Effective 19 August 20263 min readGDPR art. 28

Data processing agreement

You are the controller of the personal data your quizzes collect. We process it only for you. Where this DPA and the Terms disagree about personal data, this DPA wins.

No signature needed. This DPA applies from the day you sign up — there is nothing to countersign and nothing to request.

ANNEX IWhat is processed

SUBJECT MATTER
Hosting a quiz and storing the responses it collects
DATA SUBJECTS
Respondents to your quizzes; your own team members
CATEGORIES
Contact details and quiz answers — whatever fields you choose to ask for
SPECIAL CATEGORIES
None. Sondr must not be used to collect health, biometric, political or other art. 9 data
DURATION
For the term of your subscription, plus a 30-day export window
LOCATION
As set out in Annex III at the time of processing

1Roles and instructions

We process personal data solely on your documented instructions, which are: run the service as configured in your workspace. Your configuration — fields, retention, integrations, recipients — is the instruction. We are not responsible for whether that configuration is lawful, proportionate or accurate; that is yours as controller, together with the notice and any consent respondents need.

2Confidentiality and access

Staff access is role-based, logged, and granted only where support requires it. Sondr staff cannot sign in as one of your users, and cannot read a stored provider key. Everyone with access is under written confidentiality obligations.

ANNEX IISecurity measures

  • TLS in transit; disks encrypted at rest by the infrastructure provider in Annex III.
  • Provider keys sealed with AES-256-GCM before they reach the database, under a secret held in the deployment's environment — one key, not a managed KMS with per-workspace keys and automatic rotation.
  • Card numbers never reach Sondr: checkout and storage happen at the payment provider.
  • Sign-in is a single-use email link, so there is no password to steal, reuse or phish out of a user.
  • Tenant isolation is enforced at the query layer: every read of lead data is scoped to a workspace the caller belongs to.
  • Uploads are restricted to raster images and re-encoded on arrival, so an upload cannot become a script on our origin.
  • Encrypted, provider-managed backups of the database.
  • Production changes are reviewed before release, and administrative actions are written to an audit log.
We do not hold an ISO 27001 or SOC 2 certification, and we do not claim one. Annex II is the honest list of what is in place.

ANNEX IIISub-processors

Each provider is named, with its purpose and location, on the sub-processors page, which is the list in force at the time you sign up. We give 30 days' notice before adding to it. You may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected service for the unused period.

PROVIDERPURPOSELOCATIONWHAT IT CAN SEE
Hosting, database and file storageProvider to be confirmedRuns the application, the Postgres database and the images you uploadSee note belowAll of it — account data and lead data alike
ResendTransactional email: result emails, lead alerts, invitations, account noticesUnited States, with EU delivery infrastructureRecipient address and the contents of the message
StripeSubscriptions, card details and invoicesIreland and United StatesBilling contact and company details. No lead data, and no card number reaches Sondr
OpenAIDrafting questions and suggesting scoring — only while AI is switched on for the workspaceUnited StatesOnly the source text and question wording a maker submits. No respondent names, emails or answers
One entry is not yet filled in. Sondr is deployed by its operator, and the hosting, database and file storage provider is named here once that deployment is fixed. Ask through the help panel if you need it before then.

3Breach, assistance, audit

We notify you without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting your data, with what we know at the time. Notifying authorities and data subjects remains yours. We assist with rights requests, DPIAs and authority enquiries at cost for anything beyond routine effort. Audit is satisfied by our security documentation; on-site audits only where law requires, once a year, at your expense.

4Transfers

Where a provider in Annex III processes data outside the EEA, that transfer is covered by the European Commission's standard contractual clauses in the provider's own data processing terms, which we have entered into. Model-provider traffic leaves the EEA only while AI is switched on for your workspace, and an admin can switch it off.

5Deletion and liability

On termination we delete your data after the 30-day export window, backups included as they roll off, unless law requires retention. A claim, complaint or request from a data subject is directed to you as controller and answered by you; we owe them nothing directly. Liability under this DPA is subject to the cap in clause 9 and the claim process in clause 11 of the Terms, and each party bears its own responsibility for its own role: yours as controller, ours as processor.

Version 1.0, effective 19 August 2026. Material changes are emailed to workspace owners 30 days before they take effect.Questions about this document reach us through the help panel in your workspace. Nothing on this page is legal advice to you.