Privacy Policy
SUMMARY
Welcome to Forminit!
You stay in control of your data at all times.
Who is this for?
This applies to anyone whose personal data Forminit may collect or process when using our service.
What do we collect?
- Your name and account details
- How you use Forminit
- Your payment and your plan information
Why do we collect it?
To give you a secure and personalized experience while using Forminit, and to deliver the service as outlined in our Terms & Conditions.
What control do you have?
You can request to view, change, or delete your data anytime by following the steps in your account.
How do we protect your data?
We store personal information on servers with restricted access in secure, controlled facilities. We use a range of technical and organisational measures to protect it against loss, misuse, unauthorised access, disclosure, alteration, or destruction. We follow industry best practice and take reasonable precautions to keep your data safe.
Our application and data servers are hosted in the 🇪🇺 EU regions of Amazon Web Services (AWS). AWS maintains a wide set of independent certifications, including SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27017 (Cloud Security), ISO 27018 (Cloud Privacy), PCI DSS v3.2, and HIPAA, verified by third-party auditors.
1. GENERAL
- 1. Forminit ("we", "us", "our"), registered office: 86–90 Paul Street, 3rd Floor, London, England, EC2A 4NE, company number 11357429, is responsible for processing your personal data as the Controller, including in connection with your use of Forminit.
- 2. Personal Data means any information relating to you as an identified or identifiable natural person and user of Forminit. Forminit processes Personal Data in accordance with applicable law, including Regulation (EU) 2016/679 (the GDPR) and the UK GDPR.
- 3. By accessing or using Forminit, you acknowledge that you have read and understood this Privacy Notice and how Forminit collects, uses and processes your Personal Data, in line with this Notice and for the purposes set out here.
2. WHAT PERSONAL DATA DOES FORMINIT COLLECT?
We value your trust and follow strict, ethical standards when collecting, using and protecting the information you share with us.
Forminit is used by two groups:
- Users: people who create and manage forms.
- Respondents: people who complete those forms.
The information we collect and how we handle it differs for each group. The sections below explain our approach for Users and Respondents separately.
a. Forminit Users
| DATA | DETAILS | CONTEXT |
|---|---|---|
| Your name and account details | Name Email address Password (stored as a hash) | When you create an account to use Forminit. |
| How you use Forminit | Features and functionality you use Preferences and settings you choose within Forminit | While you use Forminit |
| Your payment and your plan information | Subscription plan Billing status | When you select and pay for a subscription plan. |
Payments are processed by Stripe using Stripe Checkout. We do not receive or store your full card number or security code.
b. Forminit Respondents
When you complete a Forminit form hosted by us, we collect information on behalf of and under the instructions of the Forminit User (the person or organisation that created the form).
We collect and store the answers you submit to Forminit forms.
The Forminit User is the controller of this data and manages it. They may also provide their own privacy notice.
If you have questions about the form or how your data is used, please contact the form owner (the Forminit User) directly. Forminit is not responsible for the form's content.
3. HOW WE PROTECT YOUR INFORMATION
We store personal information on servers with restricted access in secure, controlled facilities. We use a range of technical and organisational measures to protect it against loss, misuse, unauthorised access, disclosure, alteration or destruction. We follow industry best practice and take reasonable precautions to keep your data safe.
No method of transmission over the internet or electronic storage is completely secure, and no safeguards can be guaranteed to be effective in all circumstances. Please use caution when deciding what personal information to share with us. If you have any questions about security on our site, please contact us using the details below.
Forminit's role as Data Processor (Respondents' data)
When Forminit processes Respondents' data on a User's behalf, the User who created the form acts as the Data Controller, and Forminit acts as the Data Processor for that Respondents' data.
In this capacity, Forminit (as Data Processor) undertakes to comply with its obligations under the Data Processing Agreement and applicable data protection laws (including the UK GDPR/GDPR) when processing Respondents' data on the Data Controller's instructions.
For the processing of Respondents' data on behalf of the Data Controller, the Data Processor undertakes to fulfill the following obligations:
- 1. Implement appropriate technical and organisational measures to protect the data.
- 2. Ensure confidentiality and restrict access to authorised personnel and approved Subprocessors.
- 3. Assist the Data Controller with data subject requests, security incident notifications, and DPIAs where required.
- 4. Delete or return Respondents' data at the end of the provision of services, and delete existing copies, subject to legal retention requirements.
- 5. Maintain records and enable appropriate audits/assessments consistent with the DPA.
- 6. Process personal data solely to deliver the contracted Services and only on the documented, written instructions of the Data Controller. If a legal obligation requires additional processing, we will inform the Data Controller before processing (unless the law prohibits notice on public-interest grounds).
- 7. Keep all personal data confidential during and after the engagement, and ensure all personnel with access are bound in writing by confidentiality obligations.
