ZenForms Logo
Legal InformationGDPR Compliance

GDPR Compliance

Your Data Protection Rights Under GDPR

Last updated: December 23, 2025

GDPR Compliance Overview

The General Data Protection Regulation (GDPR) is a European Union regulation that strengthens and unifies data protection for individuals within the EU. This page explains how ZenForms complies with GDPR and protects your data rights.

Data Controller & Infrastructure Architecture

ZenForms is developed and operated by mlxlabs.com. All application services and databases run in the European Union on dedicated AWS infrastructure:

Data Controller & Contact

Controller: mlxlabs (mlxlabs.com). Contact: support@zenforms.net for all data export, deletion, DPA, or privacy inquiries.

Server Location & Redundancy

Hosted on AWS Frankfurt, Germany (eu-central-1.compute.amazonaws.com) using TLS 1.3 in transit, AES-256 for persistent volumes, and automated daily backup snapshots.

Internal In-Host Database

Our MongoDB database is hosted directly on the application server with no public internet port exposure. Database access is strictly confined to internal localhost socket/IPC, completely isolated from outside networks.

Lawful Basis for Processing

We only process your personal information when we have a valid legal basis under GDPR:

Contractual Necessity

When processing is necessary to provide our services under our agreement with you.

Legitimate Interests

When processing is necessary for our legitimate business interests, provided they do not override your rights and freedoms.

Categories of Personal Data

We process the following categories of personal data:

Identity Data

Name, email address, username, and profile information you provide when creating an account.

Usage Data

Information about how you use our service, including forms created, submissions received, and features accessed.

Technical Data

IP address, browser type, device information, and other technical details collected automatically.

Communication Data

Messages, support requests, and other communications with our team.

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal data we hold about you, along with information about how we process it.

Right to Rectification

You can request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure (Right to be Forgotten)

You can request deletion of your personal data when it is no longer necessary for the purposes it was collected, or when you withdraw consent.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format and transfer it to another service provider.

Right to Object

You can object to processing of your personal data based on legitimate interests, direct marketing, or for scientific research purposes.

Right to Restrict Processing

You can request restriction of processing in certain circumstances, such as when data accuracy is contested.

Right to Withdraw Consent

When we process data based on your consent, you have the right to withdraw that consent at any time.

How to Exercise Your GDPR Rights (Export & Deletion)

Under the GDPR, you have the right to access, export, or permanently erase your personal data at any time:

Self-Serve Export & Deletion

You can export your form submissions directly to CSV from your ZenForms dashboard at any time, or delete individual forms and responses immediately.

Direct Privacy Requests

For full account erasure, machine-readable data dumps, or custom DPA requests, email support@zenforms.net.

Response Time & Guarantee

All legitimate GDPR requests are handled free of charge and processed within 30 days of receipt.

Data Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

Technical Measures

Encryption, secure servers, access controls, regular security testing, and secure development practices.

Organizational Measures

Staff training, data protection policies, access limitations, and regular security audits.

International Transfers

We use appropriate safeguards such as Standard Contractual Clauses for international data transfers outside the EEA.

Data Breach Notification

In the event of a personal data breach, we will notify affected individuals and relevant supervisory authorities without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area. We ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.