Draft for review. Full company particulars and outstanding policy and operational details must be finalised before these documents take effect.

LEGAL

Data Processing Agreement

Proposed processing terms and schedules for customer personal data.

Last updated: 21 September 2026Draft for review
All legal documents

1. Status, parties and scope

This is a proposed Data Processing Agreement for review between Only (Pvt Ltd) and the customer identified in an accepted order or signed agreement. It is not an executed transfer agreement or a substitute for completing the schedules below. Before relying on it, the parties must confirm their identities and contacts, processing instructions, measures, sub-processors, transfer mechanism, retention schedule and acceptance date.

When adopted, this DPA applies where Onlyform processes personal data on the customer's behalf. The customer is controller, or processor acting for its controller; Onlyform is processor or sub-processor accordingly. Onlyform's independent account administration, payments, security and legal-obligation processing is described in the Privacy Policy and is outside processor instructions to the extent it is genuinely performed as controller.

2. Processing instructions

Onlyform will process customer personal data only on documented instructions, including the customer's configuration of forms, storage, exports, integrations and supported AI features, unless applicable law requires otherwise. Where permitted, it will tell the customer about that legal requirement before processing. It will notify the customer if, in its opinion, an instruction infringes applicable data-protection law and may pause the affected processing pending clarification.

The customer is responsible for lawful instructions, appropriate notices and legal grounds, minimisation and collection of any required consent. It must not instruct processing outside the agreed scope. Children's data and sensitive categories require the applicable legal basis, safeguards and any legally required agreement before processing.

3. Confidentiality and security

Persons authorised to process customer data will be bound by confidentiality duties and access limited to their responsibilities. Onlyform will implement the technical and organisational measures documented in the completed security schedule, taking account of the nature of the information and risks to individuals. Changes must not materially reduce the agreed protection.

The schedule must state the deployed access controls, authentication, transport and storage encryption, secrets management, asset access, logging, recovery, vulnerability management and incident handling. A generic reference to a Security page does not establish unverified certification, SAML, a penetration test, a particular cipher, or a backup recovery guarantee.

4. Sub-processing

The completed provider schedule identifies authorised sub-processors, their service, locations and safeguards. Under a general authorisation, Onlyform will give at least 30 days' notice of a proposed addition or replacement through the agreed notice channel, allowing a reasonable data-protection objection before the change. If the parties cannot resolve a reasonable objection, they will agree an alternative or termination of the affected processing, with treatment of unused prepaid fees stated in the order.

Onlyform will impose materially equivalent applicable processing obligations on sub-processors and remain responsible for their performance as required by law. Customer-selected independent recipients and their own processing must be identified separately. This clause is a proposed contractual commitment; the operational notification channel must exist before it is adopted.

5. Assistance and requests

Taking account of the processing and information available, Onlyform will reasonably assist the customer with individual rights, security obligations, impact assessments and supervisory consultation. It will forward a request concerning processor-held customer data and not respond on the customer's behalf except as instructed or legally required. Charges, if any, for substantial additional assistance must be agreed in advance and cannot prevent compliance with mandatory obligations.

6. Personal data breaches

Onlyform will notify the customer without undue delay after becoming aware of a personal data breach affecting customer data. The notice will provide available information about the nature of the incident, affected categories and approximate numbers where known, contact point, likely consequences and measures taken or proposed. Information may be supplied in stages without undue delay.

Onlyform will cooperate in containment, investigation and remediation and preserve appropriate records. The customer determines notifications required in its controller role; Onlyform retains any independent statutory reporting duty. This clause does not replace a shorter mandatory local reporting deadline or assume that every jurisdiction uses a 72-hour rule.

7. Return, erasure and retention

At the customer's choice after the service ends, Onlyform will return or delete customer personal data, including existing copies, unless a binding legal obligation requires storage. The parties must complete a feasible return/deletion timetable, backup rotation and legal-hold procedure in the processing schedule before adoption. Retained data remains protected and is used only for the permitted retention purpose.

The customer must identify exports and independent destinations it controls. Onlyform cannot erase a public blockchain or an independent recipient's copies, but must carry out its own deletion duties and applicable assistance. Any restoration process must prevent previously erased data being reintroduced into ordinary use without applying the deletion again.

8. Demonstrating compliance and audit

Onlyform will make information reasonably necessary to demonstrate its obligations available to the customer and allow and contribute to audits, including inspections, by the customer or an independent auditor bound by confidentiality. The parties may agree reasonable scope, notice and security arrangements without making the audit right ineffective, obstructing a regulator or withholding evidence of material non-compliance.

9. International transfers

Onlyform will not make a restricted transfer without a valid mechanism and required safeguards. For an EU/EEA transfer this may require the applicable module of the European Commission's 2021 Standard Contractual Clauses, completed annexes, selection of options, transfer assessment and supplementary measures. UK transfers may require the UK Addendum or IDTA, and Swiss transfers appropriate Swiss adaptations.

This draft does not reproduce, modify or purport to execute those instruments by hyperlink. The parties must complete and bind the applicable instrument before the transfer. Mandatory clauses prevail over conflicting commercial terms. Indian restrictions and any other applicable transfer conditions must also be assessed; APAC infrastructure placement is not a transfer mechanism.

10. US processor/service-provider restrictions

Where applicable US state law requires, Onlyform will process information only for the specified contracted purposes, not sell or share it for cross-context behavioural advertising, retain/use/disclose it outside the direct business relationship except as permitted, or combine it with other-source information except as lawfully permitted. It will provide the required level of protection, notify the customer if it can no longer comply, and permit reasonable steps to stop and remediate unauthorised processing. Any required statutory certification must be confirmed when this agreement is executed.

11. Processing schedule

ItemScope to confirm in the executed agreement
Subject and purposeHosting customer forms, receiving/storing answers and files, results and exports, configured notifications, integrations and optional AI processing
DurationSubscription/service period and the expressly agreed return, erasure, backup and mandatory-retention period
OperationsCollection, organisation, storage, access, retrieval, disclosure on instruction, export, restriction and erasure
IndividualsCustomer personnel, invited users, respondents and people whose data a customer is lawfully authorised to submit
Data categoriesIdentity/contact information and customer-selected answers/files; response metadata, device/country/campaign information and session-linked activity; selected AI input or integration content where instructed
Data requiring additional safeguardsChildren's data and sensitive categories must be specifically described and assessed, with all required safeguards and agreements in place
Instructions and contactsCustomer administrator and Onlyform privacy/security contacts; details must be completed
Measures, providers and locationsCompleted production security and provider schedules; do not rely on unverified template claims
Transfers and deletionExecuted applicable transfer instrument, assessment and an operationally supported erasure/backup schedule

12. Order of precedence

Mandatory transfer terms and applicable law prevail, followed by this DPA for its subject matter, then the service agreement. Neither a liability clause nor a confidentiality clause removes rights that cannot lawfully be limited. Changes to this DPA require the agreement or notice process stated in the completed contract and cannot retrospectively reduce mandatory protection.