Privacy Policy

Effective date: January 11, 2024

The FormAssembly Inc. Privacy Policy was developed as an extension of our commitment to combine the highest-quality services with integrity in dealing with our Users and Subscribers. The Policy is designed to assist you in understanding how we collect, use and safeguard the personal information you provide to us and to assist you in making informed decisions when using our site and our products and services. This statement will be assessed from time to time against new technologies, business practices and our Subscribers and their Users’ needs. The use of information collected through our service shall be limited to the purpose of providing the service for which the Client has engaged FormAssembly Inc.

Definitions

Subscribers“Subscribers” are individuals or entities who use this site for free or for charge to create forms and surveys for use with their businesses.Users“Users” are customers and other invitees of a Subscriber who access such forms and voluntarily input data into the form as requested by the Subscriber.

Compliance with the Australian Federal Privacy Act

FormAssembly Inc. commits to comply with the Australian Privacy Act and the 13 Australian Privacy Principle (APP) guidelines for handling and managing personally identifiable information (PII). FormAssembly, Inc. adheres to the APP guidelines about openness and transparency, anonymity, dealing with solicited and unsolicited personal information, data collection and disclosure notifications, cross-border data disclosure, data quality, security, and accessibility, and correcting personal data.

The FormAssembly E-Signature feature also complies with the Australian Electronic Transactions Act, in addition to US e-signature regulations like The Uniform Electronic Transactions Act (UETA), where e-signature data includes personal data that is disclosed overseas.

Compliance with the EU-US Data Privacy Framework

The Data Privacy Framework (DPF) program, which is administered by the International Trade Administration (ITA) within the U.S. Department of Commerce, enables eligible U.S.-based organizations to self-certify their compliance pursuant to the EU-U.S. DPF and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. DPF.

FormAssembly complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. FormAssembly has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) under the UK Extension to the EU-U.S. DPF. FormAssembly has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

FormAssembly is responsible for the processing of personal data it receives, EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) and subsequently transfers to a third party acting as an agent on its behalf. FormAssembly complies with the EU-U.S. DPF Principles and the Swiss-U.S. DPF Principles for all onward transfers of personal data from the EU, UK, and Switzerland, including the onward transfer liability provisions.

Jurisdiction
The Federal Trade Commission has jurisdiction over FormAssembly’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. In certain situations, FormAssembly may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Disputes and recourse
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, FormAssembly commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF to TRUSTe, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://feedback-form.truste.com/watchdog/request for more information or to file a complaint. These dispute resolution services are provided at no cost to you.

For complaints regarding EU-U.S. DPF, the UK Extension to the EU-U.S DPF, and Swiss-U.S. DPF compliance not resolved by any of the other DPF mechanisms, you have the possibility, under certain conditions, to invoke binding arbitration. Further information can be found on the official DPF website: https://www.dataprivacyframework.gov/s/article/ANNEX-I-introduction-dpf?tabset-35584=2

Third parties who may receive data
FormAssembly uses a limited number of third-party service providers to assist us in providing our services to customers. These third-party providers offer infrastructure, customer support services for our customers, assist with the transmission of data, provide data storage services, and perform system monitoring and other technical operations on our behalf. These third parties may access, process, or store personal data in the course of providing their services. FormAssembly continually monitors our agreements with these third party entities, and we maintain contracts with these third parties restricting their access, use, and disclosure of personal data in order to maintain compliance with our DPF obligations.

Your rights and choices to access, to limit use, and to limit disclosure
In compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), FormAssembly has committed to respect the rights of individuals to access personal data about them, to limit use and disclosure of their personal data, and provide communication and escalation paths in the event of a dispute.
If you wish to request access, to limit use, to limit disclosure, or have any other questions about our privacy practices or commitment to the EU-U.S. DPF Principles, please contact us.
By email: [email protected], by phone: (844) 293-2367, or by post mail at:
FormAssembly Inc.
885 S College Mall Rd, #399
Bloomington, IN 47401

What information do we collect?

When you visit our Web site www.formassembly.com you may provide two types of information: personal information you knowingly choose to disclose that is collected on an individual basis and Web site use information collected on an aggregate basis as you and others browse our Web site.

1. Personal information you choose to provide

If you choose to subscribe to our services, we collect personal information such as: Name, Email Address, Mailing Address, and Credit Card Information.

When a User completes a form created, or purchased, by one of our Subscribers, the User may choose to provide the Subscriber with personal information, such as:

Name
Mailing address
E-mail address
Social security number
Health-related information
Home and business phone number
Other personal information (i.e., mother’s maiden name)
E-mail Information

We ask that Subscribers who create forms on our Site do not use the forms to collect credit card information. However, WE ARE NOT ABLE TO MONITOR OR RESTRICT ALL OF THE INFORMATION REQUESTED BY OUR SUBSCRIBERS. FURTHER, DESPITE OUR EFFORTS TO PROTECT INFORMATION, WE DO NOT GUARANTEE THAT ALL INFORMATION THAT IS PROVIDED WILL REMAIN SECURE. See the section titled ‘How Can Your Information be Secured?’ below for further information.

