Skip to content

The Free plan is free forever. Pro and Business are buzzing in soon. See pricing

Legal

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the HornetForms Terms of Service ("Terms") between the customer that accepted the Terms ("Customer", "you") and PhraseMine LLC, a Delaware limited liability company, with its registered address at 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA ("PhraseMine", "we", "us"), which operates HornetForms (the "Service").

1. Parties and scope#

  1. This DPA applies when PhraseMine processes Customer Personal Data on your behalf in providing the Service, and that processing is subject to Data Protection Laws.
  2. You act as a controller, or as a processor on behalf of your own controller. PhraseMine acts as your processor, or as your sub-processor where you are a processor.
  3. You accept this DPA when you accept the Terms. No signature is needed. If you need a countersigned copy, email info@hornetforms.com.
  4. This DPA does not cover personal data for which PhraseMine is itself the controller, such as account data, website data and security data. That data is described in our Privacy Policy.

2. Definitions#

Terms such as "controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given in the GDPR. In addition:

  • "Customer Personal Data" means personal data that PhraseMine processes on your behalf in providing the Service, in particular form responses, files uploaded by respondents and response metadata.
  • "Data Protection Laws" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as it forms part of UK law and the UK Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), and US state privacy laws such as the California Consumer Privacy Act as amended ("CCPA"), in each case to the extent they apply to the processing.
  • "Sub-processor" means a third party that PhraseMine engages to process Customer Personal Data.
  • "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
  • "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

3. Processing instructions#

  1. PhraseMine processes Customer Personal Data only on your documented instructions. Your instructions are the Terms, this DPA and the way you configure and use the Service (for example the questions you ask, the notifications, webhooks and retention periods you set, and the responses you export or delete).
  2. If the law to which PhraseMine is subject requires other processing, we will tell you before processing, unless that law prohibits it.
  3. We will tell you promptly if, in our opinion, an instruction infringes Data Protection Laws.
  4. You are responsible for the lawfulness of your instructions and of the Customer Personal Data you collect, including providing notices to and obtaining any consents from respondents.
  5. Annex I describes the processing.

4. Confidentiality#

PhraseMine ensures that everyone it authorises to process Customer Personal Data is bound by a duty of confidentiality, and gives access only to those who need it to provide, secure or support the Service.

5. Security#

  1. PhraseMine implements and maintains the technical and organisational measures in Annex II to protect Customer Personal Data, taking into account the state of the art, the costs, the nature and purposes of the processing and the risks to data subjects.
  2. We may update these measures over time, provided the overall level of protection is not reduced.
  3. You are responsible for the security features within your control, such as keeping passwords and API keys secret, the roles you give workspace members, and the security of the email addresses, webhook endpoints and other destinations you send responses to.

6. Sub-processors#

  1. You give PhraseMine a general authorisation to engage Sub-processors. The current list is on our Sub-processors page (Annex III).
  2. We will give at least 30 days' notice before a new Sub-processor starts processing Customer Personal Data, by updating the Sub-processors page and by emailing customers who have subscribed to updates. To subscribe, email info@hornetforms.com with the subject "Subscribe to sub-processor updates".
  3. You may object to a new Sub-processor on reasonable data-protection grounds by emailing us within that notice period. We will discuss your concerns in good faith. If we cannot resolve them, you may stop using the affected part of the Service, or terminate the Terms by deleting your account, as your sole remedy.
  4. PhraseMine imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA, by written contract.
  5. PhraseMine remains fully liable to you for the performance of its Sub-processors' obligations.

7. Data subject requests#

  1. The Service lets you answer most requests from data subjects yourself: you can find, export, edit and delete responses and their files.
  2. Taking into account the nature of the processing, PhraseMine will give you reasonable assistance, by appropriate technical and organisational measures, so you can respond to requests to exercise data subjects' rights.
  3. If we receive a request directly from a data subject about Customer Personal Data, we will forward it to you where we can identify you, and we will not respond to it ourselves except to tell the data subject to contact you, unless the law requires otherwise.

8. Personal data breaches#

  1. PhraseMine will notify you without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
  2. The notice will include, as far as it is available: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the name and contact details of our contact point; the likely consequences of the breach; and the measures taken or proposed to address it and to mitigate its possible adverse effects. Where we cannot give all of this at once, we will give it in phases without undue further delay.
  3. We will take reasonable steps to contain and investigate the breach and will cooperate with you so you can meet your own obligations. Our notice is not an admission of fault or liability.

