LEGAL

Data Processing Agreement

How we process personal data in your forms on your behalf, with transfer terms and security measures.

Last updated: 10 October 2026
All legal documents

1. Parties and scope

This Data Processing Agreement ("DPA") is between Webbebo Technologies, H946, Phase 4, Ganapathy Maanagar, Coimbatore, Tamil Nadu 641006, India ("Onlyform", "we") and the customer that has accepted the Onlyform Terms of Service ("Customer"). It forms part of the Terms and applies automatically whenever we process personal data on the Customer's behalf while providing Onlyform. No separate signature is required.

The Customer is the controller of the personal data in its forms and responses, or a processor acting for its own controller. Onlyform is the Customer's processor, or sub-processor. Personal data that Onlyform processes for its own purposes, such as account administration, billing and security, is covered by our Privacy Policy and not by this DPA.

2. Processing on instructions

We process Customer personal data only on the Customer's documented instructions. The Customer's instructions are these Terms and DPA and the way it configures and uses Onlyform, including its forms, exports, integrations, follow-ups and AI features. If the law requires us to process data in another way, we will tell the Customer first unless the law prohibits it. We will tell the Customer if we believe an instruction breaks data protection law.

The Customer is responsible for the lawfulness of its instructions, for giving respondents the required notices, for having a legal basis and any consent needed, and for the accuracy of the data it collects.

3. Confidentiality and personnel

We give access to Customer personal data only to personnel who need it to provide, support or secure the service, and every such person is bound by a duty of confidentiality.

4. Security

We implement and maintain the technical and organisational measures in Annex 2 to protect Customer personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. We may update these measures over time, but never in a way that reduces the overall level of protection.

5. Sub-processors

The Customer gives general authorisation for us to use the sub-processors listed on our Service Providers and Sub-processors page. We will update that page at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period by emailing support@onlyform.com. If we cannot resolve the objection, the Customer may terminate the affected service and receive a refund of prepaid fees for the unused period.

We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.

6. Data subject requests and assistance

If we receive a request from a data subject about Customer personal data, we will pass it to the Customer and will not respond ourselves unless the Customer instructs us to or the law requires it. Taking into account the nature of the processing, we will help the Customer respond to data subject requests and meet its obligations on security, breach notification, data protection impact assessments and consultation with supervisory authorities.

7. Personal data breaches

We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer personal data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed and a contact point. Where not all information is available at once, we will provide it in stages. We will take reasonable steps to contain and remedy the breach.

8. Deletion and return

During the subscription, the Customer can export and delete its forms and responses at any time. When the Customer's account is closed, we delete Customer personal data within 30 days, unless the law requires us to keep it. Data in backups is deleted when the backups rotate and is not restored into active use.

9. Audits

We will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including answers to security questionnaires. Where that information is not sufficient, we will allow an audit by the Customer or an independent auditor bound by confidentiality, on at least 30 days' written notice, no more than once a year unless a supervisory authority requires it or a breach has occurred, and in a way that does not disrupt the service or expose other customers' data.

10. International transfers

Where Customer personal data subject to the GDPR is transferred to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, which are incorporated into this DPA by reference: Module 2 (controller to processor) where the Customer is a controller, and Module 3 (processor to processor) where the Customer is a processor. For those clauses: clause 7 (docking) applies; clause 9 option 2 (general authorisation, 30 days' notice) applies; the optional wording in clause 11 does not apply; clauses 17 and 18 are governed by and subject to the courts of Ireland; and Annexes I and II are completed by Annexes 1 and 2 of this DPA.

For transfers subject to the UK GDPR, the UK International Data Transfer Addendum issued by the Information Commissioner applies, with the parties' details, these selected clauses and Annexes 1 and 2 of this DPA as its tables. For transfers subject to Swiss law, the Standard Contractual Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection and the competent supervisory authority being the Federal Data Protection and Information Commissioner.

11. US state privacy laws

Where US state privacy laws apply, we act as the Customer's service provider or processor. We will not sell or share Customer personal data, will not retain, use or disclose it outside the direct business relationship or for any purpose other than providing the service, and will not combine it with personal data from other sources except as those laws permit.

12. Liability and precedence

Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the law does not allow it to be limited. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer personal data. If it conflicts with the Standard Contractual Clauses or UK Addendum, those prevail.

13. Annex 1: Details of processing

ItemDetails
Data exporterThe Customer, contactable at the email address on its Onlyform account. Role: controller or processor
Data importerWebbebo Technologies, H946, Phase 4, Ganapathy Maanagar, Coimbatore, Tamil Nadu 641006, India. Contact: support@onlyform.com. Role: processor or sub-processor
Subject matter and purposeProviding Onlyform to the Customer: hosting forms, collecting, storing and displaying responses and files, exports, notifications, integrations and AI features the Customer chooses to use
Nature of processingCollection, storage, organisation, retrieval, use, transmission on instruction, export and deletion
Data subjectsRespondents to the Customer's forms, and the Customer's workspace members
Categories of personal dataWhatever the Customer collects in its forms, typically names, contact details and answers; uploaded files and signatures; response metadata such as IP address, device type, approximate country, campaign parameters and timestamps
Sensitive dataOnly if the Customer chooses to collect it, in which case the Customer must apply the safeguards required by law and our Acceptable Use Policy
Frequency of transferContinuous, for as long as the Customer uses Onlyform
DurationThe term of the Customer's account, plus up to 30 days for deletion and the backup rotation period
Sub-processorsAs listed on the Service Providers and Sub-processors page
Competent supervisory authorityThe supervisory authority of the EU member state in which the Customer is established, or the Irish Data Protection Commission where the Customer is not established in the EU

14. Annex 2: Security measures

AreaMeasures
EncryptionAll traffic is encrypted in transit with TLS. Files stored in Cloudflare R2 are encrypted at rest
AuthenticationPasswords are stored as salted hashes. Sessions use secure, HttpOnly cookies. Two-factor authentication and passkeys are available to every user
Access controlWorkspace roles control who can see and edit forms and responses. Personnel access to production systems is limited to those who need it and protected by strong authentication
InfrastructureProduction runs in Hetzner data centres with physical access controls, behind Cloudflare network and DDoS protection
Application securityInput validation, rate limiting, protection against server-side request forgery for outbound requests, and regular dependency updates
AvailabilityRegular database backups, retained on a rolling schedule
Incident responseSecurity events are logged and reviewed, and breaches are handled under section 7
Sub-processorsAssessed before use and bound by written data protection terms