Data Processing Agreement
This agreement governs personal data that we process on your behalf when you use jpforms (https://jpforms.com). It forms part of the terms of service and takes effect when you open an account.
This agreement is operative in English. No translation of it is offered, because a translated contract is a second contract.
1. Roles and parties
- You are the controller of the personal data you put into the service, and you decide why and how it is processed.
- We are the processor. We act on your instructions and for no purpose of our own.
- Where a data protection law names the parties differently, the party performing the equivalent role bears the equivalent obligation.
- We do not print our name, address or telephone number on this page. They are disclosed on request through the disclosure form (/legal/disclosure), which answers within the statutory period.
2. Subject matter, nature and purpose
- To read the form you chose and work out what each of its boxes is for.
- To keep your draft so that a form you started can be finished later.
- To compose the finished PDF you download.
- To enforce the limits of the plan you are on and to bill for it.
3. Duration
- A draft and its answers are kept while your account is open, so that a form you started can be finished.
- Deleting a draft deletes its answers and the filled PDF made from it.
- Deleting your account deletes all of them.
- Billing records are kept as long as tax and company law require.
4. Categories of personal data
| Email address | To sign you in and to send service notices. |
|---|---|
| Answers you type into a form | Your name, address, dates and the other details the form asks for, kept as a draft so you can come back to it. |
| Forms you upload | The document itself, and the rendered image of each of its pages. |
| Usage records | Counts of forms read and filled, for billing and for capacity. |
| Billing records | A Stripe customer identifier, your plan and its status. Card details never reach us. |
5. Categories of data subject
- You, and anyone else you give access to your account.
- Any person whose details you enter into a form, such as a dependant or an employee.
6. Processing on instructions
- We process personal data only on your documented instructions, which include your use of the service and any configuration you set in it.
- We do not use your personal data to train models, and we do not sell or share it for anyone else's purposes.
- If we believe an instruction breaks a data protection law, we will tell you and may pause that processing rather than carry it out.
7. Confidentiality
Everyone we authorise to process personal data is bound to keep it confidential, and access is limited to those who need it to run or support the service.
8. Security of processing
We keep technical and organisational measures appropriate to the risk. The measures in force are published and dated on the security page (/legal/trust), which forms Annex II to this agreement. We may change a measure, but not so as to lower the level of protection.
9. Sub-processors
You give general authorisation for the sub-processors listed below, which form Annex I. Each is engaged under its own data protection terms and only to the extent needed to run the service.
| Cloudflare | Hosting, storage, the browser that renders a form's pages, and the model that reads what each box is for. Documents stay inside Cloudflare's network. Country: United States |
|---|---|
| Stripe (api.stripe.com) | Subscription billing: the account email, the amount and the plan. Card details never reach us — Checkout is hosted by Stripe. Country: United States |
| Resend (api.resend.com) | Transactional email: the recipient address and the message, including sign-in links, reminders and billing notices. Country: United States |
Before a new sub-processor starts processing your personal data we will publish it on the security page at least 30 days in advance. If you object on reasonable data protection grounds within that period, you may terminate the affected part of the service and receive a refund of any fees paid for the unused remainder of the term.
We remain responsible to you for a sub-processor's performance of these obligations.
10. Assisting you with data subject rights
- The service lets you read, correct, export and delete the personal data it holds, so that you can answer a data subject yourself.
- Where you cannot, we will help you within a reasonable time, taking into account the nature of the processing.
- If a data subject comes to us directly, we will not answer for you: we will pass the request on, unless a law requires us to answer it, and we will tell you why. The route for such a request is the disclosure form (/legal/disclosure).
11. Personal data breach
- We will notify you of a personal data breach affecting your data without undue delay, and in any event within 72 hours of becoming aware of it.
- The notice will describe what happened, the categories and approximate number of records affected as far as we know them, the likely consequences, and what we have done and propose to do.
- Where we cannot give all of that at once, we will give what we have and follow it up rather than waiting.
- We will also help you meet your own obligations to notify a supervisory authority or the people affected, and with a data protection impact assessment or prior consultation where one is needed.
12. Deletion and return
- You may export your data at any time while the account is open. We do not hold it back as leverage over a renewal.
- When you close the account we delete the personal data held for it, on the schedule set out in section 3, and we keep no copy for a purpose of our own.
- Backups age out on their own schedule and are not searched for a single deleted record.
- Where a law requires us to keep something, we keep only that, only for as long as the law requires, and for no other purpose.
13. Information and audit
- We will make available the information needed to show that these obligations are met, starting with the security page and this agreement.
- You may audit no more than once in a twelve-month period, on reasonable notice, during business hours, without disrupting the service, and under confidentiality. A supervisory authority exercising its own powers is not subject to that limit.
- Where an independent report covering the relevant controls exists, we may offer it in place of an on-site audit; where none exists, the security page says so plainly rather than implying one.
14. International transfers
- Processing takes place in the United States and across Cloudflare's global network, so personal data is handled outside Japan.
- Each processor is engaged under its own data protection terms and handles data only on our instructions.
- Where a transfer needs a lawful mechanism, the one offered by that sub-processor applies, and we do not engage a sub-processor that offers none.
15. Precedence, changes and governing law
- On data protection, this agreement prevails over the terms of service where the two disagree.
- We may update it to keep it accurate or to meet a change in law. A material change is posted here with the date it takes effect.
- Governing law and jurisdiction follow the terms of service.
Last updated: 2026-09-07