Choose the information your service collects, who can access it and how long submissions are retained. Govform’s permissions, authentication, retention settings and integrations give your team practical choices for designing services around a defined purpose.
Consider privacy throughout the journey, from the first question to notifications, review and downstream processing. Each additional field, attachment, recipient or integration should have a clear role in delivering the service.
Collect the information needed for the task and explain it clearly to users.
Restrict reviewer and live-data access to the relevant roles.
Check which information appears in emails, documents and connected systems.
Our website cookie policy explains cookies and third-party website features. Within a Govform service, session and security features support the journey, while your chosen identity provider and integrations can introduce their own requirements.
Core Govform service analytics use server-side records to understand journey activity. Review any additional scripts, embedded content or third-party analytics selected for your service, and make your published information reflect the complete experience.
Review service settings and connected providers when preparing cookie information.
Include authentication and embedded features in your review.
Keep website cookie information distinct from the configuration of your own service.
Incident procedures include assessment, escalation, investigation and required notification. The response considers affected information and services, alongside the communication and processing responsibilities agreed for the customer relationship.
Prepare the people and contact routes your organisation will use if a concern arises. Your own connected systems and internal response arrangements form part of coordinating a service-wide investigation and any required communication.
Maintain the customer contacts and escalation routes agreed for your service.
Report the affected feature, time and observed behaviour to the team.
Arrange a secure channel before sharing sensitive incident material.
Govform lets you include privacy links and sign-in information within service journeys. Your organisation defines the service purpose and the explanation users need about the information collected and how it will be used.
Library authentication settings can provide default privacy content, with service-specific choices where appropriate. Review the wording alongside the actual journey, including files, notifications, identity providers and other recipients.
Provide a privacy link at the points where users need it.
Make the information specific to the service and its connected systems.
Update the wording when collection, recipients or retention arrangements change.
Privacy decisions continue after a submission is received. Service retention, controlled exports, deletion workflows and the handling of uploaded files help your team manage information as it moves through operational work.
Plan for records held in Govform and copies held in other systems. Different features and destinations can have different retention and recovery arrangements, including response history, archives, backups and locally exported files.
Define the retention purpose and owner for each destination.
Use library controls to govern live-data views, exports and deletion.
Coordinate service changes with the owners of downstream records and file stores.