Data processing agreement
This applies whenever PostForm (the processor) handles personal data on behalf of a customer (the controller). It forms part of our terms of service and needs no separate signature. Using the service accepts it. If your organisation needs a countersigned copy, email privacy@postform.dev.
Subject matter and duration
We receive, store and forward form submissions for as long as the customer has an account, and for no longer than 30 days per submission.
Nature and purpose
Receiving HTTP form submissions, validating them, storing them, and delivering a notification email to a destination address the customer has confirmed control of.
Categories of data and data subjects
- Data subjects:anyone who submits one of the customer's forms.
- Data:whatever fields the customer's form collects (which is the customer's decision, not ours), plus the submitter's email address where given and the IP address the submission came from.
We do not inspect, index or categorise field contents. If a customer's form collects special category data, that is their decision and their lawful basis to establish; we neither know nor can prevent it.
Our obligations
- Process personal data only on the customer's documented instructions, which are these terms and the customer's configuration of their keys.
- Keep it confidential and limit access to people who need it to run the service.
- Apply appropriate technical measures: encryption in transit, row-level security and revoked public grants on every database table, per-account query scoping on every read, destination-address confirmation before any send, and rate limiting on the public endpoint.
- Engage no new sub-processor without updating the list below and notifying customers first.
- Assist with data subject requests, and pass on any we receive directly that belong to a customer.
- Notify the customer without undue delay on becoming aware of a personal data breach.
- Delete submissions after 30 days automatically, and delete everything on request when an account closes.
- Make available the information needed to demonstrate compliance with these obligations.
Your obligations
- Have a lawful basis for what your forms collect.
- Name PostForm as a processor in your own privacy notice, and state the 30-day retention window. Your submitters never see our site, so this is the only way they can learn we exist.
- Only send to destination addresses you control or have been asked to send to.
- Respond to your own submitters' requests; you are the controller.
Sub-processors
| Provider | Processing | Location |
|---|---|---|
| Supabase | Postgres database and authentication | EU/US, per project region |
| Resend | Outbound email delivery | US |
| Vercel | Application hosting and edge network | Global |
| Sentry | Error reporting (identifiers only, never submission content) | US/EU |
| GitHub | Encrypted nightly database backups | US |
Transfers outside the UK/EEA rely on the providers' standard contractual clauses.
Deletion and return
Submissions are deleted 30 days after they arrive, automatically, by a scheduled job, not on request and not at our discretion. On account closure we delete the account, its keys and its submissions. Export anything you need before then; there is no recovery afterwards. Nightly encrypted backups are kept for 30 days and age out on their own schedule, so deletion from the live database can precede deletion from the last backup by up to that long.
Audit
We will answer reasonable written questions about these measures, and provide our sub-processors' own certifications where they publish them. We do not offer on-site audits.
Last updated 2026-08-04.