ProxForm
Checking… Not connected Build a form
GDPR Every claim, in one place

How ProxForm is GDPR-proof

A complete reference of every privacy and security claim ProxForm makes — what we do, what we don't do, and the technical detail behind each one. If you're doing a data-protection assessment, start here.

The four pillars

0
Servers

ProxForm has no application server. There is no backend to log into, no database, no queue, no API.

0
PHI at rest

Because there is no server, no patient health information is ever stored on ProxForm infrastructure. Local copies live only on the clinician's own device.

0
Third-party processors

No analytics, no email backend, no payment processor, no error-tracking SaaS. Patient data never touches a third party.

100%
In your browser

The whole app is HTML, CSS, and JavaScript served as static files. Every line of code runs in your browser — auditable in DevTools.

Architecture guarantees

These are the structural properties of ProxForm. They hold by construction, not by policy — there is no setting you can toggle to break them.

Cryptography & transport detail

Local-device storage scope

ProxForm uses browser storage only on the user's own device, never on any server.

What ProxForm does not do

GDPR article mapping

What ProxForm is not

Questions about a specific obligation?

If your DPO needs a written statement about something not covered here, reach out — use the Contact button in the footer below.