WPForms Data Processing Addendum
DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA“) forms part of the Agreement between WPForms, LLC (“WPForms“) and [Customer Name] (“Customer“) and shall be effective on the date both parties execute this DPA (“Effective Date“). All capitalized terms not defined in this DPA shall have the meanings set forth in the Agreement.
1. Definitions
“Affiliate” means an entity that directly or indirectly Controls, is Controlled by, or is under common Control with an entity.
“Agreement” means WPForms’ Terms of Service, which govern the provision of the Services to Customer, as such terms may be updated by WPForms from time to time.
“Control” means an ownership, voting, or similar interest representing fifty percent (50%) or more of the total interests then outstanding of the entity in question. “Controlled” is construed accordingly.
“Customer Data” means any Personal Data that WPForms processes on behalf of Customer as a Data Processor in the course of providing Services, as more particularly described in this DPA.
“Data Protection Laws” means all data protection and privacy laws applicable to the processing of Personal Data under the Agreement, including, where applicable, EU Data Protection Law and Non-EU Data Protection Laws.
“Data Controller” means an entity that determines the purposes and means of the processing of Personal Data.
“Data Processor” means an entity that processes Personal Data on behalf of a Data Controller.
“EU Data Protection Law” means all data protection laws and regulations applicable to Europe, including (i) the GDPR; (ii) Directive 2002/58/EC (ePrivacy); (iii) applicable national implementations of (i) and (ii); and (iv) UK data protection legislation following its withdrawal from the EU; and (v) any amendments and replacements thereof.
“EEA” means, for purposes of this DPA, the European Economic Area, United Kingdom, and Switzerland.
“Group” means any and all Affiliates that are part of an entity’s corporate group.
“Non-EU Data Protection Laws” means the California Consumer Privacy Act (“CCPA”); the Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”); the Brazilian General Data Protection Law (“LGPD”), Federal Law no. 13,709/2018; the Privacy Act 1988 (Cth) of Australia, as amended (“Australian Privacy Law”); and the South African Protection of Personal Information Act 4 of 2013 (“POPIA”).
“WPForms Network” means the WPForms data center facilities, servers, networking equipment, and host software systems that are within WPForms’ control and are used to provide the Services.
“Personal Data” means any information relating to an identified or identifiable natural person.
“Processing” has the meaning given to it in the GDPR, and “process,” “processes,” and “processed” are interpreted accordingly.
“Security Incident” means any unauthorized or unlawful breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data.
“Services” means any product or service provided by WPForms to Customer pursuant to the Agreement.
“Standard Contractual Clauses” (“SCCs“) means Annex D attached to and forming part of this DPA.
“Sub-processor” means any Data Processor engaged by WPForms or its Affiliates to assist in fulfilling its obligations with respect to providing the Services pursuant to the Agreement or this DPA. Sub-processors may include third parties or members of the WPForms Group.
2. Relationship with the Agreement
2.1 This DPA replaces any existing DPA the parties may have previously entered into in connection with the Services.
2.2 Except for the changes made by this DPA, the Agreement remains unchanged and in full force and effect.
2.3 If there is any conflict between this DPA and the Agreement, this DPA shall prevail to the extent of that conflict. Order of precedence: (i) SCCs; then (ii) this DPA; then (iii) the WPForms Terms of Service.
2.4 This DPA remains in effect for as long as WPForms carries out Customer Data processing operations on behalf of Customer, or until termination of the Agreement (and all Customer Data has been returned or deleted per Section 9.1).
2.5 Claims brought under this DPA are subject to the exclusions and limitations of liability set forth in the Agreement.
2.6 Claims against WPForms or its Affiliates under this DPA shall be brought solely against the entity that is a party to the Agreement. Regulatory penalties incurred by WPForms arising from Customer’s failure to comply with its obligations under this DPA or applicable Data Protection Laws count toward and reduce WPForms’ liability under the Agreement.
2.7 No one other than a party to this DPA, its successors, and permitted assignees shall have any right to enforce its terms.
2.8 This DPA shall be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Laws.
3. Scope and Applicability of this DPA
3.1 This DPA applies where and only to the extent WPForms processes Customer Data that originates from the EEA and/or is otherwise subject to EU Data Protection Law, as a Data Processor, in the course of providing Services under the Agreement.
4. Roles and Scope of Processing
4.1 Role of the parties. Customer is the controller of Customer Data; WPForms is a processor acting on Customer’s behalf, as further described in Annex A.
4.2 Prohibited data. Customer will not provide (or cause to be provided) any Sensitive Data to WPForms for processing under the Agreement, and WPForms will have no liability for Sensitive Data. This DPA does not apply to Sensitive Data.
4.3 Purpose limitation. WPForms shall process Customer Data only in accordance with Customer’s documented lawful instructions as set forth in this DPA, as necessary to comply with applicable law, or as otherwise agreed in writing (“Permitted Purposes“). The Agreement and this DPA constitute Customer’s complete and final instructions; processing outside this scope requires prior written agreement.
