Data processing agreement
Last updated: September 3, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Formable Inc. (“Processor,” “Formable,” “we,” or “us”) and the customer entity that uses the Formable Service (“Controller” or “Customer”). It applies when Formable processes Personal Data on Customer’s behalf in providing the Service.
If Customer has signed a separate written DPA with Formable, that agreement controls to the extent of any conflict with this online DPA.
1. Definitions
“Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” and “Personal Data Breach” have the meanings given in the EU GDPR, UK GDPR, or other applicable data protection law.
“Service” means Formable’s hosted software and APIs for document workflows, including e-signing, redlining, templates, and related features. “Sub-processor” means a third party engaged by Formable to Process Personal Data on behalf of Customer.
2. Roles of the parties
Customer is the Controller (or a processor acting on behalf of a controller). Formable is the Processor for Personal Data contained in Customer Content and related workflow data processed under Customer’s instructions. Each party will comply with data protection laws applicable to its role.
3. Details of processing
- Subject matter: Providing the Service to Customer.
- Duration: For the term of Customer’s use of the Service plus any retention period required by the agreement or law.
- Nature and purpose: Hosting, transmitting, displaying, signing, redlining, notifying, auditing, and supporting document workflows as configured by Customer.
- Types of Personal Data: As determined by Customer, which may include names, email addresses, titles, signature data, IP/device metadata, and document contents that include Personal Data.
- Categories of Data Subjects: As determined by Customer, which may include Customer personnel, counterparties, signers, and other individuals identified in Customer Content.
4. Customer instructions
Formable will Process Personal Data only on documented instructions from Customer, including through the Service configuration and API calls, unless required by law. If Formable believes an instruction infringes applicable data protection law, it will notify Customer without undue delay where legally permitted.
5. Confidentiality
Formable ensures that persons authorized to Process Personal Data are bound by appropriate confidentiality obligations.
6. Security measures
Formable implements appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage, including encryption in transit and at rest where appropriate, access controls, logging, and vulnerability management. Additional information is available on our Security page.
7. Sub-processors
Customer authorizes Formable to engage Sub-processors to support delivery of the Service. Formable will impose data protection obligations on Sub-processors that are no less protective than those in this DPA in material respects.
Formable will remain responsible for Sub-processor performance. Customer may request information about current Sub-processors through their Formable account where available. Formable will provide notice of material Sub-processor changes where required by applicable law or Customer’s written agreement.
8. International transfers
Where Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, Formable will implement an appropriate transfer mechanism, such as the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, unless another lawful mechanism applies.
9. Assistance to Customer
Taking into account the nature of Processing, Formable will:
- Assist Customer by appropriate technical and organizational measures with Data Subject requests, to the extent possible
- Assist Customer with security, breach, DPIA, and prior consultation obligations, considering the information available to Formable
- Make available information reasonably necessary to demonstrate compliance with this DPA
10. Personal Data Breach
Formable will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA, and will provide information reasonably available to help Customer meet its notification obligations.
11. Return or deletion
Upon termination of the Service or written request, Formable will delete or return Personal Data in Customer Content according to Service functionality and Customer instructions, unless retention is required by law or needed for short-term backups that are securely isolated and deleted on a rolling schedule.
12. Audits
Upon reasonable written request, Formable will provide documentation or reports reasonably sufficient to demonstrate compliance with this DPA. If Customer reasonably requires an audit beyond available documentation, the parties will agree on scope, timing, and confidentiality, and audits will be limited to once per twelve months unless a Personal Data Breach or regulatory requirement justifies more frequent review.
13. Liability and order of precedence
Liability under this DPA is subject to the limitations and exclusions in the Formable Terms and Conditions or other governing commercial agreement, except where prohibited by applicable data protection law. If there is a conflict between this DPA and the Terms regarding Processing of Personal Data, this DPA controls.
