Draft. Fill in the highlighted details in lib/legal.ts and have the text reviewed. Until then these pages aren't indexed or linked.
Legal
Data Processing Agreement
The terms under which we process personal data in your form submissions for you. It applies automatically to every account.
Effective 28 September 2026
In short
- You decide what your forms collect; we only process it on your instructions.
- We keep it confidential and secure, and tell you without undue delay if there's a breach.
- We help you answer requests from the people who fill in your forms.
- When you delete data or close your account, we delete it.
Parties and scope
This Data Processing Agreement ("DPA") is between you, the customer ("controller"), and [company legal name], [registered address] ("processor"). It forms part of our Terms of Service and applies whenever we process personal data on your behalf, which mainly means the form submissions, files and contacts in your workspaces.
It's written to meet Article 28 of the EU General Data Protection Regulation and the UK GDPR. Where it conflicts with the Terms of Service, this DPA wins for anything about personal data.
Details of the processing
- Subject matter: hosting, storing and delivering the form submissions your websites send to SiteBackend.
- Duration: as long as you use SiteBackend, until the data is deleted as described below.
- Nature and purpose: receiving submissions, filtering spam, storing submissions, files and contacts, showing them in the dashboard, exporting them on request, and sending them to the notification destinations you configure.
- Types of personal data: whatever your forms collect (typically names, email addresses, phone numbers, messages and attached files), plus technical details: a hashed IP address, country, browser (user agent) and referring page.
- Data subjects: people who fill in your forms, and the contacts and notes your team manages.
- Special categories: we don't intend to process them. Don't collect them through SiteBackend unless you have a lawful basis and the right safeguards.
Our obligations
We will:
- Process personal data only on your documented instructions, which are these terms, your settings and how you use the dashboard, unless the law requires otherwise. If we think an instruction breaks data protection law, we'll tell you.
- Make sure everyone who can access the data is bound to confidentiality.
- Keep appropriate technical and organisational security measures in place (see below).
- Use subprocessors only as described in this DPA.
- Help you respond to requests from data subjects, and with security, breach notifications, data protection impact assessments and consultations with authorities, taking into account what we know about the processing.
- Delete or return the data when the service ends, as described below.
- Give you the information you need to show you're meeting Article 28, and allow for audits as described below.
Security measures
- Encryption in transit (HTTPS) for all traffic to and from SiteBackend.
- Notification secrets and tokens encrypted at rest with AES-256-GCM. Sender IP addresses stored only as keyed hashes.
- Uploaded files kept private and downloadable only by signed-in members of the workspace. Anything other than common image types downloads as an attachment and is never shown as a web page.
- Access limited to each workspace's members, with owner, admin and member roles.
- Outgoing webhook requests blocked from reaching private or internal network addresses.
- Regular database backups.
Subprocessors
You authorise us to use the subprocessors listed on our Subprocessors page. We make sure each one is bound by data protection terms at least as protective as this DPA, and we remain responsible for them.
We'll update that page at least 30 days before adding or replacing a subprocessor, and email account owners when we do. If you object on reasonable data protection grounds, tell us within that time. If we can't resolve it, you can end the affected service.
Destinations you configure yourself, such as Slack, Google Sheets or your own webhook, aren't our subprocessors: you choose to send data there, under your own agreement with them.
Personal data breaches
If we become aware of a breach affecting your personal data, we'll notify you without undue delay, and within 72 hours where possible. We'll tell you what we know about what happened, the data affected, the likely consequences and what we're doing about it, and we'll keep you updated as we learn more.
International transfers
Our servers and database run in [hosting region]. Where personal data is transferred outside the UK or the European Economic Area to a country without an adequacy decision, the European Commission's Standard Contractual Clauses (and the UK Addendum, where relevant) apply, and are incorporated into this DPA by reference.
Deletion and return
- You can export submissions and contacts as CSV, and delete submissions, contacts, forms, sites and workspaces at any time. Deleting data also removes the related uploaded files from storage.
- When your account is closed, we delete the personal data we process for you within 30 days, unless the law requires us to keep it.
- Deleted data may remain in backups for a short time until they're replaced.
Audits
We'll answer reasonable written questions about our data protection practices. If that isn't enough to show compliance, you may audit us once a year, with at least 30 days' notice, during business hours, at your own cost, and under confidentiality.
Liability
Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the law doesn't allow those limits.
Contact
Data protection questions and notices: [privacy email].