# Data Processing Agreement

How formbase processes personal data on your behalf

## Data Processing Agreement

The terms under which formbase processes personal data on behalf of customers subject to the GDPR and equivalent data protection laws.

> ℹ️ **Last updated: 7 October 2026**
> <div>
>     <p>
>       This Data Processing Agreement ("DPA") forms part of the <a href="/legal/terms-of-service">Terms of Service</a> between you (the
>       "Customer") and formbase (the "Processor"). It applies automatically whenever you use formbase to collect, store, or otherwise process
>       personal data of identifiable individuals subject to the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK
>       GDPR, the Norwegian Personal Data Act (personopplysningsloven), or another applicable data protection law that requires a written
>       processing agreement.
>     </p>
>     <p>No signature is required. Your use of formbase to process personal data constitutes acceptance of this DPA.</p>
>   </div>

<h2 id="parties">1. Parties</h2>
This DPA is entered into between:

- **Customer** — the natural or legal person who has accepted the formbase [Terms of Service](/legal/terms-of-service) and on whose behalf personal data is processed (acting as the "Controller").
- **formbase** — Formbase AS, a Norwegian limited company with organisation number 937 921 217 and registered office in Oslo, Norway (acting as the "Processor").

Where the GDPR or another applicable law refers to the parties as "controller" and "processor", or "data exporter" and "data importer", those terms map to Customer and formbase respectively for the purposes of this DPA.

<h2 id="definitions">2. Definitions</h2>
Terms used in this DPA but not defined here have the meanings given in the [Terms of Service](/legal/terms-of-service) or in the GDPR. In
particular:

- **Service** — the formbase platform, including the form editor, published forms, submission management, integrations, AI Features, APIs, and all related functionality provided under the [Terms of Service](/legal/terms-of-service).
- **Form** — an online form, survey, quiz, or other data-collection page created and published by Customer through the Service.
- **Submission** — a completed or partial response submitted by a Data Subject through a Form, including all field values, file uploads, metadata, and associated timestamps.
- **Workspace** — the organisational unit within the Service under which Customer manages Forms, Submissions, members, and integrations.
- **AI Features** — the AI-powered capabilities of the Service, including AI form generation, AI chat, and any other feature that sends data to a third-party AI model for inference.
- **Personal Data** — any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR, that Customer processes through the Service.
- **Processing** — any operation performed on Personal Data, as defined in Article 4(2) GDPR.
- **Data Subject** — the identifiable individual to whom Personal Data relates, including respondents who submit Forms, members of a Workspace, and Customer's own end users.
- **Subprocessor** — any third party engaged by formbase to process Personal Data on its behalf in connection with the Service.
- **Standard Contractual Clauses** or **SCCs** — the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914, including the UK International Data Transfer Addendum where relevant.
- **Applicable Data Protection Law** — the GDPR, the UK GDPR, the Norwegian Personal Data Act, and any other privacy or data protection law that applies to Customer's processing of Personal Data through the Service.

<h2 id="scope">3. Scope and Roles</h2>
This DPA governs formbase's Processing of Personal Data on behalf of Customer through the Service. For that Processing:

- Customer is the **Controller**. Customer determines the purposes and means of the Processing, decides what Personal Data to collect through Forms, configures retention and sharing settings, and connects integrations.
- formbase is the **Processor**. formbase processes Personal Data on Customer's documented instructions, primarily to operate the Service, deliver the features Customer has enabled, and meet its security and support obligations.

For Personal Data that formbase collects directly about Customer as a formbase user — such as account details, subscription metadata received from Polar, and product usage telemetry — formbase acts as an independent **Controller**. That Processing is governed by the [Privacy Policy](/legal/privacy-policy), not by this DPA. Payment and buyer billing data is controlled by Polar, which acts as an independent controller as Merchant of Record.

For respondent payments processed through Stripe Connect, Customer is the merchant of record and Controller of the payment-related Personal Data; Stripe acts as an independent controller for payment processing. See [Annex 1](#annex-1) for details.

<h2 id="subject-matter">4. Subject Matter, Nature, Purpose and Duration</h2>
formbase processes Personal Data only as needed to provide the Service to Customer under the Terms of Service.

