Data Processing Agreement
Draft — not yet in force. The values highlighted like this are unresolved and must be filled in, and the whole set needs a lawyer's review, before these pages are linked from the product or relied on by an ethics committee. Until then this page describes intended practice, not a binding commitment.
This agreement governs our processing of participant data that you collect using Workframe. It supplements the Terms of Service and takes effect when you publish a study. Where the two conflict on data protection, this document wins.
Many institutions require a signed DPA on their own template, and their template usually prevails. Write to privacy@workframeapp.com and we will work through yours.
1. Roles
You (the researcher, or the institution you act for) are the controller of participant data collected through your studies. We are the processor. We are the controller of your own account data, which this agreement does not cover — see the Privacy Notice.
2. Subject matter and details of processing
| Subject matter | Hosting and delivery of scenario-based studies, and collection and storage of the resulting participant data |
|---|---|
| Duration | Until you delete the study or your account, or this agreement ends |
| Nature and purpose | Storage, structuring and retrieval, so you can run a study and export its data. No other purpose. |
| Categories of data subject | Participants you recruit into your studies |
| Categories of personal data | Responses; event sequences and timings; condition and assignment; the identifiers your survey or recruitment tool passes in (for example a Qualtrics response ID or Prolific PID); a derived one-way participant key; a hashed session token; a hash of the requesting network address for rate limiting |
| Special-category data | Not requested by Workframe. It may reach us if your own study questions elicit it, in which case you are responsible for the lawful basis and any required impact assessment. |
3. Our obligations
We will:
- Process participant data only on your documented instructions, of which your configuration and use of the product forms part, and never for our own purposes. If we believe an instruction breaks data protection law, we will tell you rather than carry it out.
- Keep it confidential, and ensure anyone with access is bound to confidentiality.
- Apply appropriate technical and organisational measures — see clause 6.
- Help you respond to data subject requests, and pass on any request that reaches us directly.
- Help you with impact assessments and with consultations with a supervisory authority, to the extent the information sits with us.
- Notify you without undue delay, and in any event within [48 or 72] hours, on becoming aware of a personal data breach affecting your data, with enough detail for you to meet your own notification duties.
- Delete or return the data on termination, as set out in clause 7.
- Make available the information needed to demonstrate compliance, and submit to audit as described in clause 8.
4. Your obligations
You are responsible for:
- Having a lawful basis for collecting participant data, and for giving participants the information the law requires — Workframe does not present a privacy notice or consent form to participants on your behalf.
- Any ethics or IRB approval your work needs.
- What your study asks, and what identifiers you pass in. In particular: the identifier fields store whatever string you send, verbatim, and it appears in your export. Passing in a direct identifier such as a name or email address is a choice with consequences that are yours.
- Handling exported data once it leaves Workframe.
5. Subprocessors
You authorise the subprocessors listed on the Subprocessors page. We will give you [notice period] notice before adding or replacing one; if you reasonably object on data protection grounds, and we cannot offer an alternative, you may terminate and export your data. Each subprocessor is bound by terms no less protective than these, and we remain liable for their performance.
6. Security measures
- Access to a study and its results is limited to the owning account, verified server-side on every authoring request.
- Session tokens are stored only as hashes; the raw token is never persisted.
- Data is encrypted in transit, and at rest by our infrastructure provider.
- Administrative access is limited to a named allow-list, held in configuration rather than as a database flag that could be granted from within the product.
- The participant surface loads no third-party code, which removes an entire class of supply-chain exposure from the surface where participants are.
- [Add: backup and restore testing, secret rotation cadence, onboarding and offboarding procedure, and penetration testing, once each is established — an unverifiable security commitment is worse than an omitted one.]
7. Transfers, retention and deletion
Data may be processed outside the UK/EEA by the providers on the Subprocessors page, relying on the Standard Contractual Clauses and, where relevant, the UK Addendum.
We apply no retention period of our own: participant data stays until you delete the study or the account. Deleting a study removes its sessions, events, participant records and published versions outright, and removes media that nothing else references. Deleting your account does the same across every study and additionally erases the sign-in identity held by our authentication provider. Live data is gone immediately; provider backups roll off within [window].
8. Audit
On reasonable written notice, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will answer a reasonable security questionnaire and provide the compliance documentation we hold, including our providers' certifications. On-site audit is available where a supervisory authority requires it.
9. Liability and governing law
Liability under this agreement is subject to the limits in the Terms of Service. This agreement is governed by [governing law].