account data** is kept while your account is active. When you ask us to delete your account, account records are removed from active systems shortly after the request is processed and remain in backups only until the corresponding backup window expires.
- **Form configuration and submissions** are kept while your workspace exists and you have not deleted them. Cancelling a Pro subscription moves you to the free tier; only **closing your account** triggers deletion. You can also configure a per-form submission retention period; submissions are automatically removed by a scheduled cleanup job when that period elapses.
- **Draft submissions** that a respondent starts but does not submit are kept for a limited period and then purged, unless you have configured a different retention.
- **Trashed forms** that you have moved to trash are permanently purged after a short grace period.
- **Anonymous (guest) sessions** created when you try formbase without an account are purged automatically within a short period.
- **Billing records** are kept for the period required by applicable accounting and tax law. Polar, as Merchant of Record, retains its own billing records under its own retention policy.
- **Support communications** sent to or from the formbase support inbox are kept as long as needed to resolve your request and handle any related legal claims.
- **Product usage and device data** — activity logs, device metadata, and diagnostics are retained in identifiable form for a limited period and then deleted or aggregated so that individual users can no longer be identified.
- **Operational and security logs** generated by the Service are kept for the period needed to operate, debug, and secure the Service. Where a specific incident requires a longer period, we restrict access and delete the logs as soon as the obligation expires.
- **Backups** are created on a regular schedule with a short retention window. File uploads stored in Cloudflare R2 are not covered by object versioning; deletions of file uploads are unrecoverable immediately. Personal data deleted from production becomes unrecoverable once the corresponding backup window expires.

- **AI prompts and outputs** sent to Amazon Bedrock are not stored by AWS after the request is processed and are not used to train any models, as described in the [AWS Service Terms](https://aws.amazon.com/service-terms/).

If law requires us to keep a record for longer — for example to meet a tax, anti-money-laundering, or court-order obligation — we restrict access to that record and delete it as soon as the obligation expires.

<h2 id="security">10. Security</h2>
We apply technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss,
alteration, unauthorised disclosure, and unauthorised access. These measures include:

- Encryption of personal data **in transit** using TLS 1.2 or higher, and **at rest** using industry-standard algorithms;
- **Access controls** based on least privilege, with internal access to production systems restricted on a need-to-know basis;
- **Logging and monitoring** of administrative actions in production systems;
- **Network segmentation** and isolation of production from development environments;
- **Vulnerability management**, including timely application of security updates and a responsible disclosure channel at <a href="mailto:support@formbase.so">support@formbase.so</a>;
- **Access controls** limiting production access to authorised personnel.

No system is perfectly secure. If you become aware of a vulnerability or a possible compromise, report it to <a href="mailto:support@formbase.so">support@formbase.so</a>.

<h2 id="rights">11. Your Rights</h2>
Depending on where you live, you may have the following rights over the personal data we hold about you. Many of these are guaranteed under
the GDPR, the UK GDPR, and equivalent laws in other jurisdictions.

- **Right of access** — ask for a copy of the personal data we hold about you and information about how it is processed.
- **Right to rectification** — ask us to correct inaccurate or incomplete data.
- **Right to erasure** — ask us to delete personal data when there is no overriding reason to keep it. You can also close your account and delete most of your data yourself from the product.
- **Right to restriction** — ask us to pause processing in certain situations, for example while we check a correction or objection.
- **Right to data portability** — receive your personal data in a structured, commonly used, machine-readable format, or have it sent to another controller. The export feature in the application covers most of this for forms and submissions, with CSV and Excel (XLSX) output.
- **Right to object** — object to processing based on legitimate interests, including profiling, and to direct marketing at any time.
- **Right to withdraw consent** — where we rely on your consent, you can withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
- **Right not to be subject to a decision based solely on automated processing** (Article 22 GDPR) — we do not make decisions about you that produce legal or similarly significant effects through solely automated processing, including profiling.

To exercise any of these rights, email <a href="mailto:support@formbase.so">support@formbase.so</a> or use the self-service options in the application where available. We will respond within one month, or tell you why we need more time. We may ask for information to verify your identity before acting on a request, especially for access or deletion.

If you are unhappy with how we have handled your data, you can lodge a complaint with a supervisory authority — for users in Norway, the **Norwegian Data Protection Authority** (Datatilsynet, <a href="https://datatilsynet.no">datatilsynet.no</a>). You can also complain to the authority in the EEA country where you live or work.

