Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between databooq (“the Processor”) and the account holder (“the Controller”). It applies whenever forms created by the Controller collect personal data from respondents, and implements Article 28 GDPR. No separate signature is required. Accepting the Terms accepts this DPA.
1. Subject matter and duration
The Processor hosts, stores and processes respondent submissions on the Controller’s behalf for as long as the Controller’s account exists, or until the Controller deletes the relevant forms or responses.
2. Nature and purpose of processing
Collection, storage, display, aggregation, export and deletion of form responses; delivery of related transactional email (confirmations, edit links); enforcement of capacity limits and duplicate-prevention rules configured by the Controller.
3. Categories of data subjects and personal data
- Data subjects: respondents to the Controller’s forms.
- Personal data: whatever the Controller’s forms request, typically names, email addresses, free-text answers, choices, uploaded files, plus technical submission metadata (user agent, referer). The Controller decides what is collected and must not collect special-category data without a lawful basis, nor payment-card numbers or passwords.
4. Controller responsibilities
The Controller is responsible for having a lawful basis for the data its forms collect, informing respondents (the form itself should say why data is collected), and honoring data-subject requests concerning respondent data. The Service’s tools (view, edit, export, delete responses) exist to make that possible.
5. Processor obligations
The Processor shall:
- process respondent data only on the Controller’s documented instructions, as expressed through the Service’s features and settings;
- ensure persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (Article 32): encryption in transit, hashed credentials, isolated infrastructure, transactional integrity checks, private-by-default file storage;
- assist the Controller, insofar as reasonably possible, in responding to data-subject requests and in meeting security and DPIA obligations;
- notify the Controller without undue delay after becoming aware of a personal-data breach affecting respondent data;
- delete respondent data when the Controller deletes it, the form, or the account (trash retention: 30 days), subject to statutory retention duties;
- make available the information reasonably necessary to demonstrate compliance with this DPA and allow for audits, initially satisfied by documentation and written answers.
6. Subprocessors
The Controller grants general authorisation to engage the subprocessors listed in the Privacy Policy (hosting, network, email delivery), which is the single authoritative list. Before adding or replacing a subprocessor, the Processor will update that list and notify account holders by email or in-app at least 30 days in advance; the Controller may object on reasonable data-protection grounds by terminating the affected forms or account before the change takes effect.
Integrations the Controller connects itself (for example Google Sheets sync or webhooks) are not subprocessors of the Processor. They receive respondent data on the Controller’s own instructions and under the Controller’s own agreements with those services, and the Controller is responsible for them.
7. International transfers
Respondent data is stored in the EU. Where a subprocessor processes data outside the EU/EEA (e.g. email delivery), transfers rely on an adequacy decision (EU-US Data Privacy Framework) or Standard Contractual Clauses, as set out in the Privacy Policy.
8. Liability and precedence
Liability follows the Terms of Service. If this DPA conflicts with the Terms regarding the processing of respondent personal data, this DPA prevails.
9. Contact
Data-protection questions about this DPA: [email protected]