Fillout complies with the GDPR framework. Here’s what you need to know about keeping form data private and data processing.
Fillout is GDPR-ready
and offers EU-based hosting and storage for respondent data (form submissions) on the Enterprise plan.
Fillout complies with the GDPR framework.
Fillout is engineered to keep every user’s data private and secure and we have taken a number of measures to comply with GDPR.
Privacy requests and exports
You can export your data from Fillout at any time, including all form responses, to migrate data if needed. If you would like a copy of your account data, email privacy@fillout.com. You can also request that Fillout remove form responses, if needed. Fillout will permanently delete forms, individual form responses, or your user data from our servers and backups, if deleted in Fillout or requested from privacy@fillout.com, within 45 days.
If you are an EU resident and would like to make use of your GDPR data privacy rights, please contact Plighter, our privacy representative in the EU.
To obtain a Data Processing Agreement (DPA), contact us to learn about our EU Enterprise plan.
Security
Fillout is hosted on the Google Cloud platform, via Render.com, with Google’s industry-leading security. Fillout encrypts all data in transit between you or your form respondents and Fillout’s servers over HTTPS/TLS. Data is also encrypted at rest and replicated for durability.
Fillout can also save your form data to third-party applications—and for Enterprise plans, can save data solely to external storage applications if you choose (i.e. your data is never stored on our servers). Be sure to check the app where you’re storing form data for their GDPR policies, including Airtable, Google Sheets, Notion, SmartSuite, HubSpot, and Monday.com.
For more information about Fillout’s security and data storage policies, check our Fillout Security docs.