- **Subject matter** — the hosting and operation of online forms, the collection and storage of Submissions, and the provision of related features such as analytics, integrations, AI Features, notifications, and exports.
- **Nature** — collection, storage, and all technical operations required to run the Service.
- **Purpose** — to enable Customer to build and publish Forms, collect responses from Data Subjects, manage Submissions, and connect to third-party tools, all in accordance with Customer's configuration and instructions. Customer's instructions may be given through the web application, the API, MCP (Model Context Protocol) connections, or other programmatic interfaces made available as part of the Service.
- **Duration** — for as long as Customer's account is active and Personal Data is stored in the Service, plus any limited retention period set out in [Section 12](#return-deletion).

<h2 id="categories">5. Categories of Data Subjects and Personal Data</h2>

<h3 id="data-subjects">Categories of Data Subjects</h3>
Personal Data processed under this DPA may relate to:

- Respondents who submit Customer's Forms;
- Customer's Workspace owners and members;
- Customer's contacts, leads, or end users whose data Customer imports or routes through integrations;
- Any other Data Subjects whose data Customer chooses to process through the Service.

<h3 id="data-categories">Categories of Personal Data</h3>
Customer decides what Personal Data to collect. The categories typically include:

- **Identification data** — names, email addresses, phone numbers, postal addresses.
- **Form responses** — free-text answers, choices, ratings, file uploads, signatures, payment transaction references, and any other content Data Subjects enter.
- **Draft and partial responses** — submission drafts and partial responses saved server-side while a Data Subject is filling a Form, together with the timestamps used to power abandoned-response reminders where Customer has enabled that feature.
- **Profile and account data** — Workspace member emails, display names, role and permission settings.
- **Technical data** — timestamps, approximate country, device type, browser metadata, traffic source, and engagement duration captured as part of Submissions or analytics events; visitor identifiers stored client-side to deduplicate form view and engagement counts.
- **IP addresses and security logs** — IP addresses are processed transiently at the edge (Cloudflare) for rate limiting, bot protection through Cloudflare Turnstile, and abuse prevention. IP addresses are not persisted alongside Submission content in formbase's primary database. Short-lived security and abuse logs may retain IP addresses for the limited period needed to operate those defences.
- **Integration data** — identifiers, tokens, and payloads exchanged with third-party services that Customer connects.
- **AI input/output** — prompts, form structure, and Submission samples that Customer explicitly passes as context, plus the generated outputs, where Customer uses AI Features.

formbase is not designed for, and Customer must not submit, special categories of data under Article 9 GDPR, criminal-conviction data under Article 10 GDPR, government identifiers used for primary identity proofing, payment card data outside the Payment field, or other regulated data classes listed in [Section 6 of the Terms of Service](/legal/terms-of-service#acceptable-use), unless formbase has agreed otherwise in writing.

If formbase becomes aware that Customer has submitted prohibited data classes, formbase may notify Customer and delete the data. Customer is responsible as Controller for ensuring a valid legal basis for all Personal Data submitted to the Service.

<h2 id="customer-obligations">6. Customer Obligations</h2>
Customer is responsible for its role as Controller. In particular, Customer:

- Determines a lawful basis under Article 6 GDPR (and, where applicable, Article 9 GDPR) for each Processing activity carried out through the Service;
- Provides Data Subjects with all required notices, including a privacy notice covering Customer's use of formbase, and obtains any required consent;
- Respects Data Subject rights under Articles 15–22 GDPR for the Personal Data Customer processes;
- Sets up the Service appropriately, including retention rules, sharing settings, integrations, and access controls;
- Does not upload Personal Data the Service is not designed for, as set out in [Section 5](#categories) and [Section 6 of the Terms of Service](/legal/terms-of-service#acceptable-use);
- Keeps Workspace member access lists, API keys, OAuth credentials, and MCP tokens up to date and revokes them when no longer needed;
- Documents its own Processing activities under Article 30 GDPR and carries out data protection impact assessments where required under Article 35 GDPR.

Customer warrants that it has the right to give formbase the instructions set out in this DPA and that all Personal Data has been collected and shared with formbase lawfully.

