Data processing addendum
This addendum applies where an asker (the "Controller") uses Heardback, operated by Heardback (company in formation) (the "Processor"), to collect answers from respondents. It forms part of the terms of service and is drafted to satisfy GDPR Article 28, the UK GDPR, the CCPA/CPRA service-provider requirements, and the DPDP Act's data-processor provisions.
1. Roles and scope
The Controller determines the purposes and means of the survey. The Processor processes respondent answers, contact details left for receipts, and related metadata only to provide the service. The Processor acts as an independent controller for the consent record, reveal cards, referral links and aggregate statistics described in the privacy notice.
2. Instructions
The Processor processes personal data only on the Controller's documented instructions, which are: publishing the survey, collecting and storing answers, generating reveal cards and aggregate statistics, sending receipts and cold-start cards, interpreting free-text replies with AI assistance, and producing exports and syntheses. The Processor will tell the Controller if an instruction appears to infringe the law.
3. Confidentiality
Persons authorised to process the data are bound by confidentiality obligations and access production only through named, logged accounts.
4. Security
The Processor applies the measures in the security overview: encryption in transit and at rest, hashing and encryption of contact details, least-privilege access, backups, and logging. Measures may be updated but not weakened.
5. Sub-processors
The Controller gives general authorisation for the sub-processors listed. The Processor will give 30 days' notice of additions by updating that page and emailing account holders; the Controller may object on reasonable grounds and, if unresolved, end the affected survey.
6. Data subject requests
Respondents can download and delete their own data through the service without involving the Controller. The Processor will forward any other request received directly to the Controller within five business days and assist as reasonably needed.
7. Assistance
The Processor assists the Controller with security, breach notification, data protection impact assessments and consultations with authorities, taking into account the nature of processing and the information available.
8. Breach notification
The Processor notifies the Controller without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting the Controller's data, with the information needed for the Controller's own notifications.
9. Deletion and return
At the end of the service, or on request, the Processor deletes or returns the Controller's data and deletes existing copies within 30 days, except where the law requires retention. Aggregate, non-identifying statistics may be kept.
10. Audits
The Processor makes available the information necessary to demonstrate compliance and allows audits by the Controller or an auditor mandated by it, at most once a year on 30 days' notice, subject to confidentiality and reasonable cost sharing, unless a supervisory authority requires otherwise.
11. International transfers
Where personal data is transferred outside the EU, UK or India, the parties rely on the EU Standard Contractual Clauses (Module 2, controller to processor), the UK International Data Transfer Addendum, and the applicable DPDP transfer conditions, which are incorporated by reference.
12. CCPA/CPRA service-provider terms
The Processor will not sell or share personal information, will not retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes above, will not combine it with personal information from other sources except as permitted, and will notify the Controller if it can no longer meet its obligations.
Change log
- 1.0: first public draft.