Viewshed

Data Processing Agreement

Draft — not yet in force. This document is being prepared and has not been finalized. It does not currently form an agreement, and the details it refers to are incomplete.

In short: When we handle personal information on a customer's behalf, this sets out what we will and will not do with it, who else may touch it, how quickly we tell you about a breach, and what happens to it at the end. It applies automatically — there is nothing to sign.

This Data Processing Agreement (DPA) forms part of the Terms of Service between [LEGAL ENTITY NAME]and the Customer. It applies whenever we handle personal information on the Customer’s behalf and takes effect when the Customer accepts the Terms. Terms defined there have the same meaning here.

Under US state privacy laws the Customer is the business or controller and we are its service provider or processor. Clauses 1 to 10 apply to every customer. Clause 11 adds the terms required by European and UK law, and applies only where those laws reach the processing.

Where a public body or a customer’s own counsel requires a countersigned DPA, a completed security questionnaire, or the Standard Contractual Clauses executed as a separate instrument, write to [legal@example.com]. This DPA governs in the meantime.

1. What we handle, and why

Subject matterProvision of the Viewshed engagement platform
DurationFor as long as the workspace exists, plus the deletion window in clause 9
Nature and purposeHosting, storage, retrieval, organization, analysis, publication at the Customer's direction, email delivery, and — where enabled — AI-assisted conversation, extraction, translation and summarization
Types of personal informationNames, email addresses, phone numbers, affiliations, job titles, free-text notes and answers, uploaded images and documents, IP addresses and device metadata, approximate location where a question asks for it, and any other data the Customer chooses to collect
Categories of individualsThe Customer's staff and authorized users; survey respondents and members of the public; stakeholders and contacts recorded or imported by the Customer; partner organization staff
Sensitive informationNot requested by the platform. May be present if the Customer asks for it or a respondent volunteers it in free text — see clause 3

2. Our obligations as a service provider

These are the commitments US state privacy laws require a service provider to make, and we make them for every customer regardless of where it is:

  • We handle personal information only to perform the Service, on the Customer’s documented instructions — which include its use of the Service’s features and any settings it chooses.
  • We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not retain, use or disclose it for any purpose other than performing the Service, including any commercial purpose of our own, and we do not combine it with personal information we receive from anyone else.
  • We do not use personal information to train generally available AI models.
  • We will tell the Customer promptly if we determine we can no longer meet these obligations, and we will stop and remediate any unauthorized use.
  • Personnel authorized to access personal information are bound by confidentiality and access it only as needed to operate and support the Service.
  • If we receive a law-enforcement or government demand for the Customer’s data, we will redirect the requester to the Customer where possible and notify the Customer before disclosing, unless legally prohibited from doing so.
  • The Customer may take reasonable and appropriate steps to confirm we are meeting these obligations, as described in clause 8.

3. The Customer's obligations

The Customer determines the purposes and means of the processing and is responsible for the personal information it collects through the Service: for having the right to collect it, for giving individuals the notices its own law requires, for the lawfulness of its instructions, and for the additional conditions that apply where it collects sensitive information or information about children.

4. What the Service is not for

The Service is a general-purpose engagement platform and is not designed, configured or offered as a compliant system for regulated categories of data. The Customer must not submit to the Service:protected health information subject to HIPAA; cardholder data subject to PCI DSS; information subject to the Gramm-Leach-Bliley Act; student education records subject to FERPA; classified or controlled unclassified information; or Social Security numbers, driver’s license numbers, financial account numbers or biometric identifiers.

We are not a HIPAA business associate and will not sign a business associate agreement. If the Customer needs to gather any of this, it needs a different tool — and we would rather say so here than discover it in an incident.

5. Security

We implement and maintain reasonable technical and organizational security measures appropriate to the information. These currently include: encryption in transit; passwords hashed with argon2id; opaque session tokens stored only as hashes in cookies inaccessible to scripts, with revocation and session limits; tenant isolation enforced in the data layer so records cannot be read across workspaces; role-based access control; content-type verification and sanitization of uploads; a content security policy and anti-forgery protection on every request; rate limiting and abuse detection on public endpoints; and encrypted backups with tested restore.