4.4 Customer compliance. Customer represents and warrants that it has complied and will continue to comply with Data Protection Laws with respect to Customer Data and any instructions it issues to WPForms, and that it has obtained all consents and rights necessary for WPForms to process Customer Data for the purposes described in the Agreement and this DPA. Customer is solely responsible for the accuracy, quality, and legality of Customer Data and the means by which it was acquired.
4.5 Lawfulness of instructions. Customer will ensure WPForms’ processing per Customer’s instructions will not cause WPForms to violate Data Protection Laws. WPForms shall promptly notify Customer in writing if it becomes aware or believes any instruction violates the GDPR or its implementations.
4.6 Notwithstanding the foregoing, Customer acknowledges WPForms may use and disclose data relating to the operation, support, and/or use of the Services for its legitimate business purposes (billing, account management, technical support, product development, sales and marketing). To the extent this is Personal Data, WPForms is the Data Controller of it and processes it per the WPForms Privacy Policy and Data Protection Laws.
4.7 Tracking Technologies. Tracking Technologies. Customer acknowledges that in connection with the performance of the Services, WPForms employs the use of cookies, unique identifiers, web beacons and similar tracking technologies (“Tracking Technologies”). Customer shall maintain appropriate notice, consent, opt-in and opt-out mechanisms as are required by Data Protection Laws to enable OptinMonster to deploy Tracking Technologies lawfully on, and collect data from, the devices of Subscribers (defined below) in accordance with and as described in the WPForms Privacy Policy.
5. Subprocessing
5.1 Authorized Sub-processors. Customer agrees WPForms may engage Sub-processors to process Customer Data on Customer’s behalf. The Sub-processors currently engaged and authorized are listed in Annex B.
5.2 Sub-processor obligations. WPForms shall: (i) enter into a written agreement with each Sub-processor imposing data protection terms requiring the Sub-processor to protect Customer Data to the standard required by Data Protection Laws; and (ii) remain responsible for its compliance with this DPA and for any acts or omissions of the Sub-processor that cause WPForms to breach its obligations under this DPA.
5.3 WPForms shall (i) keep an up-to-date list of Sub-processors (Annex B) on its website; (ii) provide this list upon written request from Customer; and (iii) provide notice through this agreement that Customer is responsible for checking the website for updates or requesting an updated list.
5.4 Customer may object in writing to WPForms’ appointment of a new Sub-processor within five (5) calendar days of notice, on reasonable data-protection grounds. The parties shall discuss such concerns in good faith. If unresolved, Customer may suspend or terminate the Agreement (without prejudice to fees incurred prior to suspension or termination).
6. Security
6.1 Security Measures. WPForms shall implement and maintain appropriate technical and organizational security measures designed to protect Customer Data from Security Incidents and preserve its security and confidentiality, per Annex C.
6.2 Confidentiality of processing. WPForms shall ensure any person authorized to process Customer Data is under an appropriate obligation of confidentiality (contractual or statutory).
6.3 Updates to Security Measures. Customer is responsible for independently assessing whether the Services meet its requirements and legal obligations. WPForms may update the Security Measures over time provided this does not degrade overall security.
6.4 Security Incident response. Upon becoming aware of a Security Incident, WPForms shall: (i) notify Customer without undue delay, and where feasible, no later than 48 hours from becoming aware; (ii) provide timely information as it becomes known or is reasonably requested; and (iii) promptly take reasonable steps to contain and investigate. Notification is not an acknowledgment of fault or liability.
6.5 Customer responsibilities. Customer is responsible for its secure use of the Services, including securing account credentials and the security of Customer Data in transit to and from the Services.
7. Security Reports and Audits
7.1 Audit rights. WPForms shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, exercised via the measures in 7.2–7.3 below.
7.2 Customer acknowledges that WPForms is regularly audited against SSAE 16 and PCI standards by internal auditors, respectively. Upon request, WPForms shall supply (on a confidential basis) a summary copy of its audit report(s) (“Report”) to Customer, so that Customer can verify WPForms’ compliance with the audit standards against which it has been assessed, and this DPA.
7.3 Security due diligence. Security due diligence. In addition to the Report, WPForms shall respond to all reasonable requests for information made by Customer to confirm WPForms’ compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, by making additional information available regarding its information security program upon Customer’s written request to [email protected], provided that Customer shall not exercise this right more than once per calendar year.
8. International Transfers
8.1 Data center locations. WPForms may transfer and process Customer Data anywhere in the world where WPForms, its Affiliates, or Sub-processors maintain data processing operations, provided an adequate level of protection is maintained per Data Protection Laws and this DPA.
8.2 Alternative transfer mechanism. If WPForms adopts an alternative, compliant data export mechanism, that mechanism applies instead of the one described in this DPA, to the extent it satisfies EU Data Protection Law.
9. Return or Deletion of Data
9.1 Upon termination or expiration of the Agreement, WPForms shall, at Customer’s election, delete or return all Customer Data (including copies) in its possession or control, except to the extent applicable law requires retention, or for Customer Data archived on backup systems, which WPForms shall securely isolate, protect from further processing, and eventually delete per its deletion policies.
