formbasedocs
Go to appApp

Legal

Data Processing Agreement

The terms under which formbase processes personal data on behalf of customers subject to the GDPR and equivalent data protection laws.


Last updated: 7 October 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Customer”) and formbase (the “Processor”). It applies automatically whenever you use formbase to collect, store, or otherwise process personal data of identifiable individuals subject to the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR, the Norwegian Personal Data Act (personopplysningsloven), or another applicable data protection law that requires a written processing agreement.

No signature is required. Your use of formbase to process personal data constitutes acceptance of this DPA.

1. Parties

This DPA is entered into between:

  • Customer — the natural or legal person who has accepted the formbase Terms of Service and on whose behalf personal data is processed (acting as the “Controller”).
  • formbase — Formbase AS, a Norwegian limited company with organisation number 937 921 217 and registered office in Oslo, Norway (acting as the “Processor”).

Where the GDPR or another applicable law refers to the parties as “controller” and “processor”, or “data exporter” and “data importer”, those terms map to Customer and formbase respectively for the purposes of this DPA.

2. Definitions

Terms used in this DPA but not defined here have the meanings given in the Terms of Service or in the GDPR. In particular:

  • Service — the formbase platform, including the form editor, published forms, submission management, integrations, AI Features, APIs, and all related functionality provided under the Terms of Service.
  • Form — an online form, survey, quiz, or other data-collection page created and published by Customer through the Service.
  • Submission — a completed or partial response submitted by a Data Subject through a Form, including all field values, file uploads, metadata, and associated timestamps.
  • Workspace — the organisational unit within the Service under which Customer manages Forms, Submissions, members, and integrations.
  • AI Features — the AI-powered capabilities of the Service, including AI form generation, AI chat, and any other feature that sends data to a third-party AI model for inference.
  • Personal Data — any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR, that Customer processes through the Service.
  • Processing — any operation performed on Personal Data, as defined in Article 4(2) GDPR.
  • Data Subject — the identifiable individual to whom Personal Data relates, including respondents who submit Forms, members of a Workspace, and Customer’s own end users.
  • Subprocessor — any third party engaged by formbase to process Personal Data on its behalf in connection with the Service.
  • Standard Contractual Clauses or SCCs — the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914, including the UK International Data Transfer Addendum where relevant.
  • Applicable Data Protection Law — the GDPR, the UK GDPR, the Norwegian Personal Data Act, and any other privacy or data protection law that applies to Customer’s processing of Personal Data through the Service.

3. Scope and Roles

This DPA governs formbase’s Processing of Personal Data on behalf of Customer through the Service. For that Processing:

  • Customer is the Controller. Customer determines the purposes and means of the Processing, decides what Personal Data to collect through Forms, configures retention and sharing settings, and connects integrations.
  • formbase is the Processor. formbase processes Personal Data on Customer’s documented instructions, primarily to operate the Service, deliver the features Customer has enabled, and meet its security and support obligations.

For Personal Data that formbase collects directly about Customer as a formbase user — such as account details, subscription metadata received from Polar, and product usage telemetry — formbase acts as an independent Controller. That Processing is governed by the Privacy Policy, not by this DPA. Payment and buyer billing data is controlled by Polar, which acts as an independent controller as Merchant of Record.

For respondent payments processed through Stripe Connect, Customer is the merchant of record and Controller of the payment-related Personal Data; Stripe acts as an independent controller for payment processing. See Annex 1 for details.

4. Subject Matter, Nature, Purpose and Duration

formbase processes Personal Data only as needed to provide the Service to Customer under the Terms of Service.

  • Subject matter — the hosting and operation of online forms, the collection and storage of Submissions, and the provision of related features such as analytics, integrations, AI Features, notifications, and exports.
  • Nature — collection, storage, and all technical operations required to run the Service.
  • Purpose — to enable Customer to build and publish Forms, collect responses from Data Subjects, manage Submissions, and connect to third-party tools, all in accordance with Customer’s configuration and instructions. Customer’s instructions may be given through the web application, the API, MCP (Model Context Protocol) connections, or other programmatic interfaces made available as part of the Service.
  • Duration — for as long as Customer’s account is active and Personal Data is stored in the Service, plus any limited retention period set out in Section 12.

