Data Processing Agreement

Version 1.1 · Last updated: July 17, 2026

This Data Processing Agreement (the “DPA”) forms part of, and is incorporated by reference into, the agreement between the Customer and Search Ventures Pty Ltd (ACN 639 906 353) governing the Customer’s use of the Formpaste service (the “Principal Agreement”, being our Terms of Service). It reflects the parties’ agreement on the Processing of Personal Data by Search Ventures Pty Ltd on behalf of the Customer in connection with the Services. This DPA supplements our Privacy Policy and Acceptable Use Policy, which continue to apply.

By accepting this DPA, whether by clicking “I accept”, checking a box referencing it, enabling the Services, or continuing to use the Services after being presented with it, the Customer agrees to be bound by its terms. The individual accepting represents that they are authorised to bind the Customer.

In this DPA, “Search Ventures” means Search Ventures Pty Ltd (ACN 639 906 353), the operator of Formpaste, acting as Processor or Sub-processor, as applicable; and “Customer” means the entity or person that has entered into the Principal Agreement, acting as Controller or Processor, as applicable. Each is a “party” and together the “parties”.

1. Definitions

Capitalised terms not defined here have the meaning given in the Principal Agreement. For the purposes of this DPA:

  • “Data Protection Laws” means all privacy, data protection, information-security, breach-notification, direct-marketing and electronic-communications laws applicable to the Processing of Personal Data under this DPA, including, where applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Privacy Act 1988 (Cth) and the Australian Privacy Principles, in each case as amended, replaced or re-enacted from time to time.
  • “Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach” have the meanings given in the GDPR, and “Process” and “Processed” are construed accordingly.
  • “Customer Personal Data” means Personal Data contained within form submissions, uploaded files, and related data that is submitted to, stored in, or otherwise Processed by the Services on the Customer’s behalf.
  • “Sub-processor” means any third party engaged by Search Ventures to Process Customer Personal Data.
  • “Standard Contractual Clauses (SCCs)” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 for the transfer of Personal Data to third countries, and, where relevant, the UK International Data Transfer Addendum.
  • “Services” means the Formpaste form-backend service and associated email delivery, file storage, and integration features.

2. Roles and Scope of Processing

The parties acknowledge that, with respect to Customer Personal Data, the Customer acts as Controller or Processor, as applicable, and Search Ventures acts as Processor or Sub-processor, as applicable. Where the Customer is itself a Processor acting on behalf of a third-party Controller, the Customer warrants that its instructions and actions have been authorised by that Controller.

Search Ventures shall Process Customer Personal Data only on documented instructions from the Customer, including as set out in this DPA and the Principal Agreement, and as necessary to provide the Services, unless required to do so by applicable law (in which case Search Ventures shall, where legally permitted, inform the Customer of that legal requirement before Processing).

Search Ventures shall inform the Customer without undue delay if, in its reasonable opinion, an instruction from the Customer infringes applicable Data Protection Laws, unless applicable law prohibits Search Ventures from providing that information.

The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1 (Details of Processing).

The Customer is solely responsible for the accuracy, quality and legality of Customer Personal Data and for having a valid legal basis to Process it and to authorise Search Ventures’ Processing of it under this DPA.

3. Confidentiality

Search Ventures shall ensure that any person authorised to Process Customer Personal Data, including employees and contractors, is subject to an appropriate obligation of confidentiality, whether contractual or statutory, and Processes such data only as instructed.

4. Security of Processing

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, Search Ventures shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. A description of these measures is set out in Annex 2 (Technical and Organisational Measures).

The Customer acknowledges that security measures are subject to technical progress and may be updated from time to time, provided that any update does not materially reduce the overall level of security of the Services.

5. Sub-processors

The Customer provides general authorisation for Search Ventures to engage Sub-processors to Process Customer Personal Data, subject to this Section. The Sub-processors engaged as at the effective date are listed in Annex 3.

Search Ventures shall impose data protection obligations on each Sub-processor that are, in substance, no less protective than those in this DPA, and shall remain liable to the Customer for the performance of each Sub-processor’s obligations.

Search Ventures shall notify the Customer of any intended addition or replacement of a Sub-processor, giving the Customer a reasonable opportunity (of at least fourteen days) to object on reasonable data-protection grounds. An objection must be submitted in writing within the notice period and must describe the reasonable data-protection grounds for the objection in sufficient detail. Search Ventures may, at its option, use reasonable efforts to address the objection, make available an alternative Sub-processor, or discontinue the affected feature or Services for the objecting Customer. If the parties cannot resolve the objection, the Customer may terminate the affected Services as its sole remedy.

