Text extracted from the source PDF's text layer. 32 of 33 slides have text.
1Enterprise-grade web forms with total data sovereignty,
modern SurveyJS integration, and optional AI acceleration.
Andreas Jung
Plone Conference 2026 · Maastricht
www.zopyx.com - www.andreas-jung.com
1
2SPEAKER
Andreas Jung
Plone & Python consultant · software architect · form-wrangler since the pre-Volto era
PLONE ARCHAEOLOGIST
INTEGRATION PLUMBER
AI CO-PILOTED BUILDER
Two decades around Plone, Zope and
FastAPI, databases, APIs, PDFs, exports,
Architecture, code and design discussed
Python.
auth.
with AI — then reviewed by humans…and
Still knows where the old
If data leaks, blocks, or deadlocks,
form bodies are buried.
it becomes my problem.
sometimes the Meat Proxy.
AI slop, but with tests and taste.
Personal mission: make forms boringly reliable — and prevent Germany from reinventing the fax as a web app.
Andreas Jung / ZOPYX is an official SurveyJS Partner.
2
3DISCLAIMER
Designed, built, and challenged with AI
Privacy Forms Studio is not only a forms project — it is also a case study in AI-assisted software engineering.
IMPLEMENTATION
ARCHITECTURE
VERIFICATION
Designed and implemented with AI
Discussed, iterated, and challenged
Reviewed critically — not accepted
assistance.
with AI.
blindly.
THIS IS AI SLOP — at its best.
3
4LIVE DEMO
Try it live! ✨
See Privacy Forms Studio in action — no setup, use demo login, no friction.
demo.privacyforms.studio
4
5HISTORICAL LANDSCAPE
Evolution of forms in Plone
ATSchemaEditorNG
collective.easyform
Early archetypes framework solution. Tightly coupled to legacy backend
form layers (z3c.form, Archetypes).
beast — hard to customize and limited functionality, limited styling options.
1
Modern Dexterity replacement for Plone 5/6. Better than PFG but still a
2
3
4
PloneFormGen
Volto Form Block
The classic workhorse for standard user forms.
Lightweight block solution for React frontend. Suboptimal editor experience for
non-technical users. Difficulties creating glossy, complex, multi-page workflows.
COMMON ARCHITECTURAL CHALLENGES
Legacy Coupling
Limited Customization
Editor Experience
Tight dependencies on deprecated backend form layers
make migration and modernization costly.
Restricted layout and styling options hinder enterprisegrade UI requirements.
Suboptimal interfaces for non-technical users and
difficulties building complex multi-page workflows.
5
6ENTERPRISE PRIVACY
Motivation for Privacy Forms Studio
Digital Sovereignty
Complex Requirements
AI Capabilities
EU-driven compliance mandating full
Increasing client demand for beautiful,
Leveraging modern AI to accelerate form
control over sensitive data without
multi-step digital forms with complex
creation while maintaining strict on-
third-party SaaS dependencies.
conditional logic and validation.
premise trust boundaries.
6
7DESIGN PRINCIPLES
Top Design Objectives
User & Admin Focus
Architecture Focus
•
•
Modern replacement for EasyForm and
legacy builders.
Self-hosted deployment ensuring full data
sovereignty.
•
Visual drag-and-drop authoring workspace.
•
Native Plone integration with native
•
Complex branching, logic, and multi-page flows.
•
Multilingual and accessible (WCAG compliant) by
•
Open, portable JSON-based form definitions.
default.
•
Support for different security models.
•
Seamless integration via REST APIs and Webhooks.
•
Security and professionalism by design.
security & roles.
7
8FEATURE HIGHLIGHTS
Feature Highlights
Visual Designer
Conditional Logic
Privacy-First
Intuitive drag-and-drop form builder for rapid
Powerful skip rules and expression evaluation
Zero external tracking or required SaaS calls —
development.
for complex workflows.
full data sovereignty.
PDF Digitization
Enterprise Governance
Multilingual Support
Convert paper processes to streamlined digital
Designed specifically for strict GDPR
Available in ten languages with full RTL
workflows.
environments and enterprise compliance
support.
requirements.
