Legal
Data Processing Agreement
Version 1.0 · Effective 2026-09-29
Legal
Version 1.0 · Effective 2026-09-29
1.1 This Data Processing Agreement ("DPA") is between Thinking42, Inc., a Delaware corporation, 1480 NW North River Dr, Apt 2318, Miami, FL 33125, USA ("Thinking42") and the customer that accepted the Formsieve Terms of Service ("Customer").
1.2 It forms part of the Terms. The Customer accepts it by ticking the box on /subscribe/ or /start/, or in the Formsieve plugin's set-up wizard. A countersigned copy is available on request from support@formsieve.com; it does not change the terms.
1.3 If this DPA and the Terms conflict, this DPA wins for personal data. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses win.
"GDPR" means Regulation (EU) 2016/679; "UK GDPR" the GDPR as it applies in the UK; "Data Protection Laws" the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (CCPA) and other US state privacy laws, each as far as it applies. "Controller", "processor", "personal data", "personal data breach", "data subject" and "processing" have the meanings in the GDPR. "Customer Personal Data" means the personal data in the Submission Data that the plugin sends to the Service for the Customer. "Standard Contractual Clauses" or "SCCs" means the clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0, in force 2022-03-21).
3.1 For Customer Personal Data, the Customer is the controller and Thinking42 is its processor. Where the Customer is itself a processor for a third party (for example an agency running a client's website), the Customer confirms that it has that third party's authorisation for this DPA, and Thinking42 is its sub-processor.
3.2 Thinking42 is a controller, and its Privacy Policy applies, for: the Customer's account, billing and support data; and usage counts and request records without submission content, as far as it uses them for billing, security, abuse prevention and keeping the Service running across customers.
4.1 Thinking42 processes Customer Personal Data only on the Customer's documented instructions, including for transfers. The instructions are: classify each submission sent by a Formsieve plugin for spam, and return the result, as described in Annex I. The Customer's plugin settings and use of the Service are further instructions.
4.2 Thinking42 does not: sell or share Customer Personal Data; use it to train, fine-tune or evaluate AI models; use it for profiling, advertising or any purpose of its own; combine it with personal data from other customers or other sources; or keep it after returning the result (§12).
4.3 Thinking42 tells the Customer promptly if, in its opinion, an instruction infringes Data Protection Laws, and may suspend that processing until the Customer confirms or changes the instruction.
4.4 If the law requires Thinking42 to process Customer Personal Data otherwise, it tells the Customer first unless the law forbids it.
Thinking42 gives access to Customer Personal Data only to personnel who need it to run the Service and who are bound by confidentiality. As of the effective date that is Thinking42's one administrator; any contractor added signs a confidentiality undertaking first.
Thinking42 implements and maintains the technical and organisational measures in Annex II. It may improve them over time but will not reduce their overall level.
7.1 The Customer gives Thinking42 general authorisation to engage sub-processors. The current list, with each one's purpose, location and transfer mechanism, is at https://formsieve.com/subprocessors/ (Annex III). The list includes providers held in standby for failover, marked as such.
7.2 Thinking42 gives at least 30 days' notice before adding or replacing a sub-processor, by updating the list and e-mailing every account owner and anyone who asked for notices. The Customer may object on reasonable data-protection grounds within 14 days of the notice. The parties then discuss a solution in good faith. If none is found, the Customer may terminate the affected subscription before the change takes effect and receive a refund of the unused prepaid period. In an emergency (for example the sudden loss of a provider), Thinking42 may switch to a sub-processor listed as standby with notice as soon as possible.
7.3 Thinking42 imposes on each sub-processor, by written contract, data-protection obligations that are no less protective than this DPA, as far as they apply to the service provided, and remains responsible to the Customer for them as the law requires.
7.4 AI providers (as of 2026-09-27: OpenRouter, Inc., the gateway, and TypeSafe AI, Inc., which runs the model) are sub-processors. Thinking42 requests zero-data-retention routing and "deny data collection" on every request, and keeps logging and "use of inputs" off in its OpenRouter account. As of 2026-09-25, OpenRouter's data processing agreement states that it deletes inputs and outputs promptly after generating the output unless logging is enabled. TypeSafe states that it does not train models on customer data without consent; its terms allow it to derive telemetry from the data it processes and to monitor for abuse, without a stated time limit. TypeSafe's published data processing agreement and privacy policy apply to that processing; on OpenRouter, TypeSafe is listed as a zero-retention provider (as of 2026-09-28, as represented by TypeSafe). Thinking42 will update this clause and the sub-processor list when TypeSafe confirms its retention period in writing.
Thinking42 does not store submission content, so it normally holds nothing to search. If Thinking42 receives a request from a data subject about Customer Personal Data, it forwards it to the Customer without undue delay and does not answer it itself, except to say it has forwarded it. It helps the Customer answer requests with appropriate measures, as far as possible, given the nature of the processing.
Thinking42 helps the Customer, with information it holds, to meet its obligations under GDPR Arts. 32 to 36: security, breach notification, data protection impact assessments and prior consultation. A short note for data protection impact assessments is available on request.
10.1 Thinking42 processes Customer Personal Data in the United States (Annex I). Thinking42 is not certified under the EU-U.S. Data Privacy Framework.
10.2 EU. To the extent the Customer (or its controller) is in the European Economic Area or the transfer is otherwise subject to the GDPR, the parties enter into the SCCs, which are incorporated by reference:
10.3 UK. To the extent the transfer is subject to the UK GDPR, the parties enter into the UK Addendum, which is incorporated by reference. Table 1: the parties are as in Annex I.A. Table 2: the Addendum EU SCCs are the SCCs as incorporated in §10.2, with the modules and options chosen there. Table 3: the Appendix Information is in Annexes I to III. Table 4: the Importer may end the Addendum as set out in its Section 19.