6. Data Subject Rights and Cooperation

Taking into account the nature of the Processing, Search Ventures shall assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Data Protection Laws.

If Search Ventures receives a request directly from a Data Subject relating to Customer Personal Data, it shall, unless legally prohibited, promptly forward the request to the Customer and shall not respond to it directly except on the Customer’s instructions.

Search Ventures shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, in each case solely in relation to the Processing under this DPA and taking into account the information available to Search Ventures.

7. Personal Data Breach

Search Ventures shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and, where reasonably practicable, within forty-eight (48) hours after becoming aware of the Personal Data Breach.

Such notification shall include, to the extent then known and reasonably available to Search Ventures, the nature of the Personal Data Breach; the categories and approximate number of affected Data Subjects and Personal Data records; the likely consequences; and the measures taken or proposed to address and mitigate the Personal Data Breach. Where it is not possible to provide all information at the same time, Search Ventures may provide the information in phases without undue further delay.

Search Ventures shall provide reasonable cooperation and assistance to the Customer in connection with the Customer’s assessment, investigation, notification and remediation of the Personal Data Breach, taking into account the nature of the Processing and the information available to Search Ventures.

Search Ventures’ notification of, or response to, a Personal Data Breach shall not be construed as an acknowledgement of fault, liability or responsibility.

8. Compelled Disclosure Requests

If Search Ventures receives a legally binding request from a court, regulator, law-enforcement agency or other public authority for disclosure of Customer Personal Data, Search Ventures shall, unless prohibited by applicable law, promptly notify the Customer before disclosing the Customer Personal Data.

Where permitted and reasonable in the circumstances, Search Ventures shall provide the Customer with relevant information about the request and reasonable cooperation to enable the Customer to seek a protective order or other appropriate remedy. Search Ventures shall disclose only the minimum Customer Personal Data that it is legally required to disclose and shall, where appropriate, seek confidential treatment of the disclosed Customer Personal Data.

Nothing in this Section requires Search Ventures to challenge a legally binding request, incur material costs, delay compliance with applicable law, or disclose information where prohibited by applicable law.

Where the EU SCCs apply, Search Ventures shall comply with its obligations under Clause 15 of the EU SCCs in relation to binding requests for disclosure from public authorities, and those obligations prevail to the extent of any inconsistency with this Section.

9. Return and Deletion of Data

During the term of the Principal Agreement, Customer Personal Data is retained in accordance with the retention period applicable to the Customer’s selected plan, as specified in the Services, the Customer’s account settings, or the applicable order form. The retention period is designed to apply automatically to stored submission data - currently 90 days on the Free plan and 365 days on Pro. The Customer is responsible for exporting Customer Personal Data before expiry of the applicable retention period where it requires a longer retention period.

Following termination or expiry of the Principal Agreement, Search Ventures shall delete Customer Personal Data within ninety (90) days, unless applicable law requires continued storage or the Customer requests return of Customer Personal Data before deletion and return is technically feasible through the Services or otherwise agreed by the parties.

Customer Personal Data contained in backup systems may remain until deleted or overwritten in accordance with Search Ventures’ ordinary backup-retention cycle. Until deletion or overwrite, backup copies shall be protected in accordance with this DPA, isolated from ordinary operational use, and not restored except where necessary for disaster recovery, security investigation or compliance with applicable law.

Search Ventures may retain limited account, billing, security, audit and system-log information to the extent reasonably necessary for legal compliance, fraud prevention, security, dispute resolution, enforcement of the Principal Agreement, and establishment, exercise or defence of legal claims. Any retained information remains subject to applicable confidentiality and security obligations.

10. Audits and Information

Search Ventures shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR. Search Ventures may satisfy this obligation by providing relevant policies, security documentation, completed security questionnaires, summaries of technical and organisational measures, and, where available, third-party certifications, attestations or audit reports relating to Search Ventures or its infrastructure providers.

Before requesting an audit, the Customer shall first use the information and materials made available by Search Ventures under this Section. If those materials are reasonably insufficient to demonstrate compliance with this DPA, the Customer may request a further audit in accordance with this Section.

