GDPR and forms
As soon as a form collects a name, email or address you are processing personal data and GDPR applies. It is not a formality at the end — it shapes what you ask for in the first place.
It starts with a legal basis. Consent is not the only option and often not the most suitable one: for an order or a contract the basis is performance of a contract, for statutory duties it is legal obligation. Consent fits things like marketing newsletters.
The second principle is minimisation. Collect only the data you genuinely need for that purpose. A national ID number has no place on a workshop sign-up.
Respondents must know who processes the data, why, for how long and what rights they have. Typically you link the privacy policy directly in the form.
The practical part is technical: where the data lives, who can access it and how long it is retained.
In practice
- Ask only for what the purpose requires.
- Link your privacy policy directly in the form.
- Keep consent separate from other fields and never pre-tick it.
- Limit colleagues' access with roles to only the data they need.
- Decide how long you retain data and when you delete it.
FAQ
Do I always need consent?
No. Consent is only one legal basis; for orders and contracts the basis is performance of a contract.
Where is Gatherino data stored?
On servers in the European Union, backups included.
Do forms have to be visible in search engines?
No, forms are not indexed by default.
Related
Try Gatherino for free
Free plan: 3 forms and 100 responses a month. No credit card, EU-hosted data.
Get started free →