Skip to main content
Hit enter to search or ESC to close
Close Search
formsieve
Menu
  • Features
  • How it works
  • Pricing
  • Docs
  • Support
  • My account
  • Start free trial

    Legal

    Data Processing Agreement

    Version 1.0 · Effective 2026-09-29

    On this page

    • 1. Parties and how this DPA is agreed
    • 2. Definitions
    • 3. Roles
    • 4. Instructions
    • 5. Confidentiality
    • 6. Security
    • 7. Sub-processors
    • 8. Data subject requests
    • 9. Assistance
    • 10. International transfers
    • 11. Personal data breaches
    • 12. Deletion and return
    • 13. Information and audits
    • 14. US state privacy laws
    • 15. EU and UK representatives
    • 16. Liability
    • 17. Term
    • Annex I: Description of the processing and transfer
    • Annex II: Technical and organisational measures
    • Annex III: Sub-processors

    Other policies

    • Terms
    • Refund policy
    • Privacy policy
    • Sub-processors
    • Acceptable use policy
    • Security

    1. Parties and how this DPA is agreed

    1.1 This Data Processing Agreement ("DPA") is between Thinking42, Inc., a Delaware corporation, 1480 NW North River Dr, Apt 2318, Miami, FL 33125, USA ("Thinking42") and the customer that accepted the Formsieve Terms of Service ("Customer").

    1.2 It forms part of the Terms. The Customer accepts it by ticking the box on /subscribe/ or /start/, or in the Formsieve plugin's set-up wizard. A countersigned copy is available on request from support@formsieve.com; it does not change the terms.

    1.3 If this DPA and the Terms conflict, this DPA wins for personal data. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses win.

    2. Definitions

    "GDPR" means Regulation (EU) 2016/679; "UK GDPR" the GDPR as it applies in the UK; "Data Protection Laws" the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (CCPA) and other US state privacy laws, each as far as it applies. "Controller", "processor", "personal data", "personal data breach", "data subject" and "processing" have the meanings in the GDPR. "Customer Personal Data" means the personal data in the Submission Data that the plugin sends to the Service for the Customer. "Standard Contractual Clauses" or "SCCs" means the clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0, in force 2022-03-21).

    3. Roles

    3.1 For Customer Personal Data, the Customer is the controller and Thinking42 is its processor. Where the Customer is itself a processor for a third party (for example an agency running a client's website), the Customer confirms that it has that third party's authorisation for this DPA, and Thinking42 is its sub-processor.

    3.2 Thinking42 is a controller, and its Privacy Policy applies, for: the Customer's account, billing and support data; and usage counts and request records without submission content, as far as it uses them for billing, security, abuse prevention and keeping the Service running across customers.

    4. Instructions

    4.1 Thinking42 processes Customer Personal Data only on the Customer's documented instructions, including for transfers. The instructions are: classify each submission sent by a Formsieve plugin for spam, and return the result, as described in Annex I. The Customer's plugin settings and use of the Service are further instructions.

    4.2 Thinking42 does not: sell or share Customer Personal Data; use it to train, fine-tune or evaluate AI models; use it for profiling, advertising or any purpose of its own; combine it with personal data from other customers or other sources; or keep it after returning the result (§12).

    4.3 Thinking42 tells the Customer promptly if, in its opinion, an instruction infringes Data Protection Laws, and may suspend that processing until the Customer confirms or changes the instruction.

    4.4 If the law requires Thinking42 to process Customer Personal Data otherwise, it tells the Customer first unless the law forbids it.

    5. Confidentiality

    Thinking42 gives access to Customer Personal Data only to personnel who need it to run the Service and who are bound by confidentiality. As of the effective date that is Thinking42's one administrator; any contractor added signs a confidentiality undertaking first.

    6. Security

    Thinking42 implements and maintains the technical and organisational measures in Annex II. It may improve them over time but will not reduce their overall level.

    7. Sub-processors

    7.1 The Customer gives Thinking42 general authorisation to engage sub-processors. The current list, with each one's purpose, location and transfer mechanism, is at https://formsieve.com/subprocessors/ (Annex III). The list includes providers held in standby for failover, marked as such.