Any audit must: (a) relate solely to Search Ventures’ Processing of Customer Personal Data under this DPA; (b) occur no more than once in any twelve-month period, unless required by a competent supervisory authority or following a confirmed Personal Data Breach affecting Customer Personal Data; (c) be requested on at least thirty (30) days’ prior written notice; (d) be conducted during normal business hours; (e) be carried out by an independent auditor selected by the Customer and reasonably acceptable to Search Ventures; (f) be subject to a written confidentiality agreement; and (g) not unreasonably interfere with Search Ventures’ business operations, compromise the security or confidentiality of its systems, or provide access to information relating to other customers, personnel, source code, security testing methods, trade secrets or infrastructure that is not relevant to the audit.

Search Ventures may require that an audit be conducted remotely, through document review, interviews, or another method reasonably designed to minimise disruption and security risk. On-site audits are permitted only where reasonably necessary after the alternatives described above have been exhausted.

The Customer shall bear its own audit costs and reimburse Search Ventures for its reasonable costs and time incurred in supporting any audit, except to the extent an audit identifies a material breach by Search Ventures of this DPA.

The Customer shall ensure that its auditor is not a competitor of Search Ventures and does not have any actual or reasonably foreseeable conflict of interest. Search Ventures may suspend or defer an audit where reasonably necessary to address an actual or suspected security incident, legal restriction, material operational disruption, or risk to the confidentiality, availability or integrity of the Services.

This Section does not require Search Ventures to permit direct audit of a Sub-processor’s facilities or systems. Search Ventures may instead provide relevant information reasonably available from the Sub-processor, including applicable certifications, audit reports, attestations, or contractual assurances.

11. International Data Transfers

The Customer acknowledges that Search Ventures operates from Australia and that Customer Personal Data may be Processed in Australia and in other jurisdictions where Search Ventures or its authorised Sub-processors operate, including through globally distributed infrastructure and service regions.

To the extent that Search Ventures receives Customer Personal Data from the European Economic Area, Switzerland or the United Kingdom in a manner that requires an approved transfer mechanism under applicable Data Protection Laws, the parties agree that the Standard Contractual Clauses form part of this DPA.

For transfers subject to the GDPR, the parties incorporate the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) as follows:

  • Module Two (Controller to Processor) applies where the Customer acts as Controller and Search Ventures acts as Processor.
  • Module Three (Processor to Processor) applies where the Customer acts as Processor and Search Ventures acts as Sub-processor on the Customer’s documented instructions.
  • Clause 7 (Docking Clause) is included.
  • For Clause 9, Option 2 (general written authorisation) applies, with the Sub-processor authorisation and objection process in Section 5 of this DPA.
  • For Clause 11, the optional independent dispute-resolution mechanism is not included.
  • For Clause 17 and Clause 18, the EU SCCs are governed by the law of, and disputes are subject to the courts of, an EU Member State that permits third-party beneficiary rights under the EU SCCs, as specified in Annex 4.
  • Annex 1, Annex 2 and Annex 3 of this DPA respectively form Annex I, Annex II and Annex III to the EU SCCs, supplemented by Annex 4.

For transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner’s Office (“UK Addendum”) is incorporated into this DPA. The tables in the UK Addendum are completed using the relevant provisions and annexes of this DPA, the EU SCCs and Annex 4.

For transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with the modifications necessary to provide appropriate safeguards under Swiss law, including that references to the GDPR include the Swiss Federal Act on Data Protection, references to the European Union or Member States include Switzerland where applicable, and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority to the extent required by Swiss law.

Where required by applicable Data Protection Laws, the parties shall provide reasonable cooperation in connection with transfer impact assessments, supplementary measures, or updates to the transfer mechanism. Search Ventures may take reasonable and proportionate supplementary technical, organisational or contractual measures to protect Customer Personal Data transferred internationally.

In the event of a conflict between this DPA and the EU SCCs, UK Addendum or applicable Swiss adaptations, the applicable transfer mechanism prevails to the extent of the conflict.

12. Liability

Each party’s liability arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Principal Agreement, and any reference to a party’s liability means the aggregate liability of that party under the Principal Agreement and this DPA together.

13. General

This DPA is governed by the same law and subject to the same jurisdiction and dispute-resolution provisions as the Principal Agreement (the laws of Queensland, Australia), unless the Data Protection Laws require otherwise. The governing law and forum of the EU SCCs are as set out in Section 11 and Annex 4.