We may update these measures as technology changes, provided the level of protection is not reduced.

6. Sub-processors

The Customer gives general authorization for us to engage the sub-processors listed on our sub-processor page and reproduced here:

Sub-processorPurposeDataLocation
Cloudflare, Inc.Application hosting (Workers), file storage (R2), database connection pooling (Hyperdrive), CDN and DDoS protectionAll customer data in transit; uploaded files at rest; request metadata including IP addressUnited States (primary). Requests are served from a global edge network; files are stored in the configured R2 region
Neon, Inc.Managed PostgreSQL databaseAll customer data at restUnited States (configured database region)
Anthropic PBCAI features: interview conversations, theme extraction, survey translation, alignment reportsSurvey definitions and the response or transcript text submitted to an AI feature. Only used when a customer enables an AI feature.United States
Resend, Inc.Transactional and outreach email deliveryRecipient name and email address, message contentUnited States
Stripe, Inc.Subscription billing and payment processingBilling contact and payment details. Card numbers are collected by Stripe directly and are never received or stored by us.United States

We impose obligations on each sub-processor no less protective than this DPA, and we remain responsible for their performance. We will give at least 30 days’ notice before adding or replacing one. The Customer may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.

7. Assisting with individual rights requests

The Service gives the Customer direct access to the data it holds, including export, correction, deletion and one-click unsubscribe, which is normally enough to answer a request without our involvement. Where it is not, we will provide reasonable assistance. If we receive a request directly from an individual about a Customer’s data, we will not respond substantively; we will forward it to the Customer promptly.

8. Breaches, assessments and verification

We will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a breach of security leading to the unauthorized acquisition, access, use or disclosure of its personal information. The notification will describe the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent that information is available, with further detail as the investigation progresses.

Notification is not an acknowledgment of fault. Notifying individuals and state authorities under breach-notification laws is the Customer’s responsibility for its own data; we will provide the information it reasonably needs to do so, and we will make our own notifications where the law requires them of us.

We will provide reasonable assistance with data protection assessments. The Customer may verify our compliance no more than once in twelve months, on at least 30 days’ written notice, during business hours, subject to confidentiality, and without access to other customers’ data or to our shared infrastructure. Where we hold a relevant third-party report or certification, providing it satisfies this obligation. The Customer bears its own costs, and ours where verification exceeds this scope. A regulator exercising statutory powers is not limited by this clause.

9. Deletion and return

On termination, the Customer may export its data through the Service for 30 days. We will then delete it within a further 90 days, except where storage is required by law and except for encrypted backups, which are deleted on their normal expiry cycle and remain protected by this DPA until then. We will confirm deletion in writing on request.

10. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service, except to the extent applicable law does not permit it — in particular, nothing here limits an individual’s statutory rights or either party’s liability directly to an individual or a regulator. Where this DPA conflicts with the Terms on the handling of personal information, this DPA prevails. This DPA is governed by the law identified in the Terms, except where clause 11 applies.

11. European and UK addendum

This clause applies only where the EU General Data Protection Regulation, the UK GDPR or the Swiss FADP applies to the processing. Where it does, the Customer is the controller and we are the processor, and the details in clause 1 serve as the record required by Article 28(3).

  • Article 28 terms. Clauses 2, 3, 5, 6, 7, 8 and 9 are the corresponding commitments on instructions, confidentiality, security, sub-processors, assistance with data subject rights, breach notification, audit and deletion. If we believe an instruction infringes data protection law, we will tell the Customer.
  • Transfers.Where processing involves transferring personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, the European Commission’s Standard Contractual Clauses (module two, controller to processor) are incorporated into this DPA by reference — completed with the details in clause 1, this DPA’s security measures as Annex II, and the sub-processor list in clause 6. For UK transfers the ICO International Data Transfer Addendum applies to those Clauses. Where a conflict arises, the Clauses prevail over this DPA.
  • Special category data. Not requested by the platform; the Customer is responsible for the Article 9 condition where it collects any.