2026 ·English ·33 slides

Privacy Forms Studio - Enterprise-grade forms for Plone

Enterprise-grade web forms for Plone with full data sovereignty: a visual drag-and-drop form builder on the SurveyJS engine, with conditional logic, multilingual forms, PDF digitisation and governance. Walks through the forms landscape in Plone (ATSchemaEditorNG, collective.easyform, PloneFormGen, Volto Form Block), the architecture (portable JSON schemas, ZODB or RDBMS storage, a 10-step server-side submission-validation pipeline), exports (PDF plus ten more formats) and optional, fully on-premise AI assistance. Live demo: demo.privacyforms.studio.

Slide 1 of 33 — Privacy Forms Studio - Enterprise-grade forms for Plone
1/33 arrow keys or swipe · click image for fullscreen
Slide 1 of 33 — Privacy Forms Studio - Enterprise-grade forms for Plone
1/33

Details

Presented
24 September 2026
Language
English
Slides
33
Image size
2048x1154
Uploaded format
KEY, PDF
Collected
2026-09-28

Source & completeness

Content
original
Validation
passed
Slide text
available (32 slides)
Original files
yes
  • original.key KEY · 62.4 MB
  • original.pdf PDF · 8.2 MB · 33 slides
Checksums (SHA-256)
  • original.key: 57026f825a27041972757951342c1ac1f856afe6c227f0ecc7dfcda410b7bfd3
  • original.pdf: 6bb48438532cf1d93567949338a95989f7d0c3a3231c9db3ead244da57b8b6b1

Slide images were rendered from the author's own PDF export (2048x1154 px, WebP); nothing here is reconstructed from a third-party service.

Full text of every slide

Text extracted from the source PDF's text layer. 32 of 33 slides have text.

