Workframe

Data Processing Agreement

Last updated 24 August 2026 · Back to workframeapp.com

Draft — not yet in force. The values highlighted like this are unresolved and must be filled in, and the whole set needs a lawyer's review, before these pages are linked from the product or relied on by an ethics committee. Until then this page describes intended practice, not a binding commitment.

This agreement governs our processing of participant data that you collect using Workframe. It supplements the Terms of Service and takes effect when you publish a study. Where the two conflict on data protection, this document wins.

Many institutions require a signed DPA on their own template, and their template usually prevails. Write to privacy@workframeapp.com and we will work through yours.

1. Roles

You (the researcher, or the institution you act for) are the controller of participant data collected through your studies. We are the processor. We are the controller of your own account data, which this agreement does not cover — see the Privacy Notice.

2. Subject matter and details of processing

Subject matterHosting and delivery of scenario-based studies, and collection and storage of the resulting participant data
DurationUntil you delete the study or your account, or this agreement ends
Nature and purposeStorage, structuring and retrieval, so you can run a study and export its data. No other purpose.
Categories of data subjectParticipants you recruit into your studies
Categories of personal dataResponses; event sequences and timings; condition and assignment; the identifiers your survey or recruitment tool passes in (for example a Qualtrics response ID or Prolific PID); a derived one-way participant key; a hashed session token; a hash of the requesting network address for rate limiting
Special-category dataNot requested by Workframe. It may reach us if your own study questions elicit it, in which case you are responsible for the lawful basis and any required impact assessment.

3. Our obligations

We will:

4. Your obligations

You are responsible for:

5. Subprocessors

You authorise the subprocessors listed on the Subprocessors page. We will give you [notice period] notice before adding or replacing one; if you reasonably object on data protection grounds, and we cannot offer an alternative, you may terminate and export your data. Each subprocessor is bound by terms no less protective than these, and we remain liable for their performance.

6. Security measures

7. Transfers, retention and deletion

Data may be processed outside the UK/EEA by the providers on the Subprocessors page, relying on the Standard Contractual Clauses and, where relevant, the UK Addendum.

We apply no retention period of our own: participant data stays until you delete the study or the account. Deleting a study removes its sessions, events, participant records and published versions outright, and removes media that nothing else references. Deleting your account does the same across every study and additionally erases the sign-in identity held by our authentication provider. Live data is gone immediately; provider backups roll off within [window].

8. Audit

On reasonable written notice, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will answer a reasonable security questionnaire and provide the compliance documentation we hold, including our providers' certifications. On-site audit is available where a supervisory authority requires it.

9. Liability and governing law

Liability under this agreement is subject to the limits in the Terms of Service. This agreement is governed by [governing law].