<h3 id="respondent-rights">Rights of respondents</h3>
If you are a respondent who submitted a form built on formbase, your data subject rights run primarily against the formbase user who built
that form — they are the data controller. We can help you reach them, and we will support them in responding to your request. Where we hold
the underlying data as a processor on their behalf, we will act on their documented instructions. To contact us, write to
<a href="mailto:support@formbase.so">support@formbase.so</a> and tell us which form you submitted (the URL is usually enough).

<h2 id="cookies">12. Cookies and Similar Storage</h2>
We use a small number of cookies, `localStorage`, and `sessionStorage` entries to make formbase work and to deduplicate analytics on your
forms. We try to keep the list short.

- **Strictly necessary** — keep you signed in, remember the workspace you last used, secure the application against cross-site request forgery, and store essential preferences. These cannot be disabled without breaking the product.
- **Functional** — remember UI preferences such as theme, sidebar state, and language. You can clear them from your browser.
- **Analytics on our website (formbase.so and formbase.no)** — PostHog, our analytics provider, counts every visit without storing anything on your device. Its servers combine your IP address and browser user agent with a random value that changes every day and is then deleted, so a visit can't be linked to your visits on other days. Only if you accept in the cookie banner does PostHog also set a cookie (`ph_*_posthog`) and `localStorage` entries that identify your browser, and record your visits as session replays. Your choice is stored in `localStorage` (`fb_analytics_consent`) so we don't ask on every page. You can change it at any time through **Cookie settings** in the website footer; withdrawing deletes what PostHog stored.
- **Analytics on hosted form pages** — a random visitor identifier (`fb_visitor_id`) in `localStorage`, plus short-lived `sessionStorage` flags (`fb_viewed`, `fb_engaged`), used to deduplicate view and engagement counts. This storage is not needed for the form to function and does not enable advertising, cross-site tracking, or profiling. formbase places this storage as a data processor on your instructions as controller. If your respondents are in jurisdictions where prior consent is required for non-essential storage (such as the EEA under the ePrivacy Directive or Norway under Ekomloven § 3-15), you are responsible for obtaining that consent before the form page loads.

We do not use cookies or similar storage to track respondents across other websites for advertising, and we do not place advertising cookies on hosted form pages. You can clear cookies, `localStorage`, and `sessionStorage` through your browser settings. Blocking strictly necessary cookies or storage may prevent parts of the Service from working.

If you build forms on formbase, your hosted forms will set `fb_visitor_id` in `localStorage` on respondent devices as described above. You should disclose this in your own privacy notice to respondents.

<h2 id="ai">13. AI Features</h2>
Prompts and context you submit through formbase AI Features are sent to Amazon Bedrock. Context includes, where applicable, the structure of
the form you are editing and submission samples you explicitly share for analysis or summarisation. We configure it so that, under the AWS
Service Terms, inputs and outputs are not used to train any models and are not stored by AWS after the request is processed. Processing is
in line with the security and data protection commitments in this Privacy Policy and the [Data Processing Agreement](/legal/dpa).

AI outputs are generated probabilistically and may be inaccurate, incomplete, or out of date. You are responsible for reviewing every AI-generated output before you rely on it, publish it, or send it to respondents.

You should not submit personal data, secrets, or other sensitive information through AI Features unless you have a lawful basis to share that information with our subprocessors and have considered the risks. We do not control how providers respond to lawful government requests directed at them.

<h2 id="children">14. Children</h2>
formbase is not designed for children. You must be at least sixteen (16) years old to create a formbase account, as described in our [Terms
of Service](/legal/terms-of-service).

formbase users may build forms intended for younger audiences. If you collect personal data from children through formbase, you are responsible for obtaining any required parental or guardian consent and for handling that data in accordance with applicable law, including COPPA where relevant. [Section 6 of the Terms of Service](/legal/terms-of-service#acceptable-use) lists sensitive data classes the Service is not designed for, and [Section 7](/legal/terms-of-service#prohibited-uses) sets out prohibited uses, including content that exploits or endangers minors.

We do not knowingly collect personal data from children under sixteen (16) (or under thirteen (13) where COPPA sets a lower threshold). If you believe we have inadvertently collected personal data from a child below the applicable age threshold without the required consent, contact us at <a href="mailto:support@formbase.so">support@formbase.so</a> and we will delete it without undue delay.

<h2 id="marketing">15. Communications</h2>
We send two kinds of email:

- **System emails** about your account, security, billing, and the forms you build. These are part of the Service and cannot be opted out of while your account is active.
- **Service announcements** about changes to the product, policies, or features you rely on. We keep these to the minimum needed to keep you informed.