    7.2 Thinking42 gives at least 30 days' notice before adding or replacing a sub-processor, by updating the list and e-mailing every account owner and anyone who asked for notices. The Customer may object on reasonable data-protection grounds within 14 days of the notice. The parties then discuss a solution in good faith. If none is found, the Customer may terminate the affected subscription before the change takes effect and receive a refund of the unused prepaid period. In an emergency (for example the sudden loss of a provider), Thinking42 may switch to a sub-processor listed as standby with notice as soon as possible.

    7.3 Thinking42 imposes on each sub-processor, by written contract, data-protection obligations that are no less protective than this DPA, as far as they apply to the service provided, and remains responsible to the Customer for them as the law requires.

    7.4 AI providers (as of 2026-09-27: OpenRouter, Inc., the gateway, and TypeSafe AI, Inc., which runs the model) are sub-processors. Thinking42 requests zero-data-retention routing and "deny data collection" on every request, and keeps logging and "use of inputs" off in its OpenRouter account. As of 2026-09-25, OpenRouter's data processing agreement states that it deletes inputs and outputs promptly after generating the output unless logging is enabled. TypeSafe states that it does not train models on customer data without consent; its terms allow it to derive telemetry from the data it processes and to monitor for abuse, without a stated time limit. TypeSafe's published data processing agreement and privacy policy apply to that processing; on OpenRouter, TypeSafe is listed as a zero-retention provider (as of 2026-09-28, as represented by TypeSafe). Thinking42 will update this clause and the sub-processor list when TypeSafe confirms its retention period in writing.

    8. Data subject requests

    Thinking42 does not store submission content, so it normally holds nothing to search. If Thinking42 receives a request from a data subject about Customer Personal Data, it forwards it to the Customer without undue delay and does not answer it itself, except to say it has forwarded it. It helps the Customer answer requests with appropriate measures, as far as possible, given the nature of the processing.

    9. Assistance

    Thinking42 helps the Customer, with information it holds, to meet its obligations under GDPR Arts. 32 to 36: security, breach notification, data protection impact assessments and prior consultation. A short note for data protection impact assessments is available on request.

    10. International transfers

    10.1 Thinking42 processes Customer Personal Data in the United States (Annex I). Thinking42 is not certified under the EU-U.S. Data Privacy Framework.

    10.2 EU. To the extent the Customer (or its controller) is in the European Economic Area or the transfer is otherwise subject to the GDPR, the parties enter into the SCCs, which are incorporated by reference:

    • Module 2 (controller to processor) where the Customer is a controller; Module 3 (processor to processor) where the Customer is a processor.
    • Clause 7 (docking clause): applies.
    • Clause 9(a): Option 2, general written authorisation, with the notice period in §7.2 (30 days).
    • Clause 11(a): the optional independent dispute resolution body is not used.
    • Clause 13: the supervisory authority in Annex I.C.
    • Clause 17: Option 1, the law of Ireland.
    • Clause 18(b): the courts of Ireland.
    • Annexes I, II and III of the SCCs are Annexes I, II and III of this DPA.
    • For Module 3, Thinking42 informs the Customer, and the Customer informs its controller, as Clause 8.1(b) and (c) require.

    10.3 UK. To the extent the transfer is subject to the UK GDPR, the parties enter into the UK Addendum, which is incorporated by reference. Table 1: the parties are as in Annex I.A. Table 2: the Addendum EU SCCs are the SCCs as incorporated in §10.2, with the modules and options chosen there. Table 3: the Appendix Information is in Annexes I to III. Table 4: the Importer may end the Addendum as set out in its Section 19.

    10.4 Switzerland. To the extent the transfer is subject to the Swiss Federal Act on Data Protection, the SCCs under §10.2 apply with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for such transfers; references to the GDPR are read as references to the Federal Act on Data Protection; and "Member State" includes Switzerland, so data subjects in Switzerland can enforce their rights there.

    10.5 Onward transfers from Thinking42 to its sub-processors happen within the United States under contracts that meet §7.3 and SCC Clause 8.8 and Clause 9.

    10.6 If Data Protection Laws later require a different transfer mechanism, the parties will adopt it.

    11. Personal data breaches

    11.1 Thinking42 notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the aim of doing so within 48 to 72 hours. Where California law applies to data that the Customer owns, Thinking42 notifies the Customer immediately following discovery (Cal. Civ. Code 1798.82(b)).

    11.2 The notice describes, as far as known: the nature of the breach, the categories and approximate numbers of data subjects and records, the likely consequences, and the measures taken or proposed. Information may be given in stages.

