Data Processing Addendum

Version 2026-10-06. This addendum (“DPA”) forms part of the terms of service between Doorman (“Doorman”, “we”) and the customer that accepts it (“Customer”, “you”). Doorman's company details shown in [brackets] are still being completed.

The short version

Accept this DPA

Log in, go to Settings → Data processing addendum, enter your company's legal name and the person accepting, and download a countersigned copy. You can print this page or save it as a PDF to read first.

Open Settings

1. Parties and definitions

This DPA is between the Customer named on acceptance and [Company legal name], [Registered address] (“Doorman”). Terms such as “controller”, “processor”, “personal data”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR (Regulation (EU) 2016/679) and, where it applies, the UK GDPR and the UK Data Protection Act 2018 (together, “Data Protection Law”).

2. Scope and roles

This DPA applies when Doorman processes Customer Personal Data subject to Data Protection Law. For Customer Personal Data the Customer is the controller (or a processor acting for its own controller) and Doorman is the processor, as also stated in section 4 of the terms. For account, billing and support data, Doorman is a controller and the privacy policy applies.

The Customer is responsible for having a lawful basis for collecting the data its forms collect and for telling its visitors that submissions are screened by a third-party service.

3. Processing on documented instructions

Doorman processes Customer Personal Data only on the Customer's documented instructions, unless the law requires otherwise, in which case Doorman tells the Customer first unless the law forbids it. The Customer's instructions are the terms, this DPA, and the Customer's use and configuration of the service: its forms' settings, destinations, thresholds and lists, its API calls, and the labels, rescues, exports and deletions it makes. Doorman tells the Customer if, in its opinion, an instruction breaks Data Protection Law. Doorman does not use Customer Personal Data to train or fine-tune models, and does not sell it.

4. Confidentiality

Doorman ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality, and limits that access to the people who need it to run, secure and support the service.

5. Security

Doorman implements the technical and organisational measures in Annex II, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing. Doorman may update these measures as long as the overall level of protection does not decrease.

6. Sub-processors

The Customer gives general authorisation for Doorman to engage sub-processors. The current list is in Annex III and on the privacy page. Doorman will give at least 30 days' notice of a new sub-processor by email to the account address and on the privacy page. The Customer may object on reasonable data protection grounds within that period; if the parties can't resolve the objection, the Customer may end the agreement and export its data before the change takes effect. Doorman imposes data protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible for their performance.

7. Data subject requests

If Doorman receives a request from a data subject about Customer Personal Data, it forwards it to the Customer without undue delay and does not answer it itself except to say who to contact. The service lets the Customer find, export (JSON and CSV), rescue, label and delete submissions, which covers most requests. Doorman gives reasonable further help where the Customer can't respond using the service.

8. Personal data breaches

Doorman notifies the Customer without undue delay, and no later than 72 hours after becoming aware, of a personal data breach affecting Customer Personal Data. The notice goes to the account email address and describes, as far as is then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact for more information. Information not available at first is provided as it becomes available. Notification is not an admission of fault.

9. Assistance

Taking into account the nature of the processing and the information available to it, Doorman gives the Customer reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities. Doorman may charge reasonable fees for assistance beyond what the service, this DPA and its documentation already provide.

10. Deletion and return

The Customer can export its data from Settings at any time (JSON for everything, CSV for submissions) and can delete its account, which deletes its forms, keys and submissions immediately. Submissions are also deleted automatically at the end of the plan's retention period: 30 days on Free, 180 days on Pro and 365 days on Business. Database backups roll off within 30 days. When the agreement ends, Doorman deletes Customer Personal Data in the same way, unless the law requires it to keep some.

11. Audits

Doorman makes available the information needed to demonstrate compliance with this DPA. Once a year, on written request, Doorman answers a reasonable security questionnaire in writing and provides the evidence described in this DPA. Any on-site audit is by agreement, at the Customer's cost, with at least 30 days' notice, during business hours, by an auditor bound by confidentiality, and without disrupting the service or exposing other customers' data.

12. International transfers

Doorman and its sub-processors process Customer Personal Data in the United States. To the extent a transfer from the EEA is subject to the GDPR, the SCCs, Module Two (controller to processor) or Module Three (processor to processor) as applicable, are incorporated by reference, with the Customer as data exporter and Doorman as data importer, and with these choices: Clause 7 (docking) applies; Clause 9 option 2 (general authorisation) with the notice period in section 6; the option in Clause 11 does not apply; Clause 17 option 1, governed by the law of [EU member state]; Clause 18 courts of that member state; Annexes I to III of this DPA complete the SCCs' annexes, with the competent supervisory authority under Clause 13 being [Supervisory authority for SCC Clause 13].

For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner applies, completed with the information in this DPA. For transfers subject to the Swiss Federal Act on Data Protection, the SCCs apply with references to the GDPR read as references to the FADP, and the Swiss Federal Data Protection and Information Commissioner as the competent authority where the FADP governs the transfer.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the terms, except where Data Protection Law or the SCCs do not allow them.

14. Term

This DPA takes effect when the Customer accepts it and lasts as long as Doorman processes Customer Personal Data under the terms. Doorman may update it to reflect changes in law or in the service; a new version is published here with a new version date, and the Customer can accept it from Settings. Material changes are announced by email at least 30 days in advance.

15. Precedence

For Customer Personal Data, this DPA prevails over the terms if they conflict, and the SCCs (where they apply) prevail over this DPA.

Annex I: Details of processing

Subject matterScreening website form submissions for the Customer and forwarding the genuine ones.
DurationFor as long as the Customer's account exists, plus the retention periods in section 10.
Nature and purposeReceiving submissions from the Customer's forms or API; normalising them; classifying each with an AI model (Jev, from TypeSafe); routing each to deliver, hold or drop; forwarding to the Customer's destinations; storing them for the Customer's review, rescue and labelling; deleting them.
Data subjectsPeople who submit the Customer's website forms; the Customer's staff who receive forwarded submissions.
Personal dataThe fields a form sends (for example name, email address, message and any other fields); IP address and country; page-timing, JavaScript and honeypot signals; for checkout forms, the order and payment signals the Customer chooses to send (never card numbers); Doorman's decision, evidence sentence, labels and delivery log.
Special categoriesNone intended. The terms prohibit collecting special-category data through hosted forms unless agreed in writing.
FrequencyContinuous, as submissions arrive.
Retention30 days on Free, 180 days on Pro, 365 days on Business; database backups up to 30 days.

Annex II: Security measures

Annex III: Sub-processors

Sub-processorPurposeDataLocation
TypeSafe (Jev)Judging each submissionSubmission text, signals and the form's business descriptionUnited States
ResendForwarding submissions by email and sending service emailsRecipient address and email contentUnited States
Fly.ioServers, database and networkAll service dataUnited States (San Jose, California)
Cloudflare R2Encrypted database backupsAll service dataUnited States

Doorman also uses these services for account, billing and support data, where Doorman is the controller and not acting for the Customer: Stripe (billing), Migadu (Doorman's own mailbox) and Discord (support notifications). They are listed on the privacy page.