Last updated 2026-08-16 · This applies automatically between hform and every form owner — no signature ceremony needed. It's part of the terms.
When people submit your form, you are the data controller (you decide what's collected and why) and hform is your data processor (we store and handle it on your instructions). Your instructions are what you do in the product: create forms, receive messages, export, archive, delete.
Submission contents, plus technical metadata (hashed IP, browser type, referring page) used for spam and abuse protection. We use it to provide the service — storing, protecting, notifying, exporting — and for nothing else. No selling, no profiling, no advertising.
| Who | What for | Where |
|---|---|---|
| Akamai (Linode) | Server hosting | Stockholm, Sweden (EU) |
| Postmark (ActiveCampaign) | Email delivery | USA — EU standard contractual clauses |
| Cloudflare | Bot protection (Turnstile) and DNS | Global edge, EU/US |
| Stripe (when paid plans launch) | Billing | EU/USA — SCCs |
If this list changes, we'll update this page; paying customers are notified by email and can object.
Data is encrypted in transit (TLS everywhere), stored on our own EU server with access limited to those who run the service, IP addresses are stored only as irreversible hashes, and card data never touches our systems.
Messages are kept per your plan's retention period (Free 30 days, Basic 1 year, Plus/Pro while your account is active) and deleted after. Archiving a form retires its address; deleting your account removes everything within 30 days. On request we'll confirm deletion in writing.
If we become aware of a personal data breach affecting your forms' data, we'll notify you without undue delay with what we know, so you can meet your own obligations.
We're a small operation — we won't host on-site audit visits, but we'll answer any reasonable written question about how your data is handled: contact form.