GDPR-compliant forms,
built for European businesses
Create forms, collect encrypted responses, and analyse submissions — without moving data outside the EU. No cookie banners needed.
No credit card required · Free plan available
Everything you need. Nothing you don't.
Built specifically for the EU regulatory environment.
End-to-end encryption
Responses are encrypted at rest using AES-256-GCM. Only you can read the data.
EU data residency
All data is stored and processed in Europe. No transfers to the US or third countries.
Visual form builder
Drag-and-drop builder with text, number, dropdown, date, and file fields.
Submission dashboard
View, filter, and export all responses. Decrypted on-the-fly in your browser.
Shareable links
Share a public link to any form. No account required for respondents.
GDPR Article 25
Privacy by design and by default — we don't collect what we don't need.
Up and running in minutes
Sign in with FjordID
Secure single sign-on. No separate password to manage.
Build your form
Add fields, set labels, and publish — takes under 2 minutes.
Share the link
Send your form link via email, Slack, or embed it on your site.
Analyse responses
View encrypted submissions in your personal dashboard. Export as CSV.
Part of a fully EU-hosted indie stack
FormVault is built alongside other tools that follow the same principle: European data residency by default, no US cloud dependencies, pricing that makes sense at small scale.
Read more: The EU Indie Starter Pack — a simple European stack for indie SaaS builders
Frequently asked questions
Is FormVault GDPR compliant?
Yes. FormVault is built privacy-first: all data is stored and processed in Germany (Hetzner), responses are encrypted with AES-256-GCM, and a Data Processing Agreement (DPA) is included on every plan including free. We do not embed third-party tracking scripts on form pages.
Where is form data stored?
All data is stored exclusively in Germany on Hetzner infrastructure. We do not replicate data to US data centres or any region outside the EU.
Do you offer a Data Processing Agreement?
Yes — a signed DPA is available on all plans, including the free tier. You do not need an enterprise contract or lawyer to get a DPA with FormVault.
What encryption does FormVault use?
Every form response is encrypted at rest with AES-256-GCM using a per-submission key. Responses are decrypted in your browser only — not on our servers. Even FormVault staff cannot read your respondents' data.
Is FormVault a GDPR-compliant Typeform alternative?
Yes. Unlike Typeform, FormVault provides EU data residency on all plans (including free), no third-party trackers on the form player, end-to-end encryption, and a DPA for every customer. It's built specifically for EU organisations that need guaranteed compliance.
Can respondents request deletion of their data?
Yes. FormVault has a built-in respondent portal for GDPR data subject requests. Respondents can request access to or deletion of their submissions, and deletions are logged in the audit trail.
Ready to collect data the right way?
Join European businesses that take privacy seriously.
Create your first form →