Business data protection
Forms data processing agreement — draft
This is a V1 template for the business controller and Special Guest processor, subject to legal review before V3.
Last updated: 15 September 2026
Draft and acceptance status
Viewing this page does not record acceptance. A business Owner or Administrator reviews and explicitly accepts the current version in the Forms workspace; that acceptance is recorded for the business and gates new Forms writes. This V1 template uses test operator identity and needs legal review and real identity before V3.
Parties and roles
The customer business is controller of its Forms respondent data. TEST VALUE (operator name) TEST VALUE (legal form), the Special Guest operator, is processor for those data under the business's documented instructions. The platform separately controls account and shared visitor identity data described in its privacy notice. Operator office: TEST VALUE (registered office, Romania); CUI: TEST VALUE (CUI); Trade Register: TEST VALUE (Trade Register number).
Processing scope
Forms collection, invitations, responses, identity where enabled, consent records, scores, audit findings, evidence files, frozen reports and access grants are processed to provide the business's selected Forms workflows. Respondents may be customers, staff, members or invited participants. The business chooses purposes and form content; sensitive data should be collected only where necessary and authorized.
Instructions and confidentiality
The business configures forms, access, retention and authorized members and gives documented instructions through the service. The processor may not reuse respondent content for its own marketing or another business. Authorized personnel are bound by confidentiality and access is limited to their duties. Unlawful instructions must be raised with the business.
Security and separation
Server-side business scoping, role checks, private file admission and scanning, controlled report grants, audited material actions, recovery procedures and incident handling protect Forms data. The final agreement must identify the approved technical and organizational measures and the procedures for testing them.
Subprocessors and transfers
Infrastructure, database, email, private storage, scanning and backup providers may process data to deliver the service under the controller's instructions. The final schedule must name approved subprocessors, authorization and change-notice processes, any transfers and safeguards before real customer use. This draft does not approve an unnamed provider or international transfer.
Rights, breaches and oversight
The processor must assist the controller with respondent access, correction, erasure, impact assessments and breach assessment and notification. A platform-received respondent request is forwarded to the business; the business response deadline is shown as one month. The processor provides the information needed to demonstrate compliance and support an authorized audit without exposing another business's data.
Retention and end of processing
The owner-selected target is automatic deletion of responses, evidence and frozen reports 24 months after a run closes by default, configurable per form from one month to ten years, unless a reasoned legal hold applies. The purge, legal-hold review, export and deletion workflows are still being implemented. On termination, return or deletion must follow the controller's documented choice and mandatory legal retention; protected backups follow a bounded recovery schedule.
Processor contact
Send data-protection questions to test-privacy@example.invalid; platform support is test-support@example.invalid. These are V1 test contacts until the owner supplies real operator identity.