9. Impact assessments and prior consultation#

Taking into account the nature of the processing and the information available to us, PhraseMine will give you reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities that relate to the Service, and with your other obligations under Articles 32 to 36 GDPR.

10. Deletion and return#

  1. You can export Customer Personal Data through the Service at any time while you have an account.
  2. When you delete responses, forms, a workspace or your account, PhraseMine deletes the related Customer Personal Data from its live systems. Deleted forms stay in the trash for 30 days before they are deleted.
  3. Backups expire on their normal rotation. Encrypted off-site and on-server database backups are kept for 14 days, and our hosting provider's whole-server backups for 7 days, so deleted data is gone from all backups within about three weeks. Backups are used only to restore the Service.
  4. This does not apply where EU or Member State law (or other law applicable to PhraseMine) requires storage of the personal data.

11. Audits#

  1. PhraseMine will make available to you all information necessary to demonstrate compliance with this DPA and Article 28 GDPR. This includes this DPA, the Sub-processor list, a summary of our security measures, and answers to a reasonable security or privacy questionnaire once per year.
  2. Where that information is not sufficient to demonstrate compliance, or where a supervisory authority or Data Protection Laws require it, PhraseMine will allow for and contribute to audits, including inspections, by you or by an independent auditor you mandate.
  3. Audits must be requested with at least 30 days' notice (unless a supervisory authority requires less), take place during business hours, avoid disrupting the Service and other customers, respect the confidentiality of other customers' data and our security, and be carried out under a confidentiality agreement. You bear the costs of the audit.
  4. Nothing in this section limits the rights of a supervisory authority or any audit right under the SCCs.

12. International transfers#

  1. Customer Personal Data is stored in the European Union (Germany). PhraseMine LLC is established in the United States, so its access to Customer Personal Data from the EEA, the UK or Switzerland is a restricted transfer.
  2. EU SCCs. To the extent a transfer is subject to the GDPR, the SCCs are incorporated into this DPA by reference, with you as the data exporter and PhraseMine as the data importer, as follows:
    • Module 2 (controller to processor) applies where you are a controller, and Module 3 (processor to processor) applies where you are a processor;
    • Clause 7 (docking clause) is included;
    • Clause 9(a): option 2 (general written authorisation) applies, with the notice period in section 6 of this DPA (30 days);
    • Clause 11(a): the optional language is not included;
    • Clause 13: the competent supervisory authority is determined as set out in Clause 13(a) of the SCCs;
    • Clauses 17 and 18: the SCCs are governed by the law of Ireland, and disputes are resolved by the courts of Ireland;
    • Annexes I, II and III of the SCCs are completed by Annexes I, II and III of this DPA.
  3. Onward transfers. PhraseMine's onward transfers to its own Sub-processors outside the EEA are made in line with Clause 8.8 of the SCCs, and PhraseMine has its own transfer safeguards in place with each such Sub-processor (the SCCs or, where the Sub-processor is certified, the EU-U.S. Data Privacy Framework).
  4. UK. To the extent a transfer is subject to the UK GDPR, the UK Addendum applies and is incorporated by reference. Its Part 1 tables are completed as follows: Table 1 by Annex I.A of this DPA; Table 2 by the modules and clause options in section 12.2; Table 3 by Annexes I to III of this DPA; and in Table 4, either party may end the UK Addendum as set out in its Section 19.
  5. Switzerland. To the extent a transfer is subject to the FADP, the SCCs apply with these changes: the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority; references to the GDPR are read as references to the FADP; and the term "Member State" is read to include Switzerland, so that data subjects in Switzerland can bring claims in their place of habitual residence.
  6. Data Privacy Framework. Where a recipient is certified under the EU-U.S. Data Privacy Framework (or its UK extension or the Swiss-U.S. framework) and the certification covers the transfer, the parties may rely on it instead.
  7. Precedence. If the SCCs or the UK Addendum conflict with this DPA or the Terms, the SCCs or the UK Addendum prevail.

13. US state privacy laws#

To the extent the CCPA or a similar US state law applies, PhraseMine acts as your "service provider" or "processor" and will not:

  • sell or share Customer Personal Data (as those terms are defined in the CCPA);
  • retain, use or disclose Customer Personal Data for any purpose other than the business purpose of providing the Service under the Terms, or outside the direct business relationship between you and us;
  • combine Customer Personal Data with personal data it receives from or on behalf of anyone else, or collects from its own interactions with consumers, except as those laws permit.

