Privacy Policy
Last updated: April 15, 2026
This Privacy Policy explains how FormWire ("we", "us", or "our") collects, uses, and protects personal data. We're a company registered in the Netherlands, with our registered office in Amsterdam.
This policy is written under the EU General Data Protection Regulation (GDPR) and the Dutch Telecommunications Act. If you have questions, contact us at privacy@formwire.app.
A note on who we're processing data for
FormWire plays two different roles depending on whose data we're handling. This policy covers both, but they're legally distinct.
When we're a controller. We make decisions about how and why your personal data is used. This is the case when:
- You sign up for a FormWire account.
- You visit our website (formwire.app).
- You contact our support team.
- You receive marketing from us.
When we're a processor. We process personal data on behalf of one of our customers, on their instructions. This is the case when:
- You submit a form on a website that uses FormWire to handle its form submissions.
In that case, the website operator (our customer) is the controller of your data — not us. To exercise your rights over that data, contact the website operator directly. If you can't reach them, contact us at privacy@formwire.app and we'll help you identify them.
1. What data we collect, and why
1.1 Account data
When you sign up, we collect:
- Email address. For account login, service notifications, and (with your consent or where permitted) marketing.
- Name. For personalization in the dashboard and on receipts.
- Password. Stored as a salted hash — we never see or store your actual password.
- Organization name (optional). For team and billing purposes.
Lawful basis: performance of a contract (GDPR Article 6(1)(b)).
1.2 Billing data
If you upgrade to a paid plan:
- Billing address, VAT number, country. For invoicing and tax compliance.
- Payment method details. Handled by our payment processor (Stripe). We don't see or store your full card number — we receive only a token and the last four digits for reference.
- Transaction history. Invoice records, payment status.
Lawful basis: performance of a contract, and legal obligation (Article 6(1)(b) and (c)) — Dutch and EU tax law requires us to retain financial records for seven years.
1.3 Usage data
When you use the dashboard, we collect:
- Log data: IP address, browser, operating system, pages visited, actions taken, timestamps.
- Device data: screen size, language preferences, time zone.
- Performance data: response times, errors encountered.
Lawful basis: legitimate interest (Article 6(1)(f)) — we need this to operate, secure, and improve the service. You can object to this processing under Section 5.
1.4 Support data
When you contact support, we collect your conversation history and anything you choose to share in the course of getting help.
Lawful basis: performance of a contract (when you're a customer) or legitimate interest (when you're a prospect or visitor).
1.5 Website data
When you visit formwire.app:
- Analytics data: pages viewed, referring URL, approximate location (city level), browser, operating system.
- Cookies and similar technologies. See Section 7.
Lawful basis: legitimate interest for essential analytics, consent for non-essential cookies and tracking.
1.6 Marketing data
If you sign up for our newsletter, request a demo, or otherwise opt in:
- Email address, name, and any information you provide.
- Engagement data: opens, clicks.
Lawful basis: consent (Article 6(1)(a)). You can withdraw consent any time via the unsubscribe link in any email or by contacting privacy@formwire.app.
2. What we don't do with your data
- We don't sell your personal data. Ever, to anyone.
- We don't share your data with advertisers or data brokers.
- We don't use your form submissions or account data to train AI models.
- We don't read your form submissions except when strictly necessary to operate the service (e.g., debugging an issue you've raised, or running automated spam analysis).
3. Who we share data with
3.1 Sub-processors
Third parties that help us operate FormWire. They process data on our instructions and are bound by data processing agreements. A current list of sub-processors is available on request at privacy@formwire.app. The list typically includes:
- Cloud hosting (Hetzner) — where the application and database run.
- Email delivery (Postmark) — for transactional and notification emails.
- Payment processing (Stripe) — for handling payments.
- Analytics (Plausible) — for understanding website usage.
- Error tracking (Sentry) — for monitoring application errors.
3.2 Authorities and legal requests
We may disclose personal data if required by law, court order, or other valid legal process, or to protect our rights, safety, or property. We'll notify affected users where legally permitted.
3.3 Business transfers
If FormWire is acquired, merges with another company, or transfers substantially all its assets, personal data may be transferred to the acquiring entity, subject to this policy or a comparable one. We'll notify users in advance.
4. International transfers
Our infrastructure is hosted in the EU (Germany). Where personal data is transferred outside the European Economic Area (EEA) — for example, to a US-based sub-processor — we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable.
- EU-US Data Privacy Framework for transfers to certified US recipients.
- Adequacy decisions for transfers to countries the European Commission has determined offer equivalent protection.
You can request a copy of the relevant safeguards by contacting privacy@formwire.app.
5. Your rights
Under GDPR, you have the following rights regarding your personal data:
- Access. Get a copy of the personal data we hold about you.
- Rectification. Correct inaccurate or incomplete data.
- Erasure. Have your data deleted, subject to our legal retention obligations.
- Restriction. Limit how we process your data in certain circumstances.
- Portability. Receive your data in a structured, machine-readable format, or have it transmitted to another controller.
- Objection. Object to processing based on legitimate interest, or to direct marketing.
- Withdraw consent. Where processing is based on consent, withdraw it at any time.
- Complain. Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your EU country of residence.
To exercise any of these rights, email privacy@formwire.app. We'll respond within one month, and may extend by two months for complex requests (we'll tell you if we need to).
We may need to verify your identity before acting on a request. We won't charge a fee unless requests are manifestly unfounded or excessive.
6. How long we keep your data
| Data | Retention period |
|---|---|
| Account data | While your account is active, plus 90 days after termination |
| Billing/financial records | 7 years (Dutch tax law) |
| Server logs | 30 days |
| Support correspondence | 2 years after the last interaction |
| Marketing data | Until you withdraw consent or 2 years of inactivity |
| Backups | Rolling, typically overwritten within 90 days |
For form submissions we process on behalf of customers (processor role), retention is governed by the customer's configuration and our Data Processing Agreement — see Section 4.4 of our Terms of Service.
7. Cookies and similar technologies
We use cookies and similar technologies to operate the service. They fall into three categories:
- Strictly necessary. Required for the service to function (e.g., authentication, security). These don't require consent under EU law.
- Functional. Remember your preferences (e.g., dark mode). Set with your consent where required.
- Analytics. Help us understand how the service is used. Set with your consent where required.
We don't use advertising or tracking cookies.
8. Security
We take security seriously. Measures include:
- Encryption in transit (TLS) for all data flowing to and from our service.
- Encryption at rest for the database.
- Role-based access controls limiting which staff can access production data.
- Regular security reviews and dependency monitoring.
- Logging and alerting for suspicious access patterns.
If we discover a breach affecting your personal data, we'll notify you and the relevant supervisory authority within 72 hours where required by GDPR Article 33.
To report a security issue, contact security@formwire.app.
9. Children
FormWire is not directed at children. We don't knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@formwire.app and we'll delete it.
If you're a customer using FormWire to collect submissions that may include data from children, you are responsible for obtaining the necessary parental consents.
10. Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we'll notify you by email or through the dashboard at least 30 days before they take effect. The "Last updated" date at the top of this page indicates when the current version became effective.
If you don't agree with the updated policy, you can terminate your account before the changes take effect.
11. Contact us
For privacy questions, requests, or concerns:
Email: privacy@formwire.app
Post: FormWire, Amsterdam, Netherlands
Supervisory authority:
Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
Postbus 93374
2509 AJ Den Haag
Netherlands
autoriteitpersoonsgegevens.nl