Security
Written for whoever has to sign this off: how the service is run, rather than what it collects. If you answered a form and want to know where your own details went, privacy is the shorter page. If something you need here is missing, ask — you’ll get a straight answer.
Who can read responses?
The account that owns the form, and anyone that account has explicitly shared it with. Access is checked on every page and every download against the signed-in account — never against knowing a URL.
How do we remove someone who leaves?
The owner removes them from the form and access stops immediately. No password changes, no moving data.
Is data encrypted?
In transit over TLS, and at rest by the database and file storage. Backups are separately encrypted with AES-256 before they are written.
Where is it hosted?
Oregon, in the United States: both the application and the database. Nothing is stored elsewhere. If your organisation is in the UK or the EU, that makes this an international transfer, and we will sign standard contractual clauses covering it as part of a data processing agreement.
What about backups?
The database is dumped nightly, encrypted, and kept for fourteen days. Restores are scripted and have been tested rather than assumed.
How long is data kept?
You decide, per form: responses can be deleted automatically after 30, 90, 180 days, a year or three, or kept until removed. The sweep runs nightly and does not depend on anyone visiting the page. A single response can also be deleted on its own, and deleting a form removes every response and the original document with it. Files generated for printing or download are deleted after a day.
Does anything leave your systems?
When an uploaded PDF has no form fields of its own, the blank document is read once by a third party to work out the questions. Responses are never sent anywhere, and nothing sent is used to train anything. Notification emails name the form, never the answers.
Can we get our data out?
Yes. Every response as a spreadsheet, as individual PDFs, or as your original document with the answers filled in. No export fee, no request to make.
What happens if there is a breach?
You are told, with what we know and what we are doing, rather than after an investigation concludes.
What we don’t have yet
- No SOC 2 or ISO 27001. If your procurement requires one, we are not there yet and would rather say so now.
- Sign-in with Google or a Microsoft work account is available, and a Microsoft account from any directory is accepted. What is not here yet: enforcing single sign-on for an organisation, provisioning or removing accounts from your directory automatically, and enforced two-factor authentication.
- No formal uptime commitment.
- Files attached to a form are not scanned for malware. What is accepted is decided from the file’s own bytes rather than its name, and is limited to PDFs, photographs, Word and Excel documents and CSVs — programs, archives and macro-bearing documents are refused, including ones renamed to look like something else. A malicious PDF is still a PDF, so treat an attachment as you would any file emailed to you by a member of the public.
Who you would be contracting with
PDF to Web Form, 2701 Del Paso Rd, Ste 130 #379, Sacramento, CA 95835. We act as a processor: the organisation collecting responses decides what is gathered and why, and we hold it on their instructions.
A data processing agreement, and the list of companies we rely on, are available on request. Ask for them. Found a vulnerability? How to report it.