<h2 id="california">16. Notice for California Residents</h2>
If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the
California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete it, the right to
correct inaccuracies, and the right to opt out of the "sale" or "sharing" of personal information.

formbase does not sell personal information and does not share personal information for cross-context behavioural advertising. Because no sale or sharing occurs, no "Do Not Sell or Share My Personal Information" link is required or provided.

The categories of personal information we collect, purposes, and retention periods are described in [Section 4](#data-we-collect), [Section 5](#how-we-use), and [Section 9](#retention). We do not build behavioural profiles for advertising and do not use sensitive personal information for inferences or profiling.

To exercise your rights — including the right to know, delete, correct, opt out, or limit sensitive personal information — write to <a href="mailto:support@formbase.so">support@formbase.so</a>. We will not discriminate against you for exercising any of these rights.

<h2 id="changes">17. Changes to This Privacy Policy</h2>
We may update this Privacy Policy from time to time to reflect changes to the Service, our subprocessors, applicable law, or business
practices. The "Last updated" date at the top of this policy shows when it was most recently revised.

If you continue to use the Service after a change takes effect, you accept the updated Privacy Policy. If you do not agree to a change, you can close your account before it takes effect.

<h2 id="contact">18. Contact Us</h2>
For privacy questions, data subject requests, or anything else related to this policy, contact us at:

- **Privacy questions, data subject requests, and security reports** — <a href="mailto:support@formbase.so">support@formbase.so</a>

formbase has not appointed a Data Protection Officer. Our privacy team monitors the <a href="mailto:support@formbase.so">support@formbase.so</a> inbox and will route your request appropriately.

<h2 id="related">Related documents</h2>

<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Terms of Service](/legal/terms-of-service) — The rules that govern your use of formbase.
  - [Data Processing Agreement](/legal/dpa) — Terms for processing personal data on your behalf.
  - [Legal overview](/legal/overview) — Index of formbase legal documents.
</div>


# Data Processing Agreement

How formbase processes personal data on your behalf

## Data Processing Agreement

The terms under which formbase processes personal data on behalf of customers subject to the GDPR and equivalent data protection laws.

> ℹ️ **Last updated: 7 October 2026**
> <div>
>     <p>
>       This Data Processing Agreement ("DPA") forms part of the <a href="/legal/terms-of-service">Terms of Service</a> between you (the
>       "Customer") and formbase (the "Processor"). It applies automatically whenever you use formbase to collect, store, or otherwise process
>       personal data of identifiable individuals subject to the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK
>       GDPR, the Norwegian Personal Data Act (personopplysningsloven), or another applicable data protection law that requires a written
>       processing agreement.
>     </p>
>     <p>No signature is required. Your use of formbase to process personal data constitutes acceptance of this DPA.</p>
>   </div>

<h2 id="parties">1. Parties</h2>
This DPA is entered into between:

- **Customer** — the natural or legal person who has accepted the formbase [Terms of Service](/legal/terms-of-service) and on whose behalf personal data is processed (acting as the "Controller").
- **formbase** — Formbase AS, a Norwegian limited company with organisation number 937 921 217 and registered office in Oslo, Norway (acting as the "Processor").

Where the GDPR or another applicable law refers to the parties as "controller" and "processor", or "data exporter" and "data importer", those terms map to Customer and formbase respectively for the purposes of this DPA.

<h2 id="definitions">2. Definitions</h2>
Terms used in this DPA but not defined here have the meanings given in the [Terms of Service](/legal/terms-of-service) or in the GDPR. In
particular:

- **Service** — the formbase platform, including the form editor, published forms, submission management, integrations, AI Features, APIs, and all related functionality provided under the [Terms of Service](/legal/terms-of-service).
- **Form** — an online form, survey, quiz, or other data-collection page created and published by Customer through the Service.
- **Submission** — a completed or partial response submitted by a Data Subject through a Form, including all field values, file uploads, metadata, and associated timestamps.
- **Workspace** — the organisational unit within the Service under which Customer manages Forms, Submissions, members, and integrations.
- **AI Features** — the AI-powered capabilities of the Service, including AI form generation, AI chat, and any other feature that sends data to a third-party AI model for inference.
- **Personal Data** — any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR, that Customer processes through the Service.
- **Processing** — any operation performed on Personal Data, as defined in Article 4(2) GDPR.
- **Data Subject** — the identifiable individual to whom Personal Data relates, including respondents who submit Forms, members of a Workspace, and Customer's own end users.
- **Subprocessor** — any third party engaged by formbase to process Personal Data on its behalf in connection with the Service.
- **Standard Contractual Clauses** or **SCCs** — the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914, including the UK International Data Transfer Addendum where relevant.
- **Applicable Data Protection Law** — the GDPR, the UK GDPR, the Norwegian Personal Data Act, and any other privacy or data protection law that applies to Customer's processing of Personal Data through the Service.

