DPA
Data Processing Addendum
Last updated 25 July 2026
This addendum sets out how FormNest processes the personal data contained in your form responses on your behalf. It forms part of the agreement between you and FormNest.
Roles
For the personal data in the responses your forms collect, you are the controller — you decide what is asked and why. FormNest is the processor: we process that data only to provide the service, and only on your instructions.
Details of the processing
- Subject matter
- Processing of the personal data submitted through your forms.
- Nature and purpose
- Collecting, storing, and making available form responses, and providing the product's features over them.
- Duration
- For as long as your account is active, or until you delete the data.
- Data subjects
- The people who submit responses to your forms.
- Categories of data
- Whatever your forms ask for — determined by you, as the controller.
Our obligations
- We process response data only on your documented instructions, and to provide the service.
- People who handle the data are bound by confidentiality.
- We maintain appropriate technical and organisational security measures (below).
- We assist you, so far as we reasonably can, in meeting your own obligations to data subjects.
Security measures
- Encryption of data at rest and in transit.
- Role- and form-scoped access controls.
- An audit log of administrative actions.
- Use of managed, replicated infrastructure for storage.
Sub-processors
We use MongoDB Atlas to host response databases and Cloudflare R2 to store uploaded files. If we add or change a sub-processor that handles response data, we'll make that change available so you can review it.
Data subject requests
Where a data subject exercises a right over data held in your forms, we provide the tools to help you respond — including CSV export and a right-to-erasure workflow that removes a person's submissions and attached files.
Personal data breaches
If we become aware of a breach affecting response data we process for you, we'll notify you without undue delay and share what we know to help you meet your own notification duties.
Location and residency
Response data is stored on our managed infrastructure. Choosing the region your responses are stored in (data residency) is available on the Enterprise plan.
Return and deletion
On termination, you can export your response data. After that, it is deleted from our active systems.
Contact
Questions about this document, or about your data? Email us at privacy@formnest.com.