Blog ·
GDPR and contact forms: what you actually need
What GDPR requires for contact forms without marketing badges: roles, EU storage, India ops, DPA language, retention windows, and no raw IPs.
- gdpr
- compliance
- agencies
Most form tools stamp “GDPR compliant” on the pricing page. FormHeron does not use that phrase unqualified. Here is what actually matters for contact forms under GDPR-style expectations.
Controller vs processor
Your customer (the site owner) decides why leads are collected — they are the controller. FormHeron processes submissions on their behalf — processor. Privacy policy and a DPA should say so.
Where data lives — and who can see it
FormHeron stores submission data in the EU (Amsterdam). Support and operations run from India. Remote access from a third country is a transfer topic even when the disk is in Amsterdam. We disclose both in the sub-processor list and legal pages rather than hiding behind “EU-hosted” slogans.
Concrete controls
- No raw IP storage — salted HMAC for rate limiting only
- Retention: 30 / 90 / 365 days by plan, then hard delete
- Per-project JSON export and submission deletion in the dashboard
- DPA available for every account
- Terms that prohibit special-category data through forms
If a vendor only offers a marketing badge and no DPA, retention story, or export/delete path, treat the badge as decoration. Read privacy and do you need a DPA.
What to put on your own site
- A privacy notice that names FormHeron as a processor if you use us
- Lawful basis / purpose for collecting the fields you ask for
- Link to your own contact for data subject requests (you are the controller)
- Avoid collecting special-category data through open forms
Questions security teams ask
- Where is data at rest? — Amsterdam Postgres for FormHeron submissions
- Who can access it? — account owner via dashboard; operator support from India with process discipline
- How long retained? — plan retention then hard delete
- Can we export/delete? — yes, per project in the dashboard
- Is there a DPA? — yes, DPA page
Answer those in plain language. Do not paste a competitor’s “GDPR compliant” badge into your own security pack. Product capabilities without compliance theatre: features.
FormHeron is a form backend with spam controls, a lead inbox, HMAC webhooks and Slack. Free plan: 250 submissions/month. Leads stored in the EU (Amsterdam); operated from India. No raw IPs.