FormBody

Data Processing Agreement

Effective 5 September 2026 · version consent@2026-09-05

Before publishing: insert FormBody's registered ABN ([ABN — insert your registered ABN]) and the governing State/Territory ([State/Territory — e.g. New South Wales]). Everything else is final.

This Data Processing Agreement ("DPA") forms part of the FormBody Terms of Service between FormBody ([ABN — insert your registered ABN]) ("FormBody", "we", "us") and the shop ("you", "the shop"). It governs how FormBody handles Customer personal information on the shop's behalf. It is written for Australian law — the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Terms defined in the Terms of Service have the same meaning here. Where this DPA and the Terms conflict on data handling, this DPA prevails.

Australia does not use the "controller/processor" labels of the GDPR. In this DPA, "the shop determines" the purposes and means of handling Customer Data, and "FormBody handles it on the shop's behalf" as the shop's service provider. Both parties remain APP entities responsible for their own obligations.

1. Roles and scope

2. Nature and purpose of the handling

FormBody handles Customer Data to: render the shop's intake form; receive and route submissions to the shop's staff queue; surface safety information to staff; operate the cross-shop Safety Flag; and purge intake data on session completion. FormBody does not use Customer Data for its own purposes, does not sell it, and does not use it for advertising.

3. Categories of data and data subjects

4. Retention and the purge model

5. Confidentiality and personnel

FormBody ensures that personnel authorised to handle Customer Data are subject to confidentiality obligations and access it only as needed to provide the Service.

6. Security (APP 11)

FormBody takes reasonable technical and organisational measures appropriate to the risk, including: per-shop data isolation enforced at the database level (row-level security); authentication for hub and staff access; a separate cookie-based access boundary for staff devices scoped to a single shop and excluding billing; least-privilege access; and the minimal-retention (purge) model that limits data at rest. FormBody reviews these measures and improves them over time.

7. Sub-processors

The shop authorises FormBody to engage sub-processors to provide the Service. Current sub-processors:

Sub-processorPurposeLocation
VercelApplication hosting and deliveryMay include overseas infrastructure
SupabaseDatabase, authentication, storageMay include overseas infrastructure
StripeSubscription billing and payment processingMay include overseas infrastructure
SMS provider (if appointment messaging is enabled)Sending appointment messagesAustralia / as configured

FormBody imposes data-protection obligations on its sub-processors consistent with this DPA and remains responsible for their performance. FormBody will give reasonable notice of any intended addition or replacement of a sub-processor; if the shop reasonably objects on data-protection grounds, the shop's remedy is to cancel before the change takes effect.

8. The Safety Flag (special handling)

The Safety Flag is Customer Data handled for a safety purpose and is subject to specific rules:

The shop agrees to raise flags only in good faith on a genuine safety concern and never to harass, discriminate against, victimise, or retaliate against any person, and indemnifies FormBody for flags raised otherwise (as set out in the Terms).

9. Overseas disclosure (APP 8)

Where a sub-processor stores or processes personal information outside Australia, FormBody takes reasonable steps to ensure the handling is consistent with the APPs through the sub-processor's contractual terms and security commitments. The minimal-retention model means very little Customer personal information is held at any time.

10. Assistance to the shop

Taking into account the nature of the handling, FormBody will provide reasonable assistance to help the shop meet its own obligations, including in relation to Customer requests for access or correction that reach FormBody, and in relation to security and breach obligations. Because intake data is purged after each session, most Customer requests about intake data are directed to the shop; FormBody assists in reaching the right party.

11. Data breaches (NDB scheme)

FormBody will, without undue delay after becoming aware of a data breach affecting Customer Data it handles for the shop, notify the shop and provide information reasonably needed for the shop to assess the breach and meet its obligations under the Notifiable Data Breaches scheme. Where FormBody is itself required to notify the OAIC or affected individuals, it will do so in line with the scheme. Each party cooperates in good faith on containment, assessment, and any required notifications.

12. Return and deletion on termination

On termination or expiry of the shop's account, FormBody will delete or, where reasonably requested and technically practicable, return Account Data, and will apply the standard retention and purge model to Customer Data. Safety Flags persist as described in Section 8. FormBody may retain information where required by law, holding it under continued protection.

13. Audit and compliance

On reasonable written request and no more than once a year (unless required by a regulator or following a breach), FormBody will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and to protecting other shops' and Customers' data.

14. General

This DPA is governed by the same law and jurisdiction as the Terms. If any part is unenforceable, the rest continues. This DPA, the Terms, and the Privacy Policy are the entire agreement on their subject matter. Questions: enquiries@formbody.com.au.


Related: Terms of Service · Privacy Policy · © FormBody