Data Processing Addendum
Version 2026-10-06. This addendum (“DPA”) forms part of the terms of service between Doorman (“Doorman”, “we”) and the customer that accepts it (“Customer”, “you”). Doorman's company details shown in [brackets] are still being completed.
The short version
- For the form submissions Doorman screens, you are the controller and Doorman is your processor. We act only on your instructions.
- Data is processed in the United States. Transfers from the EEA, the UK and Switzerland rely on the Standard Contractual Clauses.
- Our sub-processors are listed in Annex III and on the privacy page. We give 30 days' notice of new ones.
- You can export or delete your data at any time from Settings. We notify you of a personal data breach within 72 hours of becoming aware of it.
- Accept this DPA from Settings in the dashboard and download a countersigned copy.
Accept this DPA
Log in, go to Settings → Data processing addendum, enter your company's legal name and the person accepting, and download a countersigned copy. You can print this page or save it as a PDF to read first.
1. Parties and definitions
This DPA is between the Customer named on acceptance and [Company legal name], [Registered address] (“Doorman”). Terms such as “controller”, “processor”, “personal data”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR (Regulation (EU) 2016/679) and, where it applies, the UK GDPR and the UK Data Protection Act 2018 (together, “Data Protection Law”).
- Customer Personal Data means personal data in the form submissions and related data that Doorman processes for the Customer to provide the service, as described in Annex I.
- Sub-processor means another processor Doorman engages to process Customer Personal Data.
- SCCs means the standard contractual clauses approved by the European Commission in Decision (EU) 2021/914.
2. Scope and roles
This DPA applies when Doorman processes Customer Personal Data subject to Data Protection Law. For Customer Personal Data the Customer is the controller (or a processor acting for its own controller) and Doorman is the processor, as also stated in section 4 of the terms. For account, billing and support data, Doorman is a controller and the privacy policy applies.
The Customer is responsible for having a lawful basis for collecting the data its forms collect and for telling its visitors that submissions are screened by a third-party service.
3. Processing on documented instructions
Doorman processes Customer Personal Data only on the Customer's documented instructions, unless the law requires otherwise, in which case Doorman tells the Customer first unless the law forbids it. The Customer's instructions are the terms, this DPA, and the Customer's use and configuration of the service: its forms' settings, destinations, thresholds and lists, its API calls, and the labels, rescues, exports and deletions it makes. Doorman tells the Customer if, in its opinion, an instruction breaks Data Protection Law. Doorman does not use Customer Personal Data to train or fine-tune models, and does not sell it.
4. Confidentiality
Doorman ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality, and limits that access to the people who need it to run, secure and support the service.
5. Security
Doorman implements the technical and organisational measures in Annex II, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing. Doorman may update these measures as long as the overall level of protection does not decrease.
6. Sub-processors
The Customer gives general authorisation for Doorman to engage sub-processors. The current list is in Annex III and on the privacy page. Doorman will give at least 30 days' notice of a new sub-processor by email to the account address and on the privacy page. The Customer may object on reasonable data protection grounds within that period; if the parties can't resolve the objection, the Customer may end the agreement and export its data before the change takes effect. Doorman imposes data protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible for their performance.
7. Data subject requests
If Doorman receives a request from a data subject about Customer Personal Data, it forwards it to the Customer without undue delay and does not answer it itself except to say who to contact. The service lets the Customer find, export (JSON and CSV), rescue, label and delete submissions, which covers most requests. Doorman gives reasonable further help where the Customer can't respond using the service.
8. Personal data breaches
Doorman notifies the Customer without undue delay, and no later than 72 hours after becoming aware, of a personal data breach affecting Customer Personal Data. The notice goes to the account email address and describes, as far as is then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact for more information. Information not available at first is provided as it becomes available. Notification is not an admission of fault.
9. Assistance
Taking into account the nature of the processing and the information available to it, Doorman gives the Customer reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities. Doorman may charge reasonable fees for assistance beyond what the service, this DPA and its documentation already provide.
10. Deletion and return
The Customer can export its data from Settings at any time (JSON for everything, CSV for submissions) and can delete its account, which deletes its forms, keys and submissions immediately. Submissions are also deleted automatically at the end of the plan's retention period: 30 days on Free, 180 days on Pro and 365 days on Business. Database backups roll off within 30 days. When the agreement ends, Doorman deletes Customer Personal Data in the same way, unless the law requires it to keep some.
