GDPR Overview

FormCraft is designed to be GDPR-compliant out of the box.

Your rights as a data subject

Right to access your personal data
Right to correct inaccurate data
Right to erasure ('right to be forgotten')
Right to data portability (export as JSON/CSV)
Right to restrict processing
Right to object to processing

How FormCraft supports your compliance

  • • All data stored in the EU (AWS eu-west-1)
  • • DPA available on request for PRO customers
  • • Consent collection block available in the form builder
  • • Response data export in one click from your dashboard
  • • Account deletion removes all personal data within 30 days
  • • Sub-processors listed below and kept to a minimum

Sub-processors

AWS

Infrastructure & storage

EU (Paris)

Stripe

Payment processing

USA (SCCs)

Resend

Transactional email

USA (SCCs)

Questions? Email privacy@formcraft.io or read our full Privacy Policy.