FAQ
6Is formcel HIPAA-compliant, and do you sign a BAA?
The technical safeguards for PHI are in place today: encrypted storage, mandatory access logging and enforced 6+ year audit retention. Formal attestation and business associate agreements are still on our roadmap, so we do not sign BAAs yet.
Are you GDPR-compliant, and how do I get a signed DPA?
We self-attest to GDPR and UK GDPR: EU data residency in 12 European regions, right to erasure, data portability and consent management. Our standard DPA with EU Standard Contractual Clauses is available on request from privacy@formcel.com.
Where is my data stored, and can I choose a region?
You pick a region at signup. Data is stored and processed there on dedicated, isolated infrastructure and does not leave it unless you explicitly configure cross-region replication.
How is data encrypted, in transit and at rest?
All stored data, including backups and file uploads, is encrypted with AES-256. Connections use TLS 1.3 with HSTS enforced and no fallback to older protocols.
Do you have a SOC 2 report?
Not yet. Our controls are SOC 2 aligned and the audit is planned, but no report has been issued. We will publish the report here as soon as one exists.
How will I know when you add a subprocessor?
Customers are notified 30 days before a new subprocessor is added. The full list, with purpose, data category and location, is published on this page with its last-change date.