    11.3 Thinking42 records every breach, takes reasonable steps to contain it, and helps the Customer notify authorities and data subjects where required. A notice is not an admission of fault.

    12. Deletion and return

    12.1 Thinking42 does not store the content of submissions: it holds Customer Personal Data in memory only for the duration of the request. Request records without submission content are deleted after 30 days; daily totals per key and site (no personal data from submissions) are kept 25 months for billing questions.

    12.2 At the end of the Service, there is no stored submission content to return. Remaining request records are deleted within 30 days. Backups are overwritten within 14 days. Thinking42 confirms deletion in writing on request.

    13. Information and audits

    13.1 Thinking42 makes available the information needed to show compliance with Art. 28 GDPR: this DPA, the security measures in Annex II, the sub-processor list, and its answers to one reasonable written security questionnaire a year.

    13.2 If that is not enough to meet a legal requirement or a regulator's demand, the Customer may audit, once a year, with at least 30 days' notice, during business hours, through an independent auditor bound by confidentiality, at the Customer's cost, without access to other customers' data. Thinking42 does not hold a SOC 2 or ISO 27001 certificate as of the effective date; where a sub-processor has one, Thinking42 relies on its reports.

    14. US state privacy laws

    14.1 To the extent the CCPA applies, Thinking42 is the Customer's "service provider" and processes Customer Personal Data only for the business purpose of spam detection in the Terms. Thinking42 will not: (a) sell or share it; (b) retain, use or disclose it for any purpose other than the business purposes in the Terms, including any commercial purpose; (c) retain, use or disclose it outside the direct business relationship with the Customer; or (d) combine it with personal information it receives from or on behalf of anyone else, or collects from its own interactions with consumers, except as the CCPA permits. Thinking42 complies with the CCPA's applicable obligations, gives the same level of privacy protection the CCPA requires, notifies the Customer if it can no longer meet its obligations, and allows the Customer to take reasonable steps to stop and remediate unauthorised use. Thinking42 certifies that it understands these restrictions.

    14.2 For Virginia, Colorado, Connecticut, Utah and other US state laws with processor terms, §§ 4 to 13 set out the instructions, the nature and purpose of processing, the type of data, the duration, confidentiality, deletion, the information to show compliance, assessments and written flow-down to subcontractors.

    15. EU and UK representatives

    Thinking42 has not yet appointed a representative in the European Union under Art. 27 GDPR or in the United Kingdom under Art. 27 UK GDPR (as of the effective date above). This section will name them once they are appointed. Until then, requests from supervisory authorities and data subjects in those territories go to support@formsieve.com.

    16. Liability

    Each party's liability under this DPA is subject to the limits in the Terms (§16), except where Data Protection Laws or the SCCs do not allow such a limit (for example the SCCs' own liability clause as between the parties and towards data subjects).

    17. Term

    This DPA applies while Thinking42 processes Customer Personal Data for the Customer, and ends when that processing ends and §12 is complete.

    Annex I: Description of the processing and transfer

    A. Parties

    • Data exporter: the Customer (name, address and contact as in its Formsieve account). Role: controller (Module 2) or processor (Module 3). Activities: runs WordPress websites with the Formsieve plugin. Signature and date: acceptance under §1.2.
    • Data importer: Thinking42, Inc., 1480 NW North River Dr, Apt 2318, Miami, FL 33125, USA. Contact: support@formsieve.com. Role: processor. Activities: provides the Formsieve spam-check service. Signature and date: acceptance under §1.2.

    B. Description of the transfer

    Item Description
    Data subjects Visitors who submit forms (or, where offered, comments) on the Customer's websites
    Categories of personal data Values and labels of ordinary form fields (for example name, company, message); the domain of the sender's e-mail address (not the full address); phone numbers, redacted by default; the website's name, address, languages and the descriptions the Customer writes for the site and form; numeric signals (for example number of links, seconds from page load to submit). Not sent: IP addresses, user agents, full e-mail addresses, passwords, uploads, payment, bank, health or ID fields (the plugin excludes fields that look like these)
    Sensitive data (special categories) None intended. The Customer must not use the Service on forms that collect such data (Terms §12, Acceptable Use Policy §2). No additional safeguards apply beyond Annex II
    Frequency Continuous: once for each submission that passes the plugin's local filters
    Nature of the processing Automated classification by an AI model reached through an AI gateway; returning numeric per-question results
    Purpose Spam detection for the Customer's websites, only
    Retention Submission content: not stored, held in memory only for the request. Request records without content: 30 days. Daily totals without submission data: 25 months
    Transfers to sub-processors To the sub-processors in Annex III, for the same purpose and duration

    C. Competent supervisory authority

    For Module 2 and Module 3 transfers: where the Customer is established in an EU Member State, the supervisory authority of that Member State. Where the Customer is not established in the EU but has a representative under Art. 27 GDPR, the supervisory authority of the Member State in which that representative is established. Otherwise, the supervisory authority of the Member State in which the data subjects whose personal data is transferred are located. For the UK: the Information Commissioner's Office. For Switzerland: the Federal Data Protection and Information Commissioner.