Optional AI Support
Scalability
AI-accelerated form generation and assistance
Supports small and large-scale Plone
— fully optional, humans stay in control.
installations for low- and high-volume form
and poll traffic.
8
9Let's see it in action!
A quick video demonstration of Privacy Forms Studio.
9
11CORE TECHNOLOGY
Powered by SurveyJS Engine
SurveyJS provides an industry-standard, client-side rendering engine and visual creator component.
By combining SurveyJS with Plone, Privacy Forms Studio delivers enterprise governance without reinventing form UX.
30+ Input Types
JSON Schema
Support for dynamic matrices, dropdowns, files, and ratings.
Clean, portable declarative JSON schema for forms and responses.
Calculated Fields
Responsive UI
Dynamic expressions, value variables, and inline validation.
Mobile-optimized and WCAG accessible out of the box.
32 Predefined Themes
Design Token System
Light & dark variants plus panelless layouts — 32 theme variations out of the box.
5-layer CSS variable architecture: palette → base → primitives → semantic →
component tokens.
Visual Theme Editor
Shared Across Products
No-code Theme Editor in Survey Creator generates reusable JSON theme objects for
brand alignment.
One theme JSON applies consistently to Form Library, Creator, Dashboard, and PDF
Generator.
11
12CORE TECHNOLOGY
SurveyJS — What is it?
SurveyJS is a set of client-side JavaScript libraries for building a full-cycle form management system on your own infrastructure.
Every form is defined by a portable JSON schema — no vendor lock-in, no third-party data storage.
CORE
FREE
CORE
COMMERCIAL
Form Library
Survey Creator
Free & open-source (MIT). Renders dynamic, JSON-based forms in React, Angular, Vue, or plain
Visual drag-and-drop builder that generates portable JSON schemas. Fully white-label and
JS — with conditional logic, validation, and branching. — the heart of Privacy Forms Studio.
customizable. Commercial license. — used for visual form authoring in Plone.
OPTIONAL
OPTIONAL
Dashboard
PDF Generator
Visualises survey results with interactive charts and tables. Interprets JSON schemas to populate
Renders any SurveyJS form as a PDF, with editable or pre-filled export. Commercial license.
custom dashboards. Commercial license.
Optional — not currently used in Privacy Forms Studio.
Optional — PDF export handled differently in Privacy Forms Studio.
Form Library is free (MIT). Survey Creator, Dashboard, and PDF Generator require a commercial license — one-time per developer. Supports React, Angular, Vue, jQuery, and Vanilla JS. Fully WCAG / Section
508 / ARIA compliant. No usage limits — unlimited forms, responses, and users.
12
13LICENSING
SurveyJS Licensing Model
CORE
CORE
OPTIONAL
Form Library Viewer
Survey Creator Basic
SurveyJS PRO Suite
Production / Runtime
Development / Authoring
Enterprise / Advanced
€0 Free
€499 one-time per developer
€899 one-time per developer
Unlimited forms, submissions, and users.
Optional renewals.
Includes PDF generator and dashboard and full
Visual drag-and-drop builder.
suite.
Zero licensing costs for end-users, content editors, or form respondents.
Editors using the "Creator" component (editor) do not need a dedicated SurveyJS license.
Integrators using Privacy Forms Studio count as integrators/developers and require a license.
One integrator/developer with multiple rollouts = one license per integrator needed.
Financially attractive for larger organizations.
Made in Estonia/EU.
13
14ARCHITECTURE
Technical Architecture
A clean separation of concerns across every layer of the stack.
Layer
Technology Choice
Key Functionality
Frontend
Plone 6 Classic & SurveyJS
Seamless form rendering, validation, and visual design workspace.
Definition Format
Open JSON Schema
Portable definitions decouples forms from underlying database
framework.
Storage Engines
ZODB or RDBMS (SQLAlchemy)
Support for local Plone ZODB or dedicated external relational SQL
databases.
Delivery & API
REST API & Webhooks
Real-time submission routing, email notifications, and background
processing.
