GDPR

The simplest way to be careful with a form is to have no third party in it

Most form plugins are a front end for somebody else's service. LocalForm is not: the questions, the answers and the fonts all live on the server you already run. There is no transfer to assess, no sub-processor to list, and no vendor who could change their terms next year.

Download free Read the privacy statement

What is actually different

Every line below is a property of the free plugin, not a promise about how we behave with your data - because we never receive it.

Responses never leave your database

Answers are written to your own WordPress tables and read back from there. There is no copy on our side, because there is no request to our side.

Nothing calls home

The free plugin makes no outbound request of its own: no telemetry, no usage statistics, no licence check, no "anonymous" ping. Switch off your server's internet access and it still works.

Fonts from your own domain

The seven bundled font families are served by your site. Rendering a form sends your visitor's IP address to nobody - the exact exposure a 2022 ruling by the Regional Court of Munich turned into a live risk for German site owners embedding fonts from Google's servers.

Optional encryption at rest

Switch it on and stored answers are unreadable in a database dump - useful when the form asks something you would rather not have sitting in plain text in a nightly backup.

A spam log with no IP addresses

Blocked attempts are recorded against a one-way hash, so you can see the same device trying eleven times without the log becoming a record of who visits you.

Access and erasure, through WordPress

LocalForm registers its responses with Tools → Export Personal Data and Tools → Erase Personal Data, so a request covering your site covers your forms too.

Only the people who need to read them

Two permissions of LocalForm's own, granted per role, let a coordinator read the registrations for their event without becoming an administrator of your site.

Spam protection without a challenge

A rotating honeypot, browser and timing checks, rate limits and a content filter - none of which sends your visitor to a third-party service to prove they are human.

No lock-in on the way out

Back up every form, submission and setting to a single file, export responses to XLSX or CSV, or read them over the REST API. The data is yours in a format you can leave with.

Where a third party still appears - and where it does not

Being straight about this is the whole point. Nothing below is hidden in a sub-processor list; it is all a choice you make deliberately, or not at all.

What Who else is involved
Building forms and collecting responses (free plugin) Nobody. Your server, your database, your domain.
Buying and licensing LocalForm Pro Freemius handles the checkout and the licence. That is about you as a customer - your visitors' answers are not part of it.
Taking payment for a registration (Pro) The Stripe, Mollie or WooCommerce account you chose and connected. You have that relationship already.
Adding someone to a mailing list (Pro) Flexmail, Brevo, MailerLite or Mailchimp - only for the people who ticked your own consent question, and only if you set it up.
Sending a submission onward by webhook Whatever endpoint you pointed it at. Off unless you configure it.
An optional anti-spam challenge Cloudflare Turnstile or hCaptcha, if you switch one on. Off by default, precisely because it involves someone else.

What to hand the person who has to approve it

Schools, municipalities, works councils and hospitals tend to need a short pack rather than a feature list. These four links are it:

  • The privacy statement - written against Articles 13 and 14, naming who we are, what we hold and what we do not.
  • The security policy - how to report a vulnerability, what is in scope, and the design decisions that look like findings but are deliberate.
  • Permissions - which role can read responses, and how to grant that without handing over the site.
  • Forms → Settings → Support in your own admin - a site report listing which features your forms actually use. It is generated locally and sent nowhere; paste it into the assessment.

Not legal advice. LocalForm removes the third party from your form; it cannot make your processing lawful on its own. You still decide what to ask, why you may ask it, how long to keep it and what to tell people - and you are the controller for all of it.

Questions we get from data protection officers

Do I need a data processing agreement with you?

Not for the responses. The free plugin makes no outbound request of its own and sends us nothing, so we never process the personal data your forms collect and there is nothing for such an agreement to cover. Buying a Pro licence is a separate relationship - about you as a customer, not about your visitors.

Does LocalForm load Google Fonts?

No. The seven bundled families are served from your own domain, so rendering a form sends your visitor's IP address to nobody.

How do I answer an access or erasure request?

With WordPress's own Tools → Export Personal Data and Tools → Erase Personal Data. LocalForm registers its responses with both.

Are form responses encrypted?

Optionally, yes - encryption at rest can be switched on so stored answers are unreadable in a database dump. As with any encryption, the site keeps the key it needs to read them back.

Does the spam protection log IP addresses?

No. The blocked-attempts log stores a one-way hash instead, so you can tune the settings without the log itself becoming a record of who your visitors are.

Where is the data stored, physically?

Wherever your WordPress site is. That is the answer we cannot give you and you can - which is usually what the question is really about.

Take the third party out of your forms

The free plugin is the whole form builder. Install it, move one form across, and see what the assessment looks like when there is nothing to assess.

Download free Move from Google Forms