<h2 id="formbase-obligations">7. formbase's Obligations</h2>

<h3 id="instructions">Documented instructions</h3>
formbase processes Personal Data only on Customer's documented instructions, including transfers of Personal Data outside the European
Economic Area, unless required to do otherwise by Union or Member State law. Customer's instructions are set out in this DPA, in the Terms
of Service, in the configuration of the Service, and in any further written instructions Customer may give from time to time.

formbase does not process Personal Data for its own marketing purposes, profiling, or any purpose beyond providing and securing the Service as instructed by Customer.

If formbase believes an instruction infringes Applicable Data Protection Law, it will inform Customer and not carry out the instruction.

<h3 id="confidentiality">Confidentiality</h3>
formbase ensures that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate
statutory obligation of confidentiality. Access to Personal Data is limited to personnel who need it to perform their duties.

<h3 id="security">Security measures</h3>
formbase implements appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction,
loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature,
scope, context, and purposes of Processing. The current measures are described in [Annex 2](#annex-2).

<h3 id="assistance">Assistance</h3>
Taking into account the nature of the Processing and the information available to it, formbase will assist Customer, by appropriate
technical and organisational measures, in fulfilling its obligations to:

- Respond to Data Subject requests under Articles 15–22 GDPR (see [Section 8](#data-subjects-rights));
- Maintain the security of Processing (Article 32 GDPR);
- Notify Personal Data breaches (Article 33 GDPR) — see [Section 11](#breach);
- Communicate breaches to Data Subjects where required (Article 34 GDPR);
- Carry out data protection impact assessments (Article 35 GDPR); and
- Consult with supervisory authorities where required (Article 36 GDPR).

Where this assistance materially exceeds what is available through standard product features, formbase may charge a reasonable fee, confirmed with Customer in writing (including by email) before work begins.

<h2 id="data-subjects-rights">8. Data Subject Rights</h2>
The Service is designed so that Customer can respond to most Data Subject requests directly, without formbase's involvement. Customer can:

- View, export, and delete Submissions from the Submissions area of any Form;
- Export Workspace data, including Forms and Submissions, in CSV or Excel (XLSX) — these structured, machine-readable formats also satisfy Article 20 GDPR data portability requests;
- Restrict or delete a Workspace member's access;
- Delete entire Forms, Workspaces, or the account, subject to the retention rules in the [Privacy Policy](/legal/privacy-policy).

formbase does not carry out automated decision-making or profiling on Customer's Personal Data within the meaning of Article 22 GDPR.

If a Data Subject contacts formbase directly with a request relating to Personal Data processed for Customer, formbase will redirect the Data Subject to Customer where possible and will not respond on Customer's behalf.

<h2 id="subprocessors">9. Subprocessors</h2>
Customer authorises formbase to engage the Subprocessors listed in [Annex 1](#annex-1) for the Processing of Personal Data. formbase will:

- Enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those set out in this DPA, including, where applicable, the SCCs;
- Remain fully liable to Customer for the performance of each Subprocessor's data protection obligations, in accordance with Article 28(4) GDPR.

formbase will give Customer reasonable advance notice before a new Subprocessor begins Processing Personal Data. Customer may object to a new Subprocessor on reasonable, documented data protection grounds by writing to <a href="mailto:support@formbase.so">support@formbase.so</a> within a reasonable period.

If formbase cannot reasonably accommodate Customer's objection, Customer may terminate the affected Processing.

<h2 id="international-transfers">10. International Transfers</h2>
formbase is established in Norway, which is part of the European Economic Area (EEA). No transfer safeguard is required for flows between
formbase and Customers located within the EEA. Several of formbase's Subprocessors are established in the United States or process Personal
Data on infrastructure located outside the EEA or the United Kingdom. For each such international transfer, formbase relies on one or more
of the following safeguards:

