Data processing agreement
Scope and instructions
This short agreement applies between the customer as controller and FormHush, published by Sacha Dumont, as processor for submitted form data. Its purpose is receipt, classification, temporary storage and routing during the service agreement. Data subjects are form senders; data includes message text and optional names and email addresses. The customer controls fields and destinations and must not send special-category data or credentials.
Confidentiality and security
FormHush processes data only on documented customer instructions, including destination configuration, unless legally required otherwise. Access is limited to authorised persons subject to confidentiality. Measures include HTTPS, hashed account keys, account isolation, rate limits, a required honeypot, email and phone masking before Jev, and scheduled deletion. The customer protects its keys and destination credentials.
Subprocessors and transfers
The customer authorises the providers listed in the privacy policy: Cloudflare, TypeSafe AI (Jev, United States), Polar for billing, and an email delivery provider once named and enabled. Polar may act independently for its own Merchant of Record obligations. Customer-selected delivery channels act according to the customer's instructions. Equivalent data protection obligations and applicable international transfer safeguards must be established before activation. We will notify customers before a new processing provider is enabled, allowing an objection on data protection grounds or termination of the affected service.
Assistance and incidents
FormHush assists with data subject requests, security incidents, impact assessments and regulator enquiries, taking account of the processing and information available. We notify the controller without undue delay after becoming aware of a personal data breach and provide information as it becomes available. We will flag an instruction we believe infringes applicable data protection law.
Deletion, return and verification
Submissions and notification jobs are automatically deleted after 30 days, including after termination. On a verified request we assist with earlier deletion or return of remaining data, except where law requires retention. The customer may export available submissions through its authenticated dashboard API. We provide information needed to demonstrate compliance and allow proportionate audits subject to confidentiality and protection of other customers. Contact hello@formhush.com for instructions, requests or audit arrangements.