Skip to Content
Lawful Basis for Processing

Lawful Basis for Data Processing

Last updated: February 14, 2026

Under the GDPR (Article 6), every processing activity must have a lawful basis. This page documents the lawful basis Rowform relies on for each category of data processing.


1. Account Holders (Form Creators)

These are users who sign up for a Rowform account to create and manage forms.

Processing ActivityData ProcessedLawful BasisGDPR Article
Account registration and authenticationEmail, name, OAuth profileContract — necessary to provide the serviceArt. 6(1)(b)
Billing and payment processingEmail, payment details (via DodoPayments)Contract — necessary to fulfill the subscription agreementArt. 6(1)(b)
Transactional emails (welcome, password reset, invitations)Email, nameContract — necessary to operate and secure the accountArt. 6(1)(b)
Submission email notificationsEmailContract — core feature of the serviceArt. 6(1)(b)
Product updates and marketing emailsEmail, nameConsent — opt-in toggle in Account Settings, revocable at any timeArt. 6(1)(a)
Audit logging (logins, exports, deletions, consent changes)User ID, action, timestamp, IPLegitimate interest — security monitoring and GDPR accountabilityArt. 6(1)(f)
Cookie and analytics trackingBrowser metadata, cookiesConsent — managed via CookieYes consent bannerArt. 6(1)(a)

2. Form Respondents (End Users)

These are individuals who fill out forms created by Rowform account holders. In this context, the account holder is the Controller and Rowform is the Processor.

Processing ActivityData ProcessedLawful BasisGDPR Article
Collecting form responsesAnswers, email (if requested by form creator)Determined by the Controller — the form creator is responsible for establishing their own lawful basis (typically consent or legitimate interest)Art. 6(1)(a) or (f)
Storing and displaying responses to the form creatorResponse data, timestampsContract — necessary to provide the service to the ControllerArt. 6(1)(b)
Partial response storage (abandoned sessions)Partial answers, session metadataLegitimate interest — allows respondents to resume incomplete formsArt. 6(1)(f)
Anonymizing respondent emails after 365 daysEmail addressesLegal obligation — GDPR data minimization principleArt. 6(1)(c)

3. Team Members and Collaborators

These are users invited to a workspace by an account holder.

Processing ActivityData ProcessedLawful BasisGDPR Article
Workspace invitation emailsEmail, inviter nameLegitimate interest — facilitating team collaboration as requested by the account holderArt. 6(1)(f)
Workspace access and role managementEmail, user ID, roleContract — necessary to provide multi-user access to the serviceArt. 6(1)(b)

4. Data Retention Justification

Data TypeRetentionJustification
Partial responses30 daysLegitimate interest — allows session resumption; deleted after reasonable window
Respondent emails365 days then anonymizedData minimization (Art. 5(1)(e)) — analytics preserved, PII removed
Webhook delivery logs90 daysLegitimate interest — debugging and operational monitoring
Audit logs2 yearsLegitimate interest — security review and regulatory compliance
Account dataUntil account deletionContract — retained while service is active

Where consent is the lawful basis, Rowform ensures:

  • Freely given — Consent is not a precondition for using the service (except where necessary, e.g., cookies for site functionality).
  • Specific — Each consent is for a defined purpose (marketing emails, cookie tracking).
  • Informed — Users are told what they are consenting to at the point of collection.
  • Revocable — Consent can be withdrawn at any time via Account Settings (marketing) or the CookieYes banner (cookies), with the same ease as it was given.
  • Recorded — All consent events are timestamped and stored in user metadata (consent_given_at, marketing_consent_at).

6. Legitimate Interest Assessments

Where legitimate interest is relied upon, Rowform has considered:

Audit Logging

  • Purpose: Detect unauthorized access, support GDPR accountability, and assist in breach investigations.
  • Necessity: Cannot be achieved without logging user actions with identifiers.
  • Balancing: Minimal data collected (user ID, action type, timestamp). Logs are automatically deleted after 2 years. Data Subjects can request access to their audit logs via data export.

Partial Response Storage

  • Purpose: Allow respondents to resume incomplete forms without losing progress.
  • Necessity: Requires temporary storage of partial answers linked to a session.
  • Balancing: Data is automatically deleted after 30 days. No marketing or profiling use. Benefits the Data Subject directly.

Workspace Invitations

  • Purpose: Enable account holders to invite team members to collaborate.
  • Necessity: Requires sending an email to the invitee with workspace details.
  • Balancing: Single transactional email. No further processing unless the invitee accepts and creates an account.

7. Contact

For questions about our lawful basis for processing or to exercise your data protection rights:

Last updated on