Public traffic uses HTTPS/TLS. Managed database, EU-jurisdiction object storage, and backup services provide encryption at rest where configured. Secrets are supplied through deployment configuration and excluded from source control.
Backend-managed authentication, MFA, sessions, scoped role checks, and resource authorization protect organizations, projects, forms, records, media, billing, and privileged actions.
Source control, reviewed migrations, leased background jobs, monitoring, error reporting, backups, deletion workers, and incident procedures support availability, recovery, and accountability.
Customers control form purposes and content and must establish lawful bases, Article 9 conditions where needed, notices, retention, security, and DPIA screening. Reform processes customer form data on documented instructions.
Customers are responsible for ensuring that calculations and event scripts they create or deploy are lawful, do not harm respondents or third parties, and comply with the Product Terms and the Acceptable Use and Restricted Data Policy. Reform may restrict or suspend scripts or use that violates those requirements.
Current subprocessors, roles, regions, and transfer information are listed on the Subprocessors page. Suspected incidents are recorded, contained, assessed, and escalated using private operational contacts. Public questions may be sent to support@paqu.io or privacy@paqu.io.