Blog ·

GDPR and contact forms: what you actually need

What GDPR requires for contact forms without marketing badges: roles, EU storage, India ops, DPA language, retention windows, and no raw IPs.

  • gdpr
  • compliance
  • agencies

Most form tools stamp “GDPR compliant” on the pricing page. FormHeron does not use that phrase unqualified. Here is what actually matters for contact forms under GDPR-style expectations.

Controller vs processor

Your customer (the site owner) decides why leads are collected — they are the controller. FormHeron processes submissions on their behalf — processor. Privacy policy and a DPA should say so.

Where data lives — and who can see it

FormHeron stores submission data in the EU (Amsterdam). Support and operations run from India. Remote access from a third country is a transfer topic even when the disk is in Amsterdam. We disclose both in the sub-processor list and legal pages rather than hiding behind “EU-hosted” slogans.

Concrete controls

  • No raw IP storage — salted HMAC for rate limiting only
  • Retention: 30 / 90 / 365 days by plan, then hard delete
  • Per-project JSON export and submission deletion in the dashboard
  • DPA available for every account
  • Terms that prohibit special-category data through forms

If a vendor only offers a marketing badge and no DPA, retention story, or export/delete path, treat the badge as decoration. Read privacy and do you need a DPA.

What to put on your own site

  1. A privacy notice that names FormHeron as a processor if you use us
  2. Lawful basis / purpose for collecting the fields you ask for
  3. Link to your own contact for data subject requests (you are the controller)
  4. Avoid collecting special-category data through open forms

Questions security teams ask

  • Where is data at rest? — Amsterdam Postgres for FormHeron submissions
  • Who can access it? — account owner via dashboard; operator support from India with process discipline
  • How long retained? — plan retention then hard delete
  • Can we export/delete? — yes, per project in the dashboard
  • Is there a DPA? — yes, DPA page

Answer those in plain language. Do not paste a competitor’s “GDPR compliant” badge into your own security pack. Product capabilities without compliance theatre: features.

FormHeron is a form backend with spam controls, a lead inbox, HMAC webhooks and Slack. Free plan: 250 submissions/month. Leads stored in the EU (Amsterdam); operated from India. No raw IPs.