We take data security and privacy seriously. This page provides information about third party companies and services that we use and share data with. We never share data unnecessarily, and make sure to choose partners who meet our privacy and security standards.
When sharing personal data, sometimes we need to transfer it outside of the European Union. We make a serious effort to protect this data: we follow GDPR regulations, and we want to keep our customers informed at all times.
Any provider we share our data with is thoroughly assessed, and subject to contract terms designed to ensure the proper processing of personal data.
The following list shows the service providers (sub-processors) and subsidiaries we use to deliver our services, where they are located, and a description of their purpose and the tasks they carry out.
You can sign up to our newsletter to get notified of any changes to this page here.
How do we deal with international data transfers? SCCs and supplementary measures
We use Data Protection Agreements (DPAs) with all the recipients of personal data (our providers). They always include the latest Standard Contractual Clauses (SCCs) as the valid legal transfer mechanism, to provide appropriate safeguards that ensure rights and effective legal remedies are available for individuals.
Where SCCs safeguards can’t provide an equivalent level of protection for data transferred to third countries, Typeform has included supplementary security measures to cover the risks identified in said countries.
Typeform enforces a security and privacy program that addresses the treatment of data from its collection, to the end of its lifecycle. We adopt a risk management cycle to properly identify, correct, remediate and learn of any issue as swiftly as possible.
We encourage you to visit our Security at Typeform page for more information about our Security program and the frameworks we are certified in.
We just don’t share respondent data
We don’t share any data provided by the respondents of your typeforms with anyone. There are two exceptions: Amazon Web Services (AWS), our infrastructure provider, where data is stored and managed; and Cloudflare, our Content Delivery Network or CDN, which allows us to provide our service faster, better and more secure by helping us cache content, prevent abuse, provide DNS service and traffic management.
However, all our data is encrypted in transit and at rest, so not even our providers are able to access this data.
Finally, we keep the email address of anyone contacting us for support (customer, respondent or visitor), as we register our interactions with them to improve our service and identify recurrent problems.
For more information on security measures at Typeform, you can visit our Security at Typeform page.
List of third party services we use
Below you can find all the companies we may share data with, with an explanation of why. If you have any more questions about the data we share, please get in touch by clicking the Contact Support button at the bottom of this page.
- Respondent: anyone answering a typeform created by a customer
- Customer: anyone with a Typeform account using Typeform services
- Prospect: a potential Typeform customer
List of providers processing respondent data
Subprocessor |
Purpose of transfer |
Personal data transferred |
Sensitive data? |
Country |
Storage and data management |
Data collected while answering a typeform built by a customer (the type of personal data depends on each customer and form) |
No |
US, EU for EU data hosting customers. |
|
Provide content distribution, security, abuse prevention and DNS services for web traffic transmitted to and from the Typeform platform. This allows Typeform to efficiently manage traffic and secure the services provided. Cloudflare processes a limited amount of Personal Data (specifically user agent and end-user IP addresses) for logging and abuse prevention purposes. |
IP address, user agent |
No |
US, Luxemburg (EU) |
|
Google (Gmail) |
Provide support for respondents when contacting us by form for any doubt or to exercise their rights as data subjects. |
Email address |
No |
EU |
Provide support for respondents when contacting us by form for any doubt or to exercise their rights as data subjects. |
Email address |
No |
US |
List of providers processing customer data
Processor |
Purpose of transfer |
Personal data transferred |
Sensitive data? |
Country |
Studying customer behavior while browsing and filling in typeforms to improve the service and propose new features |
Cookies, customer ID, tracking of customer data while browsing and operating with Typeform services (all user personal data excluding billing and invoice details) |
No |
US |
|
Analyze the business and business-related matters, such as product interaction, product issues |
Identification and contact: Name, surname, email, country Billing info: Billing name, Stripe ID, invoices sent to the client and related information (billing address and expiry date for credit card, no other information on credit cards) Business info: forms, form name, questions in the form Communications held with the client |
No |
||
Understanding user behavior on the Typeform platform, reporting and analytics |
Cookies, customer ID, tracking of customer data when browsing and operating with Typeform services (all user personal data excluding billing and invoice details) |
No |
||
Infrastructure services for data storage, communications, and security |
All data managed by Typeform can potentially be stored and transferred by AWS |
No |
US, EU for EU data hosting customers |
|
Web and form management Statistical website data Cookies Contact with social networks |
Name, email address, cookies |
No |
US, EU for EU data hosting customers |
|
Target marketing campaigns at relevant audience and profiling |
All customer or prospect personal data: name, surname, email, country, communications and campaigns or interactions held with the client |
No |
US |
|
AWS (Amazon Web Services Inc.), Cloudflare Inc., G Suite (Google Inc.), Slack Inc. |
Notify supervisory authorities and/or affected data subjects of security breaches, if necessary. |
