Legal
Data Processing Agreement
The terms under which UAB Silotech processes the personal data you collect through Formius. It is part of the Terms of Service and applies when you accept them, with no separate signature.
- Version:
- 2026-09-28
- Effective:
- September 28, 2026
- Processor:
- UAB Silotech, company code 306971572
- Controller:
- The Formius customer
- Contact:
- privacy@silotech.xyz
- Subprocessors:
- Current list
1. Parties and how this agreement is concluded
This Data Processing Agreement ("DPA") is between the customer who holds a Formius account ("Customer", "you") and UAB Silotech, company code 306971572, VAT LT100020253611, registered in Lithuania ("Silotech", "we"). UAB Silotech was formerly named UAB Saakuru Technologijos; the company was renamed on 15 May 2026 and its code and obligations did not change.
This DPA forms part of the Formius Terms of Service. It is concluded electronically when you accept the Terms and this DPA in the Service, as allowed by Article 28(9) GDPR. No separate signature is needed. We store the DPA version you accepted and the time of acceptance.
Contact for data protection matters: privacy@silotech.xyz.
2. Roles
When you collect personal data of other people through Formius (for example form respondents, candidates or learners, and the files they upload), you are the controller and Silotech is the processor. This DPA covers that processing ("Customer Personal Data").
When we process your own account, billing and usage data, Silotech is the controller and our Privacy Policy applies instead of this DPA.
3. Subject matter, duration, nature and purpose
Subject matter: providing the Formius service to you.
Duration: for as long as your account is active, and afterwards until the data is deleted under section 12.
Nature and purpose: storing and making available your form definitions, the responses and files your respondents submit, sending submission confirmation emails to respondents, notifying you of new responses, rate limiting and abuse prevention, optional AI feedback on lesson answers when a learner requests it, and exporting data to you. AI form generation uses only the prompts and form structures you provide, not respondent answers.
4. Categories of data subjects and personal data
Data subjects: the people who fill in your forms or lessons (respondents), and people whose data a respondent includes in an answer.
Personal data: whatever you choose to collect through your forms, which can include names, contact details, answers to your questions, and uploaded files such as CVs, photos, identity document images and driving licence images. We also process each respondent email address (used to confirm the submission), the IP address and browser user agent of the submission, and submission and confirmation times.
Special categories and identity documents: if you collect special category data (Article 9 GDPR) or identity document images, you are responsible for having a lawful basis, for telling respondents why you need it, and for setting a retention period that fits the purpose. Formius stores such files like any other upload; it does not read, classify or verify them.
5. Instructions
We process Customer Personal Data only on your documented instructions. Your instructions are this DPA, the Terms, and your use and configuration of the Service (for example the forms you publish, your retention settings, exports and deletions).
If EU or member state law requires us to process the data in another way, we will tell you before processing unless that law forbids it. We will tell you if we believe an instruction infringes data protection law.
6. Confidentiality
Everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality. Access is limited to people who need it to run, support or secure the Service.
7. Security measures
We apply the following technical and organizational measures under Article 32 GDPR. They describe the Service as it runs today.
Encryption in transit: all traffic to the Service and between the Service and its subprocessors uses HTTPS (TLS).
Encryption at rest: the database and file storage are hosted by Supabase in Frankfurt, Germany, which encrypts stored data at rest.
Private file storage: uploaded files are kept in a private storage bucket. Files are uploaded and downloaded only through short-lived signed URLs issued after a permission check; there are no public file links.
Access control: database access is protected by row level security, and response data is written only by the server using a service key that is never exposed to browsers. Signed-in users reach a form and its responses only if they own it or it was shared with them, and each share has a permission level (view, edit or admin). Exports and file downloads require export permission on that form.
Respondent side: forms can be protected with a password, and every submission must be confirmed through a link sent to the respondent email address before it counts.
Backups: the database is backed up daily and each backup is kept for 7 days. Point in time recovery is not enabled.
Retention: you can set a retention period per form. A scheduled job runs daily and deletes responses and their uploaded files once they are older than that period. Files are stored as soon as a respondent picks them, before the form is sent; the same daily job deletes files that never became part of a submission (removed, replaced or left in an unsent form) once they are more than 48 hours old.
Error reports: error monitoring is configured not to collect default personal data. Before a report is sent, cookies and authorization headers are removed, email addresses are masked in error messages and in the attached diagnostic context, and IP addresses and user agents are removed from that context. Error session replays mask all text and block all media.
We may change these measures over time, but not in a way that lowers the overall level of protection.
8. Subprocessors
You give general authorization for us to use the subprocessors listed at https://www.formius.ai/subprocessors, which states what each one does, what data it receives and where.
We will announce any new or replacement subprocessor at least 30 days before it starts processing Customer Personal Data, by updating that page and emailing the account owner. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate the affected part of the Service without penalty.
We impose on each subprocessor data protection obligations that are no less protective than this DPA, and we remain responsible to you for their performance.
9. International transfers
Form responses and uploaded files are stored in the EU (Frankfurt, Germany). Some subprocessors, such as hosting, email, error monitoring, billing and AI providers, may process data in the United States or other countries outside the EEA.
Where personal data is transferred outside the EEA, the transfer relies on an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module 3 (processor to processor), which are incorporated into our agreements with those subprocessors.
10. Data subject requests and assistance
You answer requests from your respondents. The Service gives you the tools to do so: you can view and export responses and files, delete a single response, delete a whole form with its responses and files, and set a retention period.
If a respondent sends a request about your form to us directly, we forward it to you without undue delay and do not answer it ourselves unless you ask us to.
Taking into account the nature of the processing and the information available to us, we assist you with your obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), for example by providing the information in this DPA and on the subprocessor page.
11. Personal data breaches
We notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice goes to the account email address and includes what we know at that time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We send further information as it becomes available.
We take reasonable steps to contain the breach and limit its effects. Notifying supervisory authorities and data subjects remains your decision as controller, and we help you with it.
12. Deletion and return
While your account is active you can export your data at any time and delete responses or forms yourself. When you delete a response, or confirm the deletion of a form, the data and its uploaded files are removed from the live database and file storage.
When your account ends, we delete Customer Personal Data within 90 days, as stated in the Terms, unless EU or member state law requires us to keep it. Export anything you want to keep before you close the account; on request made before the account ends we help you return the data in the export formats the Service offers.
Deleted data can remain in database backups until those backups expire, which is at most 7 days.
13. Information and audits
On request we make available the information needed to demonstrate compliance with Article 28 GDPR, including this DPA, the subprocessor list and a description of our security measures.
If that information is not enough, you or an independent auditor bound by confidentiality may audit our compliance, with at least 30 days written notice, during business hours and without disrupting the Service, once per year unless a personal data breach or a supervisory authority requires more. Each party bears its own costs. Audits of subprocessors rely on the reports and certifications they publish.
14. Liability and precedence
Liability under this DPA is subject to the limitation of liability in the Terms, except where the GDPR does not allow such a limitation.
If this DPA conflicts with the rest of the Terms, this DPA prevails for the processing of Customer Personal Data. If it conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
15. Changes and governing law
We may update this DPA, for example to reflect a change in law or in the Service. Each version has a date. Material changes are announced to account owners at least 30 days before they take effect, and we ask you to accept the new version in the Service.
This DPA is governed by the laws of the Republic of Lithuania, the same as the Terms.