Data Processing Addendum

Last updated: August 13, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Wisecat Software LLC, operating Nextforms (“Processor”, “we”), and the customer accepting the Terms (“Controller”, “you”). It applies where we process personal data of your form respondents on your behalf and such processing is subject to the GDPR, UK GDPR, or similar data protection laws. It is incorporated into the Terms automatically — no signature is required. If you need a countersigned copy, email [email protected].

1. Roles and scope

You are the controller of respondent personal data collected through your forms; we are your processor. The subject matter of processing is the operation of your forms and workflows; the duration is the term of your account; the nature and purpose are hosting, storing, and processing submissions and executing the workflow actions you configure. The categories of data subjects and personal data are determined by you through the fields you create. You agree not to collect special-category data, full payment card numbers, or government identifiers through form fields (payments are handled by Stripe as an independent processor).

2. Processing on instructions

We process respondent data only on your documented instructions — which are: the configuration of your forms and workflows, your use of product features, and the Terms — unless processing is required by law, in which case we will inform you unless legally prohibited. Sending a submission to a service you connected (for example your Google Sheet or Slack workspace) is processing on your instruction.

3. Confidentiality

We ensure that persons authorized to process respondent data are bound by confidentiality obligations.

4. Security

We implement appropriate technical and organizational measures, including: encryption of data in transit (TLS); encrypted storage of integration credentials; logical tenant isolation; role-based access within customer organizations; authentication with optional multi-factor; bot and abuse protection on public endpoints; and infrastructure hosted with providers maintaining recognized security certifications.

5. Subprocessors

You authorize the subprocessors listed in our Privacy Policy. We will update that list at least 14 days before a new subprocessor processes respondent data; if you reasonably object, you may terminate the affected service. We remain responsible for our subprocessors’ performance.

6. Assistance

Taking into account the nature of processing, we will assist you with reasonable measures to respond to data subject requests (the product’s export and deletion features are the primary mechanism) and to meet your obligations regarding security, breach notification, and data protection impact assessments.

7. Personal data breach

We will notify you without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting respondent data, with information reasonably available to help you meet your own notification obligations.

8. Deletion and return

You can export submissions at any time. On account deletion or termination, we delete respondent personal data within 30 days, except where law requires retention. Deletion of individual submissions in the product is immediate and permanent, including uploaded files.

9. International transfers

Where respondent data originating from the EEA, UK, or Switzerland is transferred to us in the United States, the parties incorporate the European Commission’s Standard Contractual Clauses (Module 2: controller-to-processor), and the UK Addendum where applicable, with you as data exporter and us as data importer. Our security measures in Section 4 apply as the technical annex.

10. Audits

On written request no more than once per year, we will provide information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant third-party attestations of our infrastructure providers. Where this is insufficient, we will allow an audit under reasonable confidentiality, scope, and timing conditions, at your expense.

11. Liability

The limitations of liability in the Terms apply to this DPA.

Coming soon

Nextforms is almost ready — sign-ups aren't open quite yet. Check back soon.