Forms9 min read
Comparing online form tools: criteria for Swiss SMEs
Eight criteria for putting online form providers side by side — and where each answer can be found in the vendors’ own public documentation.

A landscaping business in Sursee has been taking quote requests by telephone and now wants to collect them through a form on its website: name, address, phone number, plot size, a field for remarks, plus a photo of the garden. Three providers make the shortlist. All three home pages look tidy, all three talk about security and data protection, and after an hour of reading the decision has not moved an inch.
That is rarely because information is missing. It is because the information does not sit side by side. A comparison that helps is therefore less an opinion than a table: the same questions, put to every provider, answered out of what each one publishes itself.
How that table is built
One column per provider, one row per criterion. Three things in every cell: the answer in half a sentence, the address of the page it comes from, and the date it was looked up. The date sounds like bureaucracy and is the most useful part of the whole exercise — documentation changes, and an undated note cannot be placed later.
Two rules keep the table usable. First: a cell holds only what the provider’s own documentation says, not what a comparison site writes about it and not what was said in a sales call. Second: anything that cannot be found stays blank. A blank cell is not a verdict about the provider; it records that a question is open and can be put by email.
Eight criteria
| Criterion | The question behind it | Where the answer usually sits |
|---|---|---|
| Storage location | Which country holds the responses — and the uploaded files? | Security or privacy page, help centre |
| Sub-processors | Who else is involved, and which of them see form responses? | Public list, privacy notice |
| Contract | Is there a data processing agreement, and when does it apply? | Terms, contract page, sign-up |
| Export | In what format do the responses come back out? | Product help under “Export” |
| Deletion and contract end | What happens on deletion, and what on cancellation? | Terms, help pages on retention |
| Data subject rights | Can the software find one person’s data again? | Product help, contract |
| Languages | Does the form run in German, French and Italian? | Feature page, help centre |
| Uploads and embedding | Which files are accepted, and how does the form reach your site? | Product help |
The order is not a ranking. For one practice the languages decide it; for another business the storage location does. The table does not say what matters more — it only makes sure nothing is forgotten.
Storage location: the statement applies to something specific
The storage question rarely has a one-word answer, because it is almost always tied to a product variant, a region or a setting.
Jotform, for instance, describes a European option on a page of its own and puts it like this: “The data will be kept exclusively in our EU servers in Germany.” That is a precise statement — and one that applies to that option rather than to every account in general. Tally writes in its help centre that all form data is encrypted in transit and at rest and stored in Europe. And Formsly, a provider based in Switzerland, states in its FAQ that all data, responses and uploaded files are stored exclusively on dedicated servers in Switzerland, in a Zurich data centre, with Exoscale as its infrastructure partner.
Three providers, three differently worded answers — and in all three cases one that can be quoted and dated. That is exactly what belongs in the cell. What “data in Switzerland” answers and what it does not, we took apart in a separate post.
Sub-processors: the column that makes the difference
Behind every form service sit further service providers — a data centre, a mail sender, an error log, a support tool. Legally this is no sideshow: a processor may only transfer processing to a third party with the controller’s prior authorisation (Art. 9 para. 3 FADP). Where that authorisation is general, the processor informs the controller of any intended addition or replacement, and the controller may object (Art. 7 DPO). The Federal Data Protection and Information Commissioner asks accordingly, in its cloud checklist, whether the provider has an overview of its sub-processors and whether the documentation shows in which countries processing takes place.
For the table it matters not only whether a list exists, but how fine-grained it is. Tally publishes its sub-processors as a table with name, purpose, country — and a column headed “May process form submissions”, that is, the distinction of whether a service provider comes into contact with form responses at all. Several entries there point to a setting, for example file uploads or notification emails. That answers a question which is otherwise hard to answer: which part of the chain actually becomes active when this one form is used?
Contract, export and the end
Three rows that almost never come up in the selection meeting and all the more often afterwards.
The contract. What is interesting is less whether a data processing agreement exists — it is standard with many providers — than whether it can be read before signing up, and how it comes into force. Tally describes that professional users, by agreeing to the terms when creating an account, are also bound by its data processing agreement, and that the document does not have to be signed. Formsly writes that a data processing agreement is made available directly at registration. Both are statements that can be read before an account exists.