- An **adequacy decision** by the European Commission or a competent authority, where one exists for the destination country;
- The **Standard Contractual Clauses** adopted by the European Commission in [Decision (EU) 2021/914](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914) (as extended to the EEA by EEA Joint Committee Decision), incorporated by reference into this DPA, with the module that applies depending on the transfer in question (Module 2 — Controller to Processor — for Customer's transfer to formbase; Module 3 — Processor to Processor — for formbase's onward transfer to Subprocessors that act as processors). Where a Subprocessor (such as Polar or Stripe) collects billing or payment data **directly** from buyers or respondents as an independent controller, that collection is outside formbase's processor chain and the Subprocessor's own transfer mechanisms apply between the data subject and the Subprocessor;
- The **UK International Data Transfer Addendum** issued by the UK Information Commissioner (in force March 2022), where Personal Data is subject to the UK GDPR;
- The **Standard Contractual Clauses** as recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC), with the Swiss-specific adaptations set out in the FDPIC's guidance of 27 August 2021 (clarifying that references to "Member State" must not be interpreted to exclude Switzerland, designating the FDPIC as the competent supervisory authority, and extending the scope to cover personal data of legal entities), where Personal Data is subject to the Swiss Federal Act on Data Protection (nFADP);
- The **EU–US Data Privacy Framework** (DPF), its UK extension, and the **Swiss–US Data Privacy Framework**, where the specific US-based Subprocessor is self-certified under the applicable framework (formbase falls back to SCCs where certification is absent or lapses); and
- **Supplementary technical and organisational measures** as described in [Annex 2](#annex-2).

Where formbase relies on SCCs for a transfer to a country without an adequacy decision, formbase considers the legal framework in the destination country and applies the supplementary measures in [Annex 2](#annex-2) to address identified risks.

Where SCCs are the applicable transfer safeguard, by accepting this DPA Customer is deemed to have signed the SCCs as the data exporter and formbase signs them as the data importer. For the purposes of Annex I to the SCCs: (a) the parties are identified in [Section 1](#parties) of this DPA; (b) the description of the transfer — categories of data subjects, categories of personal data, frequency of transfer, nature and purpose of processing, and retention period — is set out in [Sections 4](#subject-matter) and [5](#categories) of this DPA; and (c) the competent supervisory authority is the Norwegian Data Protection Authority (Datatilsynet). This DPA thereby satisfies the Annex I requirements of the SCCs. The SCCs apply only to transfers that require them. In the event of a conflict between this DPA and the SCCs, the SCCs prevail to the extent of the conflict.

<h2 id="breach">11. Personal Data Breaches</h2>
formbase will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The
notification will include, to the extent known at the time, the nature and scope of the breach, the likely consequences, and the measures
formbase has taken or proposes to take.

Where complete information is not available at the time of the initial notification, formbase will provide it in stages without undue delay. Customer is responsible for keeping its contact details up to date and for notifying its own Data Subjects and supervisory authorities where required.

Notifying Customer is not, by itself, an admission by formbase of fault or liability for any breach.

<h2 id="return-deletion">12. Return and Deletion of Data</h2>
Customer can export Forms and Submissions in standard formats at any time while its account is active, as described in the [Terms of
Service](/legal/terms-of-service).

On termination of the Service or written request by Customer, formbase will delete all Personal Data Processed on Customer's behalf, unless Union law, Member State law, or applicable Norwegian law requires further storage. Customer is responsible for exporting any data it wishes to keep before closing the account, using the in-product tools described in [Section 8](#data-subjects-rights). Specifically:

- When a Form or Workspace is deleted from the Service, the underlying records are removed from active systems and become unreachable through the application;
- When a Customer account is closed, the account's Personal Data is removed from active systems. Customer is responsible for exporting any data it wishes to keep before closing the account;
- Personal Data is removed from backups when the corresponding backup window expires. File uploads stored in Cloudflare R2 are not covered by object versioning; deletions of file uploads are unrecoverable immediately;
- Draft and partial responses are retained for a limited period (or until the Data Subject completes the Submission), after which they are automatically purged from active systems;
- Personal Data that formbase is required to retain by law — such as billing records or records relating to a legal claim — will be archived in restricted-access systems for the period required by law.

<h2 id="audits">13. Audits</h2>
formbase will make available to Customer all information reasonably necessary to demonstrate compliance with its obligations under Article
28 GDPR and this DPA, where Customer has justifiable grounds — such as a confirmed Personal Data Breach, a material breach of this DPA, or a
request from a supervisory authority. By default, this information takes the form of:

- This DPA and the [Privacy Policy](/legal/privacy-policy) in formbase's documentation;
- The list of Subprocessors in [Annex 1](#annex-1) and the technical and organisational measures described in [Annex 2](#annex-2);
- Written responses to reasonable, specific questions sent to <a href="mailto:support@formbase.so">support@formbase.so</a>.

