Draft for review. Full company particulars and outstanding policy and operational details must be finalised before these documents take effect.
LEGALData Processing Agreement
Proposed processing terms and schedules for customer personal data.
1. Status, parties and scope
This is a proposed Data Processing Agreement for review between Only (Pvt Ltd) and the customer identified in an accepted order or signed agreement. It is not an executed transfer agreement or a substitute for completing the schedules below. Before relying on it, the parties must confirm their identities and contacts, processing instructions, measures, sub-processors, transfer mechanism, retention schedule and acceptance date.
When adopted, this DPA applies where Onlyform processes personal data on the customer's behalf. The customer is controller, or processor acting for its controller; Onlyform is processor or sub-processor accordingly. Onlyform's independent account administration, payments, security and legal-obligation processing is described in the Privacy Policy and is outside processor instructions to the extent it is genuinely performed as controller.
2. Processing instructions
Onlyform will process customer personal data only on documented instructions, including the customer's configuration of forms, storage, exports, integrations and supported AI features, unless applicable law requires otherwise. Where permitted, it will tell the customer about that legal requirement before processing. It will notify the customer if, in its opinion, an instruction infringes applicable data-protection law and may pause the affected processing pending clarification.
The customer is responsible for lawful instructions, appropriate notices and legal grounds, minimisation and collection of any required consent. It must not instruct processing outside the agreed scope. Children's data and sensitive categories require the applicable legal basis, safeguards and any legally required agreement before processing.
3. Confidentiality and security
Persons authorised to process customer data will be bound by confidentiality duties and access limited to their responsibilities. Onlyform will implement the technical and organisational measures documented in the completed security schedule, taking account of the nature of the information and risks to individuals. Changes must not materially reduce the agreed protection.
The schedule must state the deployed access controls, authentication, transport and storage encryption, secrets management, asset access, logging, recovery, vulnerability management and incident handling. A generic reference to a Security page does not establish unverified certification, SAML, a penetration test, a particular cipher, or a backup recovery guarantee.
4. Sub-processing
The completed provider schedule identifies authorised sub-processors, their service, locations and safeguards. Under a general authorisation, Onlyform will give at least 30 days' notice of a proposed addition or replacement through the agreed notice channel, allowing a reasonable data-protection objection before the change. If the parties cannot resolve a reasonable objection, they will agree an alternative or termination of the affected processing, with treatment of unused prepaid fees stated in the order.
Onlyform will impose materially equivalent applicable processing obligations on sub-processors and remain responsible for their performance as required by law. Customer-selected independent recipients and their own processing must be identified separately. This clause is a proposed contractual commitment; the operational notification channel must exist before it is adopted.
5. Assistance and requests
Taking account of the processing and information available, Onlyform will reasonably assist the customer with individual rights, security obligations, impact assessments and supervisory consultation. It will forward a request concerning processor-held customer data and not respond on the customer's behalf except as instructed or legally required. Charges, if any, for substantial additional assistance must be agreed in advance and cannot prevent compliance with mandatory obligations.
6. Personal data breaches
Onlyform will notify the customer without undue delay after becoming aware of a personal data breach affecting customer data. The notice will provide available information about the nature of the incident, affected categories and approximate numbers where known, contact point, likely consequences and measures taken or proposed. Information may be supplied in stages without undue delay.
Onlyform will cooperate in containment, investigation and remediation and preserve appropriate records. The customer determines notifications required in its controller role; Onlyform retains any independent statutory reporting duty. This clause does not replace a shorter mandatory local reporting deadline or assume that every jurisdiction uses a 72-hour rule.
7. Return, erasure and retention
At the customer's choice after the service ends, Onlyform will return or delete customer personal data, including existing copies, unless a binding legal obligation requires storage. The parties must complete a feasible return/deletion timetable, backup rotation and legal-hold procedure in the processing schedule before adoption. Retained data remains protected and is used only for the permitted retention purpose.
The customer must identify exports and independent destinations it controls. Onlyform cannot erase a public blockchain or an independent recipient's copies, but must carry out its own deletion duties and applicable assistance. Any restoration process must prevent previously erased data being reintroduced into ordinary use without applying the deletion again.
8. Demonstrating compliance and audit
Onlyform will make information reasonably necessary to demonstrate its obligations available to the customer and allow and contribute to audits, including inspections, by the customer or an independent auditor bound by confidentiality. The parties may agree reasonable scope, notice and security arrangements without making the audit right ineffective, obstructing a regulator or withholding evidence of material non-compliance.
9. International transfers
Onlyform will not make a restricted transfer without a valid mechanism and required safeguards. For an EU/EEA transfer this may require the applicable module of the European Commission's 2021 Standard Contractual Clauses, completed annexes, selection of options, transfer assessment and supplementary measures. UK transfers may require the UK Addendum or IDTA, and Swiss transfers appropriate Swiss adaptations.
This draft does not reproduce, modify or purport to execute those instruments by hyperlink. The parties must complete and bind the applicable instrument before the transfer. Mandatory clauses prevail over conflicting commercial terms. Indian restrictions and any other applicable transfer conditions must also be assessed; APAC infrastructure placement is not a transfer mechanism.
10. US processor/service-provider restrictions
Where applicable US state law requires, Onlyform will process information only for the specified contracted purposes, not sell or share it for cross-context behavioural advertising, retain/use/disclose it outside the direct business relationship except as permitted, or combine it with other-source information except as lawfully permitted. It will provide the required level of protection, notify the customer if it can no longer comply, and permit reasonable steps to stop and remediate unauthorised processing. Any required statutory certification must be confirmed when this agreement is executed.
11. Processing schedule
| Item | Scope to confirm in the executed agreement |
|---|---|
| Subject and purpose | Hosting customer forms, receiving/storing answers and files, results and exports, configured notifications, integrations and optional AI processing |
| Duration | Subscription/service period and the expressly agreed return, erasure, backup and mandatory-retention period |
| Operations | Collection, organisation, storage, access, retrieval, disclosure on instruction, export, restriction and erasure |
| Individuals | Customer personnel, invited users, respondents and people whose data a customer is lawfully authorised to submit |
| Data categories | Identity/contact information and customer-selected answers/files; response metadata, device/country/campaign information and session-linked activity; selected AI input or integration content where instructed |
| Data requiring additional safeguards | Children's data and sensitive categories must be specifically described and assessed, with all required safeguards and agreements in place |
| Instructions and contacts | Customer administrator and Onlyform privacy/security contacts; details must be completed |
| Measures, providers and locations | Completed production security and provider schedules; do not rely on unverified template claims |
| Transfers and deletion | Executed applicable transfer instrument, assessment and an operationally supported erasure/backup schedule |
12. Order of precedence
Mandatory transfer terms and applicable law prevail, followed by this DPA for its subject matter, then the service agreement. Neither a liability clause nor a confidentiality clause removes rights that cannot lawfully be limited. Changes to this DPA require the agreement or notice process stated in the completed contract and cannot retrospectively reduce mandatory protection.