Privacy Policy
This policy explains how databooq (“we”), operated by an independent operator from the Czech Republic, handles personal data under the EU General Data Protection Regulation (GDPR). It covers two distinct roles:
- We are the controller for data about account holders (form owners) and visitors to our own pages.
- We are a processor for data that respondents submit through forms built by our users. For that data, the form owner is the controller.
1. Data we process
Account data (we are the controller)
- Name, email address, workspace names, hashed password (we never store plaintext passwords).
- Session data: rotating refresh tokens, browser user-agent per session, timestamps.
- Content you create: forms, questions, design settings, uploaded images, invite addresses.
- Technical logs: IP address, request metadata, errors, kept short-term for security and debugging.
Respondent data (we process it for the form owner)
- Answers submitted through a form, including any personal data the form asks for.
- Optional respondent email (when the form owner enables email collection or confirmations).
- Files uploaded through file-upload questions.
- Technical submission metadata (user-agent, referer) and, where the form owner enables duplicate prevention, a marker stored in the respondent’s browser (local storage).
2. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service (accounts, forms, responses) | Account data, content | Contract, Art. 6(1)(b) GDPR |
| Security, abuse and fraud prevention | Logs, session data | Legitimate interest, Art. 6(1)(f) |
| Transactional email (confirmations, invites, alerts) | Email addresses | Contract, Art. 6(1)(b) |
| Processing respondent submissions | Respondent data | Processor on the form owner’s instructions, Art. 28 |
We do not sell personal data and we do not use it for advertising or profiling.
3. Processing for form owners (Art. 28)
The binding processor terms are in the Data Processing Addendum, part of our Terms of Service. In short, for respondent data we act only on the form owner’s documented instructions, meaning we:
- store and process submissions solely to provide the service to the owner;
- give the owner tools to view, edit, export and delete responses at any time;
- impose confidentiality on anyone with access to the data;
- assist the owner, insofar as possible, with data-subject requests and security obligations;
- delete or return respondent data when the owner deletes the form or their account;
- notify the owner without undue delay after becoming aware of a personal-data breach.
If you responded to a form and want your answers accessed, corrected or deleted, contact the person or organization that ran the form. They control that data. If you cannot reach them, contact us at [email protected] and we will assist.
4. Retention
- Account data: kept while the account exists; deleted within 30 days of account deletion.
- Forms moved to trash are permanently deleted after 30 days.
- Responses and uploads: kept until the form owner deletes them, the form, or their account.
- Server logs: up to 30 days.
- Expired sessions and used reset tokens are purged automatically.
- Backups: encrypted backups run nightly and are stored within the European Union. Data you delete disappears from live systems immediately and rotates out of all backup copies within 30 days.
5. Recipients and subprocessors
We use a small number of infrastructure providers to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting (application, database, file storage) | Germany / Finland (EU) |
| Cloudflare, Inc. | DNS, TLS and network proxying | Global network; EU-hosted origin (SCCs / EU-US DPF) |
| Resend, Inc. | Transactional email delivery | USA (SCCs / EU-US DPF) |
Where a provider processes data outside the EU/EEA, transfers rely on adequacy decisions (EU-US Data Privacy Framework) or Standard Contractual Clauses. Application data and files are hosted in Germany; backups are stored within the European Union. We do not share personal data with anyone else except where required by law.
Integrations enabled by form owners
Separately from our subprocessors, a form owner can connect services of their own choosing. These receive respondent data on the owner’s instructions, under the owner’s own agreements with those services, and only when the owner turns them on:
- Google Sheets sync: each completed response is appended as a row to a spreadsheet in the owner’s own Google account. The connection uses Google’s OAuth consent; we store the resulting tokens encrypted and never see the owner’s Google password.
- Webhooks: submissions are delivered to a server address the owner configures. Whatever endpoint the owner chooses receives the response data.
6. Cookies and local storage
Inside the app and on published forms, databooq uses only what is strictly necessary to provide the service. There are no analytics, advertising or tracking cookies on any form you fill in, ever.
The marketing site (databooq.com) keeps aggregate, cookieless usage statistics: daily counts of page views and button clicks, recorded with at most the page address, the page language and the linking site’s hostname. Nothing identifies a visitor. No cookies, no IP addresses and no device fingerprints are stored, so these counters contain no personal data.
Advertising (marketing site and signup page only)
We advertise databooq through Google Ads, so our public marketing pages and the signup page load Google’s measurement tag (gtag.js) to tell us which ads lead to a signup. This tag is not present on published forms or anywhere inside the signed-in app.
If you are in the EU, the EEA, the United Kingdom or Switzerland, the tag starts with advertising storage denied: until you accept, it stores no cookies on your device and advertising identifiers are redacted from what it sends. Nothing is stored unless you choose to accept, and the legal basis is your consent (Art. 6(1)(a) GDPR).
Elsewhere, where local law permits advertising measurement on an opt-out basis, advertising cookies start enabled and the same banner lets you switch them off. Whichever applies to you, your choice is remembered, overrides the regional default, and can be changed or withdrawn at any time through the “Cookie preferences” link in our footer.
Google Ireland Limited acts as our processor for this measurement; where data reaches Google entities outside the EU/EEA, transfers rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.
| Item | Purpose | Lifetime |
|---|---|---|
| Refresh-token cookie (owners) | Keeping you signed in securely (HttpOnly, Secure) | 24 hours, or 72 hours with “Keep me signed in” |
| Google Ads cookies (marketing site and signup page) | Measuring which ads lead to a signup. In the EU, EEA, UK and Switzerland, set only after you accept; never set on a published form | Up to 90 days |
| Duplicate-prevention marker (respondents) | Local-storage flag marking that this browser already submitted a specific form, only when the owner enables duplicate prevention | Per form, until you clear your browser’s site data |
7. Security
- Passwords hashed with scrypt; sessions use short-lived tokens with rotating refresh tokens.
- TLS encryption in transit; infrastructure isolated per service with least-privilege access.
- Respondent file uploads are private by default and never publicly listed.
- Capacity and integrity checks run inside database transactions to prevent data corruption.
8. Your rights
Under the GDPR you can, at any time:
- access the personal data we hold about you (Art. 15), most of it is visible directly in the app;
- correct inaccurate data (Art. 16), editable in account settings;
- request deletion (Art. 17), deleting your account removes your data as described in Retention;
- export your data (Art. 20), responses export to CSV, XLSX, JSON and PDF;
- restrict or object to processing based on legitimate interest (Arts. 18, 21);
- lodge a complaint with a supervisory authority, in the Czech Republic, the Office for Personal Data Protection (ÚOOÚ, uoou.gov.cz), or the authority of your country of residence.
To exercise any right, email [email protected]. We respond within one month.
9. Children
databooq accounts are not intended for children under 15 (the Czech digital-consent age) or under the higher digital-consent age that applies in your country. Form owners who collect data from children are responsible for obtaining any consent their law requires.
10. Changes
We will announce material changes to this policy by email or in-app before they take effect. The “last updated” date at the top always reflects the current version.
11. Contact
Privacy questions and data-subject requests: [email protected]