Where a supervisory authority requires an on-site inspection, formbase will cooperate to the extent required by law.

<h2 id="liability">14. Liability</h2>
The liability of each party under this DPA is subject to the limitations and exclusions set out in [Section 25 (Limitation of
Liability)](/legal/terms-of-service#limitation-of-liability) of the Terms of Service. The aggregate liability of formbase under or in
connection with this DPA forms part of, and is not in addition to, the overall liability cap set out in the Terms of Service.

Notwithstanding the foregoing financial cap, nothing in this DPA limits any liability that cannot be limited under mandatory Applicable Data Protection Law, including liability towards a Data Subject under Article 82 GDPR. The Article 82 carve-out operates regardless of the aggregate cap in the Terms of Service.

formbase is not liable under Article 82 GDPR to the extent it demonstrates it is not in any way responsible for the event giving rise to the damage, in accordance with Article 82(3) GDPR.

<h2 id="term">15. Term and Termination</h2>
This DPA enters into force when Customer first submits Personal Data to the Service, and no later than the date Customer accepts the Terms
of Service. It remains in effect for as long as formbase processes Personal Data on Customer's behalf.

This DPA terminates when the Terms of Service terminate, provided that it continues in force until formbase has completed the return or deletion of all Personal Data pursuant to [Section 12](#return-deletion). The provisions of [Sections 5 (Categories)](#categories), [7 (formbase's Obligations)](#formbase-obligations) (including the confidentiality obligations therein), [9 (Subprocessors)](#subprocessors), [11 (Breach)](#breach), [12 (Return and Deletion)](#return-deletion), [13 (Audits)](#audits), [14 (Liability)](#liability), and [16 (Governing Law)](#governing-law) survive termination to the extent necessary to give effect to them.

<h2 id="governing-law">16. Governing Law and Jurisdiction</h2>
This DPA is governed by the laws of Norway, without regard to its conflict of laws principles. Any dispute arising out of or in connection
with this DPA is subject to the same dispute resolution and jurisdiction terms as the Terms of Service, except where Applicable Data
Protection Law mandates a different forum.

Where the SCCs apply, the governing law and forum specified in the SCCs prevail to the extent of any conflict.

<h2 id="updates">17. Updates to This DPA</h2>
formbase may update this DPA from time to time to reflect changes in the Service, in Applicable Data Protection Law, or in the supervisory
authorities' guidance.

- **Non-material changes** (formatting, clarifications that do not alter obligations, updates to Annex 1 that follow the [Section 9](#subprocessors) notice process) take effect upon publication.
- **Material changes** (any change that alters the scope of Processing, reduces the level of protection afforded to Personal Data, or modifies the parties' obligations) take effect after reasonable advance notice. Continued use of the Service after the notice period constitutes acceptance.

<h2 id="contact">18. Contact</h2>
For any matter relating to this DPA, including data subject requests that cannot be handled through the Service, subprocessor objections,
audit requests, or breach notifications, contact us at:

- **DPA enquiries, data subject requests, and security reports** — <a href="mailto:support@formbase.so">support@formbase.so</a>

formbase has not appointed a Data Protection Officer. Under Article 37 GDPR, a DPO is required for public authorities and bodies (excluding courts), or where core activities consist of large-scale, regular, and systematic monitoring of individuals, or large-scale processing of special categories of data (Article 9) or criminal-conviction data (Article 10); formbase's core activities do not meet any of these thresholds. All DPA-related matters are handled through the contact point above.

<h2 id="annex-1">Annex 1 — Subprocessors</h2>
formbase engages the following parties in connection with the Service. Convex, Cloudflare R2, Cloudflare, Amazon Web Services (AWS), Axiom,
and Unsplash act as data processors under formbase's instruction and are true subprocessors for purposes of Article 28 GDPR. Polar and
Stripe are listed here for transparency, but they act as **independent controllers** for the data they collect directly from buyers and
respondents respectively; formbase's Article 28 obligations do not apply to the data those parties control, and their own transfer
mechanisms govern where applicable. Google provides optional OAuth sign-in: users authenticate directly with Google, which acts as an
independent controller for the Google account; formbase receives only the basic sign-in profile (name, email, profile picture). PostHog is
listed for transparency: formbase uses it for analytics on its own website and account sign-ups, as controller of that data, and it receives
no Customer Personal Data.