14
16CORE PIPELINE
The Foundation Pipeline
One JSON definition flows through authoring, rendering, and response collection.
1. Form JSON
2. Survey Creator
3. Form Library
Single declarative JSON definition
Visual drag-and-drop authoring
Free runtime engine rendering interactive
containing fields, validation, logic, and
environment for form designers and
forms and collecting responses in client
localized labels.
editors.
browsers.
16
17SECURITY
Survey access modes controls the entrance
Server-side policy: who may access and submit a form or poll?
PUBLIC
TOKEN LINK
TOKEN CONTAINER
Open URL
Bearer URL
Managed token object
Polls · contact · registration
Possession grants access
Lifecycle + audit trail
Controls:
Controls:
States:
•
👷 Rate limits
•
Cryptographic token
•
valid
•
Validation
•
Expiry
•
used
•
Submission tokens
•
Scope
•
revoked / expired
Every request is checked by the backend. Standard Plone roles, groups, permissions and workflows can be applied where needed.
Strong validation on the backend in order to avoid abuse or malicious data being submitted.
17
18SECURITY
Abuse Protection
Layered controls applied before a submission is accepted.
Short-Lived Tokens
Dual Validation
JWT access tokens expire quickly, reducing the useful lifetime
The same form rules are checked in the browser and again on
of a leaked token or to avoid replay attacks.
the server.
One-Time Submission
Mass-Submission Defence (planned)
A token is consumed after use; repeated submissions with the
Token gating prevents simple replay. Rate limiting remains a
same token are rejected.
deployment issue.
Implemented: token expiry · dual validation · single-use consumption | Planned / deployment-specific: rate limiting
18
19SECURITY
Submission Validation Pipeline
Every submission passes a 10-step server-side hardening pipeline before it is stored, mailed, or forwarded.
1. Transport Limits
2. JSON Shape
3. Schema Fields
4. Text Safety
Oversized payloads rejected with
HTTP 413 before JSON parsing.
Submission must be a valid JSON
Only fields from the active form
Blocks XSS, dangerous markup, script
object; primitives and arrays rejected.
schema accepted; unknowns rejected.
injection and on* event handlers.
5. Data URLs
6. File Structure
7. Filenames
8. MIME & Content
Only Base64 PNG/JPEG allowed;
malformed or unsupported URLs
rejected.
Files must have valid filename, MIME
type and content members.
Unicode NFC normalized; path
traversal and control characters
rejected.
Allowlist enforced; magic bytes
verified for all supported formats.
9. Resource Limits
10. Canonical Hand-off
File count and decoded size limits enforced independently.
Normalized deep copy passed to validator and downstream only.
Force Server Side Validation (default: on) — compiled SurveyJS binary (automatically compiled using Deno), Submission contents and secrets are never logged.
19
20GOVERNANCE
Governance
Policy, traceability, and control over form definitions and submissions
Version Control
Audit Trail
Form Versions Are Versioned
Complete Submission Logging
Every form definition is fully versioned — changes are tracked, previous versions can
be restored, and audit trails are maintained for compliance.
All submissions and form changes are logged with timestamps and user attribution
for full traceability.
•
•
•
•
•
•
Full change history per form
Restore previous definitions
Compliance-ready audit trails
Access Control
Timestamped submission records
User attribution on every action
Tamper-evident log storage (planned)
Workflow Integration
PLONE
PLONE
Role-Based Permissions
Content Workflow Participation
Leverages Plone's native security model — roles, groups, and permissions govern
who can create, edit, publish, or view forms.
Forms participate in Plone content workflows — publish, retract, or archive forms as
part of standard editorial processes.
•
•
•
•
•
•
Plone roles & groups
Per-form permission policies
Fine-grained view/edit control
Standard Plone workflows
Publish / retract / archive states
Editorial process integration
20
21PROCESSING
Actions
Actions define what happens after a submission is accepted — any combination of store, mail, mail-notification, and post can run
simultaneously.
store — Persist the submission
mail — E-mail exported results
Saves the submission to the results store (ZODB or RDBMS) with
Sends export files (PDF by default) as e-mail attachments;
metadata including poll_id, created, user, and answer
10 different formats available and configurable.
payload. ZODB enabled by default.
mail-notification — Notification e-mail
post — Forward to HTTP endpoint
Sends a lightweight notification e-mail with a link to the
POSTs the validated payload as a webhook to a configured
submission detail view — no attachments, no data.