10.4 Switzerland. To the extent the transfer is subject to the Swiss Federal Act on Data Protection, the SCCs under §10.2 apply with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for such transfers; references to the GDPR are read as references to the Federal Act on Data Protection; and "Member State" includes Switzerland, so data subjects in Switzerland can enforce their rights there.
10.5 Onward transfers from Thinking42 to its sub-processors happen within the United States under contracts that meet §7.3 and SCC Clause 8.8 and Clause 9.
10.6 If Data Protection Laws later require a different transfer mechanism, the parties will adopt it.
11.1 Thinking42 notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the aim of doing so within 48 to 72 hours. Where California law applies to data that the Customer owns, Thinking42 notifies the Customer immediately following discovery (Cal. Civ. Code 1798.82(b)).
11.2 The notice describes, as far as known: the nature of the breach, the categories and approximate numbers of data subjects and records, the likely consequences, and the measures taken or proposed. Information may be given in stages.
11.3 Thinking42 records every breach, takes reasonable steps to contain it, and helps the Customer notify authorities and data subjects where required. A notice is not an admission of fault.
12.1 Thinking42 does not store the content of submissions: it holds Customer Personal Data in memory only for the duration of the request. Request records without submission content are deleted after 30 days; daily totals per key and site (no personal data from submissions) are kept 25 months for billing questions.
12.2 At the end of the Service, there is no stored submission content to return. Remaining request records are deleted within 30 days. Backups are overwritten within 14 days. Thinking42 confirms deletion in writing on request.
13.1 Thinking42 makes available the information needed to show compliance with Art. 28 GDPR: this DPA, the security measures in Annex II, the sub-processor list, and its answers to one reasonable written security questionnaire a year.
13.2 If that is not enough to meet a legal requirement or a regulator's demand, the Customer may audit, once a year, with at least 30 days' notice, during business hours, through an independent auditor bound by confidentiality, at the Customer's cost, without access to other customers' data. Thinking42 does not hold a SOC 2 or ISO 27001 certificate as of the effective date; where a sub-processor has one, Thinking42 relies on its reports.
14.1 To the extent the CCPA applies, Thinking42 is the Customer's "service provider" and processes Customer Personal Data only for the business purpose of spam detection in the Terms. Thinking42 will not: (a) sell or share it; (b) retain, use or disclose it for any purpose other than the business purposes in the Terms, including any commercial purpose; (c) retain, use or disclose it outside the direct business relationship with the Customer; or (d) combine it with personal information it receives from or on behalf of anyone else, or collects from its own interactions with consumers, except as the CCPA permits. Thinking42 complies with the CCPA's applicable obligations, gives the same level of privacy protection the CCPA requires, notifies the Customer if it can no longer meet its obligations, and allows the Customer to take reasonable steps to stop and remediate unauthorised use. Thinking42 certifies that it understands these restrictions.
14.2 For Virginia, Colorado, Connecticut, Utah and other US state laws with processor terms, §§ 4 to 13 set out the instructions, the nature and purpose of processing, the type of data, the duration, confidentiality, deletion, the information to show compliance, assessments and written flow-down to subcontractors.
Thinking42 has not yet appointed a representative in the European Union under Art. 27 GDPR or in the United Kingdom under Art. 27 UK GDPR (as of the effective date above). This section will name them once they are appointed. Until then, requests from supervisory authorities and data subjects in those territories go to support@formsieve.com.
Each party's liability under this DPA is subject to the limits in the Terms (§16), except where Data Protection Laws or the SCCs do not allow such a limit (for example the SCCs' own liability clause as between the parties and towards data subjects).
This DPA applies while Thinking42 processes Customer Personal Data for the Customer, and ends when that processing ends and §12 is complete.
A. Parties
B. Description of the transfer
| Item | Description |
|---|---|
| Data subjects | Visitors who submit forms (or, where offered, comments) on the Customer's websites |
| Categories of personal data | Values and labels of ordinary form fields (for example name, company, message); the domain of the sender's e-mail address (not the full address); phone numbers, redacted by default; the website's name, address, languages and the descriptions the Customer writes for the site and form; numeric signals (for example number of links, seconds from page load to submit). Not sent: IP addresses, user agents, full e-mail addresses, passwords, uploads, payment, bank, health or ID fields (the plugin excludes fields that look like these) |
| Sensitive data (special categories) | None intended. The Customer must not use the Service on forms that collect such data (Terms §12, Acceptable Use Policy §2). No additional safeguards apply beyond Annex II |
| Frequency | Continuous: once for each submission that passes the plugin's local filters |
| Nature of the processing | Automated classification by an AI model reached through an AI gateway; returning numeric per-question results |
| Purpose | Spam detection for the Customer's websites, only |
| Retention | Submission content: not stored, held in memory only for the request. Request records without content: 30 days. Daily totals without submission data: 25 months |
| Transfers to sub-processors | To the sub-processors in Annex III, for the same purpose and duration |
C. Competent supervisory authority
For Module 2 and Module 3 transfers: where the Customer is established in an EU Member State, the supervisory authority of that Member State. Where the Customer is not established in the EU but has a representative under Art. 27 GDPR, the supervisory authority of the Member State in which that representative is established. Otherwise, the supervisory authority of the Member State in which the data subjects whose personal data is transferred are located. For the UK: the Information Commissioner's Office. For Switzerland: the Federal Data Protection and Information Commissioner.
The same measures are published at /security/.
The list at https://formsieve.com/subprocessors/ applies. Table A as of 2026-09-27: Cloudflare, Inc.; Amazon Web Services, Inc.; OpenRouter, Inc.; TypeSafe AI, Inc.; and TypeSafe AI, Inc.'s direct API as the standby route.