Legal
GDPR Compliance
QuipForm is designed with privacy and data protection in mind.
Last updated: June 20, 2026
What is GDPR?
The General Data Protection Regulation (GDPR) is a European Union (EU) privacy law that gives individuals greater control over how their personal data is collected, stored, and processed.
If you collect personal information from individuals located in the European Economic Area (EEA), GDPR may apply to your use of QuipForm.
Is QuipForm GDPR Compliant?
Yes.
QuipForm is designed with privacy and data protection in mind and follows GDPR principles for the processing and protection of personal data.
We implement the following measures:
- Data is encrypted in transit using HTTPS/TLS.
- Data is stored securely using industry-standard infrastructure.
- Users maintain control over the data collected through their forms.
- Users can export or delete their form data at any time.
- Access to customer data is restricted to authorized personnel only when required to operate and support the service.
- Privacy and security are considered throughout product development.
For more information about how we collect and process data, please review our Privacy Policy.
Data Processing Agreement (DPA)
QuipForm provides a Data Processing Agreement (DPA) for customers who require one for GDPR compliance purposes.
If your organization requires a signed DPA, please contact our support team.
Who Owns Form Response Data?
QuipForm provides form-building and submission collection infrastructure.
The creator of a form is the Data Controller for the information collected through that form.
QuipForm acts as a Data Processor and processes form response data solely on behalf of the form creator.
As the form owner, you retain full control over:
- The data you collect
- How long you store it
- Who has access to it
- Whether it is exported or deleted
Data Deletion
You may delete forms and submissions at any time from your QuipForm account.
When data is deleted, it is removed from active systems and scheduled for permanent removal from backups according to our retention policies.
How QuipForm Uses Personal Data
QuipForm acts as a Data Controller for account information required to provide our services, such as:
- Name
- Email address
- Billing information
- Account settings
We do not sell personal information to third parties.
We only share information with trusted service providers that help us operate the platform and deliver requested services.
Subprocessors
QuipForm uses carefully selected third-party providers to operate the service.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, storage |
| Vercel | Application hosting and deployment |
| Cloudflare | DNS, CDN, security |
| Resend | Transactional email delivery |
| Lemon Squeezy | Billing and subscription management |
| Google Cloud | Optional integrations such as Google Sheets |
| OpenAI / Anthropic | Optional AI-powered form generation features |
These providers may process data only as necessary to provide their services and are subject to their own privacy and security obligations.
International Data Transfers
Depending on the services you choose to use, your data may be processed in multiple jurisdictions.
Where applicable, QuipForm works with providers that offer GDPR-compliant safeguards for international data transfers.
Your Rights
Depending on your location, you may have the right to:
- Access your personal data
- Correct inaccurate information
- Request deletion of your data
- Restrict or object to processing
- Request data portability
- Withdraw consent where applicable
Requests can be submitted through our support channels.
Contact
If you have questions regarding GDPR, privacy, or data protection, please contact: hello@quipform.com
or visit: https://quipform.com/privacy