FormAssembly Inc. collects information under the direction of its Clients, and has no direct relationship with the individuals whose personal data it processes. FormAssembly Inc. works with its Clients to help them provide notice to their customers concerning, the purpose for which personal information is collected.

We collect information for our clients, if you are a customer of one of our Clients and would no longer like to be contacted by one of our Clients that use our service, please contact the client that you interact with directly. If you are a Client and would like to update your account please contact us here.

In addition to providing the foregoing information to our Subscribers, if you choose to correspond further through e-mail, we may retain the content of your e-mail messages together with your e-mail address and our responses. We provide the same protections for these electronic communications that we employ in the maintenance of information received by mail and telephone.

2. Website use information

As is true of most websites, we gather certain information automatically and store it in log files. This information includes Internet protocol (IP) addresses, browser type, Internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and clickstream data. We do not link this automatically-collected data to other information we collect about you.

How do we use the information that you provide to us?

Broadly speaking, we may use personal information for purposes of administering our business activities and for providing Subscriber service. We are a Web site host and our primary function as it relates to User data is to facilitate use of the forms and to store such User inputted data for use by the Subscriber for their business purposes. We may provide your personal information to companies that provide services to help us with our business activities, such as offering customer service. These companies are authorized to use your personal information only as necessary to provide these services to us. We will share your personal information with third parties only in the ways that are described in this privacy policy. WE DO NOT SELL OR SHARE ANY COLLECTED INFORMATION WITH ANY THIRD PARTY OTHER THAN THE SUBSCRIBER TO WHOM YOU CHOOSE TO PROVIDE INFORMATION TO. WE ARE NOT RESPONSIBLE FOR HOW THE SUBSCRIBER USES THE INFORMATION PROVIDED BY USERS. If you do not want us to share your personal information with these companies, contact us here.

We do not spam email and we do not permit our Subscribers to spam to the extent we can reasonably prevent such efforts. Our Terms of Service prohibit all Subscribers from engaging in spam activity. Violations of this policy may result in immediate termination of service and legal action.

Subscriber credit card information

For subscribers, any Credit Card information collected by FormAssembly is used for the following general purposes:

  1. Product and services provisioning;
  2. Billing; and,
  3. Identification and authentication.

Subscriber Credit Card information is processed and stored by a third-party payment provider, Stripe, Inc., (“Stripe”) a certified PCI Level 1 Service Provider. Stripe will never provide your card information to FormAssembly. Stripe will share contact information to FormAssembly to enable FormAssembly to deliver product and services provisioning. Stripe will not share Subscriber information with third-parties unless Subscriber authorizes Stripe to do so. For more information, please review Stripe’s Privacy Policy (https://stripe.com/us/privacy).

FormAssembly Inc. may transfer personal information to companies that help us provide our service. Transfers to subsequent third parties are covered by the provisions in this Policy regarding notice and choice and the service agreements with our Clients.

Choice/opt-out

We enable you to create an account, and share information such as messages, offers, & requests with others.

Newsletters & promotional emails
As part of our service, you have the option to receive our newsletter. Out of respect for your privacy, if you wish to no longer receive our newsletters you may follow the instructions in the email and/or make the appropriate setting changes directly in your account.

Service-related announcements
We will send you strictly service-related announcements on rare occasions when it is necessary to do so. For instance, if our service is temporarily suspended for maintenance, we might send you an email. These emails are service related and not marketing/promotional in nature therefore you might not be able to opt-out.

Surveys or contests
From time-to-time we may provide you the opportunity to participate in contests or surveys on our site. If you participate, we will request certain personally identifiable information from you. Participation in these surveys or contests is completely voluntary and you therefore have a choice whether or not to disclose this information. The requested information typically includes contact information (such as name and shipping address), and demographic information (such as zip code).

We use this information to gather feedback on new or improved features, determine what improvements should be made to the application, and improve personalization of the application. In the case of a contest, information is used to notify winners and award prizes.

Blog and forum
Our Web site offers publicly accessible blogs or community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them. To request removal of your personal information from our blog or community forum, contact us at [email protected]. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why.

Our blog is also managed by a third party application that may require you to register to post a comment. We do not have access or control of the information posted to the blog. You will need to contact or login into the third party application if you want the personal information that was posted to the comments section removed. To learn how the third party application uses your information, please review their privacy policy.

Tracking technologies

We use technologies such as cookies or similar technologies to analyze trends, administer the website, track users’ movements around the website, and to gather demographic information about our user base as a whole.

We use cookies to remember users’ settings (e.g., language preference) and for authentication. Users can control the use of cookies at the individual browser level. If you reject cookies, you may still use our site, but your ability to use some features or areas of our site may be limited.

Behavioral targeting / re-targeting

We partner with a third party to manage the advertising of our service on other sites. We use retargeting to advertise our product. Our third-party partner may use technologies such as cookies to gather information about your activities on this site and other sites in order to provide you with advertising based on your browsing activities and interests.

