Data Protection

Data Processing Agreement

This DPA describes how Form500mg processes personal data on your behalf, in compliance with GDPR and applicable data protection laws.

Last Updated: February 19, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Form500mg ("Processor," "we," "us") and the customer ("Controller," "you") governing your access to and use of our Services.

This DPA addresses the requirements of Article 28 of the General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws regarding the processing of personal data.

2. Roles of the Parties

You (the Customer)

Act as the Data Controller — you determine the purposes and means of processing personal data collected through forms you create on Form500mg.

Form500mg

Acts as the Data Processor — we process personal data on your behalf solely to provide, secure, and support the Services.

You are responsible for the accuracy, quality, and lawfulness of the personal data you collect and for establishing an appropriate legal basis for processing (e.g., consent, legitimate interest, contractual necessity).

3. Scope & Nature of Processing

Form500mg processes personal data solely to:

1Host and deliver forms created by you.
2Collect and store responses submitted by respondents to your forms.
3Send transactional email notifications (via Amazon SES) related to form submissions.
4Provide analytics and reporting on form responses.
5Provide AI-assisted form creation (via Google Gemini API) when you use AI features.
6Maintain the security, availability, and integrity of the Services.

Data Subjects

  • Form creators (your authorized users)
  • Form respondents

Types of Personal Data

  • Contact information
  • Account & form response data
  • Technical data (IP, device info)

Processing continues for the duration of the agreement. Upon termination, data handling follows Section 9 of this DPA.

4. Processor Obligations

Form500mg shall:

1Process personal data only on your documented instructions, unless required by applicable law.
2Ensure that persons authorized to process personal data are bound by appropriate confidentiality obligations.
3Implement appropriate technical and organizational security measures.
4Not engage sub-processors without your prior authorization.
5Assist you in responding to data subject rights requests.
6Notify you of personal data breaches without undue delay.
7Delete or return personal data upon termination.
8Make available information necessary to demonstrate compliance with this DPA.

5. Security Measures

🔐Encryption

HTTPS/TLS in transit, industry-standard encryption at rest

🛡️Access Controls

Role-based access, MFA for admins, least privilege principle

☁️Infrastructure

AWS with multi-availability zone deployment

🔑Authentication

JWT-based with secure token rotation, OAuth 2.0

📊Monitoring

Continuous security monitoring and anomaly detection

✉️Email Security

DKIM, SPF, DMARC for Amazon SES; bounce/complaint handling via SNS

🚨Incident Response

Documented procedures for prompt identification and remediation

6. Sub-processors

You provide general authorization for Form500mg to engage sub-processors to assist in providing the Services.

Sub-processorPurpose
Amazon Web Services (AWS)Cloud hosting, email delivery (SES), storage
Google Cloud (Gemini API)AI-assisted form generation
Payment ProcessorSubscription billing

We will provide at least 15 days' advance notice before engaging a new sub-processor. You may object on documented data protection grounds. If we cannot reasonably accommodate your objection, you may terminate the affected Services.

7. Data Subject Rights

Form500mg will provide reasonable assistance to you in responding to requests from data subjects exercising their rights under applicable data protection laws, including requests for access, rectification, erasure, restriction, portability, and objection.

If Form500mg receives a request directly from a data subject, we will promptly redirect the request to you unless legally required to respond directly.

8. Data Breach Notification

Form500mg will notify you of any confirmed personal data breach within 72 hours of becoming aware of the breach. The notification will include:

1A description of the nature of the breach, including the categories and approximate number of data subjects affected.
2The likely consequences of the breach.
3A description of the measures taken or proposed to address the breach and mitigate its effects.

Form500mg will take reasonable steps to contain and remediate the breach and will cooperate with your investigation and notification obligations.

9. Data Return & Deletion

Upon termination of the agreement:

30

Data Export Period

Form500mg will make your data available for export for 30 days after termination.

90

Permanent Deletion

After the 30-day period, all personal data will be permanently deleted within 90 days, unless retention is required by applicable law.

Backup copies will be deleted in accordance with our standard backup rotation schedule.

10. International Data Transfers

Form500mg's Services are hosted in the United States. For personal data originating from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission to ensure an adequate level of data protection.

In such transfers, you act as the data exporter and Form500mg acts as the data importer. The SCCs are incorporated by reference into this DPA.

11. Audits & Compliance

Upon reasonable written request (no more than once annually), Form500mg will provide documentation demonstrating compliance with this DPA. If on-site audits are required, they must be conducted with at least 15 days' advance notice, during business hours, and at your expense.

12. Liability & Miscellaneous

The liability limitations set forth in the Terms of Service apply to claims arising under this DPA, subject to mandatory provisions of applicable data protection law that cannot be contractually limited.

In the event of a conflict between this DPA and the Terms of Service regarding personal data processing, this DPA shall prevail.

Form500mg may update this DPA to comply with changes in applicable data protection laws, with notice to you.

This DPA is governed by the same governing law as the Terms of Service.

13. Contact Us

For questions about this DPA or data processing practices: