A contact form that respects people’s data from the first field.
Set it up once and every response lands sorted, private, and ready to act on.
- Who it’s for
- Privacy leads, compliance teams, and EU-based founders
- How it flows
- A visitor writes in → stored in the EU → kept only as long as you set → deleted on request
What changes
Fewer dropped balls. More done.
The boring parts - sorting, filtering, routing, and keeping data tidy - happen on their own.
Every reply in one place
No more answers scattered across inboxes and tabs. Each response lands in a shared, organized stream your whole team can act on.
Spam stays out, files stay private
Junk is filtered automatically, and any uploads arrive with the limits you set - never as forever-links floating around email.
Goes where your team works
Send each answer to a chat ping, a spreadsheet row, or your contacts - automatically, the moment someone hits submit.
Everyone knows who’s got it
Every response carries a status, and a form response can be handed to a named owner, so nobody asks “wait, did someone reply to this?” ever again.
Most form backends were built in San Francisco and bolted on a DPA template years later. Formspring was built in Germany, runs on EU-resident infrastructure, and treats retention and erasure as first-class form settings, and is equally plain about the compliance work that stays yours. If your DPO has ever asked "where exactly is this data stored?" and the answer involved a 40-page transfer impact assessment, this page is for you.
This is the same backend powering forms on regulated European sites - public sector, healthcare-adjacent, EU SaaS - where Schrems II is a daily reality rather than a footnote. The list of GDPR-relevant controls below is what you actually get out of the box, not what's promised in a sales call.
The compliance pillars, at a glance
Every GDPR question a procurement team or DPO will ask, with the Formspring answer in the same row. No "contact us for details," no "available on enterprise."
| Pillar | What Formspring provides |
|---|---|
| Data residency | Submissions, files, and logs stored and processed in EU data centres, and any infrastructure-level disaster-recovery snapshots stay in the same EU location. One region, no US replicas, no second region to fail over to. Two exceptions, both disclosed on the sub-processors page: the email that notifies you of a submission carries a copy of it to a transactional email provider that processes outside the EU/EEA under Standard Contractual Clauses, and a custom domain you configure yourself terminates TLS at a global edge network before traffic reaches us. |
| Signed DPA | A pre-signed Data Processing Agreement under GDPR Art. 28 is available on every paid plan. Download it, counter-sign, attach to your records. No legal negotiation required for the standard template. |
| Lawful basis | Yours to choose and to document. Formspring is the processor and acts on your instructions, so there is no lawful-basis setting on a form and nothing stamps a basis onto a submission. What it does record, when you use the consent field, is the consent event itself. |
| Retention controls | Per-form retention rules. Default 30 days on Free, unlimited on paid with explicit choice. Submissions are deleted via queued job after the rule fires; deletion is logged. |
| Right to erasure | One-click erasure from the dashboard, one submission or many. The deletion is queued, removes the submission and its files from object storage, and writes a deletion-audit record. There is no public endpoint a data subject can call: requests reach you as the controller and you run them. |
| Consent capture | Built-in consent checkbox field type. Each submission stores a consent record: the exact text shown to the visitor, whether they accepted it, whether it was required, and when. The submission it belongs to also stores the visitor's IP address and user agent in full, under the same retention rule and removed by the same deletion. |
| Sub-processors disclosure | Public sub-processors page, dated, with a plain-text download and a change log recording every addition, correction, and removal with its reason. There is no notification mailing list: the dated page is the notice. |
| Encryption | TLS 1.3 in transit, AES-256 at rest. File uploads land in private, encrypted object storage with signed, time-limited download URLs only. |
| Deletion audit trail | Every deletion, whether you ran it or a retention rule did, writes an append-only record: what was deleted, when, and whether the cascade to file storage completed or failed. A whole cascade is reconstructible from one correlation id. There is no view log and no export log, so this shows what left the system rather than who looked at it. |
The matrix is intentionally short. If your DPO has more questions, the answer is almost always "yes, here is the page" rather than "let me check."
What GDPR actually requires - article by article
Most "GDPR-compliant" claims gloss over which articles they're talking about. Here are the five that govern a contact form, with the Formspring control that maps to each.