1
Enterprise-grade web forms with total data sovereignty, modern SurveyJS integration, and optional AI acceleration. Andreas Jung Plone Conference 2026 · Maastricht www.zopyx.com - www.andreas-jung.com 1
2
SPEAKER Andreas Jung Plone & Python consultant · software architect · form-wrangler since the pre-Volto era PLONE ARCHAEOLOGIST INTEGRATION PLUMBER AI CO-PILOTED BUILDER Two decades around Plone, Zope and FastAPI, databases, APIs, PDFs, exports, Architecture, code and design discussed Python. auth. with AI — then reviewed by humans…and Still knows where the old If data leaks, blocks, or deadlocks, form bodies are buried. it becomes my problem. sometimes the Meat Proxy. AI slop, but with tests and taste. Personal mission: make forms boringly reliable — and prevent Germany from reinventing the fax as a web app. Andreas Jung / ZOPYX is an official SurveyJS Partner. 2
3
DISCLAIMER Designed, built, and challenged with AI Privacy Forms Studio is not only a forms project — it is also a case study in AI-assisted software engineering. IMPLEMENTATION ARCHITECTURE VERIFICATION Designed and implemented with AI Discussed, iterated, and challenged Reviewed critically — not accepted assistance. with AI. blindly. THIS IS AI SLOP — at its best. 3
4
LIVE DEMO Try it live! ✨ See Privacy Forms Studio in action — no setup, use demo login, no friction. demo.privacyforms.studio 4
5
HISTORICAL LANDSCAPE Evolution of forms in Plone ATSchemaEditorNG collective.easyform Early archetypes framework solution. Tightly coupled to legacy backend form layers (z3c.form, Archetypes). beast — hard to customize and limited functionality, limited styling options. 1 Modern Dexterity replacement for Plone 5/6. Better than PFG but still a 2 3 4 PloneFormGen Volto Form Block The classic workhorse for standard user forms. Lightweight block solution for React frontend. Suboptimal editor experience for non-technical users. Difficulties creating glossy, complex, multi-page workflows. COMMON ARCHITECTURAL CHALLENGES Legacy Coupling Limited Customization Editor Experience Tight dependencies on deprecated backend form layers make migration and modernization costly. Restricted layout and styling options hinder enterprisegrade UI requirements. Suboptimal interfaces for non-technical users and difficulties building complex multi-page workflows. 5
6
ENTERPRISE PRIVACY Motivation for Privacy Forms Studio Digital Sovereignty Complex Requirements AI Capabilities EU-driven compliance mandating full Increasing client demand for beautiful, Leveraging modern AI to accelerate form control over sensitive data without multi-step digital forms with complex creation while maintaining strict on- third-party SaaS dependencies. conditional logic and validation. premise trust boundaries. 6
7
DESIGN PRINCIPLES Top Design Objectives User & Admin Focus Architecture Focus • • Modern replacement for EasyForm and legacy builders. Self-hosted deployment ensuring full data sovereignty. • Visual drag-and-drop authoring workspace. • Native Plone integration with native • Complex branching, logic, and multi-page flows. • Multilingual and accessible (WCAG compliant) by • Open, portable JSON-based form definitions. default. • Support for different security models. • Seamless integration via REST APIs and Webhooks. • Security and professionalism by design. security & roles. 7
8
FEATURE HIGHLIGHTS Feature Highlights Visual Designer Conditional Logic Privacy-First Intuitive drag-and-drop form builder for rapid Powerful skip rules and expression evaluation Zero external tracking or required SaaS calls — development. for complex workflows. full data sovereignty. PDF Digitization Enterprise Governance Multilingual Support Convert paper processes to streamlined digital Designed specifically for strict GDPR Available in ten languages with full RTL workflows. environments and enterprise compliance support. requirements. Optional AI Support Scalability AI-accelerated form generation and assistance Supports small and large-scale Plone — fully optional, humans stay in control. installations for low- and high-volume form and poll traffic. 8
9
Let's see it in action! A quick video demonstration of Privacy Forms Studio. 9
11
CORE TECHNOLOGY Powered by SurveyJS Engine SurveyJS provides an industry-standard, client-side rendering engine and visual creator component. By combining SurveyJS with Plone, Privacy Forms Studio delivers enterprise governance without reinventing form UX. 30+ Input Types JSON Schema Support for dynamic matrices, dropdowns, files, and ratings. Clean, portable declarative JSON schema for forms and responses. Calculated Fields Responsive UI Dynamic expressions, value variables, and inline validation. Mobile-optimized and WCAG accessible out of the box. 32 Predefined Themes Design Token System Light & dark variants plus panelless layouts — 32 theme variations out of the box. 5-layer CSS variable architecture: palette → base → primitives → semantic → component tokens. Visual Theme Editor Shared Across Products No-code Theme Editor in Survey Creator generates reusable JSON theme objects for brand alignment. One theme JSON applies consistently to Form Library, Creator, Dashboard, and PDF Generator. 11
