Draft — not yet in force. This document is being prepared and has not been finalized. It does not currently form an agreement, and the details it refers to are incomplete.
In short: When we handle personal information on a customer's behalf, this sets out what we will and will not do with it, who else may touch it, how quickly we tell you about a breach, and what happens to it at the end. It applies automatically — there is nothing to sign.
This Data Processing Agreement (DPA) forms part of the Terms of Service between [LEGAL ENTITY NAME]and the Customer. It applies whenever we handle personal information on the Customer’s behalf and takes effect when the Customer accepts the Terms. Terms defined there have the same meaning here.
Under US state privacy laws the Customer is the business or controller and we are its service provider or processor. Clauses 1 to 10 apply to every customer. Clause 11 adds the terms required by European and UK law, and applies only where those laws reach the processing.
| Subject matter | Provision of the Viewshed engagement platform |
| Duration | For as long as the workspace exists, plus the deletion window in clause 9 |
| Nature and purpose | Hosting, storage, retrieval, organization, analysis, publication at the Customer's direction, email delivery, and — where enabled — AI-assisted conversation, extraction, translation and summarization |
| Types of personal information | Names, email addresses, phone numbers, affiliations, job titles, free-text notes and answers, uploaded images and documents, IP addresses and device metadata, approximate location where a question asks for it, and any other data the Customer chooses to collect |
| Categories of individuals | The Customer's staff and authorized users; survey respondents and members of the public; stakeholders and contacts recorded or imported by the Customer; partner organization staff |
| Sensitive information | Not requested by the platform. May be present if the Customer asks for it or a respondent volunteers it in free text — see clause 3 |
These are the commitments US state privacy laws require a service provider to make, and we make them for every customer regardless of where it is:
The Customer determines the purposes and means of the processing and is responsible for the personal information it collects through the Service: for having the right to collect it, for giving individuals the notices its own law requires, for the lawfulness of its instructions, and for the additional conditions that apply where it collects sensitive information or information about children.
The Service is a general-purpose engagement platform and is not designed, configured or offered as a compliant system for regulated categories of data. The Customer must not submit to the Service:protected health information subject to HIPAA; cardholder data subject to PCI DSS; information subject to the Gramm-Leach-Bliley Act; student education records subject to FERPA; classified or controlled unclassified information; or Social Security numbers, driver’s license numbers, financial account numbers or biometric identifiers.
We are not a HIPAA business associate and will not sign a business associate agreement. If the Customer needs to gather any of this, it needs a different tool — and we would rather say so here than discover it in an incident.
We implement and maintain reasonable technical and organizational security measures appropriate to the information. These currently include: encryption in transit; passwords hashed with argon2id; opaque session tokens stored only as hashes in cookies inaccessible to scripts, with revocation and session limits; tenant isolation enforced in the data layer so records cannot be read across workspaces; role-based access control; content-type verification and sanitization of uploads; a content security policy and anti-forgery protection on every request; rate limiting and abuse detection on public endpoints; and encrypted backups with tested restore.
We may update these measures as technology changes, provided the level of protection is not reduced.
The Customer gives general authorization for us to engage the sub-processors listed on our sub-processor page and reproduced here:
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Cloudflare, Inc. | Application hosting (Workers), file storage (R2), database connection pooling (Hyperdrive), CDN and DDoS protection | All customer data in transit; uploaded files at rest; request metadata including IP address | United States (primary). Requests are served from a global edge network; files are stored in the configured R2 region |
| Neon, Inc. | Managed PostgreSQL database | All customer data at rest | United States (configured database region) |
| Anthropic PBC | AI features: interview conversations, theme extraction, survey translation, alignment reports | Survey definitions and the response or transcript text submitted to an AI feature. Only used when a customer enables an AI feature. | United States |
| Resend, Inc. | Transactional and outreach email delivery | Recipient name and email address, message content | United States |
| Stripe, Inc. | Subscription billing and payment processing | Billing contact and payment details. Card numbers are collected by Stripe directly and are never received or stored by us. | United States |
We impose obligations on each sub-processor no less protective than this DPA, and we remain responsible for their performance. We will give at least 30 days’ notice before adding or replacing one. The Customer may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.
The Service gives the Customer direct access to the data it holds, including export, correction, deletion and one-click unsubscribe, which is normally enough to answer a request without our involvement. Where it is not, we will provide reasonable assistance. If we receive a request directly from an individual about a Customer’s data, we will not respond substantively; we will forward it to the Customer promptly.
We will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a breach of security leading to the unauthorized acquisition, access, use or disclosure of its personal information. The notification will describe the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent that information is available, with further detail as the investigation progresses.
Notification is not an acknowledgment of fault. Notifying individuals and state authorities under breach-notification laws is the Customer’s responsibility for its own data; we will provide the information it reasonably needs to do so, and we will make our own notifications where the law requires them of us.
We will provide reasonable assistance with data protection assessments. The Customer may verify our compliance no more than once in twelve months, on at least 30 days’ written notice, during business hours, subject to confidentiality, and without access to other customers’ data or to our shared infrastructure. Where we hold a relevant third-party report or certification, providing it satisfies this obligation. The Customer bears its own costs, and ours where verification exceeds this scope. A regulator exercising statutory powers is not limited by this clause.
On termination, the Customer may export its data through the Service for 30 days. We will then delete it within a further 90 days, except where storage is required by law and except for encrypted backups, which are deleted on their normal expiry cycle and remain protected by this DPA until then. We will confirm deletion in writing on request.
Liability under this DPA is subject to the limitations in the Terms of Service, except to the extent applicable law does not permit it — in particular, nothing here limits an individual’s statutory rights or either party’s liability directly to an individual or a regulator. Where this DPA conflicts with the Terms on the handling of personal information, this DPA prevails. This DPA is governed by the law identified in the Terms, except where clause 11 applies.
This clause applies only where the EU General Data Protection Regulation, the UK GDPR or the Swiss FADP applies to the processing. Where it does, the Customer is the controller and we are the processor, and the details in clause 1 serve as the record required by Article 28(3).