ResponseDock uses service providers to operate the platform. The exact production account, processing region, and transfer mechanism are reviewed before customer data is enabled in a region.
| Provider | Purpose | Data |
|---|---|---|
| Fly.io | Application hosting and network delivery | Requests, application data in transit, operational logs |
| MongoDB Atlas | Production database | Accounts, workspaces, surveys, responses, configuration |
| Stripe | Checkout, subscriptions, invoices, customer portal | Billing contact and subscription metadata |
| Optional OAuth and customer-configured Sheets integration | OAuth profile or exported survey data, as configured | |
| OpenAI | Optional AI survey generation, improvement, and translation | Prompts and survey content submitted to AI features |
| Transactional email provider | Password reset, invitations, deletion, and billing notices | Recipient address and message content |
The ResponseDock Data Processing Addendum (DPA) governs how we process personal data on behalf of workspace customers. Business and Enterprise customers may also request a countersigned copy or supplementary transfer documentation from privacy@responsedock.com. A signed order form controls where it differs from the published DPA.
Security reports: security@responsedock.com
Privacy requests: privacy@responsedock.com
Support: support@responsedock.com