<h2 id="scope">3. Scope and Roles</h2>
This DPA governs formbase's Processing of Personal Data on behalf of Customer through the Service. For that Processing:

- Customer is the **Controller**. Customer determines the purposes and means of the Processing, decides what Personal Data to collect through Forms, configures retention and sharing settings, and connects integrations.
- formbase is the **Processor**. formbase processes Personal Data on Customer's documented instructions, primarily to operate the Service, deliver the features Customer has enabled, and meet its security and support obligations.

For Personal Data that formbase collects directly about Customer as a formbase user — such as account details, subscription metadata received from Polar, and product usage telemetry — formbase acts as an independent **Controller**. That Processing is governed by the [Privacy Policy](/legal/privacy-policy), not by this DPA. Payment and buyer billing data is controlled by Polar, which acts as an independent controller as Merchant of Record.

For respondent payments processed through Stripe Connect, Customer is the merchant of record and Controller of the payment-related Personal Data; Stripe acts as an independent controller for payment processing. See [Annex 1](#annex-1) for details.

<h2 id="subject-matter">4. Subject Matter, Nature, Purpose and Duration</h2>
formbase processes Personal Data only as needed to provide the Service to Customer under the Terms of Service.

- **Subject matter** — the hosting and operation of online forms, the collection and storage of Submissions, and the provision of related features such as analytics, integrations, AI Features, notifications, and exports.
- **Nature** — collection, storage, and all technical operations required to run the Service.
- **Purpose** — to enable Customer to build and publish Forms, collect responses from Data Subjects, manage Submissions, and connect to third-party tools, all in accordance with Customer's configuration and instructions. Customer's instructions may be given through the web application, the API, MCP (Model Context Protocol) connections, or other programmatic interfaces made available as part of the Service.
- **Duration** — for as long as Customer's account is active and Personal Data is stored in the Service, plus any limited retention period set out in [Section 12](#return-deletion).

<h2 id="categories">5. Categories of Data Subjects and Personal Data</h2>

<h3 id="data-subjects">Categories of Data Subjects</h3>
Personal Data processed under this DPA may relate to:

- Respondents who submit Customer's Forms;
- Customer's Workspace owners and members;
- Customer's contacts, leads, or end users whose data Customer imports or routes through integrations;
- Any other Data Subjects whose data Customer chooses to process through the Service.

<h3 id="data-categories">Categories of Personal Data</h3>
Customer decides what Personal Data to collect. The categories typically include:

- **Identification data** — names, email addresses, phone numbers, postal addresses.
- **Form responses** — free-text answers, choices, ratings, file uploads, signatures, payment transaction references, and any other content Data Subjects enter.
- **Draft and partial responses** — submission drafts and partial responses saved server-side while a Data Subject is filling a Form, together with the timestamps used to power abandoned-response reminders where Customer has enabled that feature.
- **Profile and account data** — Workspace member emails, display names, role and permission settings.
- **Technical data** — timestamps, approximate country, device type, browser metadata, traffic source, and engagement duration captured as part of Submissions or analytics events; visitor identifiers stored client-side to deduplicate form view and engagement counts.
- **IP addresses and security logs** — IP addresses are processed transiently at the edge (Cloudflare) for rate limiting, bot protection through Cloudflare Turnstile, and abuse prevention. IP addresses are not persisted alongside Submission content in formbase's primary database. Short-lived security and abuse logs may retain IP addresses for the limited period needed to operate those defences.
- **Integration data** — identifiers, tokens, and payloads exchanged with third-party services that Customer connects.
- **AI input/output** — prompts, form structure, and Submission samples that Customer explicitly passes as context, plus the generated outputs, where Customer uses AI Features.

formbase is not designed for, and Customer must not submit, special categories of data under Article 9 GDPR, criminal-conviction data under Article 10 GDPR, government identifiers used for primary identity proofing, payment card data outside the Payment field, or other regulated data classes listed in [Section 6 of the Terms of Service](/legal/terms-of-service#acceptable-use), unless formbase has agreed otherwise in writing.

If formbase becomes aware that Customer has submitted prohibited data classes, formbase may notify Customer and delete the data. Customer is responsible as Controller for ensuring a valid legal basis for all Personal Data submitted to the Service.