HTTP(S) endpoint.
21
22EXPERIMENTAL
AI Assistance
Optional AI acceleration that keeps humans in the loop and data on-premise.
All AI features are fully optional — zero AI is the default. You choose if, when, and where AI is used.
Prompt → Form
Document → Form
Chatbot Assistant
Draft complete forms from a simple text description.
Convert existing documents into digital forms: upload
An integrated chatbot helps users navigate Privacy
Forms Studio: answers questions, guides
configuration, and explains features in plain language.
Describe structure, fields, and logic in plain
language — AI generates the JSON schema instantly.
mockups, scanned PDF forms, or plain-text specifications
— AI extracts fields, types, and structure automatically.
Infrastructure & Governance
Local AI Support
Human Control
Integrates with Ollama for zero data leakage.
Any local or remote AI provider supported.
AI generates drafts; human editors review & publish.
Full control: use no AI, a local model (Ollama), or any remote provider — configured per deployment. You decide the level of AI involvement.
Most decent models work well, including lightweight flash/small models — no need for the largest or most expensive ones.
22
23INFRASTRUCTURE
Data Handling & Processing
Enterprise-grade data management with flexible storage, multi-format export, and automated hand-off capabilities.
Flexible Storage
Multi-Format Export
Automated Hand-off
Store submissions in ZODB or
Export response data instantly to
Trigger secure webhooks, custom
relational databases via SQLAlchemy,
10 different formats like PDF,
Python processing pipelines, and
or route directly without persistent
XLSX, CSV, DOCX, HTML, Markdown,
configurable multi-recipient emails.
XML, and JSON formats.
Support of Plone notifications/events.
storage.
23
24INFRASTRUCTURE
Deployment & Storage Strategy
Keep definitions in Plone. Configure submission and caching backends independently for each Plone site.
✅ Plone Core
✅ Small Deployments
🚧 High-Volume Use
•
Form definitions
•
Standalone or ZEO
•
RDBMS submissions
•
Version history
•
Submission data in Plone
•
Shared RDBMS-backed cache
•
Permissions & workflows
•
Shared SQLite cache
•
Avoid ZODB write contention
Plone 6.2 remains the authoritative
A simple setup is sufficient for low traffic
Designed for busy forms, polls and multi-
configuration layer.
and modest form usage.
node deployments.
Per-site configuration: Submission and caching backends are configured independently for each Plone site.
Recommendation: Use an RDBMS when traffic or concurrency grows.
24
25Digital workflows
and PDF forms
25
26USE CASE
Use Case: PDF to Web Form
Transform legacy paper-based processes into modern, accessible digital workflows.
Ingest Paper Forms
Smart Extraction
Scan legacy paper or PDF forms into the system.
AI extracts form fields, titles, and section structures.
Interactive Web Form
Structured Data
Generates accessible, multi-page SurveyJS web forms.
Responses captured as clean JSON for backend
processing.
26
27EXPORTS & PDF
EXPERIMENTAL
Workflows with fillable PDFs 1/3
"Fillable PDF forms are a plague — limited functionality, poor UX, and still printed out anyway."
Limited Functionality
Poor User Experience
Still Gets Printed
Fillable PDFs can't branch, validate properly, or adapt to user input.
Clunky, inconsistent across viewers, and not mobile-friendly.
Despite being "digital", most fillable PDFs end up printed and filed anyway.
Digital Twin Workflow
PDF Round-trip
Create Digital Twin
Create Digital Twin
Build an online equivalent of the PDF form using SurveyJS — same fields, same logic, better UX.
Build an online equivalent of the PDF form using SurveyJS — same fields, same logic, better UX.
Fill Online
Fill Online
Users complete the form in the browser — mobile-friendly, validated, accessible.
Same digital form, same great UX.
