1. Purpose and roles of the parties
This agreement governs the processing of personal data that the Creator (the “Controller”) collects from their Respondents by means of the forms they publish on Meliform, and that Kassim MONDOHA (the “Processor”) processes on their behalf.
It does not apply to the Creator’s own account data, for which the Processor acts as controller: that data is covered by the privacy policy.
2. Description of the processing (Art. 28(3) GDPR)
| Item | Description |
|---|---|
| Subject matter | Hosting and provision of a service for creating, distributing and analysing online forms |
| Nature of operations | Collection, recording, organisation, structuring, storage, consultation, making available, erasure |
| Purpose | Enabling the Controller to collect and use responses to their forms |
| Duration | The lifetime of the Controller’s account, or until the relevant forms and responses are deleted |
| Types of data | Answers to the questions asked, score and progress, timestamps, participation duration, the Respondent’s identity and email address where the form requests them or the Respondent is signed in |
| Categories of data subjects | Respondents to the Controller’s forms (students, candidates, customers, members, visitors, etc.) |
The Controller alone determines the questions asked and, consequently, the categories of data actually collected.
3. Your obligations as controller
You undertake to:
- have a valid legal basis for each collection you carry out (consent, contract, legal obligation, legitimate interest, etc.);
- inform your Respondents, before they answer, of the controller’s identity, the purposes, the recipients, the retention periods and their rights — your form’s description or introduction page is the appropriate place;
- collect only data that is strictly necessary for your purpose (data minimisation);
- not collect special category data (Article 9 GDPR) or criminal offence data (Article 10) without meeting the specific conditions that apply;
- respond to your Respondents’ requests to exercise their rights, within the statutory time limits;
- document your instructions and use the Service only in accordance with the terms of use;
- maintain your record of processing activities where you are required to do so;
- delete responses you no longer need.
4. Our obligations as processor
We undertake to:
- process the data only on your documented instructions — your use of the Service and this agreement constituting such instructions — unless required by law, in which case we will inform you beforehand unless legally prohibited;
- alert you if an instruction appears to us to infringe the GDPR;
- not use collected responses for our own purposes: they are not commercially exploited, transferred, or used to train artificial intelligence models;
- ensure that persons authorised to process the data are bound by a duty of confidentiality;
- implement the security measures described in section 5;
- comply with the conditions applicable to engaging a sub-processor (section 6);
- assist you in complying with your own obligations (section 7);
- return or delete the data at the end of the service (section 9);
- make available the information necessary to demonstrate compliance with Article 28 (section 10).
5. Technical and organisational measures (Art. 32)
- encryption of communications in transit (HTTPS/TLS);
- data partitioning by account and by organisation, with a systematic access check on every read or write;
- password authentication with one-way hashing, and sign-in attempt rate limiting;
- fine-grained rights management within an organisation (roles, per-resource permissions);
- logging of sensitive actions;
- hosting in data centres located within the European Union, with regular backups;
- keeping software components up to date and applying security patches.
6. Sub-processors
You give general authorisation for the use of the following sub-processors, the list of which is kept up to date on this page:
| Provider | Role | Data location |
|---|---|---|
| OVH SAS | Website and database hosting | France (European Union) |
| OVH SAS | Sending the service's emails | France (European Union) |
| Mistral AI SAS | Artificial intelligence assistance features | France (European Union) |
| Umami | Anonymous, cookie-free audience measurement | France (European Union) — self-hosted |
Where a sub-processor is added or replaced, we will inform you at least thirty days in advance by email or by a notification within the Service. You will have that period to raise reasoned objections; failing a solution, you may terminate by deleting the forms concerned or your account. Each sub-processor is bound by data protection obligations equivalent to those in this agreement.
7. Assistance, data subject rights and personal data breaches
- Respondents’ rights: the Service gives you access to responses and lets you view, export and delete them, so that you can answer access, rectification, erasure or portability requests yourself. If a request is sent directly to us, we will forward it to you rather than answering on your behalf.
- Data breach: we will notify you of any personal data breach affecting your Respondents within forty-eight hours of becoming aware of it, providing the information available to us (nature, categories and approximate volume of data concerned, likely consequences, measures taken). It is your responsibility to notify the supervisory authority (Article 33) and to inform the data subjects (Article 34) where required.
- Impact assessment: on request, we will provide the technical information needed to carry out a data protection impact assessment and any prior consultation of the supervisory authority.
8. Transfers outside the European Union
Hosting and storage of responses take place within the European Union. No transfer of responses outside the Union takes place, including by the sub-processors listed in section 6.
9. Fate of the data at the end of the service
When a form is deleted, the associated responses are deleted. When your account is deleted, all forms and responses for which you are the controller are deleted or anonymised. You are advised to export any data you wish to keep before deleting anything: deletion is permanent and we keep no copy, subject to temporary technical backups whose retention does not exceed thirty days.
10. Documentation and audit
On request sent to contact@meliform.com, we make available the information needed to demonstrate compliance with the obligations of this agreement. You may carry out an audit, at most once a year and subject to thirty days’ notice, on terms agreed between the parties and without affecting the security of other users of the Service. Audit costs are borne by you, as the Service is provided free of charge.
11. Liability
Each party is liable for damage caused by processing that infringes the GDPR, under the conditions of Article 82. In particular, the Processor is not liable for the lawfulness of the collection decided by the Controller, for the content of the questions asked, or for informing the Respondents.