GDPR Compliance
Last updated: July 25, 2026
Formit AI is committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines our approach to GDPR compliance for account holders and form respondents.
Our role under GDPR
For account holder data (your name, email, billing info, usage analytics), Formit AI acts as the data controller.
For respondent submission data (answers submitted through forms you create), you are the data controller and Formit AI acts as your data processor. We process respondent data only as instructed by you and as necessary to provide the service.
Legal basis for processing
- Contract performance: Processing account data to provide the services you signed up for.
- Legitimate interest: Security measures, fraud prevention, and service improvement analytics.
- Consent: Optional communications and non-essential cookies (where applicable).
Your responsibilities as a form creator
When you use Formit AI to collect personal data from respondents, you must:
- Have a lawful basis for collecting and processing their data;
- Inform respondents about what data you collect and why (e.g. via a privacy notice on your form);
- Respond to respondent access, correction, and deletion requests;
- Not collect special category data without explicit consent and a valid legal basis.
Data subject rights
Under GDPR, individuals in the EEA have the right to:
- Access their personal data;
- Rectification of inaccurate data;
- Erasure (“right to be forgotten”);
- Restriction of processing;
- Data portability;
- Object to processing based on legitimate interest;
- Withdraw consent at any time.
Account holders can exercise these rights by emailing tahir@neurodek.com. Respondents should contact the form creator who collected their data.
International data transfers
Formit AI is operated from Pakistan. When data is transferred outside the EEA, we ensure appropriate safeguards are in place, including the use of hosting providers that maintain adequate protection standards.
Security measures
We implement technical and organizational measures including TLS encryption, access controls, secure authentication, and regular security reviews. See our Security page for details.
Data retention
Account data is retained while your account is active. After deletion, data is permanently removed after a 7-day recovery window, with backups purged within 30 days. Submission data retention is managed by the form creator.
Data Processing Agreement
Paid plan customers who require a formal Data Processing Agreement (DPA) can request one by emailing tahir@neurodek.com.
Contact
- Email: tahir@neurodek.com
- Location: Formit AI, Lahore, Pakistan
Related policies