Draft pending legal review

Privacy policy | Weform

How personal data is processed on the Weform website and platform.

Draft prepared on August 4, 2026

1. Controller and scope

The controller for Weform's own processing is Basilio Bravo Porto, a self-employed professional established in Spain. Provisional NIF: XXXXXXXXX. Address: Rambla Marina número 40, Hospitalet de Llobregat, Barcelona, 08907, Spain. Contact: hello@weform.app. This policy is a draft and must be completed against the records of processing, provider contracts and final service configuration.

2. Weform's role

For account, contact, billing, security and own operational data, Weform may act as controller. When an organisation uses Weform to create experiences and collect participant data, that organisation normally decides the purposes and means and acts as controller; Weform acts as processor under its instructions. The relationship must be set out in the applicable terms and data processing agreement.

3. Data and purposes

The platform applies data minimisation and should process only the data needed for each purpose. The data received depends on the account, organisation and experience configuration.

  • Messages sent to hello@weform.app: answer the request and, where appropriate, take pre-contractual steps. The contact page has no form of its own.
  • Account and authentication: email, account identifiers, display name, preferences and data needed to sign in, recover access and maintain security.
  • Organizations and teams: memberships, roles, name, email and workspace settings to manage permissions and provide the service.
  • Contracting and billing: plan, subscription status, customer and invoice identifiers and data needed to manage payments and legal obligations.
  • Security and operation: technical records, dates, identifiers, product events and data needed to prevent abuse, investigate incidents and maintain separation between organisations.
  • Sessions, answers, progress and data requested by an organisation through an experience. In this case, the organisation must inform participants and configure an appropriate legal basis, retention and access.

4. Legal bases

The legal basis depends on the specific purpose: performance of a contract or pre-contractual steps for accounts and requests; compliance with legal obligations for billing and mandatory retention; legitimate interest for security, abuse prevention and essential operation, balanced against people’s rights; and consent where a feature requires it. Not every processing activity is assumed to rely on consent.

5. Providers and recipients

Weform uses providers needed to provide the platform. The definitive list of subprocessors, locations, functions and safeguards must be closed before this policy is finally published.

  • Firebase and Google Cloud for authentication, database, storage, functions, logs and infrastructure services.
  • Stripe for payments, subscriptions, billing and customer portal management when a plan is purchased.
  • Email providers for transactional messages and operational communications.
  • Cloudflare R2 for video-derivative storage and delivery when the production configuration enables it.
  • YouTube or Google when an organisation chooses an external video; that choice may create a direct connection to the provider.

6. International transfers

The infrastructure is designed with a preference for European Union services and regions, but the effective location, support access and transfers of each provider must be audited. The final policy will identify existing transfers and applicable safeguards, such as adequacy decisions, standard contractual clauses or other valid measures.

7. Retention

Data is kept for the time needed for the relevant purpose, while the account or service is active and for periods required by legal obligations or to handle liabilities. The customer organisation must define retention for its participant data; Weform must provide deletion, export and purging according to the contract and technical feasibility. Specific periods remain pending legal and operational decisions.

8. Rights and complaints

People may request access, rectification, erasure, objection, restriction and portability where applicable by writing to hello@weform.app. If the customer organisation is controller for experience data, the request should first be addressed to it and Weform will assist as appropriate. A complaint may also be lodged with the Spanish Data Protection Agency.

9. Cookies and local storage

A specific cookie policy remains pending because the consent system for non-essential cookies has not yet been decided or implemented. This draft does not publish analytics or advertising purposes that are not implemented. Functional language, theme and authentication preferences must be documented with the final technical solution before non-essential cookies are enabled.

10. Security

Weform uses authentication, organisation-based authorisation, access rules, backend services and publication controls to reduce unauthorised access. No Internet service can guarantee zero risk. The security documentation distinguishes implemented controls, pending work and future capabilities.

11. Changes and review

This policy will be updated when purposes, providers, infrastructure, law or cookie configuration changes. The final version must show an effective date and review date.