Privacy Notice
Draft — not yet in force. The values highlighted like this are unresolved and must be filled in, and the whole set needs a lawyer's review, before these pages are linked from the product or relied on by an ethics committee. Until then this page describes intended practice, not a binding commitment.
Contents
Workframe is a tool for building scenario-based studies and embedding them in a survey you already run. This notice explains what we do with personal data — both the data of researchers who hold an account, and the data of participants who complete a study.
1. Who we are
Workframe is operated by [legal entity name], registered at [registered address]. For anything in this notice, write to privacy@workframeapp.com.
We have not appointed a statutory Data Protection Officer; [confirm this remains correct — an appointment becomes mandatory if large-scale processing of special-category data begins].
2. Two kinds of data, two different roles
This distinction runs through everything below, so it comes first.
- Researcher account data — the email you sign in with, your studies, your uploaded media. Here we are the controller: we decide what to collect and why.
- Participant study data — the responses, timings and identifiers collected when someone completes your study. Here we are a processor, and the researcher (or their institution) is the controller. You decide who is recruited, what is asked, what identifiers are passed in, and on what lawful basis. We act on your instructions and do not use that data for our own purposes.
The practical consequence: if you are a participant and want your data removed, we usually cannot identify you or act unilaterally — the researcher who ran the study is your first point of contact. See Your rights.
3. Researcher account data
| What | Why | Lawful basis |
|---|---|---|
| Email address, and the identity our sign-in provider holds for you | To authenticate you and attach your studies to an account | Contract — you cannot have an account without it |
| Studies you build: names, descriptions, scenes, clips, variables, published versions | To provide the product | Contract |
| Media you upload (images, audio, video) | To render your study to participants | Contract |
| Whether you have completed the first-run tour | So the tour follows your account rather than one browser | Legitimate interests — a usable first run |
| Correspondence, including pilot access requests | To answer you and administer the pilot | Legitimate interests |
We do not run analytics, advertising or session-replay tools, on any surface. We do not profile you and we take no automated decisions about you. We do not sell or share personal data.
4. Participant study data
When a participant opens a published study, we store, on the researcher's behalf:
- Responses to the questions in the study, and any signals the study sets.
- An event sequence — each exposure and choice with elapsed time — plus start and completion time, duration, and how many scenes were seen.
- Condition and assignment, and which attempt this is.
- The identifiers the researcher's survey or recruitment tool passes in — for example a Qualtrics response ID or a Prolific PID. These are stored as provided and appear in the researcher's export, because joining a run to survey data and approving payment is what they are for. A separate one-way key is derived from them to detect repeat attempts, but it does not replace the original.
Researchers, note. Those identifier fields accept any string up to 256 characters and store it verbatim. If your survey passes in a name, an email address or a university ID, that is what will be stored and exported. Pass a study-scoped pseudonymous ID instead. Workframe itself never asks a participant for a name, an email address or an account.
The participant surface sets no cookies and writes nothing to browser storage, and loads no third-party resource — the session token lives in memory for the length of the run. See the Cookie and Storage Notice.
We derive two hashed values that are never stored in the clear: a hash of the session token, and a hash of the study version plus the requesting network address, used to rate-limit abuse.
Workframe does not ask for special-category data (health, beliefs, sexual orientation, and the rest). A study's own questions can of course elicit it. If yours does, that is a decision you make as controller, and it is on you to have the lawful basis and, where required, the ethics approval and a Data Protection Impact Assessment.
5. Where data is stored, and transfers
Studies, participant data and uploaded media are stored on Cloudflare's platform (Workers, D1, R2). Researcher sign-in is handled by Clerk, which holds researcher identity only and is never called from the participant surface. Both are US companies operating global infrastructure, so personal data may be processed outside the UK/EEA.
Those transfers rely on the Standard Contractual Clauses (and the UK Addendum where relevant) incorporated in each provider's data processing terms. The current list, with what each provider does and where, is on the Subprocessors page.
6. How long we keep things
- Participant study data: until you delete it. There is no automatic expiry and no scheduled purge. Research retention periods belong to the researcher and their ethics approval, not to us, so we do not impose one. Deleting a study deletes its sessions, events, participant records and published versions outright, and removes media nothing else references.
- Account data: until you delete your account. That removes your studies and their data, your sign-in identity at our provider, and the account record itself. Signing in again afterwards creates a genuinely new account.
- Inactive sessions expire twelve hours after they start.
- Correspondence is kept for [period].
- Backups. Deletion removes data from the live database immediately; provider backups roll off on [confirm Cloudflare D1 point-in-time recovery window, currently understood to be up to 30 days].
7. Your rights
Where the UK GDPR or EU GDPR applies you have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable form, and complain to a supervisory authority.
If you are a researcher
Access and portability are built in and need no request: export any dataset as CSV or JSON in full, at any time. Deleting a study, or your whole account, is available in the product and takes effect immediately. For anything else, write to privacy@workframeapp.com and we will respond within one month.
If you are a participant
Contact the researcher or institution that ran the study. They are the controller, they know which identifier belongs to you, and they can delete your data. We hold no name, email or account for you and generally cannot identify you from our records alone. If you reach us anyway, we will pass the request to the relevant researcher and help them act on it.
You can complain to your local supervisory authority — in the UK, the Information Commissioner's Office; in the EU, the authority for your country. Our lead authority is [authority, once the establishment is confirmed].
8. Security
Access to a study and its results is limited to the account that owns it, and every authoring request is verified server-side before it reaches project data. Session tokens are stored only as hashes. Traffic is encrypted in transit. Administrative access is restricted to a named allow-list.
If a breach affecting personal data occurs, we will notify affected researchers without undue delay and, where the law requires it, the relevant supervisory authority within 72 hours of becoming aware.
9. Changes to this notice
The date at the top changes whenever this notice does. For a change that materially affects how we handle your data — a new subprocessor, a new purpose — we will tell account holders directly before it takes effect.