Privacy Policy
Last updated August 21, 2026
This describes what Unda Forms actually collects and does with it — not a generic template. Where something below only applies once a feature is actually configured or used, that's noted explicitly.
Who this applies to, and who's the controller
Unda Forms is B2B software: organizations ("customers") use it to publish forms and manage the applications that come in. There are two different kinds of person this policy covers, and they're not treated the same way:
- Account holders — the staff, owners, and agents who sign up for and use an organization's Unda Forms dashboard. For this data, Unda Forms is the data controller.
- Applicants — the people who fill out a public form published by one of our customer organizations. For the data an applicant submits, the organization that published the form is the data controller, and Unda Forms is a data processor acting on that organization's instructions. If you filled out a form and want to know what happens to your answers, the organization you applied to is who to ask — we host the infrastructure, but the form content, retention decisions, and review process are theirs.
What we collect
Account & organization data
When you sign up: your email address, name, and a password (stored as an Argon2 hash — we never store or can recover your actual password), plus your organization's name. If your organization enables SSO, we store your identity provider's subject identifier instead of a password. If you enable two-factor authentication, we store a TOTP secret and one-time backup codes. Your organization may also record a notification email address for submission alerts, and billing details are handled by Stripe (see Third parties below) — we store which plan an organization is on and Stripe's reference IDs for it, not card numbers.
Form submission data
Whatever fields an organization builds into their form is what an applicant's submission contains — this can range from a name and email to structured answers like income figures or health questions, depending entirely on what that specific organization is collecting. We also record the submission's IP address, browser user-agent string, and (if the form uses e-signature or email OTP verification) the verified email address and verification timestamp, so the organization has a record of how a submission was authenticated.
Uploaded files
Forms can include file-upload or drawn-signature fields. Uploaded files (PDF, PNG, JPEG, or WebP) are stored in S3-compatible object storage and linked to the submission that included them.
Audit & security data
Meaningful account and form actions (publishing a version, changing a member's role, and similar) are recorded in an audit log tied to the acting user and organization, so an organization can review who did what.
Cookies
We set exactly one cookie: refresh_token, used to keep you signed in between visits. It's httpOnly (invisible to page JavaScript), marked secure in production, scoped only to our own authentication endpoint, and expires after 7 days. That's it — we don't set analytics, advertising, or third-party tracking cookies, and nothing on this site profiles you across other sites. Because this cookie is strictly necessary for you to stay logged in, there's nothing to opt out of; the notice you may have seen on your first visit was disclosure, not a consent request for something optional.
Third parties we actually use
These only run when the corresponding feature is actually configured and used — several are optional per deployment:
- Stripe — payment processing for paid plans. Card details go directly to Stripe; we never see or store them.
- Email delivery (SMTP) — sending verification codes, password resets, and submission notifications. Only your email address and the message content pass through it.
- S3-compatible object storage — where uploaded files and drawn signatures are kept.
- Anthropic's API — only if you use the optional "draft a form from a PDF" feature: the PDF you upload is sent to Anthropic to generate a draft schema, and isn't used for anything else.
- Sentry — error monitoring, only in deployments that have it configured. When active, it can receive stack traces and request metadata (which may include your IP address) from a crash, to help us fix it.
How we use it
To operate the account you signed up for: authenticating you, enforcing the plan and role permissions your organization has set, delivering the emails a form or account action triggers, computing things like premium totals server-side so they can't be tampered with client-side, and keeping the audit log an organization uses to review its own activity. We don't sell personal data, and we don't use account or submission data to train any model.
How long we keep it
Account and organization data is kept for as long as the account or organization exists. Form submissions are business records belonging to the organization that published the form, and are kept under that organization's own retention decisions — deleting your personal account (below) doesn't remove submissions you reviewed, since those remain the organization's records.
Your rights over your own account
From your account settings, you can:
- Export your data — download your profile, every organization you belong to and your role in each, and your recent audit log activity.
- Erase your account — your email, name, password, and MFA credentials are permanently removed and your email is replaced with a non-reversible placeholder; every active session is revoked immediately. Business records that reference your account (form versions you published, audit log entries, agent records) stay with the organization, the same way an employee leaving a company doesn't erase the company's own records of what they did — but they're no longer tied to identifying information about you specifically. If you're the sole owner of an organization, you'll need to promote another member to owner (or delete the organization) first, since erasing the only owner's account would leave it with nobody able to manage it.
If you're an applicant rather than an account holder, these tools don't apply to you directly — contact the organization whose form you filled out, since they control that data.
Security
Passwords are hashed with Argon2, never stored or logged in plain text. Sessions use short-lived access tokens plus the httpOnly refresh cookie described above. Two-factor authentication (TOTP) and SSO are available. Public endpoints (form submission, file upload) are rate-limited per IP address to reduce abuse. No system is perfectly secure, but these are the concrete measures actually in place, not aspirational ones.
Children's privacy
Unda Forms is a B2B product for organizations and their applicants, and isn't directed at children. We don't knowingly collect personal data from children under 16.
Changes to this policy
If this changes in a way that meaningfully affects how your data is handled, we'll update the date at the top of this page and, where required, notify account holders directly.
Contact
Questions about this policy, or a data request outside of the self-service tools above: privacy@undaforms.com.