12
CORE TECHNOLOGY SurveyJS — What is it? SurveyJS is a set of client-side JavaScript libraries for building a full-cycle form management system on your own infrastructure. Every form is defined by a portable JSON schema — no vendor lock-in, no third-party data storage. CORE FREE CORE COMMERCIAL Form Library Survey Creator Free & open-source (MIT). Renders dynamic, JSON-based forms in React, Angular, Vue, or plain Visual drag-and-drop builder that generates portable JSON schemas. Fully white-label and JS — with conditional logic, validation, and branching. — the heart of Privacy Forms Studio. customizable. Commercial license. — used for visual form authoring in Plone. OPTIONAL OPTIONAL Dashboard PDF Generator Visualises survey results with interactive charts and tables. Interprets JSON schemas to populate Renders any SurveyJS form as a PDF, with editable or pre-filled export. Commercial license. custom dashboards. Commercial license. Optional — not currently used in Privacy Forms Studio. Optional — PDF export handled differently in Privacy Forms Studio. Form Library is free (MIT). Survey Creator, Dashboard, and PDF Generator require a commercial license — one-time per developer. Supports React, Angular, Vue, jQuery, and Vanilla JS. Fully WCAG / Section 508 / ARIA compliant. No usage limits — unlimited forms, responses, and users. 12
13
LICENSING SurveyJS Licensing Model CORE CORE OPTIONAL Form Library Viewer Survey Creator Basic SurveyJS PRO Suite Production / Runtime Development / Authoring Enterprise / Advanced €0 Free €499 one-time per developer €899 one-time per developer Unlimited forms, submissions, and users. Optional renewals. Includes PDF generator and dashboard and full Visual drag-and-drop builder. suite. Zero licensing costs for end-users, content editors, or form respondents. Editors using the "Creator" component (editor) do not need a dedicated SurveyJS license. Integrators using Privacy Forms Studio count as integrators/developers and require a license. One integrator/developer with multiple rollouts = one license per integrator needed. Financially attractive for larger organizations. Made in Estonia/EU. 13
14
ARCHITECTURE Technical Architecture A clean separation of concerns across every layer of the stack. Layer Technology Choice Key Functionality Frontend Plone 6 Classic & SurveyJS Seamless form rendering, validation, and visual design workspace. Definition Format Open JSON Schema Portable definitions decouples forms from underlying database framework. Storage Engines ZODB or RDBMS (SQLAlchemy) Support for local Plone ZODB or dedicated external relational SQL databases. Delivery & API REST API & Webhooks Real-time submission routing, email notifications, and background processing. 14
15
Deep dive… 15
16
CORE PIPELINE The Foundation Pipeline One JSON definition flows through authoring, rendering, and response collection. 1. Form JSON 2. Survey Creator 3. Form Library Single declarative JSON definition Visual drag-and-drop authoring Free runtime engine rendering interactive containing fields, validation, logic, and environment for form designers and forms and collecting responses in client localized labels. editors. browsers. 16
17
SECURITY Survey access modes controls the entrance Server-side policy: who may access and submit a form or poll? PUBLIC TOKEN LINK TOKEN CONTAINER Open URL Bearer URL Managed token object Polls · contact · registration Possession grants access Lifecycle + audit trail Controls: Controls: States: • 👷 Rate limits • Cryptographic token • valid • Validation • Expiry • used • Submission tokens • Scope • revoked / expired Every request is checked by the backend. Standard Plone roles, groups, permissions and workflows can be applied where needed. Strong validation on the backend in order to avoid abuse or malicious data being submitted. 17
18
SECURITY Abuse Protection Layered controls applied before a submission is accepted. Short-Lived Tokens Dual Validation JWT access tokens expire quickly, reducing the useful lifetime The same form rules are checked in the browser and again on of a leaked token or to avoid replay attacks. the server. One-Time Submission Mass-Submission Defence (planned) A token is consumed after use; repeated submissions with the Token gating prevents simple replay. Rate limiting remains a same token are rejected. deployment issue. Implemented: token expiry · dual validation · single-use consumption | Planned / deployment-specific: rate limiting 18
19
SECURITY Submission Validation Pipeline Every submission passes a 10-step server-side hardening pipeline before it is stored, mailed, or forwarded. 1. Transport Limits 2. JSON Shape 3. Schema Fields 4. Text Safety Oversized payloads rejected with HTTP 413 before JSON parsing. Submission must be a valid JSON Only fields from the active form Blocks XSS, dangerous markup, script object; primitives and arrays rejected. schema accepted; unknowns rejected. injection and on* event handlers. 5. Data URLs 6. File Structure 7. Filenames 8. MIME & Content Only Base64 PNG/JPEG allowed; malformed or unsupported URLs rejected. Files must have valid filename, MIME type and content members. Unicode NFC normalized; path traversal and control characters rejected. Allowlist enforced; magic bytes verified for all supported formats. 9. Resource Limits 10. Canonical Hand-off File count and decoded size limits enforced independently. Normalized deep copy passed to validator and downstream only. Force Server Side Validation (default: on) — compiled SurveyJS binary (automatically compiled using Deno), Submission contents and secrets are never logged. 19
