Data Processing Policy
Last updated: 23 July 2026 · Branova Forms (forms.branova.in)
This policy describes how Branova Forms processes personal data on your behalf as a data processor, where you are the data controller.
1. Roles
You determine what data your forms collect and why. We process that data solely to provide the service under your instructions.
2. Security measures
- Organization-level data isolation and role-based access control.
- Passwords hashed with bcrypt; sessions hardened (HttpOnly, SameSite, Secure over HTTPS).
- CSRF protection, rate limiting, input validation and audit logging.
- Secure file storage not exposed through predictable public URLs.
3. Sub-processors
Hosting infrastructure and Razorpay (payments) act as sub-processors. They process data only as needed to deliver their function.
4. Data retention & deletion
We retain data for as long as your organization is active. Deleting a submission, form, or your organization removes the associated data.
5. International transfers & breach
We take reasonable steps to protect data in transit and at rest, and will notify you without undue delay of any breach affecting your data.
