🔐 GDPR Art. 28(2) compliance

Sub-processors

These are all the data processors we engage. Per GDPR Art. 28(2), this list is updated whenever we add or change a sub-processor.

Last updated: 2026-06-20

Processor Purpose Data shared Location
FastComet Web hosting (database + uploaded files) Account data, form configurations, submitted responses, billing metadata Canada (Toronto)
Stripe Payment processing Billing email, payment method, subscription status (NO respondent data) Ireland (EU) for EU customers, US for non-EU
Cloudflare CDN + DDoS protection (owner-facing pages only) The connecting IP and User-Agent of every request to the site, form pages included - Cloudflare sits in front of everything as our CDN, exactly as any web server sees the address that connects to it. It is never passed on to us and never stored: there is no IP column anywhere in our database. Global PoPs - a request is served by the one nearest to the visitor
Telegram Admin event notifications (signups, plan upgrades, cron errors) Admin alerts about our own account activity: the user email and plan for a signup, upgrade, payment or cancellation. Bug reports sent through the support chatbot include what the person typed, and their email if they gave one. New-mail alerts include who wrote to us and the subject. Never respondent survey data. US / SG (data crosses EU borders)
Anthropic AI support chatbot, and optional AI insights on a form's answers The text you type into the support chatbot; and, only when a Pro or Team owner presses the AI Insights button, up to 250 anonymous open-text answers from that form. No identities are attached, because none are stored. Never passwords. Not used to train models USA (Anthropic PBC) - engaged only when the chatbot or AI Insights is used

Change notifications

We will notify subscribed customers at least 30 days before adding a new sub-processor, per GDPR Art. 28(2). To receive these notifications, email [email protected] with your account email.

Need a DPA / AVV?

Email [email protected] to request a signed Data Processing Agreement (Auftragsverarbeitungsvertrag / AVV). Standard contractual clauses (SCCs) covered for any non-EU transfers. Response within 3 business days.

What we never share

Respondent identities - because we never collect them. No IP addresses, no User-Agents, no fingerprinting on form-fill pages, and no cookies unless the respondent opts in to a reply channel. There is no respondent identity data to share with any sub-processor, because the database column for it does not exist.