GDPR Compliance
Your Data Protection Rights Under GDPR
GDPR Compliance Overview
The General Data Protection Regulation (GDPR) is a European Union regulation that strengthens and unifies data protection for individuals within the EU. This page explains how ZenForms complies with GDPR and protects your data rights.
Data Controller & Infrastructure Architecture
ZenForms is developed and operated by mlxlabs.com. All application services and databases run in the European Union on dedicated AWS infrastructure:
Data Controller & Contact
Controller: mlxlabs (mlxlabs.com). Contact: support@zenforms.net for all data export, deletion, DPA, or privacy inquiries.
Server Location & Redundancy
Hosted on AWS Frankfurt, Germany (eu-central-1.compute.amazonaws.com) using TLS 1.3 in transit, AES-256 for persistent volumes, and automated daily backup snapshots.
Internal In-Host Database
Our MongoDB database is hosted directly on the application server with no public internet port exposure. Database access is strictly confined to internal localhost socket/IPC, completely isolated from outside networks.
Lawful Basis for Processing
We only process your personal information when we have a valid legal basis under GDPR:
Consent
When you explicitly consent to our processing of your data for specific purposes, such as marketing communications.
Contractual Necessity
When processing is necessary to provide our services under our agreement with you.
Legal Obligation
When we are required by law to process your data, such as for tax or regulatory compliance.
Legitimate Interests
When processing is necessary for our legitimate business interests, provided they do not override your rights and freedoms.
Categories of Personal Data
We process the following categories of personal data:
Identity Data
Name, email address, username, and profile information you provide when creating an account.
Usage Data
Information about how you use our service, including forms created, submissions received, and features accessed.
Technical Data
IP address, browser type, device information, and other technical details collected automatically.
Communication Data
Messages, support requests, and other communications with our team.
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
Right to Rectification
You can request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure (Right to be Forgotten)
You can request deletion of your personal data when it is no longer necessary for the purposes it was collected, or when you withdraw consent.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and transfer it to another service provider.
Right to Object
You can object to processing of your personal data based on legitimate interests, direct marketing, or for scientific research purposes.
Right to Restrict Processing
You can request restriction of processing in certain circumstances, such as when data accuracy is contested.
Right to Withdraw Consent
When we process data based on your consent, you have the right to withdraw that consent at any time.
How to Exercise Your GDPR Rights (Export & Deletion)
Under the GDPR, you have the right to access, export, or permanently erase your personal data at any time:
Self-Serve Export & Deletion
You can export your form submissions directly to CSV from your ZenForms dashboard at any time, or delete individual forms and responses immediately.
Direct Privacy Requests
For full account erasure, machine-readable data dumps, or custom DPA requests, email support@zenforms.net.
Response Time & Guarantee
All legitimate GDPR requests are handled free of charge and processed within 30 days of receipt.
Data Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
Technical Measures
Encryption, secure servers, access controls, regular security testing, and secure development practices.
Organizational Measures
Staff training, data protection policies, access limitations, and regular security audits.
International Transfers
We use appropriate safeguards such as Standard Contractual Clauses for international data transfers outside the EEA.
Data Breach Notification
In the event of a personal data breach, we will notify affected individuals and relevant supervisory authorities without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area. We ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.