Privacy Policy
Last updated September 29, 2026
This describes what Unda Forms actually collects and does with it — not a generic template. Where something below only applies once a feature is actually configured or used, that's noted explicitly.
Who this applies to, and who's the controller
Unda Forms is B2B software: organizations ("customers") use it to publish forms and manage the applications that come in. There are two different kinds of person this policy covers, and they're not treated the same way:
- Account holders — the staff, owners, and agents who sign up for and use an organization's Unda Forms dashboard. For this data, Unda Forms is the data controller.
- Applicants — the people who fill out a public form published by one of our customer organizations. For the data an applicant submits, the organization that published the form is the data controller, and Unda Forms is a data processor acting on that organization's instructions. If you filled out a form and want to know what happens to your answers, the organization you applied to is who to ask — we host the infrastructure, but the form content, retention decisions, and review process are theirs. An organization can show its own privacy notice on a form, before you submit; when it does, that notice is the organization's words, and we add only a factual list of where the service stores and processes the answers.
What we collect
Account & organization data
When you sign up: your email address, name, and a password (stored as an Argon2 hash — we never store or can recover your actual password), plus your organization's name. If your organization enables SSO, we store your identity provider's subject identifier instead of a password. If you enable two-factor authentication, we store a TOTP secret and one-time backup codes. Your organization may also record a notification email address for submission alerts, and billing details are handled by Paystack (see Third parties below) — we store which plan an organization is on and Paystack's reference IDs for it, not card numbers.
Form submission data
Whatever fields an organization builds into their form is what an applicant's submission contains — this can range from a name and email to structured answers like income figures or health questions, depending entirely on what that specific organization is collecting. We also record the submission's IP address, and (if the form verifies an email address with a one-time code) the verified email address and verification timestamp, so the organization has a record of how a submission was made. We no longer record your browser's user-agent string; submissions made before September 2026 may still hold one until the organization's retention settings clear it. Where the form shows a privacy notice, we also record which version you were shown and whether you gave consent, if it asked for it.
Uploaded files
Forms can include file-upload or drawn-signature fields. Uploaded files (PDF, PNG, JPEG, or WebP) are stored in Lineserve object storage in Nairobi, Kenya, and linked to the submission that included them.
Audit & security data
Meaningful account and form actions (publishing a version, changing a member's role, and similar) are recorded in an audit log tied to the acting user and organization, so an organization can review who did what.
Cookies
We set exactly one cookie: refresh_token, used to keep you signed in between visits. It's httpOnly (invisible to page JavaScript), marked secure in production, scoped only to our own authentication endpoint, and expires after 7 days. That's it — we don't set analytics, advertising, or third-party tracking cookies, and nothing on this site profiles you across other sites. Because this cookie is strictly necessary for you to stay logged in, there's nothing to opt out of; the notice you may have seen on your first visit was disclosure, not a consent request for something optional.
Third parties we actually use, and where
The service is hosted by Lineserve in Nairobi, Kenya. We treat every other service below as processing data outside Kenya. For most of them the location is known; where we have not yet recorded the country, we say so rather than guess. The maintained list — with what each one receives, where, and whether it is in use — is at /subprocessors; it is published from the same record the product itself is checked against.
- Lineserve — hosts the application, its database, its background worker and the website and forms, in Nairobi, Kenya, and stores uploaded files, drawn signatures and our encrypted backups there. Everything the service stores is stored here, and it receives your IP address and the page you request.
- Hostinger — relays our email (verification codes, password resets, notifications, and the receipt a form may send you). Only the address and the message pass through it. We have not yet recorded the country its mail servers are in.
- Paystack — payment processing for paid plans (cards and M-Pesa). Payment details go directly to Paystack; we never see or store them.
- Paystack, for form payments — when a form asks you to pay, the payment goes to the organization that sent you the form, through that organization's own Paystack account. Your M-Pesa phone number, an email for the receipt, the amount and the payment and submission references go to Paystack. Your M-Pesa PIN is entered on your phone and card details on Paystack's own page — never on UndaForms. We keep the payment record (amount, status, references, times) and a masked form of your number; if the organization erases your submission, the payment record stays as a financial record, without your number and without your answers. We have not yet recorded the country Paystack processes payments in.
