GDPR & data protection
Personal data on your terms.
SnagBane runs on your server, so the answers people give never pass through us. And it gives you the tools to collect less, keep it shorter and prove who saw what.
Who is responsible for what
- Your organisation is the controller of everything collected in your SnagBane: forms, answers, files, approvals and accounts. You decide what is collected, why and for how long.
- SnagBane (the vendor) is not a processor of that data. It is software you install; we have no access to your installation or database, so there is no form data to sign a data processing agreement about.
- Where the data lives is your choice — your own data centre, or a cloud region you pick (for example inside the EU). Nothing is replicated anywhere else.
- Integrations are yours too. If you connect Microsoft 365, Google, Slack, a CRM or a webhook, data goes from your server to that service under your agreement with it.
Built-in tools that help
- Data minimisation: Anonymous responses store no name, email, IP address or browser. Ask only what a form needs; conditional logic and branching show questions only when they apply.
- Transparency: put your privacy notice in the form description or a text block, and ask for consent with a required checkbox question when consent is your legal basis.
- Storage limitation: a retention policy deletes old responses automatically.
- Access control: roles, workspaces and per-form access; approvers see only the requests assigned to them. Single sign-on with Microsoft 365, Google, Okta or SAML, and two-step verification.
- Accountability: an audit log of sign-ins, exports, deletions and approval decisions, which you can stream to your SIEM.
- Security of processing: HTTPS with HSTS, encrypted secrets, private file storage, signed updates — see the security overview.
Retention policy
Administration → Security → Data retention: switch on Delete old responses automatically and choose how long to keep them — 30 days to 10 years, or any number of days.
- Every night, older responses are deleted for good with their uploaded files, signatures and approval history.
- Requests still waiting for approval are never deleted.
- See what is due per form, and Delete now when you need to.
- Forms can keep their responses or use their own period — or make every form follow the organisation policy.
- Every run is recorded in the audit log.
Requests from people (access, erasure, portability)
- Find a person’s responses by searching their name or email in Results.
- Export responses as CSV or Excel to answer an access or portability request.
- Delete a response and its files; the audit log records who deleted it.
- Accounts can be deactivated or deleted by administrators; what a deleted person owned can be handed to a colleague first.
What SnagBane (the vendor) processes
Only this, and never the contents of your forms:
- Update checks: edition, version, PHP version and site address (can be turned off).
- Licence checks (Enterprise): a random installation ID, the Freemius installation ID and a hash of the licence key.
- Purchases: handled by Freemius as reseller; see the privacy policy.
- This website: served by Cloudflare; no cookies, analytics or advertising trackers.
This page describes product features; it isn’t legal advice. Your data protection officer decides how to use them for your organisation.