Data Processing Addendum

Last updated: September 6, 2026

このページは英語のみです。GDPR / UK GDPR が適用されるお客様向けのデータ処理契約です。

1. Scope and roles

This Data Processing Addendum (“DPA”) applies where the General Data Protection Regulation (“GDPR”) or the UK GDPR applies to the Customer’s use of FormEdge, operated by Value Inc. (“FormEdge”). It forms part of the Terms of Service and is accepted by accepting those Terms; no signature is required.

The Customer is the controller of Submission Data and FormEdge is the processor acting on the Customer’s behalf. For Account Data, FormEdge acts as an independent controller, as described in the Privacy Policy.

2. Details of processing

  • Subject matter: provision of the FormEdge service.
  • Duration: the term of the agreement between the Customer and FormEdge.
  • Nature and purpose: hosting and storing form responses, delivering notifications, providing exports, and optional AI spam screening where the Customer enables it.
  • Categories of personal data: the form responses and attachments the Customer chooses to collect, and the respondent’s IP address and user agent.
  • Categories of data subjects: the Customer’s form respondents.

3. FormEdge's obligations

  • Process Submission Data only on the Customer’s documented instructions, which consist of the Terms of Service, the Customer’s use of the service, and the settings the Customer configures.
  • Ensure that personnel authorised to process Submission Data are bound by confidentiality.
  • Implement the technical and organisational measures described in the Annex.
  • Assist the Customer, as reasonably needed and taking into account the nature of the processing, with requests from data subjects and with the Customer’s security, breach notification and impact assessment obligations.
  • Notify the Customer without undue delay after becoming aware of a personal data breach affecting Submission Data (target: within 72 hours), with the information then reasonably available.
  • Delete Submission Data within 60 days after termination of the agreement. The Customer may export its data before termination takes effect.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA, by providing written responses to reasonable requests.

4. Sub-processors

The Customer gives FormEdge general authorisation to engage sub-processors. The current list is published at Sub-processors, and changes are announced as described on that page. A Customer that objects to a new sub-processor may stop using the affected feature or terminate under the Terms of Service.

Destinations the Customer configures — including notification channels, webhooks and AI clients connected via MCP or the API — are not FormEdge sub-processors.

5. International transfers

Submission Data is processed by FormEdge from Japan and is hosted by the sub-processors listed on the Sub-processors page, mainly in Singapore and the United States. Transfers from the EU/UK to Japan rely on the EU and UK adequacy decisions for Japan. Transfers to sub-processors are made under their respective data processing agreements, including EU Standard Contractual Clauses where applicable.

6. UK GDPR

Where the UK GDPR applies, this DPA applies mutatis mutandis, with references to the GDPR read as references to the UK GDPR and references to supervisory authorities read as references to the Information Commissioner’s Office.

7. Liability and governing law

Liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA is governed by the laws of Japan, and the Tokyo District Court has exclusive jurisdiction as the court of first instance.

Annex: Technical and organisational measures

  • TLS for data in transit.
  • Encryption at rest provided by the hosting providers.
  • Tenant isolation enforced at the database layer (row-level security).
  • Role-based access with least privilege for internal operations.
  • Bot protection on public forms (Cloudflare Turnstile).
  • Access to production systems restricted to authorised personnel.
  • Automated backups by the database provider.
  • Vulnerability and dependency updates as part of normal development.

Last updated: September 6, 2026