Data Processing Addendum (DPA)

Last updated: November 5, 2025

1. Purpose

This Data Processing Addendum ("Addendum") supplements the Terms of Service and governs the processing of personal data by FormsBee on behalf of customers who use the FormsBee platform to collect and manage personal data (for example, email waitlists and form submissions).

2. Roles

Customer (Controller): the account owner who determines the purposes and means of processing personal data collected via FormsBee forms.
FormsBee (Processor): processes personal data on behalf of the Customer and only in accordance with Customer instructions and this Addendum.

3. Types of Personal Data Processed

Personal data processed may include (depending on Customer configuration):

  • Form submission fields (e.g., email addresses, names, optional text fields).
  • Account information (Customer account owner name, email, hashed password, account metadata).
  • Technical metadata (IP address, user agent, timestamps) for security and logging.
  • Support communications and associated logs provided to FormsBee support.

4. Hosting & Storage

Customer data is stored in MySQL databases hosted on third-party shared hosting infrastructure managed via cPanel (Namecheap or equivalent hosting provider). The exact physical location of the servers depends on the hosting provider configuration and may include multiple regions.

Important: as infrastructure is shared, FormsBee relies on the hosting provider for infrastructure-level security, network protection, and physical access controls. FormsBee is responsible for application-layer protections and database access controls configured by FormsBee.

5. Security Measures

FormsBee implements reasonable technical and organizational measures to protect personal data, including:

  • Encrypted transport (HTTPS/TLS) for all network communications.
  • Secure password storage (modern hashing algorithms such as bcrypt or equivalent).
  • Database access restricted by credentials and limited privileges.
  • Periodic backups (managed as per hosting provider capability) and regular monitoring.
  • Access controls and least privilege for operational staff.

While FormsBee takes reasonable precautions, Customers acknowledge that shared hosting entails limits at the infrastructure layer and that certain responsibilities remain with the hosting provider.

6. Sub-Processors

FormsBee may engage sub-processors to provide hosting, email delivery, analytics, or other services. Current known sub-processor(s):

  • Namecheap — hosting infrastructure and control panel (cPanel) used for MySQL database hosting and server management.

FormsBee requires sub-processors to implement appropriate safeguards and process personal data only on FormsBee’s instructions. Customers will be notified of any material additions or replacements of sub-processors.

7. Customer Responsibilities

Customers are responsible for:

  • Maintaining lawful bases for any personal data they collect (consent, contract, legitimate interest, etc.).
  • Providing appropriate privacy notices to their form respondents and obtaining any necessary consents.
  • Configuring forms to avoid collecting special category (sensitive) data unless they have lawful justification.
  • Requesting deletion, export, or other actions in accordance with the service features if needed.

8. Data Subject Rights

FormsBee will assist Customers, to the extent possible, in responding to data subject requests such as requests for access, rectification, deletion, portability, or restriction. Customers should route requests to: uxsubash@gmail.com

Provide sufficient information to identify the account and the data subject in question. FormsBee may require verification of identity prior to executing requests.

9. Data Retention

Form submission data is retained until deleted by the Customer or the account is terminated. Backups may retain copies for a limited period per hosting provider retention policies. Upon account deletion, FormsBee will delete Customer data within a reasonable period, subject to retained backups and legal obligations.

10. International Transfers

Because hosting provider infrastructure may operate across multiple countries, personal data may be transferred internationally. FormsBee will implement contractual and technical safeguards where required by law (for example, standard contractual clauses or similar measures).

11. Term & Termination

This Addendum is effective during the period the Customer uses the FormsBee service. Upon termination of the service, FormsBee will delete Customer data in accordance with the Data Retention section, subject to retention for backups and compliance with law.

12. Contact

If you have questions about this Addendum or need help with data subject requests, contact:

FormsBee
Website: https://formsbee.com
Email: uxsubash@gmail.com

This Addendum is provided for informational purposes and does not constitute legal advice. Consider consulting legal counsel to ensure compliance with applicable laws based on your jurisdiction and use case.