10. Cooperation
10.1 Data subject requests. The Services provide Customer, at no additional cost, with controls to retrieve, correct, delete, or restrict Customer Data to assist with its Data Protection Law obligations. WPForms shall, taking into account the nature of processing, provide reasonable additional assistance (at Customer’s expense) as needed. If a data subject request is made to WPForms directly, WPForms will not respond directly except to redirect the data subject to Customer, unless legally required, without Customer’s prior authorization.
10.2 Law enforcement requests. If a law enforcement agency demands Customer Data from WPForms, WPForms shall attempt to redirect the request to Customer, and if compelled to disclose, shall give Customer reasonable notice to allow it to seek a protective order, unless legally prohibited.
10.3 Data protection impact assessments. To the extent required, WPForms shall provide reasonably requested information to enable Customer to carry out DPIAs or prior consultations, via Section 7 compliance, the information in this DPA, and additional reasonable assistance (at Customer’s expense) if needed.
11. Limitation of Liability
11.1 Each party’s liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability set forth in the Agreement.
11.2 Claims against WPForms or its Affiliates under this DPA shall be brought solely by the Customer entity that is a party to the Agreement.
11.3 In no event shall any party limit its liability with respect to any individual’s data protection rights under this DPA or otherwise.
IN WITNESS WHEREOF, the parties have caused this DPA to be executed by their authorized representative:
WPForms, LLC By:
Name: Zach Tirrell, General Manager
Date: September 4, 2026
[Customer Name] By: Name: [ ] Title: [ ] Date: [ ]
Annex A – Details of Data Processing
(a) Controller (data exporter): Customer, being a WPForms customer that has engaged WPForms to provide the Service under the Agreement.
(b) Processor (data importer): WPForms, LLC.
(c) Subject matter: The Customer Data.
(d) Duration of processing: Until termination of the Agreement, per Section 9 (Return or Deletion of Data).
(e) Purpose of processing: WPForms shall only process Customer Data for the Permitted Purposes: (i) as necessary to provide the Service under the Agreement; (ii) processing initiated by Customer in its use of the Service; and (iii) to comply with other reasonable instructions consistent with the Agreement.
(f) Nature of the processing: WPForms provides form-building, form-submission-handling, and related plugin and software services, as more particularly described in the Agreement.
(g) Categories of data subjects: (i) Customers and Users (individuals accessing/using the Services through Customer’s account); and (ii) End Users — individuals who submit a form built using the Services, or whose information is otherwise stored on or collected via the Services.
(h) Types of Customer Data: Depending on the fields Customer configures, this may include: – Customers and Users: name, address, contact details, username, license key, payment/billing information (actual card data handled by the applicable payment processor, not stored by WPForms), site/technical environment details (WordPress version, PHP/MySQL version). – End Users: name, email address, phone number, IP address, free-text responses, file uploads, and payment-related tokens submitted through Customer-configured forms.
(i) Sensitive Data: WPForms does not intend to, nor does it intentionally, collect or process Sensitive Data in connection with the provision of the Service. Because form fields are configurable by Customer, Customer is responsible for not collecting Sensitive Data through the Services unless additional safeguards are in place.
(j) Processing Operations: Customer Data will be processed per the Agreement and this DPA and may be subject to: – Storage and processing necessary to provide, maintain, and improve the Service; – Transmission to a WPForms-hosted API for PDF generation, where Customer enables the PDF addon (see Section 4.7); – Disclosures in accordance with the Agreement and/or as compelled by applicable law.
Annex B – List of WPForms Sub-processors
WPForms uses its Affiliates and a range of third-party Sub-processors to assist in providing the Services.
Entity Name
OpenAI, LLC
Cloudflare, Inc.
Google LLC (Google Cloud)
PlanetScale, Inc.
Functional Software, Inc. (Sentry)
Annex C – Security Measures
- Information Security Program. WPForms will maintain an information security program (including internal policies and procedures) designed to help Customer secure Customer Data against accidental or unlawful loss, access, or disclosure; identify foreseeable risks; and minimize security risks through risk assessment and testing.
- Network Security. Access controls and policies manage what access is allowed to the WPForms Network, including firewalls/equivalent technology and authentication controls, with incident response plans for potential threats.
- Physical Security.
- Continued Evaluation. WPForms will conduct periodic reviews of the security of its Network and the adequacy of its information security program against industry standards, and will evaluate whether additional measures are needed in response to new risks.
Annex D – Standard Contractual Clauses as applied to Customers
Common provisions (Clauses 1–7, 14–16, 18) may be adapted from the official EU Commission Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) largely as OM has done, once the Module Two substitution above is resolved.
Appendix (Annex I/II equivalent): – List of Parties (data exporter = Customer, data importer = WPForms, LLC) — names, addresses, contact/DPO details to be completed per-Customer at signature. – Description of Transfer — categories of data subjects, categories of Personal Data, frequency, nature, purpose, and retention period: pull from Annex A above once finalized. – Technical and organizational measures: pull from Annex C above once finalized.