Please note that you may opt out of all activity-based ads, from us and others, by clicking here (or if located in the European Union click here). Please note you will continue to receive generic ads.

Behavioral tracking/analysis

We use third-party behavior tracking and analytics services to better understand our Subscribers’ needs and to optimize our product and user experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.). This information enables us to build and maintain our product with user feedback. These services use cookies and other technologies to collect data on our users’ behavior and their devices. This usage data is stored on our behalf in a pseudonymized user profile in an aggregated or de-identified form for statistical purposes. These services are contractually forbidden to sell any of the data collected on our behalf.

How can your information be secured?

We provide the capability for your data to be encrypted. However, the creator of the form in which you input data chooses how and whether to encrypt your information. Before inputting any sensitive information, determine if encryption is enabled by looking for the “lock” symbol on your web browser or a yellow highlight in the web browser address bar.

INFORMATION OR E-MAIL THAT YOU SEND TO US MAY NOT BE SECURE UNLESS WE ADVISE YOU THAT SECURITY MEASURES WILL BE IN PLACE PRIOR TO YOUR TRANSMITTING THE INFORMATION. For that reason, we ask that you do not send confidential information such as a social security number to us through an unsecured e-mail.

Information security

The security of your personal information is important to us. When you enter sensitive information (such as a credit card number) on our registration forms, we encrypt the transmission of that information using secure socket layer technology (SSL).

We follow generally accepted standards to protect the personal information submitted to us, both during transmission and once we receive it. No method of transmission over the Internet, or method of electronic storage, is 100% secure, however. Therefore, we cannot guarantee its absolute security. If you have any questions about security on our Web site, you can contact us at [email protected]. We do not, however, secure your personal information that is in the possession or control of our Subscriber.

How can you access and correct your information?

FormAssembly Inc. has no direct relationship with the individuals whose personal data it processes. An individual who seeks access, who seeks to correct, amend, delete inaccurate data or withdraw consent to further contact should direct his/her query to FormAssembly Inc.‘s Client (the data controller). If the Client requests FormAssembly Inc. to remove the data, we will respond to their request within 30 days.

Upon request FormAssembly Inc. will provide you with information about whether we hold, or process on behalf of a third party, any of your personal information. If your personally identifiable information changes, or if you no longer desire our service, you may request access to all your personally identifiable information to correct, update, amend, delete/remove or deactivate it by making the change by logging into your account, by emailing us at [email protected], or by contacting us by postal mail at the contact information listed below. We will respond to your request to access within 30 days.

We will retain your information for as long as your account is active or as needed to provide you services. FormAssembly Inc. will retain personal data we process on behalf of our Clients for as long as needed to provide services to our Client. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

What about legally compelled disclosure of information?

In certain situations, FormAssembly Inc. may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may disclose your personal information:

  • as required by law, such as to comply with a subpoena, or similar legal process,
  • when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request,
  • if FormAssembly Inc. is involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via email and/or a prominent notice on our Web site of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information,
  • to any other third party with your prior consent to do so.

Integration with 3rd party services (Google Apps, Salesforce and more) requires exchange of information, such as credentials (username, password, open ID/single-sign-on tokens) and any other data required for implementation of said integration. Integration is optional, and subscribers must explicitly authorize such transaction. Any data received from 3rd party service is covered by this privacy policy.

We are not responsible for the practices employed by Web sites linked to or from our Web site (such as our blog) nor the information or content contained therein. Often links to other Web sites are provided solely as pointers to information on topics that may be useful to the Users of our Web site.

Please remember that when you use a link to go from our Web site to another Web site, our Privacy Policy is no longer in effect. Browsing and interaction on any other Web site, including Web sites which have a link to our Web site, is subject to that Web site’s own rules and policies. Please read over those rules and policies before proceeding.

Although not owned, controlled, or moderated by our site, we do offer a link to our publicly accessible customer feedback tool. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them.

Social media feature and widget on our website

Our Web site includes Social Media Features, such as the Follow us on Twitter button [and Widgets, such as Google Plus button or interactive mini-programs that run on our site]. These Features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the Feature to function properly. Social Media Features and Widgets are either hosted by a third party or hosted directly on our Site. Your interactions with these Features are governed by the privacy policy of the company providing it.

By using our Web site you consent to our collection and use of your personal information as described in this Privacy Policy. If we change our privacy policies and procedures, we will post those changes on our Web site to keep you aware of what information we collect, how we use it and under what circumstances we may disclose it. Your continued or subsequent use of our services after any such change shall constitute your consent to such change.

With your consent we may post your testimonial along with your name. If you want your testimonial removed please contact us at [email protected].

Notification of privacy statement changes

We may update this privacy statement to reflect changes to our information practices. If we make any material changes we will notify you by email (sent to the e-mail address specified in your account) or by means of a notice on this Site prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.

Questions & privacy dispute resolution

If you have questions or complaints regarding our privacy policy or practices, please contact us by email at: [email protected],
by phone: (844) 293-2367, or by post mail at:

FormAssembly Inc.
885 S College Mall Rd, #399
Bloomington, IN 47401