20
GOVERNANCE Governance Policy, traceability, and control over form definitions and submissions Version Control Audit Trail Form Versions Are Versioned Complete Submission Logging Every form definition is fully versioned — changes are tracked, previous versions can be restored, and audit trails are maintained for compliance. All submissions and form changes are logged with timestamps and user attribution for full traceability. • • • • • • Full change history per form Restore previous definitions Compliance-ready audit trails Access Control Timestamped submission records User attribution on every action Tamper-evident log storage (planned) Workflow Integration PLONE PLONE Role-Based Permissions Content Workflow Participation Leverages Plone's native security model — roles, groups, and permissions govern who can create, edit, publish, or view forms. Forms participate in Plone content workflows — publish, retract, or archive forms as part of standard editorial processes. • • • • • • Plone roles & groups Per-form permission policies Fine-grained view/edit control Standard Plone workflows Publish / retract / archive states Editorial process integration 20
21
PROCESSING Actions Actions define what happens after a submission is accepted — any combination of store, mail, mail-notification, and post can run simultaneously. store — Persist the submission mail — E-mail exported results Saves the submission to the results store (ZODB or RDBMS) with Sends export files (PDF by default) as e-mail attachments; metadata including poll_id, created, user, and answer 10 different formats available and configurable. payload. ZODB enabled by default. mail-notification — Notification e-mail post — Forward to HTTP endpoint Sends a lightweight notification e-mail with a link to the POSTs the validated payload as a webhook to a configured submission detail view — no attachments, no data. HTTP(S) endpoint. 21
22
EXPERIMENTAL AI Assistance Optional AI acceleration that keeps humans in the loop and data on-premise. All AI features are fully optional — zero AI is the default. You choose if, when, and where AI is used. Prompt → Form Document → Form Chatbot Assistant Draft complete forms from a simple text description. Convert existing documents into digital forms: upload An integrated chatbot helps users navigate Privacy Forms Studio: answers questions, guides configuration, and explains features in plain language. Describe structure, fields, and logic in plain language — AI generates the JSON schema instantly. mockups, scanned PDF forms, or plain-text specifications — AI extracts fields, types, and structure automatically. Infrastructure & Governance Local AI Support Human Control Integrates with Ollama for zero data leakage. Any local or remote AI provider supported. AI generates drafts; human editors review & publish. Full control: use no AI, a local model (Ollama), or any remote provider — configured per deployment. You decide the level of AI involvement. Most decent models work well, including lightweight flash/small models — no need for the largest or most expensive ones. 22
23
INFRASTRUCTURE Data Handling & Processing Enterprise-grade data management with flexible storage, multi-format export, and automated hand-off capabilities. Flexible Storage Multi-Format Export Automated Hand-off Store submissions in ZODB or Export response data instantly to Trigger secure webhooks, custom relational databases via SQLAlchemy, 10 different formats like PDF, Python processing pipelines, and or route directly without persistent XLSX, CSV, DOCX, HTML, Markdown, configurable multi-recipient emails. XML, and JSON formats. Support of Plone notifications/events. storage. 23
24
INFRASTRUCTURE Deployment & Storage Strategy Keep definitions in Plone. Configure submission and caching backends independently for each Plone site. ✅ Plone Core ✅ Small Deployments 🚧 High-Volume Use • Form definitions • Standalone or ZEO • RDBMS submissions • Version history • Submission data in Plone • Shared RDBMS-backed cache • Permissions & workflows • Shared SQLite cache • Avoid ZODB write contention Plone 6.2 remains the authoritative A simple setup is sufficient for low traffic Designed for busy forms, polls and multi- configuration layer. and modest form usage. node deployments. Per-site configuration: Submission and caching backends are configured independently for each Plone site. Recommendation: Use an RDBMS when traffic or concurrency grows. 24
25
Digital workflows and PDF forms 25
26