5. Categories of Data Subjects and Personal Data

Categories of Data Subjects

Personal Data processed under this DPA may relate to:

  • Respondents who submit Customer’s Forms;
  • Customer’s Workspace owners and members;
  • Customer’s contacts, leads, or end users whose data Customer imports or routes through integrations;
  • Any other Data Subjects whose data Customer chooses to process through the Service.

Categories of Personal Data

Customer decides what Personal Data to collect. The categories typically include:

  • Identification data — names, email addresses, phone numbers, postal addresses.
  • Form responses — free-text answers, choices, ratings, file uploads, signatures, payment transaction references, and any other content Data Subjects enter.
  • Draft and partial responses — submission drafts and partial responses saved server-side while a Data Subject is filling a Form, together with the timestamps used to power abandoned-response reminders where Customer has enabled that feature.
  • Profile and account data — Workspace member emails, display names, role and permission settings.
  • Technical data — timestamps, approximate country, device type, browser metadata, traffic source, and engagement duration captured as part of Submissions or analytics events; visitor identifiers stored client-side to deduplicate form view and engagement counts.
  • IP addresses and security logs — IP addresses are processed transiently at the edge (Cloudflare) for rate limiting, bot protection through Cloudflare Turnstile, and abuse prevention. IP addresses are not persisted alongside Submission content in formbase’s primary database. Short-lived security and abuse logs may retain IP addresses for the limited period needed to operate those defences.
  • Integration data — identifiers, tokens, and payloads exchanged with third-party services that Customer connects.
  • AI input/output — prompts, form structure, and Submission samples that Customer explicitly passes as context, plus the generated outputs, where Customer uses AI Features.

formbase is not designed for, and Customer must not submit, special categories of data under Article 9 GDPR, criminal-conviction data under Article 10 GDPR, government identifiers used for primary identity proofing, payment card data outside the Payment field, or other regulated data classes listed in Section 6 of the Terms of Service, unless formbase has agreed otherwise in writing.

If formbase becomes aware that Customer has submitted prohibited data classes, formbase may notify Customer and delete the data. Customer is responsible as Controller for ensuring a valid legal basis for all Personal Data submitted to the Service.

6. Customer Obligations

Customer is responsible for its role as Controller. In particular, Customer:

  • Determines a lawful basis under Article 6 GDPR (and, where applicable, Article 9 GDPR) for each Processing activity carried out through the Service;
  • Provides Data Subjects with all required notices, including a privacy notice covering Customer’s use of formbase, and obtains any required consent;
  • Respects Data Subject rights under Articles 15–22 GDPR for the Personal Data Customer processes;
  • Sets up the Service appropriately, including retention rules, sharing settings, integrations, and access controls;
  • Does not upload Personal Data the Service is not designed for, as set out in Section 5 and Section 6 of the Terms of Service;
  • Keeps Workspace member access lists, API keys, OAuth credentials, and MCP tokens up to date and revokes them when no longer needed;
  • Documents its own Processing activities under Article 30 GDPR and carries out data protection impact assessments where required under Article 35 GDPR.

Customer warrants that it has the right to give formbase the instructions set out in this DPA and that all Personal Data has been collected and shared with formbase lawfully.

7. formbase’s Obligations

Documented instructions

formbase processes Personal Data only on Customer’s documented instructions, including transfers of Personal Data outside the European Economic Area, unless required to do otherwise by Union or Member State law. Customer’s instructions are set out in this DPA, in the Terms of Service, in the configuration of the Service, and in any further written instructions Customer may give from time to time.

formbase does not process Personal Data for its own marketing purposes, profiling, or any purpose beyond providing and securing the Service as instructed by Customer.

If formbase believes an instruction infringes Applicable Data Protection Law, it will inform Customer and not carry out the instruction.

Confidentiality

formbase ensures that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Personal Data is limited to personnel who need it to perform their duties.

Security measures

formbase implements appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing. The current measures are described in Annex 2.