PhraseMine will comply with the obligations that apply to it under those laws, provide the same level of privacy protection they require, and tell you if it can no longer meet them. You may take reasonable steps to stop and remediate any unauthorised use of Customer Personal Data. PhraseMine certifies that it understands and will comply with the restrictions in this section.

14. Liability#

Each party's liability arising from or related to this DPA is subject to the limitations of liability in the Terms, to the extent permitted by law. Nothing in this DPA limits a party's liability to data subjects under the SCCs.

15. Order of precedence#

If there is a conflict between documents, this order applies: (1) the SCCs and the UK Addendum, where they apply; (2) this DPA; (3) the Terms.

Annex I: Description of the processing#

A. List of parties#

Data exporter: the Customer, as identified in its HornetForms account. Contact: the email address of the account owner. Role: controller (Module 2) or processor (Module 3). Activities: using the Service to create forms and collect responses. Signature and date: by accepting the Terms.

Data importer: PhraseMine LLC, 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA. Contact: info@hornetforms.com. Role: processor (Module 2) or sub-processor (Module 3). Activities: providing the Service. Signature and date: by making the Service available under the Terms.

B. Description of the transfer#

ItemDescription
Categories of data subjectsRespondents to the Customer's forms; the Customer's users and workspace members, to the extent their data appears in Customer Personal Data
Categories of personal dataWhatever the Customer chooses to collect in its forms (for example names, contact details, answers and files), and response metadata: timestamps, duration, browser user agent, referring page, UTM parameters, language and a hashed IP address
Special categories of dataOnly if the Customer chooses to collect them. The Customer is responsible for having a legal basis for them. The safeguards in Annex II apply to all data.
Frequency of the transferContinuous, for as long as the Customer uses the Service
Nature of the processingHosting, storage, delivery (email notifications, confirmation emails and webhooks), cookieless form analytics, export, backup and deletion
Purpose of the processingProviding the Service to the Customer under the Terms
Subject-matter and durationThe subject-matter is the provision of the Service. The processing lasts for the term of the Terms, plus the deletion period in section 10 of this DPA.
RetentionAs configured by the Customer (for example a form's automatic deletion period of 1 to 3,650 days), or until the Customer deletes the data, then as set out in section 10
Transfers to Sub-processorsAs listed in Annex III, for the subject-matter, nature and duration described there

C. Competent supervisory authority#

The supervisory authority determined in accordance with Clause 13 of the SCCs. For transfers under the UK Addendum, the UK Information Commissioner's Office; for transfers subject to the FADP, the Swiss FDPIC.

Annex II: Technical and organisational measures#

  • Encryption in transit: HTTPS for every connection to the Service, using TLS 1.2 or higher.
  • Hosting: servers, database and uploaded files hosted by Hetzner Online GmbH in ISO 27001-certified data centres in Germany.
  • Server hardening: network firewall that allows only web traffic and administrative SSH, administrative access by SSH keys only (no password logins), protection against repeated failed logins, and automatic installation of security updates.
  • Data minimisation and hashing: passwords, sign-in and verification tokens, API key secrets and respondents' IP addresses are stored only as hashes. Raw IP addresses are not stored with responses.
  • Encryption of secrets: webhook signing secrets and other integration secrets are stored encrypted.
  • Access control in the Service: role-based access to workspaces; API keys are scoped to a workspace and can be revoked.
  • Abuse protection: rate limiting, optional bot protection (Cloudflare Turnstile), honeypots and minimum fill times on forms.
  • Backups: nightly database and upload backups, encrypted before they are copied off-site, kept for 14 days; restores are tested.
  • Logging: technical logs without form answers, request bodies, raw IP addresses, email addresses, passwords or tokens.
  • Error reporting: error reports are scrubbed of email addresses, IP addresses, tokens, query strings, cookies and answer data before they leave our servers.
  • Least privilege: administrative access to production systems is limited to the people who need it.
  • Incident response: monitoring of availability and errors, and a process to investigate, contain and notify personal data breaches as described in section 8.

Annex III: Sub-processors#

The Sub-processors authorised under section 6 are listed on our Sub-processors page, which forms part of this DPA.