Art. 6 - Lawful basis for processing. Every processing operation needs one of six lawful bases. For contact forms it is almost always (a) consent or (b) contract necessity. Choosing one and documenting it is the controller's job, which is yours: Formspring is the processor and acts on your instructions, so there is no lawful-basis setting on a form and nothing stamps a basis onto a submission row. What the product gives you toward the evidence is narrower and real: the consent field records, per submission, the exact text the visitor was shown, whether they accepted it, and when. If you want the basis on the row as well, add it as a hidden field and it is stored in the payload like any other value. Full text: https://eur-lex.europa.eu/eli/reg/2016/679/oj.
Art. 13 - Transparency at collection. You must tell the data subject who you are, why you're processing, retention period, their rights, and how to contact your DPO - at the moment of collection. Formspring forms render a configurable transparency notice block above the submit button, with a link to your privacy policy. The notice is part of the form payload, so a screenshot at the time of submission is reproducible.
Art. 17 - Right to erasure. The data subject can ask you to delete their data, and you have one month. Formspring exposes a one-click erasure flow in the dashboard, one submission or many at once. The deletion is queued, removes the submission and any attached files from object storage, and writes a deletion-audit record you can show a regulator. There is no public erasure endpoint a data subject can call directly, which is also where the law puts the obligation: the request reaches you as the controller and you execute it. Note the boundary. Deletion does not reach a copy you have already forwarded to an integration or a webhook destination; that copy sits in your systems, on your retention rules, and the one month runs on it too. Full text: https://gdpr-info.eu/art-17-gdpr/.
Art. 28 - Processor agreement. If anyone else processes personal data on your behalf, you need a contract with them that meets Art. 28's mandatory clauses. Formspring's DPA is built on the EDPB-approved template, includes Standard Contractual Clauses where required, and is pre-signed by us. You download it, counter-sign it, file it. No tickets, no legal review cycle. Full text: https://gdpr-info.eu/art-28-gdpr/.
Art. 32 - Security of processing. Appropriate technical and organisational measures. That's TLS 1.3 in transit, AES-256 at rest, access logging, principle of least privilege on operator accounts, encrypted infrastructure-level disaster-recovery snapshots held in the same EU location, a published vulnerability disclosure process with a stated acknowledgement and triage window, and a contractual commitment in the DPA to notify you of a personal data breach without undue delay so that you can meet your own Art. 33 deadline. We do not currently commission scheduled third-party penetration tests, and this page will say so until we do.
Implementation - three steps
The dashboard does the heavy lifting. The form itself is plain HTML with a consent field.
-
Create the form. New form in the dashboard, pick the GDPR contact template. EU-hosted storage is not a toggle at any level - there is one region, it is in the EU, and it is enforced at the infrastructure layer.
-
Add the consent field. Drop in the built-in
consentfield type. It renders a checkbox with your configurable consent text and records, on the submission, the exact text shown, whether the visitor accepted it, and when. The submission row itself keeps the visitor's IP address and user agent. There is no lawful-basis dropdown to set: if you are relying on contract necessity or legitimate interest, the consent field is simply not the control you need, and the basis belongs in your privacy notice rather than in a form setting. -
Set the retention policy. Per-form rule, default 30 days on Free. On paid plans you choose: 7 days, 30 days, 90 days, 1 year, or indefinite (with explicit acknowledgement that retention should match your published privacy policy). The deletion job runs nightly and writes an audit-log row when it fires.
That's it. No DPA addendum, no Schrems II transfer impact assessment, no fighting with a US vendor's EU-region toggle that might fall back to us-east-1 on failover.