Assistance

Taking into account the nature of the Processing and the information available to it, formbase will assist Customer, by appropriate technical and organisational measures, in fulfilling its obligations to:

  • Respond to Data Subject requests under Articles 15–22 GDPR (see Section 8);
  • Maintain the security of Processing (Article 32 GDPR);
  • Notify Personal Data breaches (Article 33 GDPR) — see Section 11;
  • Communicate breaches to Data Subjects where required (Article 34 GDPR);
  • Carry out data protection impact assessments (Article 35 GDPR); and
  • Consult with supervisory authorities where required (Article 36 GDPR).

Where this assistance materially exceeds what is available through standard product features, formbase may charge a reasonable fee, confirmed with Customer in writing (including by email) before work begins.

8. Data Subject Rights

The Service is designed so that Customer can respond to most Data Subject requests directly, without formbase’s involvement. Customer can:

  • View, export, and delete Submissions from the Submissions area of any Form;
  • Export Workspace data, including Forms and Submissions, in CSV or Excel (XLSX) — these structured, machine-readable formats also satisfy Article 20 GDPR data portability requests;
  • Restrict or delete a Workspace member’s access;
  • Delete entire Forms, Workspaces, or the account, subject to the retention rules in the Privacy Policy.

formbase does not carry out automated decision-making or profiling on Customer’s Personal Data within the meaning of Article 22 GDPR.

If a Data Subject contacts formbase directly with a request relating to Personal Data processed for Customer, formbase will redirect the Data Subject to Customer where possible and will not respond on Customer’s behalf.

9. Subprocessors

Customer authorises formbase to engage the Subprocessors listed in Annex 1 for the Processing of Personal Data. formbase will:

  • Enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those set out in this DPA, including, where applicable, the SCCs;
  • Remain fully liable to Customer for the performance of each Subprocessor’s data protection obligations, in accordance with Article 28(4) GDPR.

formbase will give Customer reasonable advance notice before a new Subprocessor begins Processing Personal Data. Customer may object to a new Subprocessor on reasonable, documented data protection grounds by writing to support@formbase.so within a reasonable period.

If formbase cannot reasonably accommodate Customer’s objection, Customer may terminate the affected Processing.

10. International Transfers

formbase is established in Norway, which is part of the European Economic Area (EEA). No transfer safeguard is required for flows between formbase and Customers located within the EEA. Several of formbase’s Subprocessors are established in the United States or process Personal Data on infrastructure located outside the EEA or the United Kingdom. For each such international transfer, formbase relies on one or more of the following safeguards:

  • An adequacy decision by the European Commission or a competent authority, where one exists for the destination country;
  • The Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 (as extended to the EEA by EEA Joint Committee Decision), incorporated by reference into this DPA, with the module that applies depending on the transfer in question (Module 2 — Controller to Processor — for Customer’s transfer to formbase; Module 3 — Processor to Processor — for formbase’s onward transfer to Subprocessors that act as processors). Where a Subprocessor (such as Polar or Stripe) collects billing or payment data directly from buyers or respondents as an independent controller, that collection is outside formbase’s processor chain and the Subprocessor’s own transfer mechanisms apply between the data subject and the Subprocessor;
  • The UK International Data Transfer Addendum issued by the UK Information Commissioner (in force March 2022), where Personal Data is subject to the UK GDPR;
  • The Standard Contractual Clauses as recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC), with the Swiss-specific adaptations set out in the FDPIC’s guidance of 27 August 2021 (clarifying that references to “Member State” must not be interpreted to exclude Switzerland, designating the FDPIC as the competent supervisory authority, and extending the scope to cover personal data of legal entities), where Personal Data is subject to the Swiss Federal Act on Data Protection (nFADP);
  • The EU–US Data Privacy Framework (DPF), its UK extension, and the Swiss–US Data Privacy Framework, where the specific US-based Subprocessor is self-certified under the applicable framework (formbase falls back to SCCs where certification is absent or lapses); and
  • Supplementary technical and organisational measures as described in Annex 2.

Where formbase relies on SCCs for a transfer to a country without an adequacy decision, formbase considers the legal framework in the destination country and applies the supplementary measures in Annex 2 to address identified risks.

