Skip to main content

Data Processing Agreement

Last updated 16 July 2026

This Data Processing Agreement (“DPA”) applies when you (the “Customer”, acting as data controller) use Fillo, operated by Jafu ApS (“Fillo”, the data processor), to collect responses through forms. It forms part of, and is governed by, the Terms of Service. Terms not defined here have the meaning given in the GDPR.

1. Scope and instructions

Fillo processes personal data contained in form responses only on the Customer’s documented instructions — which include using the product’s features and this DPA — and as required by law. Fillo will tell the Customer if it believes an instruction breaches data-protection law.

2. Subject matter, duration, nature and purpose

  • Subject matter: processing of form responses on the Customer's behalf.
  • Duration: for as long as the Customer's account is active, plus the deletion grace and any short period needed to delete or return data.
  • Nature and purpose: collecting, storing, displaying, exporting, sending to Customer-configured destinations, and deleting responses so the Customer can run its forms.

3. Types of data and data subjects

  • Personal data: whatever the Customer chooses to collect in its forms (e.g. names, email addresses, free-text answers) plus response metadata (source route, timestamps, status). The Customer controls which fields exist.
  • Saved-progress drafts (where the Customer enables Save and resume): in-progress answers stored before submission — visible to the Customer's workspace members only where the Customer additionally enables the in-progress content view — deleted on submit, when the respondent starts over, or automatically 7 days after the last change. Where the Customer enables resume emails, an address the respondent entered (or their verified account email) is processed to send one resume link.
  • Respondent identity (where the Customer uses identify()): an identifier the Customer’s own application supplies for the person filling a form, plus any email, name, or attributes the Customer includes, and any server-side signature it provides to verify that identifier.
  • Data subjects: the Customer's end users and respondents.
  • Uploaded files: these reside in the Customer's own connected storage. Fillo stores file metadata and references, verifies upload completion, and may stream authenticated Drive or Box downloads, but does not keep a long-term copy of file contents.

4. Fillo’s obligations

  • Process personal data only as described in section 1.
  • Ensure people authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (section 8).
  • Assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting its obligations under Articles 32–36 GDPR.
  • Make available the information needed to demonstrate compliance with Article 28 GDPR.

5. Sub-processors

The Customer gives general authorisation for Fillo to engage the sub-processors listed on the Sub-processors page. The list explains what each provider does, what data it receives, where processing happens, and which safeguards apply. Fillo imposes data-protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible for their performance. Fillo will update that page before adding or replacing a sub-processor; the Customer may object on reasonable data-protection grounds.

Customer-connected storage, webhooks, Google Sheets, Notion, Zapier, and similar destinations are used only on the Customer’s instructions and are controlled by the Customer, not by Fillo.

6. International transfers

Fillo runs on servers in the European Union, and the primary database holding response data is hosted there too. Our hosting provider is a US company operating that EU infrastructure; its data-processing agreement incorporates the EU Standard Contractual Clauses for any processing or access from the US. Where a feature uses a sub-processor outside the EEA, such as transactional email or optional AI drafting, Fillo limits the transfer to the data needed for that feature and uses the EU Standard Contractual Clauses and the relevant provider’s data-processing terms.

7. Data-subject requests

If Fillo receives a request from a data subject relating to the Customer’s responses, it will forward it to the Customer and will not respond directly except on the Customer’s instruction. The Customer can access, export, and delete responses directly in the product at any time.

8. Security measures

  • Encryption in transit (TLS) and encryption at rest for the database.
  • Stored app-used provider credentials, including storage and integration tokens, are encrypted with AES-256-GCM.
  • Workspace isolation: each form, response, file reference, storage connection, and integration is scoped to its workspace.
  • Account passwords are hashed, never stored in plain text.
  • Public submission endpoints validate schema, cap request size, and use rate limiting and honeypot protection.
  • Uploaded file references must belong to the expected form before they can be attached to a response.
  • Signed webhooks; customer-connected destinations are used only on the Customer's instructions.

9. Personal data breaches

Fillo will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s data, with the information the Customer reasonably needs to meet its own notification duties.

10. Return and deletion

On termination, the Customer can export its responses. Fillo then deletes the Customer’s responses after the 21-day deletion grace period, except where retention is required by law. Files remain in the Customer’s own storage unless the Customer deletes them through Fillo or directly in that storage account.

11. Audits

Fillo will make available information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality and security arrangements.

12. Governing law and signing

This DPA is governed by the laws of Denmark. To request a countersigned copy, contact hello@fillo.so.