Formspring vs the usual alternatives
The honest comparison. Each row picks the one thing a DPO will actually care about.
| Backend | Data residency | DPA status | Transfer mechanism |
|---|---|---|---|
| Formspring | EU storage and processing, no replicas outside the EEA, no other region to choose | Pre-signed Art. 28 DPA on every paid plan | SCCs for the transactional email path and for the optional providers, each named with its region |
| Google Forms (Workspace) | US Workspace defaults to US; EU storage available on Enterprise tiers; Workspace data has crossed the Atlantic historically | DPA available via Workspace terms | Standard Contractual Clauses + Data Privacy Framework certification |
| Typeform | Ireland data centre (AWS eu-west-1); responses may transit US-based services for analytics and ML features | DPA available | SCCs for any US-routed processing |
| US-hosted form backends (generic) | US primary storage | DPA usually available; quality varies | SCCs + DPF; Schrems II transfer impact assessment is on you |
The Typeform row is the one most teams under-estimate. Ireland storage doesn't mean Ireland-only processing - third-party analytics, ML features, and shared infrastructure can route response data through US-based services depending on plan tier. EU residency as the only option beats EU-on-request with carve-outs, every time a DPO reads the small print.
Schrems II and why US-only backends carry extra weight
The Court of Justice of the European Union invalidated the EU-US Privacy Shield in Schrems II (case C-311/18, July 2020): https://curia.europa.eu/juris/document/document.jsf?docid=228677. The ruling held that US surveillance law (FISA Section 702, Executive Order 12333) does not provide European data subjects with rights equivalent to those guaranteed by the GDPR, so transfers to US-based processors require additional safeguards - typically Standard Contractual Clauses plus a Transfer Impact Assessment documenting that the SCCs are actually effective in the specific case. In practice, that TIA is a document that has to be re-done whenever the underlying processor's architecture changes - and it's the controller (you), not the processor, who carries the regulatory risk if it's wrong.
The EU-US Data Privacy Framework (adequacy decision, July 2023) restored a transfer route for certified US recipients, but it's already facing legal challenges and the EDPB has signalled it will revisit it. The same Max Schrems-led complaint that took down Privacy Shield is the template for the case currently working its way toward the CJEU. A form backend whose primary data path crosses the Atlantic is a backend whose compliance posture depends on a contested legal mechanism that could be invalidated again, possibly on short notice, with no graceful migration path for the submissions already in storage.
Formspring's answer is narrower than "no transfers," and it is worth stating exactly rather than rounding up. The submissions themselves, the uploaded files, and the database holding them do not leave the EU: no US replica, no second region, nothing to fail over to. What does cross is the notification email carrying a copy of the submission, plus the captcha, spam-scoring, AI, SMS, and phone-validation calls a customer switches on. Each is covered by Standard Contractual Clauses and each is named with its region on the sub-processors page. So the transfer surface is small, enumerated, and mostly yours to turn off, rather than absent. Procurement teams who have lived through one Schrems-style invalidation tend to value the structural answer over the paperwork answer - because they remember what the paperwork answer looked like the morning after the ruling came down.
Who this is for, and who it is not
This page is written for the audiences most likely to need an out-of-the-box answer rather than a custom-built one:
- DPOs and compliance teams standing up forms on behalf of a marketing or growth team that needs an answer this quarter rather than next year.
- EU founders who want their stack to default to compliant rather than retrofitting it after the first sales-cycle questionnaire.
- Regulated industries - healthcare-adjacent, public sector, financial services, ed-tech - where the contact-form layer is one of many places that has to hold up to a Data Protection Impact Assessment.
- Agencies serving European clients who would rather use one EU-hosted backend across every client than negotiate a fresh DPA per project.
If you are a single-developer side project with no European visitors, the residency story is less load-bearing and a US-hosted backend will likely work fine. If you operate inside a regulated industry that mandates ISO 27001 or SOC 2 Type II at the form-backend layer: Formspring holds neither certification, and you should know that here rather than three weeks into a vendor review. What a procurement reviewer can have instead is specific and checkable today - a pre-signed Art. 28 DPA, a dated sub-processor list with a plain-text download, single-region EU storage and processing with no second region to fail over to, per-form retention windows enforced by a nightly deletion job, deletion that cascades to file storage, encryption in transit and at rest with an additional per-workspace key for fields you mark sensitive, and a published security contact with a stated acknowledgement and triage window. If your policy requires the certificate itself rather than the controls behind it, we are not your answer yet. The honest answer is that Formspring is the default for the audience above; for the long-tail outside it, the comparison page is the better starting point.