Name, surname, Spanish ID card, address (physical or electronic), phone number |
No |
AWS: US, EU for EU data hosting customers Cloudflare: Luxemburg (EU) G-Suite: EU Slack: US |
Provide services to the Company aimed at improving the security of its systems, and protecting its assets and interests |
IP address |
No |
US, Ireland (EU) |
|
Provides content distribution, security, abuse prevention, and DNS services for web traffic transmitted to and from the Typeform platform. This allows them to efficiently manage traffic and secure the services provided. Cloudflare processes a limited amount of personal data (specifically user agent and end user IP addresses) for logging and abuse prevention purposes. |
IP address, user agent |
No |
US, Luxemburg (EU) |
|
Email and document management for presentations, word processes, spreadsheets, etc. to support any business activity. |
Potentially any data from customers can be processed with this service eventually |
No |
EU |
|
Create marketing campaigns targeting relevant audiences. |
Customer email address |
No |
US, UK |
|
Landwell PricewaterhouseCoopers Tax & Legal Services S.L. (dba PwC) |
Managing our accounting needs and meeting our legal requirements by supporting the processing of the financial data of subscriptions, invoices, and billing details. |
Financial data related to subscriptions, invoices, and billing details Identification and contact: name and surname, postal and electronic address, credit card information (kept by Stripe 'tokenized') |
No |
Spain (EU) |
Analyze the business and business-related matters, such as product interaction, product issues |
Identification and contact: Name, surname, email, country Billing info: Billing name, Stripe ID, invoices sent to the client and related information (billing address and expiry date for credit card, no other information on credit cards) Business information: forms, form names, questions in the form Communications held with the client |
No |
US |
|
Create a single sign-on system for login and authentication on the Typeform platform (also supports MFA) |
Email, password |
No |
US, UK |
|
Sales and customer relationship management |
All customer and prospect personal data: name, surname, email, country, communications and campaigns or interactions held with the client |
No |
Germany (EU), France (EU) |
|
Allows us to manage daily operations and collaboration with essential stakeholders. |
Might share some user related personal data |
No |
US |
|
Managing our accounting needs and meeting our legal requirements by supporting the processing of the financial data of subscriptions, invoices, and billing details. |
Financial data related to subscriptions, invoices, and billing details
Identification and contact: name and surname, post and electronic address, credit card information (kept by Stripe tokenized) |
No |
US |
|
Provide customers and users Typeform SaaS, and relationship management with said customers |
Identification and contact: Name, surname, address, email address Financial information: invoices, subscription plans (no credit card or payment details, as those are processed by providers) Data related to the relationship: questions addressed to the Customer Success team |
No |
US |
|
We provide support to ensure that Typeform's data subjects (customers, providers, etc.) are properly handled and responded to in a timely manner, and are able to exercise their GDPR rights according to regulations. |
Identification and contact: Name, surname, email address, ID number, telephone |
No |
||
Customer support, customer relationship management and onboarding through emails and in-app communications |
Identification and contact: Name and surname, email, country Communications with the client |
No |
||
Customer insights tool for searching, organizing and managing customer feedback and related research projects |
Customer name, email address, messages written to Typeform Support |
No |
UK, US |
Typeform subsidiaries
Processor |
Purpose of transfer |
Personal data transferred |
Sensitive data? |
Country |
TYPEFORM UK Limited |
Customer Services: Provide a support service for the reception, assessment, or dispatch of all Typeform customer enquiries and requests, in accordance with the procedures specified by Typeform. |
Data subjects: Customers, Respondents Personal data: name, surname, email address, billing details, other information related to queries raised by customers |
No |
UK |
Business Development Services: Seek, sell and promote Typeform’s SaaS in the United Kingdom, assist in concluding joint ventures, collaborations, partnerships and sales of SaaS with clients, and coordinate and discuss the activities and plans to be carried out in the United Kingdom with Typeform SL. |
Data subjects: Customers Personal data: name, surname, email address, and deal-related details. |
No |
UK |
|
Software Services: Solve problems and incidents related to customer requests |
Data subjects: Customers Personal data: any customer data needed to access and solve problems reported by customers |
No |
UK |
|
TYPEFORM US LLC |
Customer Services: Provide a support service for the reception, assessment, or dispatch of all Typeform customer enquiries and requests in accordance with the procedures specified by Typeform. |
Data subjects: Customers, Respondents Personal data: name, surname, email address, billing details, other information related to queries raised by customers |
No |
US |
Business Development Services: Seek, sell and promote Typeform’s SaaS in the United States of America, assist in concluding joint ventures, collaborations, partnerships and the sales of SaaS with clients, and coordinate and discuss the activities and plans to be carried out in the United States of America with Typeform SL. |
Data subjects: Customers Personal data: name, surname, email address, and deal-related details |
No |
US |
|
Software Services: Solve problems and incidents related to customer requests |
Data subjects: Customers Personal data: any customer data needed to access and solve problems reported by customers |
No |
US |
Want to learn more about other GDPR data subject rights, or privacy in general? Read our Privacy and Security article.