The export. The FADP gives every person the right to receive the personal data they have disclosed to the controller in a commonly used electronic format, where processing is automated and rests on consent or on a contract (Art. 28 FADP). What “commonly used” means is set out in the ordinance: formats that allow the data to be transferred and reused with proportionate effort (Art. 21 DPO). For the table that is a solid row — CSV, Excel, an interface, or nothing but a PDF printout.
The end. Two different questions that often get rolled into one: what happens when a single response is deleted, and what happens when the contract ends. For the first, Tally describes a deadline: deleted form data is permanently removed from backups within 90 days, unless the trash is emptied by hand before that. For the second, the Commissioner puts the question explicitly in its cloud checklist: whether the contract governs, or the customer can determine, that the provider deletes or returns the personal data once the contract has ended.
When someone asks for access
A row that is not needed for years and then needed immediately. Anyone can request information as to whether personal data about them is being processed, and receives among other things the data itself, the purpose, the retention period and the recipients (Art. 25 FADP). The addressee is the business: where a controller has data processed by a processor, the controller remains under the duty to provide information (Art. 25 para. 4 FADP). The processor assists, unless it answers the request on the controller’s behalf (Art. 17 para. 2 DPO).
In the table this turns into a very practical question: can the software search for a person across all forms? A business with seven forms and five years of responses notices the difference between one search and seven exports.
The everyday criteria
They rarely appear in data protection comparisons and often decide more in daily use.
Languages. A business in Biel or in Graubünden needs the same form in two or three languages. The question is whether one form can hold several language versions and how much of that happens automatically. Jotform advertises the feature with translations into more than 130 languages. A second, finer row pays off here: are error messages, drop-down options and the confirmation page translated too, or only the questions?
Uploads. As soon as a form accepts files, a second storage location appears with rules of its own. Tally names a 10 MB per-file limit on the free plan and describes that uploaded files are kept as long as the account exists and the response is not deleted. The same documentation shows that file uploads run through a particular service provider — a good example of the upload row and the sub-processor row belonging together.
Embedding. How the form reaches your own website is a design question and a data question at once. Tally documents three variants — embedded in a page, as a popup, as a full page. To the visitor, an embedded form looks like part of your own site; technically the response still goes to the provider’s address on submit. Knowing that changes how the privacy notice is written.
What the table achieves in the end
These examples are not a selection of the best providers, and the list is not exhaustive. They are three providers whose documentation on these points is public and readable without an account. Providers whose statements we could not read ourselves we left out, rather than writing about them at second hand — which is not a verdict on them but on our sources.
What ends up on the page is not a ranking but a basis for a decision that can be shown: to a business partner, to the fiduciary, to the customer who calls and asks where the photos of her garden actually sit. And because every cell carries an address and a date, it can be refreshed in half an hour two years from now instead of started over.
The online forms app we are building will have to answer the same rows. Our answers on storage location, encryption and export will be on the app page, with the same verifiability we expect here of others — the only yardstick that applies equally to everyone.
Sources
- 1.Tally: GDPR & Tally (Speicherort, Unterauftragsbearbeiter, Löschung) (checked on 23 September 2026)
- 2.Tally: File uploads (checked on 23 September 2026)
- 3.Tally: Embed your form (checked on 23 September 2026)
- 4.Jotform: EU Safe Forms (checked on 23 September 2026)
- 5.Jotform: Translate your Forms into 130+ Languages (checked on 23 September 2026)
- 6.Formsly: Online-Formulare & Umfragen nach Schweizer Datenschutz (checked on 23 September 2026)
- 7.Bundesgesetz über den Datenschutz (DSG, SR 235.1) (checked on 23 September 2026)
- 8.Datenschutzverordnung (DSV, SR 235.11) (checked on 23 September 2026)
- 9.EDÖB: Datenbearbeitungen in der Cloud (checked on 23 September 2026)
SchweizerformThis idea became Schweizerform.
Online forms with end-to-end encryption, made and hosted in Switzerland.