- 8. Taking into account technology, implementation costs, and the nature, scope, context and purposes of processing as well as the risks to individuals implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, where relevant:
- pseudonymisation and encryption of personal data;
- the ability to ensure ongoing confidentiality, integrity, availability and resilience of systems and services;
- the ability to restore availability and access to personal data promptly following a physical or technical incident;
- regular testing, assessment and evaluation of the effectiveness of security measures.
- 9. Keep personal data under our control and custody and do not disclose, transfer or otherwise communicate it to anyone unrelated to delivery of the Services under this Agreement (including for storage), unless instructed or permitted in writing by the Data Controller or required by law.
- 10. Engage another processor ("Sub-processor") only with the Data Controller's prior, written authorisation. We will provide the Data Controller with the Sub-processor's identity (legal name and tax ID) and the services to be subcontracted at least one (1) month in advance, and notify any intended additions or replacements so the Data Controller has the opportunity to object.
- 11. Flow down to every authorised Sub-processor all obligations imposed on Forminit by this Agreement, and obtain sufficient guarantees that they will implement appropriate technical and organisational measures to ensure processing in compliance with applicable data protection law.
- 12. Permit access to personal data by natural persons engaged by the Data Processor within our organisational framework (including non-employee contractors) and by companies/professionals providing internal services (e.g., IT, consulting, audits), provided such access is necessary to deliver those services and is not used to subcontract all or a material part of the Services to a third party without authorisation.
- 13. At the Data Controller's choice, return or delete all personal data processed on their behalf when the Services end, and delete existing copies, unless retention is required by law. (Personnel may access Users' and Respondents' data only insofar as necessary to discharge their contractual duties.)
- 14. Notify the Data Controller without undue delay upon becoming aware of a personal data breach, and provide reasonable assistance with any notifications to the UK Information Commissioner's Office (ICO) or other competent supervisory authority, and where required affected individuals. Provide reasonable assistance with data protection impact assessments (DPIAs) and any prior consultations with the ICO, and support the Data Controller in responding to data subject rights requests.
- 15. Keep a written record of all categories of processing activities carried out on the Data Controller's behalf.
- 16. Co-operate with the UK Information Commissioner's Office (ICO) or any other competent supervisory authority upon request.
- 17. Make available to the Data Controller all information necessary to demonstrate compliance with this Agreement and applicable data protection law, and allow for and contribute to audits and inspections by the Data Controller or its authorised third-party auditor.
- 18. If the Data Processor or any authorised Sub-processor determines the purposes and means of processing in breach of this Agreement or applicable law, they will be responsible for that processing.
- 19. Where a Sub-processor is located in a country without data protection laws equivalent to those of the UK/EU ("Third Country"), the Data Processor will implement all safeguards required under UK/EU data protection law (e.g., Standard Contractual Clauses and appropriate supplementary measures) for data transfers, and will promptly inform the Data Controller of those safeguards upon request.
4. YOUR RIGHTS
4.1 Right of access (copy of your data)
You may request access to the personal data we hold about you at any time, and obtain a copy, along with information about the purposes of processing.
4.2 Right to rectification, erasure or restriction
If you believe your personal data is inaccurate, you can ask us to correct it.
You may request that we restrict processing while we verify accuracy or handle another objection.
Where appropriate, you may also request deletion of your personal data (or anonymisation where deletion is not feasible), subject to legal retention duties.
4.3 Right to object
You may object to our processing of your personal data where you have serious and legitimate grounds.
You may object to direct marketing at any time for no reasons required.
4.4 Right to data portability
You may request the personal data you have provided to us in a structured, commonly used and machine-readable format, and ask us to transmit it to another controller where technically feasible.
4.5 Right to withdraw consent
Where we rely on your consent, you may withdraw it at any time. This will not affect processing carried out before withdrawal.
4.6 Rights in relation to automated decision-making and profiling
You may request not to be subject to a decision based solely on automated processing (including profiling) that has legal or similarly significant effects on you.
4.7 How to exercise your rights
Please contact us with a copy of the essential parts of your ID (e.g., name and registered email address) so we can verify your identity:
Post: UXPLUS LTD, 86–90 Paul Street, 3rd Floor, London, England, EC2A 4NE, United Kingdom
4.8 Right to complain
If you have concerns about how we process your personal data, you can lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ICO):
Wilmslow - Cheshire SK9 5AF
Tel. +44 1625 545 745
e-mail: international.team@ico.org.uk
Website: https://ico.org.uk
If you are in the EEA, you may contact your national data protection authority. A list of EU supervisory authorities is available from the European Commission.
If you are a California consumer you can find out more about your rights here.
This is without prejudice to your right to seek a remedy before the courts. If you have suffered damage as a result of the processing of your personal data, you may also have the right to claim compensation.
5. CONTACT US
For questions or comments about this Privacy Policy, or to exercise your data protection rights, contact:
Post: UXPLUS LTD, 86–90 Paul Street, 3rd Floor, London, England, EC2A 4NE, United Kingdom