11. Audits
Doorman makes available the information needed to demonstrate compliance with this DPA. Once a year, on written request, Doorman answers a reasonable security questionnaire in writing and provides the evidence described in this DPA. Any on-site audit is by agreement, at the Customer's cost, with at least 30 days' notice, during business hours, by an auditor bound by confidentiality, and without disrupting the service or exposing other customers' data.
12. International transfers
Doorman and its sub-processors process Customer Personal Data in the United States. To the extent a transfer from the EEA is subject to the GDPR, the SCCs, Module Two (controller to processor) or Module Three (processor to processor) as applicable, are incorporated by reference, with the Customer as data exporter and Doorman as data importer, and with these choices: Clause 7 (docking) applies; Clause 9 option 2 (general authorisation) with the notice period in section 6; the option in Clause 11 does not apply; Clause 17 option 1, governed by the law of [EU member state]; Clause 18 courts of that member state; Annexes I to III of this DPA complete the SCCs' annexes, with the competent supervisory authority under Clause 13 being [Supervisory authority for SCC Clause 13].
For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner applies, completed with the information in this DPA. For transfers subject to the Swiss Federal Act on Data Protection, the SCCs apply with references to the GDPR read as references to the FADP, and the Swiss Federal Data Protection and Information Commissioner as the competent authority where the FADP governs the transfer.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the terms, except where Data Protection Law or the SCCs do not allow them.
14. Term
This DPA takes effect when the Customer accepts it and lasts as long as Doorman processes Customer Personal Data under the terms. Doorman may update it to reflect changes in law or in the service; a new version is published here with a new version date, and the Customer can accept it from Settings. Material changes are announced by email at least 30 days in advance.
15. Precedence
For Customer Personal Data, this DPA prevails over the terms if they conflict, and the SCCs (where they apply) prevail over this DPA.
Annex I: Details of processing
| Subject matter | Screening website form submissions for the Customer and forwarding the genuine ones. |
|---|---|
| Duration | For as long as the Customer's account exists, plus the retention periods in section 10. |
| Nature and purpose | Receiving submissions from the Customer's forms or API; normalising them; classifying each with an AI model (Jev, from TypeSafe); routing each to deliver, hold or drop; forwarding to the Customer's destinations; storing them for the Customer's review, rescue and labelling; deleting them. |
| Data subjects | People who submit the Customer's website forms; the Customer's staff who receive forwarded submissions. |
| Personal data | The fields a form sends (for example name, email address, message and any other fields); IP address and country; page-timing, JavaScript and honeypot signals; for checkout forms, the order and payment signals the Customer chooses to send (never card numbers); Doorman's decision, evidence sentence, labels and delivery log. |
| Special categories | None intended. The terms prohibit collecting special-category data through hosted forms unless agreed in writing. |
| Frequency | Continuous, as submissions arrive. |
| Retention | 30 days on Free, 180 days on Pro, 365 days on Business; database backups up to 30 days. |
Annex II: Security measures
- Encryption in transit: HTTPS for all traffic to the service and to sub-processors.
- Credentials: passwords hashed with scrypt; API keys and session tokens stored only as hashes.
- Integrity of deliveries: webhooks are signed (HMAC) so the Customer can verify they came from Doorman.
- Hosting: one region in the United States (San Jose, California) on Fly.io; the database volume is encrypted at rest.
- Backups: the database is streamed continuously to Cloudflare R2 (encrypted at rest), kept 30 days and restorable to a point in time.
- Access control: access to production data is limited to the people who run Doorman.
- Tenant isolation: every account-scoped route is scoped to the account, with automated tests that one account can't read or change another's data, run on every change.
- Abuse protection: per-address, per-form and per-account rate limits; outbound requests to customer-supplied URLs are checked against private and internal addresses.
- Monitoring: error alerting to the operators and a public status page fed by checks every minute.
- Minimisation: file uploads are ignored and not stored; field lengths are clipped; submissions are not used for model training.
- Deletion: automatic deletion at the end of each plan's retention period and immediate deletion on account deletion.
Annex III: Sub-processors
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| TypeSafe (Jev) | Judging each submission | Submission text, signals and the form's business description | United States |
| Resend | Forwarding submissions by email and sending service emails | Recipient address and email content | United States |
| Fly.io | Servers, database and network | All service data | United States (San Jose, California) |
| Cloudflare R2 | Encrypted database backups | All service data | United States |
Doorman also uses these services for account, billing and support data, where Doorman is the controller and not acting for the Customer: Stripe (billing), Migadu (Doorman's own mailbox) and Discord (support notifications). They are listed on the privacy page.