Who is responsible: you or the form service?
A contact form collects personal data: a name, an email address, often a phone number. Under the GDPR, you decide why that data is collected, so you are the controller. The form backend stores and forwards the data for you, so it is your processor.
That split matters. Art. 28 requires a contract with every processor, usually called a DPA. It also means the service can help you comply, but it cannot do it for you. You still need a legal basis, a privacy notice and a sensible retention period.
Marketing pages that say “100% GDPR compliant” are a starting point, not an answer. The checks below tell you what is behind the claim.
Seven checks for a GDPR-friendly form backend
- A DPA you can accept. Look for an Art. 28 agreement, either signed in the dashboard or included in the terms. No DPA means no lawful basis for the processor relationship.
- Where submissions are stored. EU or EEA storage is simplest. Storage in the US can still be lawful: the EU–US Data Privacy Framework has been in force since July 2023, and standard contractual clauses also work. An appeal against the framework is pending at the EU Court of Justice (as of 03.10.2026), so EU storage is the lower-risk option.
- A sub-processor list. Hosting, email delivery, captcha and AI providers should be named, with a way to learn about changes.
- Retention and deletion. You should be able to set how long submissions are kept, delete single entries and export data for access requests.
- Extras that leave the EU. Chat apps such as Telegram or Slack process messages under their own terms, often outside the EEA. So do many AI features and Google reCAPTCHA. Turn them on only if your privacy notice covers them.
- Data minimisation. Does the service store raw IP addresses or set tracking cookies in your visitors' browsers? Less collected means less to explain.
- Security and breach notice. HTTPS, access control and a promise to tell you about a breach without undue delay are the basics.
EU-hosted options compared
These services say they store submissions in the EU. Facts come from their public pages, checked on 03.10.2026. Prices change, so check before you buy.
- Formgong (we build it). Submissions in Cloudflare D1 with EU jurisdiction; email through ZeptoMail from an EU data centre; raw IPs are not stored. A public DPA is part of the terms. Free plan: 300 submissions a month. Telegram delivery and AI lead scoring are optional, and both can process data outside the EU.
- Formward. Hosting and database in Sweden, AI by Mistral in France, hashed IPs. The DPA is accepted in the dashboard. Free plan: 100 submissions a month; paid plans from €15 a month.
- FormPost. Servers at Hetzner in Germany, a DPA you sign in your account, and its own arithmetic question instead of reCAPTCHA. Free plan: one form and ten notification emails a day; Pro costs €17.85 a year including VAT.
- Forminit (formerly Getform). Based in the UK, with form data in AWS EU regions. Its DPA is accepted with the terms.
US-based services such as Formspree say data may be processed in the United States and other countries. That can be lawful with a DPA and a transfer tool, but it is more paperwork. Our form backend comparison covers plans and features side by side.
What your privacy notice should say
Once you pick a service, your privacy notice needs a few lines about it. Name the form service as a recipient, say where it stores data, and state how long you keep submissions. Mention Telegram, email providers or AI scoring if you use them.
Put a short notice next to the form and link to the full text. A checkbox is not needed just to reply to a message; consent is needed for marketing. Our GDPR contact form guide has a ready notice template and a form with an optional marketing checkbox.
<form action="https://formgong.com/submit" method="POST">
<input type="hidden" name="access_key" value="fk_your_access_key">
<input type="hidden" name="_lang" value="en">
<label>Email <input type="email" name="email" required autocomplete="email"></label>
<label>Message <textarea name="message" required></textarea></label>
<p>We use your details only to reply to you. <a href="/privacy">Privacy notice</a>.</p>
<div aria-hidden="true" style="position:absolute;left:-10000px">
<input type="text" name="botcheck" tabindex="-1" autocomplete="off">
</div>
<button type="submit">Send</button>
</form>Setting up Formgong with GDPR in mind
- Create a form on formgong.com. The DPA applies from account creation; read it and the where data lives page.
- Set retention in the form settings. Free keeps submissions for 30 days. Pro and Business let you choose 30, 90 or 365 days, or keep them until you delete them.
- Decide on extras. For EU-only processing, use email and keep Telegram and AI scoring off. If you turn them on, add them to your privacy notice.
- Ask only for fields you need. Name, email and message are enough for most contact forms.
Plans and limits are on the pricing section.
Frequently asked questions
Is any form backend GDPR compliant on its own?
No. The service is your processor. It can offer a DPA, EU storage and deletion tools, but you still need a legal basis, a privacy notice and a retention period.
Do I need a DPA with a form backend?
Yes. Art. 28 GDPR requires a contract with every processor that handles personal data for you. Many services include it in their terms or let you accept it in the dashboard.
Can I use a US form service under the GDPR?
Yes, if the transfer is covered, for example by the EU–US Data Privacy Framework or standard contractual clauses. An appeal against the framework is pending at the EU Court of Justice, so EU storage carries less risk.
Is sending form leads to Telegram GDPR-friendly?
It can be, but Telegram processes messages under its own terms, often outside the EEA. Mention it in your privacy notice, or use email only if you need EU-only processing.
Does Formgong sign a DPA?
Formgong publishes a standard DPA under Art. 28 that is part of the terms and is accepted when you create an account. No separate signature is needed.
Sources and documentation
Official references for this guide: GDPR (EUR-Lex), EDPB Guidelines 07/2020 on controller and processor, European Commission: EU–US data transfers, Formward, Formward DPA, FormPost, Forminit GDPR, Formspree privacy policy. Formgong DPA, where data is stored.
Read this article as Markdown