Legal
Data processing agreement
The Article 28 terms that apply whenever FormHam handles enquiries submitted through your forms. You are the controller of that data. We are your processor.
Last updated 5 September 2026.
Why this exists. Article 28 of the UK GDPR requires a written contract between a controller and its processor. If you are an agency running client sites through FormHam, you are a processor to your clients and we are your sub-processor, and this document is the link in that chain. It takes effect when you start using the service and forms part of our terms.
1. Parties and roles
“Processor” means FormHam, a trading name of a sole trader based in the United Kingdom—not a limited company. “Controller” means you, the account holder. Notices to us should be sent to tgf@xpose.online.
We process personal data only on your documented instructions. Configuring a form, a notification recipient, a webhook, a retention period or an integration in the dashboard or through the API is an instruction for this purpose. If we ever believe an instruction breaches data protection law we will tell you rather than carry it out silently.
2. Subject matter, duration, nature and purpose
| Item | Detail |
|---|---|
| Subject matter | Receiving, storing, monitoring and delivering submissions made through the controller's web forms. |
| Duration | For as long as the controller holds an account, plus the retention periods in section 6. |
| Nature and purpose | Storage; notification by email; forwarding to endpoints the controller configures; spam scoring and quarantine; automated checks that the controller's forms still function; retention, export and erasure. |
| Types of personal data | Whatever the controller's form fields collect—typically name, email address, telephone number and free-text message—plus the submitter's IP address, the page URL the form was submitted from, timestamps, and details of any attached file where uploads are enabled. |
| Categories of data subject | Visitors to the controller's websites who submit a form; the controller's own users and team members. |
| Special category data | Not requested or expected. If the controller's form design collects it, the controller is responsible for the additional conditions that then apply. |
3. Confidentiality
Anyone we allow to access submission data is bound by a duty of confidentiality. Access within the platform is scoped to the business the data belongs to, non-administrator users see submission content in a masked form by default, and every privileged read—export, bulk download, cross-business access—is written to a tamper-evident audit log recording who looked, when, and at what.
4. Security measures
These are the technical measures the platform actually implements:
- Encryption at rest of the submission payload. Every field the visitor typed, plus the IP address and source URL, is encrypted in the database and decrypted only when it is displayed, exported, or sent to a recipient you configured.
- Encryption of stored credentials. Webhook signing secrets, SMTP passwords, mail and integration API keys and reCAPTCHA secrets are encrypted and never returned by the API.
- Private file storage. Attachments are stored on private disk, outside any object store, CDN or public path, and are reachable only through short-lived signed links generated per request.
- Signed outbound webhooks, HTTPS only, with redirects refused so a payload cannot be walked to an unintended host.
- Access control. Per-business scoping, role separation, optional two-factor authentication, hashed API tokens shown once at creation, and an optional IP allowlist on administrative access.
- Rate limiting and bot scoring on submission and signup endpoints, with suspicious submissions quarantined for review rather than deleted.
- Integrity. The audit log is chained and verified daily, so a deleted or altered access record is detectable.
5. Sub-processors
You give general authorisation for the sub-processors below. We will give notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate without penalty for the unexpired term.
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Mailgun | Sending notification and system email | Submission content included in the notification, plus recipient addresses. Configured to Mailgun's EU endpoint by default. |
| Bunny.net | CDN, DNS, and edge failover buffering | Static assets in normal operation. When our origin is unreachable or errors, the edge script buffers the submission at Bunny so the enquiry survives; buffered rows are replayed and deleted within minutes, and any residue is deleted after 7 days. |
| Google (reCAPTCHA) | Bot scoring, where the controller enables it | The reCAPTCHA token; on the classic integration, the submitter's IP address as well. Google also collects data directly in the visitor's browser through its own script. |
| Stripe | Card billing | Controller billing contact and account references. No submission data. |
| GoCardless | Direct Debit billing | Controller customer and bank-account references. Bank details are entered in GoCardless's own hosted flow. No submission data. |
| Mailchimp (only if configured) | Mailing-list sync | Subscriber email address and name. |
Where you configure a Slack channel, a Formspark form, a CRM endpoint or any other webhook, we deliver the submission there on your instruction. Those destinations are your choice and your processors, not ours, and this agreement does not cover them.
SMS and WhatsApp notification exist in the product but are switched off; no submission data reaches any messaging provider under this agreement today. Several sub-processors above are US-headquartered and will process data outside the UK under their own transfer arrangements.
6. Retention, return and deletion
Submissions are dealt with 365 days after they arrive unless you set a shorter period on your account. The default treatment is anonymisation: attachments are permanently deleted and the payload is overwritten with a redaction marker, leaving the record itself — identifiers, timestamps and a keyed hash of the submitter's email — so counts stay accurate and a later erasure request can still find it. You may switch your account to hard deletion, which removes the record and everything attached to it outright. The retention job runs daily.
Quarantined submissions nobody has opened are removed after 30 days, reversibly; anything opened is exempt. Test submissions, where you enable that option, are permanently deleted after 24 hours. Subject access exports we generate are deleted from our storage after 7 days.
You can export everything at any time, without asking us. On termination we will delete the personal data we hold for you on request; absent a request, the retention rules above continue to run.
Delivery logs (the recipient and any failure reason for each notification) and form activity logs (including the raw IP of blocked and quarantined attempts) are covered by a nightly retention sweep: both are deleted after 365 days, matching the submission retention period so that a log entry cannot outlive what it describes. Stored billing-webhook payloads are deleted after 180 days. Erasing a submission additionally redacts the recipient and failure text on its delivery logs at once, and hard deletion removes them entirely.
Audit records are exempt from that sweep by design, because a record of access that can be pruned is not a record of access.
7. Assistance to the controller
Data-subject rights are built into the product rather than handled by hand, so this is assistance we can actually give:
- Access and portability. We can export everything held against an email address—every submission payload, every attachment, every mailing-list entry—as a single machine-readable file, including soft-deleted records.
- Erasure. We can erase by email address across your account: attachments permanently deleted, payloads overwritten, mailing-list entries anonymised and unsubscribed, delivery-log recipients and failure text redacted. Individual submissions can be erased one at a time from the dashboard.
- Rectification and restriction. Submissions can be edited or held from further processing on request.
If a data subject contacts us directly about data in your account, we will pass the request to you rather than act on it, and we will help you respond. We will also assist, to the extent reasonable and proportionate to the information available to us, with your obligations on security, breach notification and data protection impact assessments.
8. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data, with what we know at that point: what happened, the categories and approximate number of records involved, the likely consequences, and what we are doing about it. We will follow up as more is established. Notifying the Information Commissioner's Office and any affected data subjects is your decision as controller.
9. Audit
On reasonable notice, and no more than once a year unless a breach or a regulator's request makes it necessary, we will provide the information you need to demonstrate compliance with Article 28—including our audit-log evidence of who accessed what—and submit to an audit or inspection conducted by you or an auditor you appoint.
10. General
This agreement is governed by the law of England and Wales. Where it conflicts with our terms of service on any question about the processing of personal data, this agreement prevails. It is updated in place; the date at the top of the page reflects the current version, and we will give notice of material changes.