USE CASE Use Case: PDF to Web Form Transform legacy paper-based processes into modern, accessible digital workflows. Ingest Paper Forms Smart Extraction Scan legacy paper or PDF forms into the system. AI extracts form fields, titles, and section structures. Interactive Web Form Structured Data Generates accessible, multi-page SurveyJS web forms. Responses captured as clean JSON for backend processing. 26
27
EXPORTS & PDF EXPERIMENTAL Workflows with fillable PDFs 1/3 "Fillable PDF forms are a plague — limited functionality, poor UX, and still printed out anyway." Limited Functionality Poor User Experience Still Gets Printed Fillable PDFs can't branch, validate properly, or adapt to user input. Clunky, inconsistent across viewers, and not mobile-friendly. Despite being "digital", most fillable PDFs end up printed and filed anyway. Digital Twin Workflow PDF Round-trip Create Digital Twin Create Digital Twin Build an online equivalent of the PDF form using SurveyJS — same fields, same logic, better UX. Build an online equivalent of the PDF form using SurveyJS — same fields, same logic, better UX. Fill Online Fill Online Users complete the form in the browser — mobile-friendly, validated, accessible. Same digital form, same great UX. Process Digitally Export to Fillable PDF Store data online, process server-side, distribute via export, mail, or POST webhook. Transfer answers back into the original fillable PDF — pre-filled, ready for signature or archiving. Distribute Send the pre-filled PDF by mail, download, or forward to downstream systems. The best of both worlds: modern online UX with PDF compatibility for legacy workflows. 27
28
EXPORTS & PDF EXPERIMENTAL Workflows with fillable PDFs 2/3 What we extract from the PDF How the Digital Twin is built 01 Form Fields Geometry Name, type, value, and options. Position, size, and page number. Field Groups Non-field Content 02 Visual row clusters preserving layout logic. Labels, headings, and annotations with context. Map to SurveyJS Extract pypdf parses AcroForm fields, geometry, and RowGroups. Field types are mapped and names sanitized. 03 Enrich with Context Labels are linked to fields via spatial proximity. 04 Generate Online Form (LLM-supported) SurveyJS JSON schema produced with pdfFieldName for round-trip mapping. Tools: pypdf · privacyforms_pdf (AcroForm parsing, geometry, RowGroups) · pdfcpu (deterministic field extraction, reference pipeline) 28
29
EXPORTS & PDF EXPERIMENTAL Workflows with fillable PDFs 3/3 Filling a PDF with submitted form data is a two-step process: validate & extract with pypdf, then write values back with PyMuPDF. pypdf · Validate & Extract PyMuPDF · Fill & Return Upload Validation Receive Form Data Checks the PDF has AcroForm fields via get_fields(). Rejects non-form PDFs early. Submitted field values arrive from the browser (text, checkbox, combobox, listbox). Field Extraction Reads field names, types (/FT), flags (readonly/required), options (/Opt) and widget rects from / Annots. Mapping Check Each PDF field is checked against the SurveyJS form — marking which fields have a digital twin counterpart. Write to Widgets PyMuPDF sets widget.field_value per field name and calls update() for each widget type. Return Filled PDF A pre-filled <name>_filled.pdf is returned — ready for download, signature, or archiving. Field matching is by name — the SurveyJS form and the PDF must share identical field names for the fill to work correctly. 29
30
OPEN ISSUES Open Issues Which license? Experimental functionality AI Assistance Which license can this AI slop have in PDF fillable form workflows (digital twin Prompt-to-form, document-to-form and which legislation (EU, USA, world-wide)? creation, PDF fill-back via PyMuPDF) chatbot features require further and AI-related functionality are refinement before production use. experimental and subject to change. ❌ Volto support Unlikely and of little interest — Privacy Forms Studio targets Plone Classic; a Volto integration is not planned. ✅ SurveyJS Theming 🤷 collective-ai-settings SurveyJS 3 introduced a complete new Looking into new AI settings. theming approach and implementation PFS based on own privacyforms.ai is currently being adjusted module. 30
31
CONCLUSION Key Takeaways Professional & Decent Solution For building form-driven applications and services. Affordable & Open Almost free to deploy — open-source core with transparent, affordable commercial licensing for advanced features. Digital & Data Sovereignty Ensuring your complete control over your data. (optional) AI Assistance Under Your Control Leverage powerful AI tools with full oversight and management. Full Control Over Data & Processing Maintain command throughout the entire data lifecycle. 31
32
LIVE DEMO Try It Yourself Explore real forms built with Privacy Forms Studio. The demo resets every 6 hours. 7 Demo Forms 10 Languages LTR & RTL All 10 languages covered: English, Spanish, French, German, Arabic, Chinese, Japanese, Portuguese, Russian, Hindi — spanning both left-to-right and right-to-left scripts. 32
33
Questions & Discussion Thank you for your attention! privacyforms.studio hello@privacyforms.studio Product website Get in touch docs.privacyforms.studio github.com/zopyx/zopyx.surveyjs Documentation Source code 33