Data Processing Agreement
Last updated: 3 July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditionsbetween the customer (“Controller”, “you”) and G. Sigurdarson(“Processor”, “Formbear”) and governs our processing of personal data on your behalf under Article 28 of the GDPR. Where it conflicts with the Terms on data protection, this DPA prevails.
1. Definitions
“GDPR” means Regulation (EU) 2016/679. “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, and “Personal Data Breach” have the meanings given in the GDPR. “Subprocessor” means a third party engaged by us to process Personal Data. “Customer Personal Data” means Personal Data contained in the responses and content you process through Formbear.
2. Roles and scope
You are the Controller of Customer Personal Data and we are the Processor. We process Customer Personal Data only to provide the service and only on your documented instructions, including those set out in this DPA and the Terms. We will inform you if, in our opinion, an instruction infringes the GDPR. The subject matter, duration, nature, purpose, data types, and data subjects are set out in Annex I.
3. Our obligations
- process Customer Personal Data only on your documented instructions, including for international transfers, unless required by law (in which case we will tell you, unless the law forbids it);
- ensure that personnel authorised to process Customer Personal Data are bound by confidentiality;
- implement the technical and organisational measures in Annex II (Article 32);
- assist you, taking into account the nature of the processing, in responding to Data Subject requests under Chapter III of the GDPR;
- assist you in meeting your obligations under Articles 32 to 36 (security, breach notification, and data protection impact assessments);
- at your choice, delete or return all Customer Personal Data at the end of the service and delete existing copies, unless retention is required by law;
- make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, as described in section 7.
4. Subprocessors
You give general authorisation for us to engage the Subprocessors listed in Annex III. We impose data protection obligations on each Subprocessor no less protective than those in this DPA and remain responsible for their performance. We will give you reasonable prior notice of any intended addition or replacement of a Subprocessor, and you may object on reasonable data protection grounds.
5. International transfers
We store and process Customer Personal Data in the EU/EEA. Where a Subprocessor involves a transfer outside the EEA (for billing only), that transfer is subject to appropriate safeguards under Chapter V of the GDPR, such as the EU Standard Contractual Clauses, which are incorporated by reference where applicable.
6. Personal Data Breach
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide information reasonably available to help you meet your notification obligations.
7. Audits
We will make available information reasonably necessary to demonstrate compliance and, on reasonable prior notice and subject to confidentiality, allow audits by you or a mutually agreed auditor, no more than once per year except where required by a supervisory authority or following a Personal Data Breach.
8. Liability and term
Each party’s liability under this DPA is subject to the limitations in the Terms. This DPA takes effect when you accept the Terms and continues for as long as we process Customer Personal Data on your behalf.
9. Governing law
This DPA is governed by the law stated in the Terms, except where the GDPR or applicable Standard Contractual Clauses require otherwise.
Annex I: Details of processing
| Subject matter | Provision of the Formbear form-building, response-collection, and feedback-widget service. |
|---|---|
| Duration | For the term of the agreement and until data is deleted or returned. |
| Nature and purpose | Hosting, storage, transmission, display, export, and deletion of form and feedback responses so you can collect and manage them. This includes deriving anonymous, aggregate traffic statistics about form visits (view counts, coarse location, device and browser family, referrer domain) presented to you as analytics; the visitor’s IP address and browser details are processed transiently on our servers for this derivation and are not stored. |
| Types of personal data | Any personal data you choose to collect through your forms and widgets, for example names, email addresses, and free-text answers. You control what your forms request. Avoid collecting special category data unless you have a valid basis. |
| Categories of data subjects | Your respondents and any individuals referenced in their responses. |
Annex II: Technical and organisational measures
- encryption in transit (TLS) for all connections;
- encryption at rest: full-volume encryption plus application-layer AES-256-GCM on response answer content, with key versioning;
- tenant isolation enforced in the application: every query is scoped to the owning workspace through a single authorisation chokepoint;
- access controls and least-privilege database roles; the database is not exposed to the public internet;
- rate limiting and spam protection on public submission endpoints;
- regular, encrypted backups with a tested restore path;
- logging and monitoring, with personal data kept out of logs.
Annex III: Approved subprocessors
| Hetzner Online GmbH (Germany) | Application hosting and database. Processes all categories above. |
|---|---|
| Lettermint (Netherlands) | Transactional email. Processes email addresses. |
| Polar (Sweden; payments via Stripe) | Billing and tax as merchant of record. Processes billing data only, not form or response data. |
Contact
For data protection matters, contact [email protected]. A countersigned copy of this DPA is available on request.