<h2 id="customer-obligations">6. Customer Obligations</h2>
Customer is responsible for its role as Controller. In particular, Customer:

- Determines a lawful basis under Article 6 GDPR (and, where applicable, Article 9 GDPR) for each Processing activity carried out through the Service;
- Provides Data Subjects with all required notices, including a privacy notice covering Customer's use of formbase, and obtains any required consent;
- Respects Data Subject rights under Articles 15–22 GDPR for the Personal Data Customer processes;
- Sets up the Service appropriately, including retention rules, sharing settings, integrations, and access controls;
- Does not upload Personal Data the Service is not designed for, as set out in [Section 5](#categories) and [Section 6 of the Terms of Service](/legal/terms-of-service#acceptable-use);
- Keeps Workspace member access lists, API keys, OAuth credentials, and MCP tokens up to date and revokes them when no longer needed;
- Documents its own Processing activities under Article 30 GDPR and carries out data protection impact assessments where required under Article 35 GDPR.

Customer warrants that it has the right to give formbase the instructions set out in this DPA and that all Personal Data has been collected and shared with formbase lawfully.

<h2 id="formbase-obligations">7. formbase's Obligations</h2>

<h3 id="instructions">Documented instructions</h3>
formbase processes Personal Data only on Customer's documented instructions, including transfers of Personal Data outside the European
Economic Area, unless required to do otherwise by Union or Member State law. Customer's instructions are set out in this DPA, in the Terms
of Service, in the configuration of the Service, and in any further written instructions Customer may give from time to time.

formbase does not process Personal Data for its own marketing purposes, profiling, or any purpose beyond providing and securing the Service as instructed by Customer.

If formbase believes an instruction infringes Applicable Data Protection Law, it will inform Customer and not carry out the instruction.

<h3 id="confidentiality">Confidentiality</h3>
formbase ensures that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate
statutory obligation of confidentiality. Access to Personal Data is limited to personnel who need it to perform their duties.

<h3 id="security">Security measures</h3>
formbase implements appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction,
loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature,
scope, context, and purposes of Processing. The current measures are described in [Annex 2](#annex-2).

<h3 id="assistance">Assistance</h3>
Taking into account the nature of the Processing and the information available to it, formbase will assist Customer, by appropriate
technical and organisational measures, in fulfilling its obligations to:

- Respond to Data Subject requests under Articles 15–22 GDPR (see [Section 8](#data-subjects-rights));
- Maintain the security of Processing (Article 32 GDPR);
- Notify Personal Data breaches (Article 33 GDPR) — see [Section 11](#breach);
- Communicate breaches to Data Subjects where required (Article 34 GDPR);
- Carry out data protection impact assessments (Article 35 GDPR); and
- Consult with supervisory authorities where required (Article 36 GDPR).

Where this assistance materially exceeds what is available through standard product features, formbase may charge a reasonable fee, confirmed with Customer in writing (including by email) before work begins.

<h2 id="data-subjects-rights">8. Data Subject Rights</h2>
The Service is designed so that Customer can respond to most Data Subject requests directly, without formbase's involvement. Customer can:

- View, export, and delete Submissions from the Submissions area of any Form;
- Export Workspace data, including Forms and Submissions, in CSV or Excel (XLSX) — these structured, machine-readable formats also satisfy Article 20 GDPR data portability requests;
- Restrict or delete a Workspace member's access;
- Delete entire Forms, Workspaces, or the account, subject to the retention rules in the [Privacy Policy](/legal/privacy-policy).

formbase does not carry out automated decision-making or profiling on Customer's Personal Data within the meaning of Article 22 GDPR.

If a Data Subject contacts formbase directly with a request relating to Personal Data processed for Customer, formbase will redirect the Data Subject to Customer where possible and will not respond on Customer's behalf.

<h2 id="subprocessors">9. Subprocessors</h2>
Customer authorises formbase to engage the Subprocessors listed in [Annex 1](#annex-1) for the Processing of Personal Data. formbase will:

- Enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those set out in this DPA, including, where applicable, the SCCs;
- Remain fully liable to Customer for the performance of each Subprocessor's data protection obligations, in accordance with Article 28(4) GDPR.

formbase will give Customer reasonable advance notice before a new Subprocessor begins Processing Personal Data. Customer may object to a new Subprocessor on reasonable, documented data protection grounds by writing to <a href="mailto:support@formbase.so">support@formbase.so</a> within a reasonable period.

If formbase cannot reasonably accommodate Customer's objection, Customer may terminate the affected Processing.

