Skip to content
crispforms

Data Processing Agreement

Applies whenever you collect personal data from people through a CrispForms form.

Last updated

This DPA forms part of the Terms of Service between you (“Controller”) and CrispForms(“Processor”). It applies automatically — you do not need to sign anything to be covered.

1. Roles

You are the controller of the personal data your respondents submit. You decide what to ask and why. We are the processor, acting only on your documented instructions — which, in practice, are the settings and integrations you configure.

2. Scope of processing

  • Subject matter: providing the CrispForms form service
  • Duration: for as long as your account is active, plus the retention periods in our Privacy Policy
  • Nature and purpose: collecting, storing, displaying, analysing and transmitting form responses as you direct
  • Categories of data subject: the people who fill in your forms
  • Categories of personal data: whatever your form asks for, plus approximate location, device type and referrer

3. Our obligations

  • Process personal data only on your instructions
  • Ensure personnel with access are bound by confidentiality
  • Apply appropriate technical and organisational measures — see our Security page
  • Assist you in responding to data subject requests, and with DPIAs and regulator consultations where relevant
  • Notify you without undue delay, and in any case within 72 hours, on becoming aware of a personal data breach affecting your data
  • Delete or return personal data at the end of the service, subject to legal retention obligations
  • Make available the information needed to demonstrate compliance

4. Your obligations

  • Have a lawful basis for the data you collect, and give respondents the notice they are owed
  • Don’t collect special-category data unless you have a lawful basis and the appropriate safeguards
  • Don’t collect payment card data or protected health information through a form field — CrispForms is not a PCI or HIPAA environment
  • Respond to your respondents’ requests about their data

5. Subprocessors

You give general authorisation for us to engage the subprocessors listed on our Subprocessors page. We will update that page before a new subprocessor begins handling customer data, and we remain liable for their performance.

6. International transfers

Where personal data is transferred out of the EEA or UK, the transfer is made under the European Commission’s Standard Contractual Clauses, with the UK Addendum where applicable. Those clauses are incorporated here by reference.

7. Audits

On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we’ll provide the information reasonably necessary to demonstrate compliance with this DPA.

8. Order of precedence

If this DPA conflicts with the Terms of Service, this DPA governs for matters of personal data processing.

Questions

Email hello@crispforms.com. If your organisation needs a counter-signed copy, ask and we’ll arrange it.