    Annex II: Technical and organisational measures

    The same measures are published at /security/.

    1. Encryption in transit. HTTPS only (TLS at Cloudflare's edge). Traffic from Cloudflare to the server runs through an outbound-only, encrypted Cloudflare Tunnel.
    2. Encryption at rest. The server's disk is encrypted (AWS EBS encryption): database, logs and backups on it are encrypted.
    3. No inbound network access. The server has no open inbound ports. Administrative access (SSH) only through Cloudflare Access with a service token and an SSH key.
    4. Isolation. The spam-check API runs outside WordPress, as its own process pool and operating-system user, with its own database user that cannot read the website's database.
    5. No content storage. Submission content is processed in memory only. The web server's request-body buffer is sized so bodies are not written to disk; request bodies are never logged; error handling drops payloads; core dumps are off.
    6. Minimisation. The plugin sends the domain of an e-mail address rather than the address, redacts phone numbers by default, excludes sensitive-looking fields and caps the size of what is sent. The API refuses requests with unexpected fields.
    7. Keys. Formsieve keys are looked up by a SHA-256 hash; logs hold only a short prefix of the hash. Thinking42's AI-provider keys live only in a root-owned configuration file on the server, never in code or logs.
    8. Access control. One named administrator. Multi-factor authentication on the hosting, network, payment, e-mail and AI-provider accounts. Least-privilege cloud credentials for deployment.
    9. Logging and monitoring. Request metadata only (see Annex I). Alerts for errors, latency, spend, unexpected model versions and server health.
    10. Availability. The plugin delivers submissions if the Service is unavailable (fail open). Rate limits per key, per site and per network. A daily spending breaker. Nightly database backups kept 14 days.
    11. Patching. Operating-system security updates install automatically every day; WordPress security releases install automatically; other updates are applied within a week of release.
    12. Incident response. A written plan: detect, contain, assess, notify customers without undue delay (target 48 to 72 hours), record every incident.
    13. Vendor management. Written data-protection terms with each sub-processor; a yearly review of the list and of their transfer mechanisms.
    14. Deletion. Automatic deletion jobs for request records (30 days), idempotency records (10 minutes) and backups (14 days).

    Annex III: Sub-processors

    The list at https://formsieve.com/subprocessors/ applies. Table A as of 2026-09-27: Cloudflare, Inc.; Amazon Web Services, Inc.; OpenRouter, Inc.; TypeSafe AI, Inc.; and TypeSafe AI, Inc.'s direct API as the standby route.

    formsieve

    Every lead through. Every pitch out.

    Product

    • For Gravity Forms
    • For CF7
    • Pricing
    • Changelog

    Resources

    • Docs
    • Getting started
    • Data processing
    • Calibration

    Company

    • Support
    • Cancel a subscription

    Legal

    • Terms
    • Refund and cancellation
    • Privacy policy
    • Data Processing Agreement
    • Withdraw from contract

    Formsieve is made and sold by Thinking42, Inc. It is not affiliated with, endorsed by, or sponsored by TypeSafe AI, Inc., Rocketgenius, Inc., or Rock Lobster Inc. TypeSafe and Jev are trademarks of TypeSafe AI, Inc. Gravity Forms is a registered trademark of Rocketgenius, Inc. Contact Form 7 is a registered trademark of Rock Lobster Inc. WordPress is a registered trademark of the WordPress Foundation. Stripe is a trademark of Stripe, Inc. All other names are used only to identify compatibility or the services we use.

    Formsieve™ by Thinking42 · © 2026 Thinking42, Inc. · support@formsieve.com

    Close Menu
    formsieve
    • Features
    • How it works
    • Pricing
    • Docs
    • Support
    • My account
    • Start free trial
    Start free trial14 days or 500 AI checks. No card.