<h2 id="international-transfers">10. International Transfers</h2>
formbase is established in Norway, which is part of the European Economic Area (EEA). No transfer safeguard is required for flows between
formbase and Customers located within the EEA. Several of formbase's Subprocessors are established in the United States or process Personal
Data on infrastructure located outside the EEA or the United Kingdom. For each such international transfer, formbase relies on one or more
of the following safeguards:

- An **adequacy decision** by the European Commission or a competent authority, where one exists for the destination country;
- The **Standard Contractual Clauses** adopted by the European Commission in [Decision (EU) 2021/914](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914) (as extended to the EEA by EEA Joint Committee Decision), incorporated by reference into this DPA, with the module that applies depending on the transfer in question (Module 2 — Controller to Processor — for Customer's transfer to formbase; Module 3 — Processor to Processor — for formbase's onward transfer to Subprocessors that act as processors). Where a Subprocessor (such as Polar or Stripe) collects billing or payment data **directly** from buyers or respondents as an independent controller, that collection is outside formbase's processor chain and the Subprocessor's own transfer mechanisms apply between the data subject and the Subprocessor;
- The **UK International Data Transfer Addendum** issued by the UK Information Commissioner (in force March 2022), where Personal Data is subject to the UK GDPR;
- The **Standard Contractual Clauses** as recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC), with the Swiss-specific adaptations set out in the FDPIC's guidance of 27 August 2021 (clarifying that references to "Member State" must not be interpreted to exclude Switzerland, designating the FDPIC as the competent supervisory authority, and extending the scope to cover personal data of legal entities), where Personal Data is subject to the Swiss Federal Act on Data Protection (nFADP);
- The **EU–US Data Privacy Framework** (DPF), its UK extension, and the **Swiss–US Data Privacy Framework**, where the specific US-based Subprocessor is self-certified under the applicable framework (formbase falls back to SCCs where certification is absent or lapses); and
- **Supplementary technical and organisational measures** as described in [Annex 2](#annex-2).

Where formbase relies on SCCs for a transfer to a country without an adequacy decision, formbase considers the legal framework in the destination country and applies the supplementary measures in [Annex 2](#annex-2) to address identified risks.

Where SCCs are the applicable transfer safeguard, by accepting this DPA Customer is deemed to have signed the SCCs as the data exporter and formbase signs them as the data importer. For the purposes of Annex I to the SCCs: (a) the parties are identified in [Section 1](#parties) of this DPA; (b) the description of the transfer — categories of data subjects, categories of personal data, frequency of transfer, nature and purpose of processing, and retention period — is set out in [Sections 4](#subject-matter) and [5](#categories) of this DPA; and (c) the competent supervisory authority is the Norwegian Data Protection Authority (Datatilsynet). This DPA thereby satisfies the Annex I requirements of the SCCs. The SCCs apply only to transfers that require them. In the event of a conflict between this DPA and the SCCs, the SCCs prevail to the extent of the conflict.

<h2 id="breach">11. Personal Data Breaches</h2>
formbase will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The
notification will include, to the extent known at the time, the nature and scope of the breach, the likely consequences, and the measures
formbase has taken or proposes to take.

Where complete information is not available at the time of the initial notification, formbase will provide it in stages without undue delay. Customer is responsible for keeping its contact details up to date and for notifying its own Data Subjects and supervisory authorities where required.

Notifying Customer is not, by itself, an admission by formbase of fault or liability for any breach.

<h2 id="return-deletion">12. Return and Deletion of Data</h2>
Customer can export Forms and Submissions in standard formats at any time while its account is active, as described in the [Terms of
Service](/legal/terms-of-service).

On termination of the Service or written request by Customer, formbase will delete all Personal Data Processed on Customer's behalf, unless Union law, Member State law, or applicable Norwegian law requires further storage. Customer is responsible for exporting any data it wishes to keep before closing the account, using the in-product tools described in [Section 8](#data-subjects-rights). Specifically:

- When a Form or Workspace is deleted from the Service, the underlying records are removed from active systems and become unreachable through the application;
- When a Customer account is closed, the account's Personal Data is removed from active systems. Customer is responsible for exporting any data it wishes to keep before closing the account;
- Personal Data is removed from backups when the corresponding backup window expires. File uploads stored in Cloudflare R2 are not covered by object versioning; deletions of file uploads are unrecoverable immediately;
- Draft and partial responses are retained for a limited period (or until the Data Subject completes the Submission), after which they are automatically purged from active systems;
- Personal Data that formbase is required to retain by law — such as billing records or records relating to a legal claim — will be archived in restricted-access systems for the period required by law.