Where SCCs are the applicable transfer safeguard, by accepting this DPA Customer is deemed to have signed the SCCs as the data exporter and formbase signs them as the data importer. For the purposes of Annex I to the SCCs: (a) the parties are identified in Section 1 of this DPA; (b) the description of the transfer — categories of data subjects, categories of personal data, frequency of transfer, nature and purpose of processing, and retention period — is set out in Sections 4 and 5 of this DPA; and (c) the competent supervisory authority is the Norwegian Data Protection Authority (Datatilsynet). This DPA thereby satisfies the Annex I requirements of the SCCs. The SCCs apply only to transfers that require them. In the event of a conflict between this DPA and the SCCs, the SCCs prevail to the extent of the conflict.

11. Personal Data Breaches

formbase will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer’s Personal Data. The notification will include, to the extent known at the time, the nature and scope of the breach, the likely consequences, and the measures formbase has taken or proposes to take.

Where complete information is not available at the time of the initial notification, formbase will provide it in stages without undue delay. Customer is responsible for keeping its contact details up to date and for notifying its own Data Subjects and supervisory authorities where required.

Notifying Customer is not, by itself, an admission by formbase of fault or liability for any breach.

12. Return and Deletion of Data

Customer can export Forms and Submissions in standard formats at any time while its account is active, as described in the Terms of Service.

On termination of the Service or written request by Customer, formbase will delete all Personal Data Processed on Customer’s behalf, unless Union law, Member State law, or applicable Norwegian law requires further storage. Customer is responsible for exporting any data it wishes to keep before closing the account, using the in-product tools described in Section 8. Specifically:

  • When a Form or Workspace is deleted from the Service, the underlying records are removed from active systems and become unreachable through the application;
  • When a Customer account is closed, the account’s Personal Data is removed from active systems. Customer is responsible for exporting any data it wishes to keep before closing the account;
  • Personal Data is removed from backups when the corresponding backup window expires. File uploads stored in Cloudflare R2 are not covered by object versioning; deletions of file uploads are unrecoverable immediately;
  • Draft and partial responses are retained for a limited period (or until the Data Subject completes the Submission), after which they are automatically purged from active systems;
  • Personal Data that formbase is required to retain by law — such as billing records or records relating to a legal claim — will be archived in restricted-access systems for the period required by law.

13. Audits

formbase will make available to Customer all information reasonably necessary to demonstrate compliance with its obligations under Article 28 GDPR and this DPA, where Customer has justifiable grounds — such as a confirmed Personal Data Breach, a material breach of this DPA, or a request from a supervisory authority. By default, this information takes the form of:

  • This DPA and the Privacy Policy in formbase’s documentation;
  • The list of Subprocessors in Annex 1 and the technical and organisational measures described in Annex 2;
  • Written responses to reasonable, specific questions sent to support@formbase.so.

Where a supervisory authority requires an on-site inspection, formbase will cooperate to the extent required by law.

14. Liability

The liability of each party under this DPA is subject to the limitations and exclusions set out in Section 25 (Limitation of Liability) of the Terms of Service. The aggregate liability of formbase under or in connection with this DPA forms part of, and is not in addition to, the overall liability cap set out in the Terms of Service.

Notwithstanding the foregoing financial cap, nothing in this DPA limits any liability that cannot be limited under mandatory Applicable Data Protection Law, including liability towards a Data Subject under Article 82 GDPR. The Article 82 carve-out operates regardless of the aggregate cap in the Terms of Service.

formbase is not liable under Article 82 GDPR to the extent it demonstrates it is not in any way responsible for the event giving rise to the damage, in accordance with Article 82(3) GDPR.

15. Term and Termination

This DPA enters into force when Customer first submits Personal Data to the Service, and no later than the date Customer accepts the Terms of Service. It remains in effect for as long as formbase processes Personal Data on Customer’s behalf.

This DPA terminates when the Terms of Service terminate, provided that it continues in force until formbase has completed the return or deletion of all Personal Data pursuant to Section 12. The provisions of Sections 5 (Categories), 7 (formbase’s Obligations) (including the confidentiality obligations therein), 9 (Subprocessors), 11 (Breach), 12 (Return and Deletion), 13 (Audits), 14 (Liability), and 16 (Governing Law) survive termination to the extent necessary to give effect to them.

