Data Processing Agreement
Motivation Form data processing terms for form owners that collect respondent personal data.
Motivation Labs acts as a processor for respondent response data and file uploads collected through Motivation Form. The form owner acts as the controller and is responsible for the content of each form, the legal basis for collection, and respondent notices.
For a counter-signed Data Processing Agreement, email form@motivationlabs.ai.
Scope
This DPA applies when Motivation Labs processes personal data on behalf of a form owner through:
- Hosted public forms at
form.gold/[handler]/[slug] - Submission storage and dashboard access
- Email notifications and response exports
- API, CLI, and MCP access
- File uploads stored for form responses
Subprocessors
Motivation Form uses these subprocessors to provide the service:
| Subprocessor | Purpose | Data processed |
|---|---|---|
| Supabase | Database, auth, object storage | Account data, form config, response data, file uploads |
| Vercel | Hosting, edge rendering, CDN | Request logs, form-page traffic |
| Resend | Transactional email | Owner email, response content included in notifications |
| Cloudflare | Turnstile bot protection, DNS | Respondent IP and browser signals for bot checks |
| Stripe | Payment processing, billing | Form-owner billing data |
Security Measures
Motivation Form uses HTTPS, Supabase row-level security, server-side Turnstile verification, bcrypt-hashed API keys, and server-only service credentials. API keys are displayed once at creation and cannot be retrieved later.
Data Deletion
Form owners can delete responses, forms, and accounts from the dashboard or by request. Locked grace-buffer responses are permanently deleted 90 days after collection if not unlocked.