- DeepSeek's API — only when someone in your organization uses one of the optional AI features, and only what that feature needs:
- Create with AI: the description you type, and the text extracted from a PDF if you attach one.
- Improve with AI and Review with AI on a form: the messages you type and the form's questions and settings.
- Draft with AI, Edit with AI and Review with AI on a workflow: the messages you type, the workflow itself, the question labels of the form it runs on, and the names of your connections — never their credentials.
- Sentry — error monitoring, only in deployments that have it configured. When active, it can receive stack traces and request metadata (which may include your IP address) from a crash, to help us fix it.
- Cloudflare Turnstile — a check that a person, not a bot, is signing up, only where it is configured. It receives the IP address of the person signing up.
- Google, Slack and WhatsApp — only when an organization connects its own account (Google Sheets, Slack, WhatsApp) or you choose to sign in with Google. Connected services receive a submission's reference, status and dates — never the content of its answers. A WhatsApp message an organization sends can be addressed to the phone number you gave on its form.
How we use it
To operate the account you signed up for: authenticating you, enforcing the plan and role permissions your organization has set, delivering the emails a form or account action triggers, computing things like premium totals server-side so they can't be tampered with client-side, and keeping the audit log an organization uses to review its own activity. We don't sell personal data, and we don't use account or submission data to train any model.
How long we keep it
Account and organization data is kept for as long as the account or organization exists. Form submissions are business records belonging to the organization that published the form, and are kept under that organization's own retention decisions — deleting your personal account (below) doesn't remove submissions you reviewed, since those remain the organization's records.
Organizations can set how long submissions, and the IP address recorded with them, are kept; nothing is deleted automatically until an organization chooses a period. An organization can also delete a single submission — with its attached files — for example when the person who sent it asks. A record that a submission existed and was deleted, without its content, remains in the organization's audit log. We back up the database every six hours, encrypted, to storage in Nairobi, and keep each backup for 30 days; data deleted from the service persists in those backups until they expire.
Your rights over your own account
From your account settings, you can:
- Export your data — download your profile, every organization you belong to and your role in each, and your recent audit log activity.
- Erase your account — your email, name, password, and MFA credentials are permanently removed and your email is replaced with a non-reversible placeholder; every active session is revoked immediately. Business records that reference your account (form versions you published, audit log entries, agent records) stay with the organization, the same way an employee leaving a company doesn't erase the company's own records of what they did — but they're no longer tied to identifying information about you specifically. If you're the sole owner of an organization, you'll need to promote another member to owner (or delete the organization) first, since erasing the only owner's account would leave it with nobody able to manage it.
If you're an applicant rather than an account holder, these tools don't apply to you directly — contact the organization whose form you filled out, since they control that data.
Security
Passwords are hashed with Argon2, never stored or logged in plain text. Sessions use short-lived access tokens plus the httpOnly refresh cookie described above. Two-factor authentication (TOTP) and SSO are available. Public endpoints (form submission, file upload) are rate-limited per IP address to reduce abuse. No system is perfectly secure, but these are the concrete measures actually in place, not aspirational ones.
Children's privacy
Unda Forms is a B2B product for organizations and their applicants, and isn't directed at children: we don't knowingly create accounts for children under 16. Organizations' forms can, however, ask about children — for example dependants on an insurance application. That data belongs to the organization, which decides how it meets the Data Protection Act's requirements for children's data (section 33). An organization can mark a form as involving children; the product then keeps the applicant's receipt to a reference only and keeps the AI features off for that form unless the organization allows them.
Changes to this policy
If this changes in a way that meaningfully affects how your data is handled, we'll update the date at the top of this page and, where required, notify account holders directly.
Contact
Questions about this policy, or a data request outside of the self-service tools above: privacy@undaforms.com. If you filled out an organization's form, that organization is the one to ask first — see the top of this page.
You can also complain to the Office of the Data Protection Commissioner of Kenya (odpc.go.ke).
