1. Parties, scope, and incorporation
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (“Controller”) and Tomasz Gancarczyk, operating Zone of Truth (“Processor”), and applies whenever the Controller uses the service to process personal data of interview respondents or other data subjects. It implements Article 28 GDPR. In case of conflict with the Terms, this DPA prevails for data-protection matters.
2. Details of processing
- Subject matter and nature — hosting and operating AI-moderated research interviews: collecting respondent profiles and answers, recording and transcribing optional voice input, generating structured interview summaries, and delivering results to the Controller (in-app, API/CLI, webhooks).
- Purpose— the Controller’s product, market, and customer-discovery research, as restricted by the Terms and Acceptable Use Policy (no decisions with legal or similarly significant effects, no recruitment or employment screening, no interviews with minors).
- Duration— the life of the Controller’s account, plus the deletion window in Section 8.
- Categories of data subjects— the Controller’s interview respondents (customers, prospects, research participants), all adults.
- Categories of personal data — name, work email, role, organization; interview answers (free text); optional voice recordings and their transcripts; AI-generated summaries and research-fit assessments. The service is not intended for special-category data; the Controller must not direct interviews at collecting it.
3. Controller instructions
The Processor processes respondent data only on the Controller’s documented instructions — given through the service’s configuration surfaces (study briefs, invites, webhooks, API calls, deletion controls) and this DPA — unless processing is required by EU or member-state law, in which case the Processor informs the Controller before processing (unless the law prohibits it). The Processor will inform the Controller if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality and security
Persons authorized to process respondent data are bound by confidentiality. Taking into account the state of the art and the risks, the Processor implements appropriate technical and organizational measures (Article 32 GDPR), including: encryption in transit; hashed authentication, API, and session tokens; tenant isolation enforced at the query layer; role-based access; private audio storage; signed webhooks with SSRF protections; audit logging; and rate-limiting with hashed identifiers.
5. Sub-processors
The Controller grants general written authorization for the sub-processors listed on the Sub-processors page. The Processor imposes data-protection obligations on each sub-processor equivalent to this DPA and remains fully liable for their performance. The Processor gives at least 30 days’ notice of intended additions or replacements (via the Sub-processors page and email to organization owners); the Controller may object on reasonable data-protection grounds, and if no resolution is found may terminate the affected service and export its data.
6. Assistance
Taking into account the nature of the processing, the Processor assists the Controller with data subject requests (access, rectification, erasure, portability, objection) — including per-interview data export and deletion controls built into the service — and, considering the information available to it, with the Controller’s security, breach-notification, DPIA, and prior-consultation obligations (Articles 32–36 GDPR). The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting respondent data.
7. International transfers
Transfers outside the EEA occur only to sub-processors listed on the Sub-processors page, under adequacy decisions (including the EU-US Data Privacy Framework where the sub-processor is certified) or the European Commission’s Standard Contractual Clauses, supplemented where appropriate. The Processor keeps transfer mechanisms under review, including maintaining SCCs as a fallback where an adequacy decision is invalidated.
8. Deletion and return
The Controller can delete individual interviews, studies, or its entire organization in-app at any time; deletion cascades to transcripts, reports, and audio recordings, and an interview.deleted webhook event is available so the Controller can propagate erasure to systems it connected. On termination or account closure, the Processor deletes remaining respondent data within 30 days, unless EU or member-state law requires storage. Data can be exported before deletion via the in-app export, API, and CLI.
9. Audits
The Processor makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR — documentation, security summaries, and sub-processor terms — and allows for and contributes to audits, including inspections, conducted by the Controller or its mandated auditor, on reasonable notice, at the Controller’s cost, no more than once per year absent a supervisory-authority requirement or a personal data breach.
10. No AI training; AI transparency
The Processor does not use respondent data to train or fine-tune AI models, and contracts its AI sub-processors on terms that exclude training on the Controller’s data. AI involvement in interviews is disclosed to respondents by the service itself (see the AI Transparency page); the Controller must not disable, obscure, or misrepresent that disclosure.
11. Contact
Data-protection questions and breach reports: contact@zoneoftruth.com. This DPA is versioned with the Terms (current version on the Terms page) and updated the same way.
