Data processing agreement
You are the controller of the personal data your quizzes collect. We process it only for you. Where this DPA and the Terms disagree about personal data, this DPA wins.
ANNEX IWhat is processed
- SUBJECT MATTER
- Hosting a quiz and storing the responses it collects
- DATA SUBJECTS
- Respondents to your quizzes; your own team members
- CATEGORIES
- Contact details and quiz answers — whatever fields you choose to ask for
- SPECIAL CATEGORIES
- None. Sondr must not be used to collect health, biometric, political or other art. 9 data
- DURATION
- For the term of your subscription, plus a 30-day export window
- LOCATION
- As set out in Annex III at the time of processing
1Roles and instructions
We process personal data solely on your documented instructions, which are: run the service as configured in your workspace. Your configuration — fields, retention, integrations, recipients — is the instruction. We are not responsible for whether that configuration is lawful, proportionate or accurate; that is yours as controller, together with the notice and any consent respondents need.
2Confidentiality and access
Staff access is role-based, logged, and granted only where support requires it. Sondr staff cannot sign in as one of your users, and cannot read a stored provider key. Everyone with access is under written confidentiality obligations.
ANNEX IISecurity measures
- TLS in transit; disks encrypted at rest by the infrastructure provider in Annex III.
- Provider keys sealed with AES-256-GCM before they reach the database, under a secret held in the deployment's environment — one key, not a managed KMS with per-workspace keys and automatic rotation.
- Card numbers never reach Sondr: checkout and storage happen at the payment provider.
- Sign-in is a single-use email link, so there is no password to steal, reuse or phish out of a user.
- Tenant isolation is enforced at the query layer: every read of lead data is scoped to a workspace the caller belongs to.
- Uploads are restricted to raster images and re-encoded on arrival, so an upload cannot become a script on our origin.
- Encrypted, provider-managed backups of the database.
- Production changes are reviewed before release, and administrative actions are written to an audit log.
ANNEX IIISub-processors
Each provider is named, with its purpose and location, on the sub-processors page, which is the list in force at the time you sign up. We give 30 days' notice before adding to it. You may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected service for the unused period.
| PROVIDER | PURPOSE | LOCATION | WHAT IT CAN SEE |
|---|---|---|---|
| Hosting, database and file storageProvider to be confirmed | Runs the application, the Postgres database and the images you upload | See note below | All of it — account data and lead data alike |
| Resend | Transactional email: result emails, lead alerts, invitations, account notices | United States, with EU delivery infrastructure | Recipient address and the contents of the message |
| Stripe | Subscriptions, card details and invoices | Ireland and United States | Billing contact and company details. No lead data, and no card number reaches Sondr |
| OpenAI | Drafting questions and suggesting scoring — only while AI is switched on for the workspace | United States | Only the source text and question wording a maker submits. No respondent names, emails or answers |
3Breach, assistance, audit
We notify you without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting your data, with what we know at the time. Notifying authorities and data subjects remains yours. We assist with rights requests, DPIAs and authority enquiries at cost for anything beyond routine effort. Audit is satisfied by our security documentation; on-site audits only where law requires, once a year, at your expense.
4Transfers
Where a provider in Annex III processes data outside the EEA, that transfer is covered by the European Commission's standard contractual clauses in the provider's own data processing terms, which we have entered into. Model-provider traffic leaves the EEA only while AI is switched on for your workspace, and an admin can switch it off.
5Deletion and liability
On termination we delete your data after the 30-day export window, backups included as they roll off, unless law requires retention. A claim, complaint or request from a data subject is directed to you as controller and answered by you; we owe them nothing directly. Liability under this DPA is subject to the cap in clause 9 and the claim process in clause 11 of the Terms, and each party bears its own responsibility for its own role: yours as controller, ours as processor.