Last updated: August 2, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the Customer and ResponseDock (operated by Ondrej Strnad, "ResponseDock", "we", or "us") for the use of the ResponseDock platform and services (the "Agreement"). Where the Customer processes personal data using ResponseDock on behalf of its own end users or data subjects, this DPA applies.
Where there is any conflict between this DPA and the Agreement or other incorporated terms, this DPA takes precedence with respect to data protection obligations.
Controller means the entity that determines the purposes and means of processing personal data. In most cases this is the Customer.
Processor means the entity that processes personal data on behalf of the Controller. For the purposes of this DPA, ResponseDock acts as Processor for personal data submitted through workspace surveys, responses, and related features.
Personal Data, Processing, Data Subject, Supervisory Authority, and Sub-processor have the meanings given in applicable data protection law, including the EU General Data Protection Regulation (2016/679) ("GDPR") and equivalent national or regional legislation.
Customer Data means all personal data submitted to or collected through the ResponseDock service by or on behalf of the Customer, including survey responses, follow-up contacts, workspace member information, and SDK event context.
The Customer is the Controller of Customer Data. ResponseDock processes Customer Data solely as a Processor, acting only on documented instructions from the Customer as set out in the Agreement and this DPA.
This DPA applies to processing of Customer Data as part of the ResponseDock survey platform, including survey creation, response collection, analytics, exports, webhooks, integrations, and AI-assisted features, as configured and used by the Customer.
ResponseDock is an independent Controller for its own operational data (account registration, billing, support communications, and platform analytics), which is governed by the ResponseDock Privacy Policy.
ResponseDock will process Customer Data only on the documented instructions of the Customer as set out in this DPA and the Agreement. If applicable law requires ResponseDock to process Customer Data beyond those instructions, ResponseDock will inform the Customer before processing unless prohibited by law.
The Customer instructs ResponseDock to process Customer Data for the following purposes:
The categories of personal data and categories of data subjects processed under this DPA depend on how the Customer configures and uses the service. Typical examples include:
The Customer must not submit special category data (health, biometric, political, religious, racial, or sexual orientation data) or data relating to children under 16 without a documented lawful basis and appropriate safeguards, and must inform ResponseDock if such data is submitted.
ResponseDock will ensure that personnel authorized to process Customer Data are subject to appropriate confidentiality obligations. Access to Customer Data is limited to personnel who require it to perform the services.
ResponseDock implements technical and organizational measures designed to protect Customer Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:
The Customer is responsible for the security of its own systems, API key storage, webhook endpoint security, and the content of surveys it creates.
ResponseDock uses the following sub-processors to deliver the service. The Customer provides general authorization for ResponseDock to engage sub-processors subject to this clause.
| Sub-processor | Purpose | Location |
|---|---|---|
| Fly.io | Application hosting and network delivery | USA / EU regions |
| MongoDB Atlas (MongoDB, Inc.) | Production database | USA / EU regions |
| Stripe, Inc. | Payment processing and billing | USA |
| Google LLC | OAuth authentication; optional Sheets integration (where configured) | USA |
| OpenAI, LLC | AI survey generation and translation (only when feature is invoked) | USA |
| Transactional email provider | Delivery of password reset, invitation, and billing emails | EU |
ResponseDock will give the Customer at least 30 days' notice before adding a new sub-processor that processes Customer Data, by updating this page and notifying the Customer at the email address associated with the workspace owner account. The Customer may object to a new sub-processor by notifying ResponseDock at privacy@responsedock.com within 14 days.
ResponseDock will, to the extent possible and taking into account the nature of the processing, provide reasonable assistance to the Customer to fulfil its obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, and objection).
The Customer is responsible for receiving and triaging data subject requests relating to Customer Data and for determining the appropriate response. ResponseDock provides export and deletion tools accessible to authorized workspace owners. For assistance with data subject requests, contact privacy@responsedock.com.
ResponseDock will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, to the extent required by applicable law. The notification will describe the nature of the breach, the categories and approximate volume of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach.
The Customer is responsible for notifying the relevant supervisory authority and affected data subjects within any applicable deadlines, using the information provided by ResponseDock.
Customer Data may be processed and stored in countries outside the European Economic Area. Where such transfers occur, ResponseDock relies on one or more of the following mechanisms:
Customers in the EEA or UK may request a copy of the applicable transfer documentation by contacting privacy@responsedock.com.
ResponseDock will provide the Customer with information reasonably necessary to demonstrate compliance with the obligations set out in this DPA. The Customer may request an audit no more than once per year and with at least 30 days' written notice, at the Customer's expense, subject to reasonable confidentiality protections. ResponseDock may satisfy audit requests through third-party certifications or reports where available.
Customer Data is retained for as long as the Customer's workspace is active. On termination of the Agreement or a verified workspace closure request, ResponseDock will delete or de-identify Customer Data within a commercially reasonable time, except where retention is required by applicable law or immutable backup infrastructure.
Workspace owners can export Customer Data at any time through the ResponseDock dashboard (CSV, XLSX, or PDF) before requesting deletion. To initiate workspace closure and data deletion, contact support@responsedock.com.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Agreement. Nothing in this DPA limits a party's liability for its own fraudulent misrepresentation, gross negligence, or wilful misconduct.
This DPA is governed by the same law as the Agreement. ResponseDock may update this DPA to reflect changes in applicable law, regulatory guidance, or sub-processor arrangements. Material changes will be communicated to workspace owners by email with at least 30 days' notice. Continued use of the service after the effective date of an update constitutes acceptance of the updated DPA.
For questions about this DPA, contact privacy@responsedock.com.