Trust

Data processing agreement

A data processing agreement is the written contract Article 28 UK GDPR requires when one organisation processes personal data on another's behalf. When you run a survey on NumoForms you are the controller and NOISSIME LTD is your processor, so a DPA is needed. Ours contains the Article 28(3) terms, an annex describing the processing, general written authorisation for the sub-processors we publish, and the UK IDTA or EU Standard Contractual Clauses for transfers outside the UK. Request a copy through the contact page and we will send it for review before you sign up.

Last reviewed 22 July 2026.

Why a DPA exists at all

Data protection law does not let a controller hand personal data to a supplier on trust. Article 28 UK GDPR says the arrangement must be governed by a contract that binds the processor, and it lists what that contract has to contain. The duty runs both ways: if you collect personal data through a survey and there is no DPA in place, you are the one in breach, not only us. That is why procurement teams ask for it early, and why we would rather publish this page than field the same email forty times.

The UK GDPR page explains the controller and processor split in more detail, including the cases where we are the controller instead — account data and support correspondence.

When you need one, and when you do not

You need a DPA if your survey collects personal data. That is a lower bar than it sounds. A survey with no name field can still collect personal data through a free-text box where someone writes about themselves, through an address or email question, through a file upload, or through a hidden field carrying a case reference from your own system. If any of those apply, treat the survey as processing personal data and get the paperwork in place.

A genuinely anonymous survey — no identifiers, no hidden fields, no uploads, no free-text that invites personal detail — does not need a DPA, because there is no personal data to process. Be honest with yourself about which one you are running. The section on anonymity covers the three features that most often break it by accident.

What our DPA covers

The agreement is short and follows the structure of Article 28(3) rather than reinventing it. Each of these appears in the document:

Subject matter and duration

What is being processed and for how long: the survey content and responses you collect, for as long as your account is open and the data has not been deleted.

Nature and purpose

Hosting, storing and displaying survey responses, and providing the results, export and reporting functions of the platform — nothing else. We do not process your responses for our own purposes.

Types of data and data subjects

Determined by the questions you choose to ask. The annex describes the categories rather than pretending we can predict them, and flags special category data where equality monitoring questions are used.

Processing on documented instructions

We act only on your instructions, which in practice means your use of the platform plus anything agreed in writing. If an instruction would breach data protection law, we tell you.

Confidentiality

Anyone with access to personal data processed on your behalf is bound by a duty of confidence.

Security measures

The Article 32 measures, described concretely rather than as adjectives — the same controls set out on the security page.

Sub-processors

General written authorisation for the published list, notice before an addition begins processing, a right to object, and flow-down of the same obligations.

Assistance with data subject rights

What the platform lets you do yourself, and where we help when a request cannot be satisfied from the interface.

Breach notification

Notice to you without undue delay, with the information you need for your own Article 33 assessment.

Deletion or return

On termination, deletion or return of the data at your choice, including uploads and saved partial answers.

Audit and information

Information to demonstrate compliance, and cooperation with audits and inspections, on reasonable notice.

International transfers

The UK International Data Transfer Addendum or EU Standard Contractual Clauses where personal data is transferred outside the UK.

The annex, in plain terms

The annex is the part most people actually read, because it says where the data goes. Survey content, responses, saved partial answers and uploaded files are stored by Supabase on AWS infrastructure in London (eu-west-2). The technical controls applied to them — TLS in transit, AES-256 at rest, row-level security, organisation isolation resolved on the server rather than taken from the browser, and a private upload bucket read only through signed URLs that expire after 300 seconds — are described on the security page, and the same description forms the Article 32 schedule.

Every third party we rely on, what it does, what it sees and where it does it, is on the sub-processor page. The DPA gives general written authorisation for that list and commits us to publishing an addition before the new provider starts processing, with a right for you to object on reasonable data protection grounds. Two rows on that page are marked "to be confirmed" because we have not yet verified the region with the provider; if you need one of those confirmed before you can sign, say so and we will chase it rather than guess.

How to request a copy

Ask through the contact page. Tell us the legal name of the contracting organisation and who will sign, and whether you need it before or after an account exists — either is fine, and we would rather your data protection officer read it during evaluation than discover a problem in month three.

If your organisation has its own mandated DPA, send it. Councils, NHS bodies and universities usually do, and reviewing yours is faster than arguing about whose paper wins. We read it properly and come back with specific points where a clause does not match how the platform actually works — an audit clause requiring on-site inspection of a data centre we do not own, for example, or a retention commitment that assumes automatic expiry we do not have. We would rather flag that than sign something we cannot deliver.

What the DPA does not do

It does not choose your lawful basis, write your privacy notice or complete your data protection impact assessment. Those are controller responsibilities, and no supplier contract transfers them. We will complete the supplier sections of a DPIA and answer a security questionnaire — see the UK GDPR page for what we cover — but the assessment is yours.

It also does not confer a certification we do not hold. We are not certified to ISO 27001, have not completed a SOC 2 audit and do not hold Cyber Essentials. If your process treats one of those as a hard gate, the DPA will not get you past it, and you should know that before you spend time on an evaluation.

Related pages

Security describes the controls the DPA commits us to. UK GDPR covers roles, lawful bases, retention and respondent rights. Sub-processors is the annex list in live form. The accessibility statement is the other document procurement usually asks for in the same email.

This page describes the agreement. It is not legal advice and does not replace your own review.

Read the agreement before you sign up.

Tell us the legal name of the contracting organisation and who will sign, and we will send the DPA for review rather than produce it after signature. If your organisation has its own mandated form, send that instead and we will read it properly.

  • The Article 28(3) terms and an annex describing the processing
  • General written authorisation for the published sub-processor list
  • UK IDTA or EU Standard Contractual Clauses for transfers
Request a copy