16. Governing Law and Jurisdiction

This DPA is governed by the laws of Norway, without regard to its conflict of laws principles. Any dispute arising out of or in connection with this DPA is subject to the same dispute resolution and jurisdiction terms as the Terms of Service, except where Applicable Data Protection Law mandates a different forum.

Where the SCCs apply, the governing law and forum specified in the SCCs prevail to the extent of any conflict.

17. Updates to This DPA

formbase may update this DPA from time to time to reflect changes in the Service, in Applicable Data Protection Law, or in the supervisory authorities’ guidance.

  • Non-material changes (formatting, clarifications that do not alter obligations, updates to Annex 1 that follow the Section 9 notice process) take effect upon publication.
  • Material changes (any change that alters the scope of Processing, reduces the level of protection afforded to Personal Data, or modifies the parties’ obligations) take effect after reasonable advance notice. Continued use of the Service after the notice period constitutes acceptance.

18. Contact

For any matter relating to this DPA, including data subject requests that cannot be handled through the Service, subprocessor objections, audit requests, or breach notifications, contact us at:

formbase has not appointed a Data Protection Officer. Under Article 37 GDPR, a DPO is required for public authorities and bodies (excluding courts), or where core activities consist of large-scale, regular, and systematic monitoring of individuals, or large-scale processing of special categories of data (Article 9) or criminal-conviction data (Article 10); formbase’s core activities do not meet any of these thresholds. All DPA-related matters are handled through the contact point above.

Annex 1 — Subprocessors

formbase engages the following parties in connection with the Service. Convex, Cloudflare R2, Cloudflare, Amazon Web Services (AWS), Axiom, and Unsplash act as data processors under formbase’s instruction and are true subprocessors for purposes of Article 28 GDPR. Polar and Stripe are listed here for transparency, but they act as independent controllers for the data they collect directly from buyers and respondents respectively; formbase’s Article 28 obligations do not apply to the data those parties control, and their own transfer mechanisms govern where applicable. Google provides optional OAuth sign-in: users authenticate directly with Google, which acts as an independent controller for the Google account; formbase receives only the basic sign-in profile (name, email, profile picture). PostHog is listed for transparency: formbase uses it for analytics on its own website and account sign-ups, as controller of that data, and it receives no Customer Personal Data.

SubprocessorPurposeRegion
ConvexApplication database and backend infrastructure (hosted on AWS in the eu-west-1 region in Ireland; AWS acts as Convex's infrastructure sub-processor). Convex, Inc. is established in the United States.European Union (AWS eu-west-1, Ireland)
Cloudflare R2Object storage for file uploads and signatures. Transfer mechanism: Module 3 SCCs under Cloudflare's Data Processing Addendum, supplemented by the measures in Annex 2.Europe (Cloudflare location hint: Eastern Europe). A location hint is best effort and not a jurisdictional restriction.
CloudflareCDN, DNS, edge security, custom hostnames for hosted forms, Turnstile bot protection. Processes IP addresses transiently for bot protection and abuse prevention.Global
PolarSubscription billing and AI credit purchases. Acts as Merchant of Record and as an independent controller for the buyer billing data it collects.United States
StripeRespondent payment processing via Stripe Connect (when Payment fields are used). Acts as an independent controller for payment processing. Customer, as the merchant of record for respondent payments, is responsible for ensuring an appropriate transfer mechanism between Customer and Stripe.Global; region depends on Stripe's processing for the connected account
Amazon Web Services (AWS)Amazon Bedrock for AI inference behind AI Features (form building, AI chat). Processing governed by the AWS Service Terms; AWS does not store inputs or outputs after processing and does not use them to train any models.European Union (Amazon Bedrock cross-region inference within the EU)
Amazon Web Services (AWS) — Amazon SESDelivery of all transactional and system email: submission notifications, respondent confirmation and notification emails, magic-link logins, abandoned-response reminder emails, and other account emails. Custom sending domains are verified as SES domain identities (DKIM). Processing governed by the AWS Data Processing Addendum (SCCs incorporated).Same AWS region as formbase's AI inference (see the Amazon Web Services entry above)
AxiomOperational logging and monitoring of the Service. Logs can contain account and record identifiers and the email addresses of email recipients, including respondents. Logs are kept for 30 days. Axiom, Inc. is established in the United States.European Union (AWS eu-central-1, Frankfurt)
PostHogAnalytics for formbase's own website and account sign-ups, including session replays of website visits. Receives formbase account identifiers and website visit data; no Customer Personal Data. PostHog, Inc. is established in the United States.European Union (PostHog EU Cloud, AWS eu-central-1, Frankfurt)
UnsplashImage search API used server-side to find and retrieve form cover images. Selected images are fetched by formbase at publish time and stored in Cloudflare R2; respondents load images from R2, not directly from Unsplash. Only image URLs and search queries are sent to Unsplash — no Customer Personal Data is transmitted. Transfer mechanism: SCCs under Unsplash's API terms.United States / Global

