VeloxForm
Home Features Pricing Login

GDPR Compliance

How VeloxForm protects your data rights under the General Data Protection Regulation

Last updated: March 2026

Our Commitment: VeloxForm is fully committed to GDPR compliance. We protect the personal data of all our users, regardless of location, with the same high standards required by European law.

What is GDPR?

The General Data Protection Regulation (GDPR) is a European Union law that gives people more control over their personal data. It applies to:

  • All EU residents and citizens
  • Anyone whose data is processed by EU companies
  • Organizations worldwide that handle EU residents' data

Even if you're not in the EU, we apply GDPR protections to everyone because it's the right thing to do.

Your GDPR Rights

Under GDPR, you have these important rights:

Right to Access

You can request a copy of all personal data we hold about you. We'll provide this in a clear, readable format within 30 days.

Right to Rectification

You can correct inaccurate or incomplete personal data. Update your profile in settings or contact us for help.

Right to Erasure

You can request deletion of your personal data ("right to be forgotten"). We'll delete it within 30 days unless we have a legal reason to keep it.

Right to Restrict Processing

You can limit how we use your data in certain situations. We'll mark your data and only use it for limited purposes.

Right to Data Portability

You can get your data in a format that lets you transfer it to another service. Download your form submissions as CSV files anytime.

Right to Object

You can object to how we use your data for marketing or other specific purposes. We'll stop unless we have compelling legitimate grounds.

Rights Related to Automated Decision-Making

You have rights about decisions made by computers that significantly affect you. We don't make such decisions about our users.

Right to Data Protection

We must protect your data with appropriate security measures and notify you of any breaches that could affect you.

Lawful Basis for Processing

We only process your personal data when we have a lawful basis:

1. Contract (Primary Basis)

Most processing is necessary to provide our service to you under our Terms of Service. This includes:

  • Creating and managing your account
  • Processing form submissions
  • Sending you important service emails
  • Providing customer support

2. Legitimate Interests

We process some data for our legitimate business interests, balanced against your rights:

  • Improving our service based on usage patterns
  • Preventing fraud and spam
  • Sending you information about new features (you can opt out)
  • Maintaining security of our systems

3. Legal Obligations

Sometimes we must process data to comply with laws:

  • Tax and accounting requirements
  • Responding to lawful requests from authorities
  • Protecting our legal rights

Data We Collect and Why

We're transparent about what data we collect and why we need it:

Account Data (Required for Service)

  • Name & Email: To identify you and communicate
  • Password (encrypted): To secure your account
  • Payment info: Processed by Stripe, not stored by us

Form Data (Your Content)

  • Forms you create: Your content, you control it
  • Submissions received: Data from people filling your forms
  • File uploads: Documents uploaded through forms

Usage Data (Service Improvement)

  • IP addresses: Security and analytics (anonymized where possible)
  • Device info: To optimize our service for your device
  • Feature usage: To improve our service

International Data Transfers

Your data may be processed in different countries. We ensure appropriate protections:

  • EU-US Data Transfers: We comply with current adequacy decisions
  • Standard Contractual Clauses: Used when necessary for legal transfers
  • Data Minimization: We only transfer data that's necessary
  • Encryption: All data is encrypted in transit and at rest

Data Retention

We keep your data only as long as necessary:

  • Active accounts: While you maintain your account
  • Deleted accounts: Permanently deleted within 30 days
  • Form submissions: Based on your plan (30 days to 2 years)
  • Backups: Removed from backups within 90 days of deletion
  • Legal requirements: Longer if required by law (tax records, etc.)

Your Rights in Action

How to exercise your GDPR rights:

Access Your Data

Download your data anytime from your dashboard, or email us at admin@veloxform.com. We'll respond within 30 days.

Delete Your Data

Delete your account in settings, or contact us. We'll confirm deletion within 30 days.

Correct Your Data

Update your profile in settings, or email us corrections. We'll update within 7 days.

Port Your Data

Export your form submissions as CSV files from your dashboard anytime.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance:

Contact our DPO:

Email: admin@veloxform.com

Response time: Usually within 5 business days

Our DPO handles complex privacy questions and complaints.

Data Breach Notification

If a data breach occurs that could affect your rights, we will:

  • Notify affected users within 72 hours when possible
  • Describe what happened and what data was involved
  • Explain what we're doing to fix it
  • Provide steps you can take to protect yourself
  • Report to authorities as required by law

Supervisory Authority

You have the right to complain to a data protection authority if you believe we've violated GDPR. Contact details for EU supervisory authorities are available at:

European Data Protection Board: edpb.europa.eu

We prefer to resolve issues directly, so please contact us first.

Updates to This Policy

We update this GDPR policy as needed to reflect changes in our practices or law. When we do:

  • We'll notify you of significant changes
  • Changes take effect when posted
  • We'll update the "Last updated" date
  • Major changes will be clearly highlighted
Back to Home