Skip to content
AdvanceForm
Log in
Legal

Data Processing Addendum

Last updated 7 August 2026 · Forms part of the Terms of Service

In plain language

  • You are the controller of your respondents' data. We are your processor.
  • We only process it to run the Service for you, on your instructions.
  • Our sub-processors are listed in full, and we tell you before adding one.
  • We notify you promptly of a breach so you can meet your own obligations.
  • You can delete everything at any time, and deletion is permanent.

This summary is for orientation only. The numbered clauses below are operative.

Contents

  1. Scope and roles
  2. Details of processing
  3. Our obligations
  4. Your obligations
  5. Sub-processors
  6. Security measures
  7. Breach notification
  8. Data subject requests
  9. International transfers
  10. Return and deletion
  11. Audit and information
  12. Liability

1. Scope and roles

This Addendum applies where you use AdvanceForm to collect personal data from other people, and forms part of the Terms of Service between you and [LEGAL ENTITY NAME] ("we", "us"). If it conflicts with the Terms on data protection, this Addendum prevails.

You are the Controller. You decide what your forms ask, why, and what happens to the answers.

We are the Processor (a data intermediary under Singapore's PDPA). We process respondent personal data only to provide the Service to you.

For your own account data (your username, email, plan and credits) we act as controller, and our Privacy Policy governs instead.

2. Details of processing

Subject matterProvision of the AdvanceForm form-building, response-collection and reporting service.
DurationUntil you delete the data, or your account is closed. On the Free plan we may additionally delete responses older than 3 months; paid plans have no scheduled expiry. See clause 10.
Nature and purposeHosting, storage, retrieval, structuring, aggregation and display of form responses; generating dashboards, hand-out lists, rosters and allocation plans; and, when you invoke them, AI-assisted suggestions.
Types of personal dataWhatever your form asks for. Typically names, email addresses, phone numbers, dates, preferences, availability and free-text answers. You must not use the Service to collect payment card numbers, full government identifiers, financial credentials, or health or biometric data, see clause 8 of the Terms.
Categories of data subjectThe people who fill in your forms: for example attendees, volunteers, donors, members, students or staff.

3. Our obligations

We will:

  • process respondent personal data only on your documented instructions, which your configuration and use of the Service constitute, unless required otherwise by law, in which case we will tell you first unless the law forbids it;
  • not sell it, disclose it to advertisers, or use it for our own purposes;
  • not use it to train machine-learning models;
  • ensure that anyone we authorise to process it is bound by confidentiality;
  • implement and maintain the security measures in clause 6; and
  • assist you, so far as reasonable, with your own obligations regarding security, breach notification and data subject requests.

4. Your obligations

You warrant that you have a lawful basis for collecting the personal data your forms request, that you have given respondents any notice and obtained any consent the law requires, and that your instructions to us will not put us in breach of applicable law.

You are responsible for deciding how long to keep responses and for deleting them when the purpose has ended. We do not delete anything automatically.

5. Sub-processors

You authorise us to engage the sub-processors below. This is the complete current list.

Sub-processorPurposeEngaged
Cloudflare, Inc.Hosting, edge delivery, Cloudflare D1 database storageAlways
Google LLC: Identity ServicesAuthenticationOnly for accounts using Google sign-in
Google LLC: Generative Language APIAI generationOnly when an AI feature is invoked
Self-hosted Gemma model operated by us on our own hardware (not a third party)AI generation, fallbackOnly when an AI feature is invoked and the provider above is unavailable

We remain responsible for our sub-processors' performance. Before adding or replacing one, we will update this page and change its "last updated" date. If you reasonably object to a new sub-processor on data-protection grounds, tell us within 30 days; if we cannot offer a workable alternative, you may terminate and stop using the Service.

Note that respondent data reaches an AI sub-processor only when you choose to use an AI feature, and only the roster and summary features include a sample of real responses. If you do not use them, no respondent data is sent to any model provider.

6. Security measures

We maintain the following technical and organisational measures:

  • Encryption in transit: all traffic over HTTPS/TLS.
  • Encryption at rest: provided by Cloudflare for D1 storage.
  • Access control: event data is scoped to the owning account and enforced server-side on every request. Our administrators can see account metadata and counts only, and cannot read another account's responses.
  • Credential protection: passwords stored only as salted, iterated hashes (PBKDF2 or bcrypt). Session cookies signed, HttpOnly, Secure, SameSite=Lax.
  • Data minimisation: no IP or user-agent logging, no analytics, no third-party tracking scripts, no cookies on public form pages.
  • Segregation: responses are keyed to the owning event and never returned across account boundaries.

We may update these measures, provided the level of protection is not materially reduced.

7. Breach notification

If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay, and in any event within 72 hours of becoming aware of it, using your account email address.

Our notice will describe, so far as known: the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. We will provide reasonable assistance so you can meet your own notification obligations to the Personal Data Protection Commission and to affected individuals.

Notifying regulators and affected individuals about respondent data is your responsibility as controller, since only you know who they are and what you told them.

8. Data subject requests

The Service gives you direct access to all respondent data you hold; you can view, search, correct, export and delete responses yourself, which will satisfy most requests without involving us.

If a respondent contacts us directly, we will not action the request ourselves; we will direct them to you, and tell you if we can identify the relevant event. Where you need help we cannot provide through the interface, we will assist to a reasonable extent.

9. International transfers

The Service runs on Cloudflare's global network, so processing may occur outside Singapore. Where personal data is transferred abroad, we take steps intended to ensure protection comparable to that required by the PDPA, principally through our contractual arrangements with the sub-processors in clause 5.

10. Return and deletion

You may export your data at any time, in CSV or Excel format, without our involvement.

You may delete data at any time. Deleting an event permanently deletes its questions and every response to it; deleting an account permanently deletes every event it owns. Deletion is irreversible.

Retention limit on the Free plan. Where your account is on the Free plan, we may delete responses older than 3 months. Paid plans (Lite, Plus, Max) carry no scheduled expiry, responses are retained while the plan is active. If a paid plan lapses to Free, the 3-month limit begins to apply. Where you need a guaranteed retention period as controller, hold a paid plan and export on your own schedule.

On termination, you should export anything you need before your account is closed. Residual copies may persist in infrastructure backups for a limited period before being overwritten in the ordinary course.

11. Audit and information

On reasonable written request, and no more than once in any 12-month period unless a regulator requires otherwise, we will provide information reasonably necessary to demonstrate our compliance with this Addendum.

Given the scale of the Service, we satisfy audit rights by providing this documentation and answering reasonable questions, rather than by hosting on-site inspections.

12. Liability

The limitation of liability in clause 15 of the Terms of Service applies to this Addendum, and liability under both together is subject to that single aggregate cap.

This Addendum is governed by the laws of Singapore. Offered in other languages for convenience; the English version governs.

Questions, or a countersigned copy: zhengda@sohsimple.sg

AdvanceForm

Turn a sign-up form into a live dashboard, duty roster and hand-out list.

Product

  • Features
  • See it in action
  • Log in

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum
  • Accessibility

Contact

  • zhengda@sohsimple.sg

Language

  • English · 中文 · BM · ID
© 2026 [LEGAL ENTITY NAME]. All rights reserved. Made in Singapore