Customer-directed integrations. When Customer enables an integration (Notion, Airtable, Google Sheets, Slack, Discord, Linear, GitHub, webhooks, etc.), formbase transmits data to that service on Customer’s documented instruction. The third-party service is not a formbase Subprocessor; Customer is responsible as Controller for ensuring a lawful basis, appropriate data processing agreements, and transfer mechanisms with each service it connects.

If formbase engages a new Subprocessor or adds a new LLM provider, Annex 1 will be updated in accordance with Section 9. The contractual obligations formbase imposes on each Subprocessor are set out in Section 9.

Annex 2 — Technical and Organisational Measures

formbase implements the following technical and organisational measures to protect Personal Data, taking into account the state of the art, the cost of implementation, and the nature of the Processing. Specific measures may evolve over time, provided that the overall level of protection is not reduced.

Access control

  • Role-based access controls within the Service, with workspace-level permissions for owners and members;
  • Passwordless authentication using magic-link email or Google OAuth sign-in (Customer-managed multi-factor authentication is available on the Google account used for sign-in), with rate limiting on the login endpoints; anonymous guest sessions (created when a user tries the Service without registering) are purged automatically within a short period;
  • Internal access to production systems restricted on a need-to-know basis.

Encryption

  • TLS 1.2 or higher for all data in transit between Data Subjects, Customers, the Service, and Subprocessors;
  • Encryption at rest for the primary database, file storage, and backups, using industry-standard ciphers managed by Convex and the underlying cloud provider;
  • Secrets and API keys stored in encrypted secret stores; passwords are not stored — the Service uses passwordless authentication.

Logical isolation

  • Multi-tenant architecture with row-level access scoping by Workspace and Customer;
  • Logical separation between development, staging, and production environments; production data is not used in non-production environments;
  • Subprocessor integrations are scoped to the minimum data required to perform their function.

Resilience and backups

  • Automated, encrypted daily backups of the primary database (delegated to Convex under its infrastructure service terms); file uploads in Cloudflare R2 are not covered by object versioning;
  • Use of cloud providers with redundant infrastructure and DDoS protection.

Vulnerability management

  • Security updates for application dependencies applied as appropriate.

Organisational measures

  • Access to production systems is limited to authorised personnel;
  • Breach notification procedures aligned with Section 11;
  • Maintenance of records of processing activities in accordance with Article 30(2) GDPR, made available to supervisory authorities on request as required by Article 30(4) GDPR.

Supplementary measures for international transfers (Schrems II)

In addition to the general security measures above, formbase applies the following supplementary measures for transfers to countries without an adequacy decision, in line with EDPB Recommendations 01/2020:

  • Encryption in transit (TLS 1.2+) and at rest as described in the Encryption section; encryption keys are managed by the cloud provider’s key management service and are not accessible to third-country government authorities without a lawful order.

Data minimisation and retention

  • The Service collects only the data Customer chooses to collect through Forms and the operational data needed to run the Service. Retention and deletion rules are set out in Section 12;
  • Aggregation is applied to product analytics where the underlying identifiers are not needed for the purpose;
  • AI inputs and outputs sent to Amazon Bedrock are processed under the AWS Service Terms and are not stored by AWS after processing.