Data Processing Agreement
Last updated October 2026
This agreement applies to every customer who uses CatchForm to collect personal data from their own visitors. It is offered as it stands: you do not need to request a copy or negotiate terms. If your organisation requires a signed version, write to hello@catchform.dev with your company details and we will sign one.
1. Who is who
You are the controller. You decide which fields your form collects and why. Your visitors are your data subjects, and informing them is your duty, not ours.
We are the processor: Tilek Kubanov, sole trader, Bishkek, Kyrgyz Republic, reachable at hello@catchform.dev. We act only on your documented instructions. Using the service — creating a form, configuring where notifications go, setting webhooks — is how you give them.
For your own billing data we are not a processor at all: payments run through Paddle, which is the merchant of record and an independent controller for that data. We never see card numbers.
2. What is processed
Subject matter and duration. Receiving, storing and forwarding form submissions, for as long as your account exists.
Categories of data subjects. Anyone who submits one of your forms.
Types of personal data. Whatever your form sends — typically a name, an email address and a message — plus the submitter's IP address and browser user-agent, which we record to stop abuse. We do not choose these fields and we do not inspect them.
Special categories. The service is not built for health, biometric, political or similar data under Article 9. Do not collect it through CatchForm.
3. What we commit to
We process personal data only on your instructions, including for transfers, unless a law we are subject to requires otherwise — in which case we tell you first, unless that law forbids it.
Everyone with access is bound to confidentiality. In practice access is limited to one person: the operator named above.
We help you meet your own obligations: responding to data subject requests, reporting breaches, and running impact assessments. Submissions are exportable to CSV at any time on every plan, so access and portability requests you receive can be answered without us.
Breaches. If personal data we hold for you is exposed, we notify you without undue delay and at the latest within 48 hours of becoming aware, with what we know at that point.
End of the relationship. Delete a form and its submissions go with it. Close your account and everything is removed within 30 days, backups included, except records we must keep for accounting.
Audits. You may ask for the information needed to verify this agreement, and we answer. For on-site inspection, write to us; we are a one-person operation and will agree a reasonable way to satisfy your auditor.
4. Subprocessors
You give general authorisation for the subprocessors below. We tell you by email at least 30 days before adding or replacing one, and you may object; if we cannot resolve your objection, you may terminate and get a refund for the unused period.
- Hetzner Online GmbH (Germany) — the servers holding the database, uploaded files and backups.
- Resend — delivery of notification emails. Content of the submission travels in the notification you asked us to send.
- Paddle — your billing data only. No submission ever reaches Paddle.
Analytics is self-hosted on the same server. No advertising network, tag manager or third-party tracker runs on our pages, so there is no subprocessor behind them.
A webhook you configure sends submissions to a destination of your choosing. That destination is yours, not our subprocessor, and what happens there is outside this agreement.
5. Where the data is, and who can reach it
All submissions, uploaded files and backups are stored on servers in Germany.
The operator administering those servers is located in the Kyrgyz Republic, a country without an EU adequacy decision. Remote administrative access therefore counts as an international transfer. It is covered by the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Three, processor to processor, with Module Two applying where you are the controller), which form part of this agreement; we will sign them separately on request. Access is limited to administration and support, uses key-based SSH over an encrypted channel, and no copy of customer data is kept outside Germany.
We state this plainly because it is the kind of detail that surfaces late in a procurement review. If your policy forbids third-country administrative access, CatchForm is not a fit, and it is better that you know now.
6. Security measures
An honest list of what exists today, not what sounds good:
- All traffic over HTTPS with certificates renewed automatically; the submission endpoint accepts nothing over plain HTTP.
- Passwords stored as bcrypt hashes; API tokens stored hashed and shown once.
- Application and database on a single server in Germany; the database is not exposed to the network.
- Daily backups, 14 copies kept, held on that same server. There is no off-site copy today. A fire in that data centre would destroy the backups with the data. We are saying so rather than letting you assume otherwise.
- Data at rest is not separately encrypted beyond the provider's disk encryption.
- Rate limiting on submission and authentication endpoints; a honeypot field to drop automated spam.
- Notification recipients are confirmed by email before anything is sent to them, so a submission cannot be redirected to an address its owner has not approved.
- Administrative access: one person, SSH keys only, no shared accounts.
7. Liability and precedence
This agreement governs the processing of personal data. Where it conflicts with our terms of service, this agreement wins for data protection matters. Liability is limited as set out in the terms, except where law forbids such limitation.