Skip to content
Back to home
Sub-processors Last updated: 2026-09-17

Sub-processors

The service providers Formspring relies on to operate, bill, and communicate.

Last reviewed and revised: 2026-09-17. This revision added Cloudflare, Google, Twilio, and numverify, corrected the OpenAI and Postmark entries, and removed Anthropic. Every change is itemised with its reason in the last section of this page. We inform customers of material changes where the agreement provides for it, and customers may object; there is no notification mailing list, so this dated page and its change log are the notice. This list covers every active sub-processor with access to customer or submission data.

Hetzner Online GmbH

Purpose: hosting the application, databases, and background jobs, plus S3-compatible object storage for file uploads. Region: Germany (Frankfurt, Nuremberg, Falkenstein). Basis: data processing agreement under Article 28 GDPR.

Stripe Payments Europe Ltd.

Purpose: payment processing, subscriptions, invoicing, and tax collection. Region: Ireland (EU); Stripe processes payment data as an independent controller. Basis: Stripe Data Processing Agreement, with Standard Contractual Clauses for any onward transfers.

Postmark (Wildbit LLC / ActiveCampaign)

Purpose: sending transactional email - submission notifications, autoresponders, and account email. A notification carries the submission itself, so this is the one path on which submission content leaves our own infrastructure without a customer switching anything on. Region: the provider is US-based and we call its global API endpoint. We have not established an EU-region processing commitment for it, so treat this as processing outside the EU/EEA, on every plan. This entry previously named an EU data centre in Frankfurt and the documentation named EU servers in Dublin on paid plans. Neither is configured anywhere in the product, so both have been withdrawn rather than left standing unverified. If an EU-region arrangement is put in place, this entry gets it back with the date it started. Basis: data processing agreement under Article 28 GDPR, with Standard Contractual Clauses for the transfer.

hCaptcha (Intuition Machines, Inc.)

Purpose: optional, per-form CAPTCHA verification, active only when a customer enables it. Region: United States, with Standard Contractual Clauses. Basis: hCaptcha DPA.

Google (reCAPTCHA)

Purpose: optional, per-form reCAPTCHA verification, active only when a customer enables it on a form and supplies that form's own site and secret keys. The challenge script is loaded into the respondent's browser directly from Google, which therefore receives their IP address, user agent, and any cookies their browser sends; our server-side verification call adds the challenge token and the respondent's IP address. The submission payload itself is never sent. Region: United States, with Standard Contractual Clauses. Basis: Google's reCAPTCHA terms and data processing terms. A form that uses hCaptcha instead never contacts Google.

Automattic Inc. (Akismet)

Purpose: optional, per-form spam scoring (bring-your-own-key or platform key). Region: United States, with Standard Contractual Clauses. Basis: Automattic DPA.

OpenAI, L.L.C. (optional)

Purpose: the single AI provider behind every optional AI feature on paid plans - spam moderation, categorization, one-line summaries, duplicate detection, autoresponder drafts, weekly digests, survey question insights, question suggestions, translation, and AI-assisted form, survey, funnel, and ad-copy generation. It receives only the content the feature needs, and only when the plan includes AI features and the specific feature is switched on. No account data, no billing data, and no uploaded files are sent. Region: United States. We call OpenAI's global API endpoint rather than an EU data residency endpoint, so this processing is covered by Standard Contractual Clauses. Basis: OpenAI DPA and API terms, under which API inputs and outputs are not used to train their models. We have not agreed a zero-retention arrangement, so OpenAI's standard API retention window applies. A workspace that cannot accept US-routed processing of submission content should leave AI features off, which is the default.

Twilio Inc. (optional)

Purpose: sending SMS from our own Twilio account, for the SMS step in automations and the confirmation text on link-in-bio SMS signup blocks. Twilio receives the recipient's phone number and the message body. Active only when a customer builds one of those. Region: United States, with Standard Contractual Clauses. Basis: Twilio DPA. A Twilio account you connect yourself, for funnel SMS or WhatsApp one-time passcodes, runs on your credentials and is your processor rather than ours.

numverify / APILayer (optional)

Purpose: network validation of phone numbers entered in funnels, on our platform API key. Off by default: it runs only when a workspace selects numverify as its phone validation driver. The provider receives the phone number in E.164 form and nothing else - no name, no email, no submission content. Region: the provider's hosted API. We have not established an EU processing commitment for it, so treat it as a transfer outside the EU/EEA. A workspace that cannot accept that should leave phone validation disabled, which is how it ships. Basis: provider terms.

Cloudflare, Inc. (custom domains only)

Purpose: edge TLS termination and reverse proxy for customer-configured custom domains on funnel pages and agency portals, including the submissions posted to them. Pages served on our own hostnames never pass through it. Region: global anycast network; the serving location follows the visitor. Basis: Cloudflare Customer DPA with Standard Contractual Clauses.

Self-hosted analytics (Pixel & Process UG)

Purpose: cookieless, anonymous web analytics for the marketing site. Region: Germany. No third-party processing relationship; no access to submission data.

Changes to this list

2026-09-17 - Cloudflare added. It terminates TLS for customer-configured custom domains, which makes the submissions posted to those domains readable at its edge. 2026-09-17 - Google added, for optional per-form reCAPTCHA. The feature was already in the product and this entry was missing. 2026-09-17 - Twilio and numverify added, for the optional SMS and phone-validation features that run on our own accounts rather than on credentials a customer supplies. 2026-09-17 - The Postmark entry corrected. It read "Region: EU data center (Frankfurt)" while our documentation read "US, with EU data routing on Pro and above" and named Dublin. Nothing in the product configures an EU region for it: the application calls the provider's global API endpoint on every plan. Both claims are withdrawn and the entry now states processing outside the EU/EEA under Standard Contractual Clauses. This is the conservative reading and it is pending confirmation against the provider account; if an EU-region arrangement exists or is put in place, it will be recorded here with its date rather than assumed. 2026-09-17 - The OpenAI entry corrected. It previously read "alternative AI provider for embeddings and duplicate detection" in "Ireland (EU)." OpenAI is in fact the default and only AI provider the application calls, for every AI feature, on its global endpoint. The entry now says so. 2026-09-17 - Anthropic removed. It was listed as an optional AI provider with "zero-retention mode enabled." No part of the application selects it, no credential is provisioned for it, and no zero-retention setting existed anywhere to back that claim. No customer or submission data was sent to it under that entry. It is recorded here rather than quietly dropped: this list gets shorter only on the record, never in silence.