Data Processing Addendum

Last updated: August 2, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between the Customer and ResponseDock (operated by Ondrej Strnad, "ResponseDock", "we", or "us") for the use of the ResponseDock platform and services (the "Agreement"). Where the Customer processes personal data using ResponseDock on behalf of its own end users or data subjects, this DPA applies.

Where there is any conflict between this DPA and the Agreement or other incorporated terms, this DPA takes precedence with respect to data protection obligations.

1. Definitions

Controller means the entity that determines the purposes and means of processing personal data. In most cases this is the Customer.

Processor means the entity that processes personal data on behalf of the Controller. For the purposes of this DPA, ResponseDock acts as Processor for personal data submitted through workspace surveys, responses, and related features.

Personal Data, Processing, Data Subject, Supervisory Authority, and Sub-processor have the meanings given in applicable data protection law, including the EU General Data Protection Regulation (2016/679) ("GDPR") and equivalent national or regional legislation.

Customer Data means all personal data submitted to or collected through the ResponseDock service by or on behalf of the Customer, including survey responses, follow-up contacts, workspace member information, and SDK event context.

2. Roles and Scope

The Customer is the Controller of Customer Data. ResponseDock processes Customer Data solely as a Processor, acting only on documented instructions from the Customer as set out in the Agreement and this DPA.

This DPA applies to processing of Customer Data as part of the ResponseDock survey platform, including survey creation, response collection, analytics, exports, webhooks, integrations, and AI-assisted features, as configured and used by the Customer.

ResponseDock is an independent Controller for its own operational data (account registration, billing, support communications, and platform analytics), which is governed by the ResponseDock Privacy Policy.

3. Processing Instructions

ResponseDock will process Customer Data only on the documented instructions of the Customer as set out in this DPA and the Agreement. If applicable law requires ResponseDock to process Customer Data beyond those instructions, ResponseDock will inform the Customer before processing unless prohibited by law.

The Customer instructs ResponseDock to process Customer Data for the following purposes:

  • Providing, operating, securing, and improving the ResponseDock platform and features selected by the Customer
  • Storing, transmitting, and displaying Customer Data within the workspace as directed by Customer configuration
  • Exporting Customer Data in formats requested by authorized workspace users
  • Delivering Customer Data to Customer-configured webhooks and integrations
  • Processing Customer Data through AI features when explicitly invoked by authorized users
  • Maintaining audit logs, usage counters, and operational records required for service delivery and security

4. Data Categories and Subjects

The categories of personal data and categories of data subjects processed under this DPA depend on how the Customer configures and uses the service. Typical examples include:

  • Workspace members: name, email address, authentication method, role, and activity timestamps
  • Survey respondents: responses, timestamps, optional follow-up email, device metadata, source context, and — where the Customer enables identified mode — external user IDs or respondent tokens
  • SDK-identified users: external user IDs, allowed event properties, and allowed context keys as configured per workspace

The Customer must not submit special category data (health, biometric, political, religious, racial, or sexual orientation data) or data relating to children under 16 without a documented lawful basis and appropriate safeguards, and must inform ResponseDock if such data is submitted.

5. Confidentiality

ResponseDock will ensure that personnel authorized to process Customer Data are subject to appropriate confidentiality obligations. Access to Customer Data is limited to personnel who require it to perform the services.

6. Security

ResponseDock implements technical and organizational measures designed to protect Customer Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:

  • Encrypted data transmission (TLS) between clients and the API
  • Password hashing (bcrypt) and secure token storage
  • Tenant isolation enforced at the API layer with workspace-scoped authorization
  • API authentication via JWT and short-lived embed tokens
  • Webhook signature verification to prevent payload spoofing
  • Rate limiting on authentication and public submission endpoints
  • Dependency and container vulnerability scanning on production releases
  • Secrets never committed to source control; rotation procedures documented internally

The Customer is responsible for the security of its own systems, API key storage, webhook endpoint security, and the content of surveys it creates.

7. Sub-processors

ResponseDock uses the following sub-processors to deliver the service. The Customer provides general authorization for ResponseDock to engage sub-processors subject to this clause.

Sub-processorPurposeLocation
Fly.ioApplication hosting and network deliveryUSA / EU regions
MongoDB Atlas (MongoDB, Inc.)Production databaseUSA / EU regions
Stripe, Inc.Payment processing and billingUSA
Google LLCOAuth authentication; optional Sheets integration (where configured)USA
OpenAI, LLCAI survey generation and translation (only when feature is invoked)USA
Transactional email providerDelivery of password reset, invitation, and billing emailsEU

ResponseDock will give the Customer at least 30 days' notice before adding a new sub-processor that processes Customer Data, by updating this page and notifying the Customer at the email address associated with the workspace owner account. The Customer may object to a new sub-processor by notifying ResponseDock at privacy@responsedock.com within 14 days.

8. Data Subject Rights

ResponseDock will, to the extent possible and taking into account the nature of the processing, provide reasonable assistance to the Customer to fulfil its obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, and objection).

The Customer is responsible for receiving and triaging data subject requests relating to Customer Data and for determining the appropriate response. ResponseDock provides export and deletion tools accessible to authorized workspace owners. For assistance with data subject requests, contact privacy@responsedock.com.

9. Personal Data Breaches

ResponseDock will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, to the extent required by applicable law. The notification will describe the nature of the breach, the categories and approximate volume of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach.

The Customer is responsible for notifying the relevant supervisory authority and affected data subjects within any applicable deadlines, using the information provided by ResponseDock.

10. International Transfers

Customer Data may be processed and stored in countries outside the European Economic Area. Where such transfers occur, ResponseDock relies on one or more of the following mechanisms:

  • European Commission adequacy decisions
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Sub-processor contractual commitments that provide equivalent protections

Customers in the EEA or UK may request a copy of the applicable transfer documentation by contacting privacy@responsedock.com.

11. Audits and Compliance Assistance

ResponseDock will provide the Customer with information reasonably necessary to demonstrate compliance with the obligations set out in this DPA. The Customer may request an audit no more than once per year and with at least 30 days' written notice, at the Customer's expense, subject to reasonable confidentiality protections. ResponseDock may satisfy audit requests through third-party certifications or reports where available.

12. Retention and Deletion

Customer Data is retained for as long as the Customer's workspace is active. On termination of the Agreement or a verified workspace closure request, ResponseDock will delete or de-identify Customer Data within a commercially reasonable time, except where retention is required by applicable law or immutable backup infrastructure.

Workspace owners can export Customer Data at any time through the ResponseDock dashboard (CSV, XLSX, or PDF) before requesting deletion. To initiate workspace closure and data deletion, contact support@responsedock.com.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Agreement. Nothing in this DPA limits a party's liability for its own fraudulent misrepresentation, gross negligence, or wilful misconduct.

14. Governing Law and Amendments

This DPA is governed by the same law as the Agreement. ResponseDock may update this DPA to reflect changes in applicable law, regulatory guidance, or sub-processor arrangements. Material changes will be communicated to workspace owners by email with at least 30 days' notice. Continued use of the service after the effective date of an update constitutes acceptance of the updated DPA.

For questions about this DPA, contact privacy@responsedock.com.