<h2 id="audits">13. Audits</h2>
formbase will make available to Customer all information reasonably necessary to demonstrate compliance with its obligations under Article
28 GDPR and this DPA, where Customer has justifiable grounds — such as a confirmed Personal Data Breach, a material breach of this DPA, or a
request from a supervisory authority. By default, this information takes the form of:

- This DPA and the [Privacy Policy](/legal/privacy-policy) in formbase's documentation;
- The list of Subprocessors in [Annex 1](#annex-1) and the technical and organisational measures described in [Annex 2](#annex-2);
- Written responses to reasonable, specific questions sent to <a href="mailto:support@formbase.so">support@formbase.so</a>.

Where a supervisory authority requires an on-site inspection, formbase will cooperate to the extent required by law.

<h2 id="liability">14. Liability</h2>
The liability of each party under this DPA is subject to the limitations and exclusions set out in [Section 25 (Limitation of
Liability)](/legal/terms-of-service#limitation-of-liability) of the Terms of Service. The aggregate liability of formbase under or in
connection with this DPA forms part of, and is not in addition to, the overall liability cap set out in the Terms of Service.

Notwithstanding the foregoing financial cap, nothing in this DPA limits any liability that cannot be limited under mandatory Applicable Data Protection Law, including liability towards a Data Subject under Article 82 GDPR. The Article 82 carve-out operates regardless of the aggregate cap in the Terms of Service.

formbase is not liable under Article 82 GDPR to the extent it demonstrates it is not in any way responsible for the event giving rise to the damage, in accordance with Article 82(3) GDPR.

<h2 id="term">15. Term and Termination</h2>
This DPA enters into force when Customer first submits Personal Data to the Service, and no later than the date Customer accepts the Terms
of Service. It remains in effect for as long as formbase processes Personal Data on Customer's behalf.

This DPA terminates when the Terms of Service terminate, provided that it continues in force until formbase has completed the return or deletion of all Personal Data pursuant to [Section 12](#return-deletion). The provisions of [Sections 5 (Categories)](#categories), [7 (formbase's Obligations)](#formbase-obligations) (including the confidentiality obligations therein), [9 (Subprocessors)](#subprocessors), [11 (Breach)](#breach), [12 (Return and Deletion)](#return-deletion), [13 (Audits)](#audits), [14 (Liability)](#liability), and [16 (Governing Law)](#governing-law) survive termination to the extent necessary to give effect to them.

<h2 id="governing-law">16. Governing Law and Jurisdiction</h2>
This DPA is governed by the laws of Norway, without regard to its conflict of laws principles. Any dispute arising out of or in connection
with this DPA is subject to the same dispute resolution and jurisdiction terms as the Terms of Service, except where Applicable Data
Protection Law mandates a different forum.

Where the SCCs apply, the governing law and forum specified in the SCCs prevail to the extent of any conflict.

<h2 id="updates">17. Updates to This DPA</h2>
formbase may update this DPA from time to time to reflect changes in the Service, in Applicable Data Protection Law, or in the supervisory
authorities' guidance.

- **Non-material changes** (formatting, clarifications that do not alter obligations, updates to Annex 1 that follow the [Section 9](#subprocessors) notice process) take effect upon publication.
- **Material changes** (any change that alters the scope of Processing, reduces the level of protection afforded to Personal Data, or modifies the parties' obligations) take effect after reasonable advance notice. Continued use of the Service after the notice period constitutes acceptance.

<h2 id="contact">18. Contact</h2>
For any matter relating to this DPA, including data subject requests that cannot be handled through the Service, subprocessor objections,
audit requests, or breach notifications, contact us at:

- **DPA enquiries, data subject requests, and security reports** — <a href="mailto:support@formbase.so">support@formbase.so</a>

formbase has not appointed a Data Protection Officer. Under Article 37 GDPR, a DPO is required for public authorities and bodies (excluding courts), or where core activities consist of large-scale, regular, and systematic monitoring of individuals, or large-scale processing of special categories of data (Article 9) or criminal-conviction data (Article 10); formbase's core activities do not meet any of these thresholds. All DPA-related matters are handled through the contact point above.