In the event of any conflict between this DPA and the Principal Agreement in relation to the Processing of Personal Data, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.

If any provision of this DPA is held invalid or unenforceable, the remainder shall continue in full force and effect.

Search Ventures may update this DPA to reflect changes in applicable Data Protection Laws, the Services, its Sub-processors, security measures, or operational practices. Search Ventures shall not make an update that materially reduces the protections afforded to Customer Personal Data during the then-current paid subscription term, except where required by applicable law or necessary to address a material security, fraud or operational risk. Where an update materially affects the Customer’s rights or obligations under this DPA, Search Ventures shall provide reasonable prior notice through the Services, by email, or by another reasonable means. The current version of this DPA will be made available through the Services.

Notices, Sub-processor objections and requests relating to this DPA must be sent to privacy@formpaste.com or using the contact method specified in the Services or the Privacy Policy.

Annex 1 - Details of Processing

Subject matter and duration

The Processing of Customer Personal Data submitted through the Formpaste Services for the duration of the Principal Agreement, plus the retention period described in Section 9.

Nature and purpose of Processing

Receiving, validating, storing, and forwarding web form submissions; delivering notification and autoresponse emails; storing and virus-scanning uploaded file attachments; managing spam filtering, bounce and complaint handling; and enabling integrations selected by the Customer.

Categories of Data Subjects

  • Individuals who submit the Customer’s web forms (e.g., website visitors, leads, applicants, customers of the Customer).
  • Any other individuals whose Personal Data the Customer includes in submissions or configuration.

Types of Personal Data

Determined by the Customer through the fields it configures in its forms. This may include, without limitation:

  • Contact details such as name, email address, phone number, and postal address.
  • Message content and free-text fields submitted by Data Subjects.
  • File attachments and their contents.
  • Technical metadata such as IP address, timestamp, and referrer information.

The Customer must not configure its forms to collect Special Categories of Personal Data under Article 9 of the GDPR, personal data relating to criminal convictions and offences under Article 10 of the GDPR, payment-card data, financial-account credentials, government-issued identification numbers, authentication credentials, or other highly sensitive Personal Data, unless the Customer has ensured an appropriate legal basis and implemented all additional safeguards required by applicable Data Protection Laws. Search Ventures does not require such data to provide the Services.

Annex 2 - Technical and Organisational Measures

Search Ventures maintains technical and organisational measures appropriate to the risk. For transfers under the EU SCCs, this Annex 2 constitutes Annex II to the EU SCCs. The measures include the following:

Encryption

  • Encryption of data in transit using TLS for connections to the Services.
  • Encryption of data at rest for stored submissions and file attachments held with cloud infrastructure providers.

Access control

  • Role-based access to production systems on a least-privilege basis, restricted to authorised personnel.
  • Authentication controls and access logging for administrative access.

Network and application security

  • A web application firewall and edge protection applied to submission endpoints.
  • Rate limiting, spam filtering, and abuse-prevention controls, performed in-house using heuristics (see Annex 3).
  • Virus scanning of uploaded file attachments before delivery.

Resilience and recovery

  • Use of managed, redundant cloud infrastructure with the ability to restore availability and access to Personal Data in a timely manner following an incident.
  • Automated backups within the infrastructure providers’ environments.

Governance

  • Confidentiality obligations imposed on personnel with access to Customer Personal Data.
  • Data-minimisation and retention controls, including time-to-live expiry of stored submissions.
  • Processes to review and update security measures in light of technical developments.

Annex 3 - Authorised Sub-processors

Search Ventures engages the following Sub-processors to Process Customer Personal Data as at the effective date of this DPA. For transfers under the EU SCCs, this Annex 3 constitutes Annex III to the EU SCCs.

Sub-processor Service / Purpose Location / Region
Cloudflare, Inc. Cloud infrastructure and related services used to provide, secure, support and operate the Services, including hosting, compute, database and object storage, content delivery, DNS, edge security, web application firewall, rate limiting, observability, backup and recovery, and email-delivery functionality, as configured by Search Ventures. Regions used by Cloudflare’s globally distributed network and services, as configured or made available by Cloudflare.
Cloudmersive, LLC Virus and malware scanning of uploaded file attachments before delivery. File content is transmitted for scanning and processed only for the duration necessary to perform the scan. United States

Spam filtering and abuse prevention. Search Ventures performs spam and abuse detection using in-house rules and heuristics, including rate limiting, honeypots and content signals. Where Cloudflare services are used to provide edge security, bot protection, rate limiting or related protections, Cloudflare is listed above as a Sub-processor. Search Ventures may in future engage CleanTalk Inc. (United States / global) for cloud-based spam and abuse prevention, which would receive submitter IP addresses and email addresses to assess submissions; CleanTalk is not engaged as at the effective date, and any engagement will be notified in accordance with Section 5 before CleanTalk Processes any Customer Personal Data.

