GDPR Article 28 DPA

Data Processing Agreement (DPA)

Standard Contractual Clauses & Article 28 GDPR Terms governing the processing of personal data. Last Updated: August 15, 2026.

Binding Processor Terms

This Data Processing Addendum (“DPA”) automatically supplements the Formtruck Terms of Service between Formtruck Inc. (acting as Data Processor) and the Customer (acting as Data Controller). It fulfills the statutory requirements of Article 28(3) of the EU GDPR.

1. Scope & Roles of the Parties

In the course of providing form processing services under the Master Agreement, Formtruck may process personal data on behalf of Customer. The parties acknowledge and agree that Customer is the Data Controller and Formtruck is the Data Processor. Formtruck will process personal data strictly in accordance with Customer's documented instructions as set forth in the Master Agreement.

2. Technical & Organizational Security Measures (TOMs)

Formtruck implements and maintains comprehensive technical and organizational security measures designed to protect Customer Data against unauthorized access, accidental loss, destruction, alteration, or disclosure:

  • Encryption in Transit: All HTTP traffic and API communications are encrypted using Transport Layer Security (TLS 1.3/1.2) with strict HSTS enforcement.
  • Encryption at Rest: All database volumes, backups, and file storage are encrypted at rest using industry-standard AES-256 encryption.
  • Access Control: Administrative access to production clusters requires multi-factor authentication (MFA/2FA), hardware security keys, and least-privilege role-based access control (RBAC).
  • Automated Threat Defense: Continuous rate limiting, IP reputation scoring, automated secret scanning, and DDoS mitigation.

3. Security Incident & Breach Notification

In the event of a confirmed security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (“Data Breach”), Formtruck shall notify Customer without undue delay and, in any event, within seventy-two (72) hours of becoming aware of the breach. Formtruck will provide reasonable assistance and documentation necessary for Customer to satisfy statutory breach reporting obligations under Arts. 33 and 34 GDPR.

4. Assistance with Data Subject Requests (DSR)

Formtruck provides self-service features in the customer dashboard (including submission search, deletion, CSV exports, and the GDPR Compliance Center) to assist Customer in fulfilling Data Subject Requests under Chapter III of the GDPR (Access, Rectification, Erasure, Portability). If Formtruck receives a request directly from a data subject regarding Customer Data, Formtruck will promptly redirect the data subject to Customer.

5. Return and Deletion of Personal Data

Upon termination of the Services or upon Customer's request via the dashboard, Formtruck shall delete or return all Customer Personal Data within thirty (30) days, unless applicable European Union or Member State law requires continued storage of the personal data.

6. Execution & Inquiries

By agreeing to the Formtruck Terms of Service or creating a workspace, you automatically execute this Data Processing Agreement. For custom enterprise DPA counter-signatures, please contact:

Formtruck DPA Compliance Team