<h2 id="annex-1">Annex 1 — Subprocessors</h2>
formbase engages the following parties in connection with the Service. Convex, Cloudflare R2, Cloudflare, Amazon Web Services (AWS), Axiom,
and Unsplash act as data processors under formbase's instruction and are true subprocessors for purposes of Article 28 GDPR. Polar and
Stripe are listed here for transparency, but they act as **independent controllers** for the data they collect directly from buyers and
respondents respectively; formbase's Article 28 obligations do not apply to the data those parties control, and their own transfer
mechanisms govern where applicable. Google provides optional OAuth sign-in: users authenticate directly with Google, which acts as an
independent controller for the Google account; formbase receives only the basic sign-in profile (name, email, profile picture). PostHog is
listed for transparency: formbase uses it for analytics on its own website and account sign-ups, as controller of that data, and it receives
no Customer Personal Data.

**Customer-directed integrations.** When Customer enables an integration (Notion, Airtable, Google Sheets, Slack, Discord, Linear, GitHub, webhooks, etc.), formbase transmits data to that service on Customer's documented instruction. The third-party service is not a formbase Subprocessor; Customer is responsible as Controller for ensuring a lawful basis, appropriate data processing agreements, and transfer mechanisms with each service it connects.

If formbase engages a new Subprocessor or adds a new LLM provider, [Annex 1](#annex-1) will be updated in accordance with [Section 9](#subprocessors). The contractual obligations formbase imposes on each Subprocessor are set out in [Section 9](#subprocessors).

<h2 id="annex-2">Annex 2 — Technical and Organisational Measures</h2>
formbase implements the following technical and organisational measures to protect Personal Data, taking into account the state of the art,
the cost of implementation, and the nature of the Processing. Specific measures may evolve over time, provided that the overall level of
protection is not reduced.

<h3 id="access-control">Access control</h3>

- Role-based access controls within the Service, with workspace-level permissions for owners and members;
- Passwordless authentication using magic-link email or Google OAuth sign-in (Customer-managed multi-factor authentication is available on the Google account used for sign-in), with rate limiting on the login endpoints; anonymous guest sessions (created when a user tries the Service without registering) are purged automatically within a short period;
- Internal access to production systems restricted on a need-to-know basis.

<h3 id="encryption">Encryption</h3>

- TLS 1.2 or higher for all data in transit between Data Subjects, Customers, the Service, and Subprocessors;
- Encryption at rest for the primary database, file storage, and backups, using industry-standard ciphers managed by Convex and the underlying cloud provider;
- Secrets and API keys stored in encrypted secret stores; passwords are not stored — the Service uses passwordless authentication.

<h3 id="logical-isolation">Logical isolation</h3>

- Multi-tenant architecture with row-level access scoping by Workspace and Customer;
- Logical separation between development, staging, and production environments; production data is not used in non-production environments;
- Subprocessor integrations are scoped to the minimum data required to perform their function.

<h3 id="resilience">Resilience and backups</h3>

- Automated, encrypted daily backups of the primary database (delegated to Convex under its infrastructure service terms); file uploads in Cloudflare R2 are not covered by object versioning;
- Use of cloud providers with redundant infrastructure and DDoS protection.

<h3 id="vulnerability">Vulnerability management</h3>

- Security updates for application dependencies applied as appropriate.

<h3 id="organisational">Organisational measures</h3>

- Access to production systems is limited to authorised personnel;
- Breach notification procedures aligned with [Section 11](#breach);
- Maintenance of records of processing activities in accordance with Article 30(2) GDPR, made available to supervisory authorities on request as required by Article 30(4) GDPR.

<h3 id="supplementary-transfer-measures">Supplementary measures for international transfers (Schrems II)</h3>

In addition to the general security measures above, formbase applies the following supplementary measures for transfers to countries without an adequacy decision, in line with EDPB Recommendations 01/2020:

- Encryption in transit (TLS 1.2+) and at rest as described in the [Encryption](#encryption) section; encryption keys are managed by the cloud provider's key management service and are not accessible to third-country government authorities without a lawful order.

<h3 id="data-minimisation">Data minimisation and retention</h3>

- The Service collects only the data Customer chooses to collect through Forms and the operational data needed to run the Service. Retention and deletion rules are set out in [Section 12](#return-deletion);
- Aggregation is applied to product analytics where the underlying identifiers are not needed for the purpose;
- AI inputs and outputs sent to Amazon Bedrock are processed under the [AWS Service Terms](https://aws.amazon.com/service-terms/) and are not stored by AWS after processing.

<h2 id="related">Related documents</h2>

<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Privacy Policy](/legal/privacy-policy) — How we collect, use, and share personal data.
  - [Terms of Service](/legal/terms-of-service) — The rules that govern your use of formbase.
  - [Legal overview](/legal/overview) — Index of formbase legal documents.
</div>