Marketing-site analytics. Search Ventures uses Clicky (Roxr Software Ltd) for analytics relating to the public Formpaste marketing website. Clicky is not a Sub-processor under this DPA to the extent it does not Process Customer Personal Data submitted through, or stored within, the Services on the Customer’s behalf. Search Ventures’ use of Clicky for its own website analytics is addressed in its Privacy Policy and, where applicable, cookie disclosures.

Payments, invoicing and tax. Search Ventures uses Stripe, Inc. to process payments, invoicing, tax and related fraud-prevention activities for Search Ventures’ own customer relationship. Stripe acts as an independent Controller in relation to those activities and is not a Sub-processor of Search Ventures under this DPA, except to the limited extent Search Ventures separately agrees in writing that Stripe will Process Customer Personal Data on the Customer’s behalf.

Customer-enabled integrations. Where the Customer enables optional outbound integrations, including webhooks to systems selected by the Customer, Customer Personal Data is transmitted to the destinations configured by the Customer. Those destinations are the Customer’s own processors or controllers and are not Sub-processors of Search Ventures under this DPA. The Customer is responsible for its relationship with, instructions to, and terms governing those destinations.

Search Ventures maintains an up-to-date list of Sub-processors and will provide notice of changes in accordance with Section 5 of this DPA.

Annex 4 - SCC and UK Addendum Details

A. Parties

Role Details
Data exporter The Customer identified in the Principal Agreement, acting as Controller or Processor, as applicable. The Customer’s contact details are those specified in the Principal Agreement, applicable order form, or Customer account.
Data importer Search Ventures Pty Ltd (ACN 639 906 353), trading as Formpaste, operating from Australia, acting as Processor or Sub-processor, as applicable. Contact details: as specified in the Principal Agreement and at privacy@formpaste.com.

B. Description of transfers

Item Details
Categories of Data Subjects As described in Annex 1.
Categories of Personal Data As described in Annex 1, including form fields, message content, files, technical metadata, and other data submitted or configured by the Customer.
Sensitive data Search Ventures does not require sensitive or special-category data to provide the Services. The Customer must not submit such data unless it has a valid legal basis, has implemented any required safeguards, and Search Ventures has agreed in writing where required by the Principal Agreement or applicable law.
Frequency of transfers Continuous and recurring for the duration of the Customer’s use of the Services, as initiated by the Customer, its users, or individuals submitting the Customer’s forms.
Nature and purpose of Processing As described in Annex 1.
Retention period For the duration of the Principal Agreement and thereafter in accordance with Section 9 of this DPA.
Sub-processors As described in Annex 3, as updated under Section 5 of this DPA.

C. Competent supervisory authority

For the EU SCCs, the competent supervisory authority is the supervisory authority determined in accordance with Clause 13 of the EU SCCs. Where the Customer is established in the European Economic Area, this will ordinarily be the supervisory authority of the EEA Member State in which the Customer is established, unless the EU SCCs require otherwise.

D. Clause 17 and Clause 18 selection

The EU SCCs are governed by the law of Ireland and disputes arising from the EU SCCs shall be resolved before the courts of Ireland, to the extent permitted and required by the EU SCCs.

E. UK Addendum

For the UK Addendum: the parties are as identified in Part A of this Annex; the EU SCCs selected are those described in Section 11; the annexes to the EU SCCs are Annexes 1 to 4 of this DPA; and the importer may end the UK Addendum in accordance with the terms of the UK Addendum.

Acceptance

This DPA becomes binding when the Customer accepts it electronically, whether by clicking “I accept”, checking a box referencing it, enabling the Services, or continuing to use the Services after being presented with it, as described above. Such acceptance has the same legal effect as a handwritten signature and no physical or electronic signature is required for this DPA to take effect. Where the Customer’s jurisdiction, internal policy, or procurement process requires a signed counterpart, please contact us here.