Trust, subprocessors, and data protection

ResponseDock uses service providers to operate the platform. The exact production account, processing region, and transfer mechanism are reviewed before customer data is enabled in a region.

ProviderPurposeData
Fly.ioApplication hosting and network deliveryRequests, application data in transit, operational logs
MongoDB AtlasProduction databaseAccounts, workspaces, surveys, responses, configuration
StripeCheckout, subscriptions, invoices, customer portalBilling contact and subscription metadata
GoogleOptional OAuth and customer-configured Sheets integrationOAuth profile or exported survey data, as configured
OpenAIOptional AI survey generation, improvement, and translationPrompts and survey content submitted to AI features
Transactional email providerPassword reset, invitations, deletion, and billing noticesRecipient address and message content

Data Processing Addendum

The ResponseDock Data Processing Addendum (DPA) governs how we process personal data on behalf of workspace customers. Business and Enterprise customers may also request a countersigned copy or supplementary transfer documentation from privacy@responsedock.com. A signed order form controls where it differs from the published DPA.

Security and privacy requests

Security reports: security@responsedock.com
Privacy requests: privacy@responsedock.com
Support: support@responsedock.com