Process Digitally
Export to Fillable PDF
Store data online, process server-side, distribute via export, mail, or POST webhook.
Transfer answers back into the original fillable PDF — pre-filled, ready for signature or archiving.
Distribute
Send the pre-filled PDF by mail, download, or forward to downstream systems.
The best of both worlds: modern online UX with PDF compatibility for legacy workflows.
27
28EXPORTS & PDF
EXPERIMENTAL
Workflows with fillable PDFs 2/3
What we extract from the PDF
How the Digital Twin is built
01
Form Fields
Geometry
Name, type, value, and options.
Position, size, and page number.
Field Groups
Non-field Content
02
Visual row clusters preserving layout logic.
Labels, headings, and annotations with
context.
Map to SurveyJS
Extract
pypdf parses AcroForm fields, geometry, and RowGroups.
Field types are mapped and names sanitized.
03
Enrich with Context
Labels are linked to fields via spatial proximity.
04
Generate Online Form (LLM-supported)
SurveyJS JSON schema produced with pdfFieldName for round-trip mapping.
Tools: pypdf · privacyforms_pdf (AcroForm parsing, geometry, RowGroups) · pdfcpu (deterministic field extraction, reference pipeline)
28
29EXPORTS & PDF
EXPERIMENTAL
Workflows with fillable PDFs 3/3
Filling a PDF with submitted form data is a two-step process: validate & extract with pypdf, then write values back with PyMuPDF.
pypdf · Validate & Extract
PyMuPDF · Fill & Return
Upload Validation
Receive Form Data
Checks the PDF has AcroForm fields via get_fields(). Rejects non-form PDFs early.
Submitted field values arrive from the browser (text, checkbox, combobox, listbox).
Field Extraction
Reads field names, types (/FT), flags (readonly/required), options (/Opt) and widget rects from /
Annots.
Mapping Check
Each PDF field is checked against the SurveyJS form — marking which fields have a
digital twin counterpart.
Write to Widgets
PyMuPDF sets widget.field_value per field name and calls update() for each widget
type.
Return Filled PDF
A pre-filled <name>_filled.pdf is returned — ready for download, signature, or
archiving.
Field matching is by name — the SurveyJS form and the PDF must share identical field names for the fill to work correctly.
29
30OPEN ISSUES
Open Issues
Which license?
Experimental functionality
AI Assistance
Which license can this AI slop have in
PDF fillable form workflows (digital twin
Prompt-to-form, document-to-form and
which legislation (EU, USA, world-wide)?
creation, PDF fill-back via PyMuPDF)
chatbot features require further
and AI-related functionality are
refinement before production use.
experimental and subject to change.
❌ Volto support
Unlikely and of little interest — Privacy
Forms Studio targets Plone Classic; a
Volto integration is not planned.
✅ SurveyJS Theming
🤷 collective-ai-settings
SurveyJS 3 introduced a complete new
Looking into new AI settings.
theming approach and implementation
PFS based on own privacyforms.ai
is currently being adjusted
module.
30
31CONCLUSION
Key Takeaways
Professional & Decent Solution
For building form-driven applications and services.
Affordable & Open
Almost free to deploy — open-source core with transparent,
affordable commercial licensing for advanced features.
Digital & Data Sovereignty
Ensuring your complete control over your data.
(optional) AI Assistance Under Your Control
Leverage powerful AI tools with full oversight and management.
Full Control Over Data & Processing
Maintain command throughout the entire data lifecycle.
31
32LIVE DEMO
Try It Yourself
Explore real forms built with Privacy Forms Studio. The demo resets every 6 hours.
7
Demo Forms
10
Languages
LTR & RTL
All 10 languages covered: English, Spanish, French, German, Arabic, Chinese, Japanese,
Portuguese, Russian, Hindi — spanning both left-to-right and right-to-left scripts.
32
33Questions & Discussion
Thank you for your attention!
privacyforms.studio
hello@privacyforms.studio
Product website
Get in touch
docs.privacyforms.studio
github.com/zopyx/zopyx.surveyjs
Documentation
Source code
33