**Customer-directed integrations.** When Customer enables an integration (Notion, Airtable, Google Sheets, Slack, Discord, Linear, GitHub, webhooks, etc.), formbase transmits data to that service on Customer's documented instruction. The third-party service is not a formbase Subprocessor; Customer is responsible as Controller for ensuring a lawful basis, appropriate data processing agreements, and transfer mechanisms with each service it connects.

If formbase engages a new Subprocessor or adds a new LLM provider, [Annex 1](#annex-1) will be updated in accordance with [Section 9](#subprocessors). The contractual obligations formbase imposes on each Subprocessor are set out in [Section 9](#subprocessors).

<h2 id="annex-2">Annex 2 — Technical and Organisational Measures</h2>
formbase implements the following technical and organisational measures to protect Personal Data, taking into account the state of the art,
the cost of implementation, and the nature of the Processing. Specific measures may evolve over time, provided that the overall level of
protection is not reduced.

<h3 id="access-control">Access control</h3>

- Role-based access controls within the Service, with workspace-level permissions for owners and members;
- Passwordless authentication using magic-link email or Google OAuth sign-in (Customer-managed multi-factor authentication is available on the Google account used for sign-in), with rate limiting on the login endpoints; anonymous guest sessions (created when a user tries the Service without registering) are purged automatically within a short period;
- Internal access to production systems restricted on a need-to-know basis.

<h3 id="encryption">Encryption</h3>

- TLS 1.2 or higher for all data in transit between Data Subjects, Customers, the Service, and Subprocessors;
- Encryption at rest for the primary database, file storage, and backups, using industry-standard ciphers managed by Convex and the underlying cloud provider;
- Secrets and API keys stored in encrypted secret stores; passwords are not stored — the Service uses passwordless authentication.

<h3 id="logical-isolation">Logical isolation</h3>

- Multi-tenant architecture with row-level access scoping by Workspace and Customer;
- Logical separation between development, staging, and production environments; production data is not used in non-production environments;
- Subprocessor integrations are scoped to the minimum data required to perform their function.

<h3 id="resilience">Resilience and backups</h3>

- Automated, encrypted daily backups of the primary database (delegated to Convex under its infrastructure service terms); file uploads in Cloudflare R2 are not covered by object versioning;
- Use of cloud providers with redundant infrastructure and DDoS protection.

<h3 id="vulnerability">Vulnerability management</h3>

- Security updates for application dependencies applied as appropriate.

<h3 id="organisational">Organisational measures</h3>

- Access to production systems is limited to authorised personnel;
- Breach notification procedures aligned with [Section 11](#breach);
- Maintenance of records of processing activities in accordance with Article 30(2) GDPR, made available to supervisory authorities on request as required by Article 30(4) GDPR.

<h3 id="supplementary-transfer-measures">Supplementary measures for international transfers (Schrems II)</h3>

In addition to the general security measures above, formbase applies the following supplementary measures for transfers to countries without an adequacy decision, in line with EDPB Recommendations 01/2020:

- Encryption in transit (TLS 1.2+) and at rest as described in the [Encryption](#encryption) section; encryption keys are managed by the cloud provider's key management service and are not accessible to third-country government authorities without a lawful order.

<h3 id="data-minimisation">Data minimisation and retention</h3>

- The Service collects only the data Customer chooses to collect through Forms and the operational data needed to run the Service. Retention and deletion rules are set out in [Section 12](#return-deletion);
- Aggregation is applied to product analytics where the underlying identifiers are not needed for the purpose;
- AI inputs and outputs sent to Amazon Bedrock are processed under the [AWS Service Terms](https://aws.amazon.com/service-terms/) and are not stored by AWS after processing.

<h2 id="related">Related documents</h2>

<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Privacy Policy](/legal/privacy-policy) — How we collect, use, and share personal data.
  - [Terms of Service](/legal/terms-of-service) — The rules that govern your use of formbase.
  - [Legal overview](/legal/overview) — Index of formbase legal documents.
</div>
