forms.ax
DRAFT — pending legal review. Not yet in force; do not rely on this text.

Privacy Policy

How forms.ax (operated by Sidcom AB, Sweden) handles data.

What we store

For form owners: account email, organization, billing metadata. For respondents: only the data a given form collects, plus minimal technical metadata (user-agent, IP-derived country, submission duration). We never store more respondent PII than the form asks for. Raw IP addresses are not stored on responses; a signature field records IP + timestamp in an access-controlled audit log solely as proof of consent.

Data residency

Respondent data is stored at rest in EU-jurisdiction storage (Cloudflare D1 in the EEUR region and R2 with EU jurisdiction). Adaptive follow-up questions and semantic validation are processed via the Anthropic API; the relevant answer text is sent to Anthropic for that purpose and is not used to train models.

AI processing (EU AI Act transparency)

Forms with adaptive fields display a notice to respondents that AI may ask follow-up questions. Follow-up questions are clearly attributed as AI-generated.

Retention

Form owners set a per-form retention period; responses past it are deleted automatically. Owners can delete any response or erase all of a person's responses on request (GDPR right to erasure).

Subprocessors

See the subprocessor list.

Contact

privacy@forms.ax · Sidcom AB, Sweden.