Data processing agreement

Last updated: September 3, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Formable Inc. (“Processor,” “Formable,” “we,” or “us”) and the customer entity that uses the Formable Service (“Controller” or “Customer”). It applies when Formable processes Personal Data on Customer’s behalf in providing the Service.

If Customer has signed a separate written DPA with Formable, that agreement controls to the extent of any conflict with this online DPA.

1. Definitions

“Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” and “Personal Data Breach” have the meanings given in the EU GDPR, UK GDPR, or other applicable data protection law.

“Service” means Formable’s hosted software and APIs for document workflows, including e-signing, redlining, templates, and related features. “Sub-processor” means a third party engaged by Formable to Process Personal Data on behalf of Customer.

2. Roles of the parties

Customer is the Controller (or a processor acting on behalf of a controller). Formable is the Processor for Personal Data contained in Customer Content and related workflow data processed under Customer’s instructions. Each party will comply with data protection laws applicable to its role.

3. Details of processing

  • Subject matter: Providing the Service to Customer.
  • Duration: For the term of Customer’s use of the Service plus any retention period required by the agreement or law.
  • Nature and purpose: Hosting, transmitting, displaying, signing, redlining, notifying, auditing, and supporting document workflows as configured by Customer.
  • Types of Personal Data: As determined by Customer, which may include names, email addresses, titles, signature data, IP/device metadata, and document contents that include Personal Data.
  • Categories of Data Subjects: As determined by Customer, which may include Customer personnel, counterparties, signers, and other individuals identified in Customer Content.

4. Customer instructions

Formable will Process Personal Data only on documented instructions from Customer, including through the Service configuration and API calls, unless required by law. If Formable believes an instruction infringes applicable data protection law, it will notify Customer without undue delay where legally permitted.

5. Confidentiality

Formable ensures that persons authorized to Process Personal Data are bound by appropriate confidentiality obligations.

6. Security measures

Formable implements appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage, including encryption in transit and at rest where appropriate, access controls, logging, and vulnerability management. Additional information is available on our Security page.

7. Sub-processors

Customer authorizes Formable to engage Sub-processors to support delivery of the Service. Formable will impose data protection obligations on Sub-processors that are no less protective than those in this DPA in material respects, and remains responsible for Sub-processor performance.

Current material Sub-processors:

  • Amazon Web Services (AWS) — cloud infrastructure and document storage (primary region: us-east-2, United States)
  • Railway — application and database hosting (United States)
  • Google (Firebase Authentication) — user authentication
  • Vercel — web application hosting and delivery
  • Resend — transactional email (invitations, signature requests, notifications)
  • PostHog — product analytics and diagnostics (United States). Sensitive information is not captured: password inputs, private content, PII, and similar fields are auto-filtered and excluded from analytics events
  • OpenAI — optional AI features when Customer enables or invokes them

Formable will update this list for material Sub-processor changes and provide notice where required by applicable law or Customer’s written agreement.

8. Location, retention, and deletion

Customer Content is stored at rest primarily in the United States (AWS us-east-2). Customer-selectable region pinning is not currently available; residency requirements require a separate written agreement.

Formable retains Customer Content for the term of Customer’s account. Completed signature audit-trail snapshots are written to WORM storage with multi-year Object Lock retention as described on our Security page and cannot be deleted during the lock period.

Upon written request identifying a specific negotiation or document, Formable will delete it from active production systems within a commercially reasonable period and can confirm that deletion in writing, subject to legal holds, WORM snapshots for completed envelopes, and residual copies in encrypted backups that are purged on a rolling schedule (not instantly erasable on demand).

9. International transfers

Where Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, Formable will implement an appropriate transfer mechanism, such as the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, unless another lawful mechanism applies. Primary hosting is in the United States as described above.

10. Assistance to Customer

Taking into account the nature of Processing, Formable will:

  • Assist Customer by appropriate technical and organizational measures with Data Subject requests, to the extent possible
  • Assist Customer with security, breach, DPIA, and prior consultation obligations, considering the information available to Formable
  • Make available information reasonably necessary to demonstrate compliance with this DPA

11. Personal Data Breach

Formable will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA, and will provide information reasonably available to help Customer meet its notification obligations.

12. Return or deletion

Upon termination of the Service or written request, Formable will delete or return Personal Data in Customer Content according to Service functionality and Customer instructions, subject to the retention, WORM, legal-hold, and backup limitations in Location, retention, and deletion.

13. Audits

Upon reasonable written request, Formable will provide documentation or reports reasonably sufficient to demonstrate compliance with this DPA. If Customer reasonably requires an audit beyond available documentation, the parties will agree on scope, timing, and confidentiality, and audits will be limited to once per twelve months unless a Personal Data Breach or regulatory requirement justifies more frequent review.

14. Liability and order of precedence

Liability under this DPA is subject to the limitations and exclusions in the Formable Terms and Conditions or other governing commercial agreement, except where prohibited by applicable data protection law. If there is a conflict between this DPA and the Terms regarding Processing of Personal Data, this DPA controls.

Formable
© 2026 Formable Inc. All rights reserved