Data Processing Agreement
Annex to the Responsly Terms of Service
Source: https://www.responsly.com/terms-and-policies/data-processing-addendum/
Contents
- Parties and conclusion of the DPA
- Recitals
- 1. Subject matter of the DPA
- 2. Customer’s representations and obligations
- 3. Customer’s instructions
- 4. Provider’s obligations
- 5. Subprocessors
- 6. Audit
- 7. Deletion of Personal Data
- 8. Liability
- 9. Final provisions
- 10. Other data protection laws
- Annex 1. Description of processing
- Annex 2. Technical and organisational measures
- Annex 3. Subprocessors
Parties and conclusion of the DPA
This data processing agreement (the “DPA”) is concluded between:
- sixpoints – Jędrzej Koronowicz, a sole proprietorship registered in the Polish Central Registration and Information on Business (CEIDG), Grunwaldzka 472, 80-309 Gdańsk, Poland, VAT ID PL5842612410, REGON 221927438 (the “Provider” or “Responsly”), and
- the Customer as defined in the Terms of Service (the “Customer”),
jointly referred to as the “Parties” and each individually as a “Party”.
This DPA is concluded electronically when the Customer accepts the Terms of Service and applies to all Plans, including during a free trial. No signature is required.
This DPA forms an integral part of the Terms of Service. Capitalised terms that are not defined in this DPA have the meanings given to them in the Terms of Service.
A Customer that needs amended provisions, or a data processing agreement signed electronically or on paper, may enter into a custom data processing agreement with the Provider on the Enterprise Plan or under a separate commercial agreement. Requests should be sent to gdpr@responsly.com. A custom data processing agreement prevails over this DPA to the extent that it amends it.
Recitals
- Providing the Service may require the Provider to process personal data for which the Customer is the controller, or a processor acting on behalf of another controller (“Personal Data”).
- The Parties wish to ensure that Personal Data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”) and other data protection laws,
the Parties agree as follows.
1. Subject matter of the DPA
- In accordance with Article 28(3) GDPR, the Customer entrusts the Provider with the processing of Personal Data, and the Provider accepts it.
- The Provider processes Personal Data:
- in accordance with this DPA and applicable law,
- solely for the purpose of providing the Service to the Customer,
- to the extent, for the purpose and in the manner described in Annex 1,
- for as long as the Service is provided and, after that, until the Personal Data is deleted in accordance with Section 7.
- The Provider’s role is to make the tools of the Service available to the Customer. The Provider does not determine the purposes or means of the Customer’s processing of Personal Data, does not influence the scope of data the Customer collects in Surveys, and does not verify the legal bases on which the Customer collects that data.
- Where the Customer acts as a processor on behalf of another controller, the Provider acts as a sub-processor, and the Customer shall ensure that its instructions are consistent with the instructions of that controller.
2. Customer’s representations and obligations
- The Customer represents that the Personal Data has been collected and is processed lawfully, and in particular that the Customer:
- has a valid legal basis for processing the Personal Data, including any consents required under applicable electronic communications and anti-spam laws for sending invitations and information to individuals electronically (email, SMS, WhatsApp),
- has provided data subjects with the information required by Articles 13 and 14 GDPR,
- is entitled to entrust the Provider with the processing of the Personal Data to the extent and for the purpose set out in this DPA and, where the Customer is not the controller, has obtained the controller’s authorisation to do so.
- The Customer confirms that it has reviewed the technical and organisational measures described in Annex 2 and considers them appropriate to the risk involved in processing Personal Data in the Service.
- The Customer shall use the Service securely, and in particular shall protect the login credentials for its Account, grant Users permissions on a least-privilege basis and use the available security features, such as two-factor authentication.
- The Service is not intended for processing special categories of personal data (Article 9 GDPR), personal data relating to criminal convictions and offences (Article 10 GDPR) or children’s data. The decision to collect such data rests solely with the Customer, who in that case shall assess on its own whether the measures described in Annex 2 are sufficient.
- Each Party shall inform the other without delay, and no later than within 3 working days, of any inspection or proceedings by a supervisory authority (in Poland, the President of the Personal Data Protection Office) concerning the Personal Data, unless prohibited by law.
3. Customer’s instructions
- The Provider processes Personal Data only on documented instructions from the Customer, unless required to do so by Union or Member State law to which the Provider is subject. In that case, the Provider shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
- The Customer’s instructions consist of this DPA, the Terms of Service and the actions taken by the Customer and its Users with the functions of the Service, including creating Surveys, importing data, sending invitations, and exporting, sharing and deleting data.
- The Customer shall send any further instructions electronically to gdpr@responsly.com. Further instructions must relate to the subject matter of this DPA and to the Service. If carrying out an instruction requires work beyond the standard functions of the Service, the Provider shall first inform the Customer of its technical feasibility and cost, and shall carry it out once the Customer has accepted the cost.
- The Provider shall immediately inform the Customer if, in the Provider’s opinion, an instruction infringes the GDPR or other data protection laws. Pending clarification, the Provider may suspend carrying out that instruction and, if carrying it out would breach the law, may refuse to carry it out.
4. Provider’s obligations
- Security. In accordance with Article 32 GDPR, the Provider applies the technical and organisational measures described in Annex 2. The Provider may change those measures, provided that the change does not reduce the overall level of protection of Personal Data.
- Confidentiality. The Provider shall allow only authorised persons who have committed themselves to confidentiality or are under a statutory obligation of confidentiality (Article 28(3)(b) GDPR) to process Personal Data, and is liable for their actions as for its own.
- Data subject rights. The Customer is responsible for responding to requests from data subjects. The Provider shall assist the Customer with this obligation insofar as possible, primarily through the functions of the Service that allow data to be searched for, exported, rectified and erased. If a request is sent directly to the Provider, the Provider shall forward it to the Customer within 5 working days and shall not respond to it without the Customer’s instruction.
- Assistance with Articles 32–36 GDPR. The Provider shall assist the Customer in meeting its obligations relating to security of processing, notification of personal data breaches, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to the Provider. Assistance beyond providing information about the Service may be chargeable, in which case the Provider shall inform the Customer of the cost before providing it.
- Personal data breaches. The Provider shall notify the Customer of a personal data breach affecting Personal Data without undue delay and no later than 48 hours after becoming aware of it. The Provider is deemed to become aware of a breach when it has confirmed that a personal data breach has occurred, not upon a mere suspicion or an unconfirmed report. The notification is sent to the Account owner’s email address and includes, to the extent known to the Provider at the time of notification, the information listed in Article 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects and of personal data records concerned, the likely consequences, the measures taken or proposed, and contact details. Where information cannot be provided at the same time, the Provider shall provide it in phases without undue delay. The notification is not an acknowledgement of fault or liability.
- Records. The Provider maintains a record of the categories of processing activities carried out on behalf of controllers in accordance with Article 30(2) GDPR.
- Data protection contact. The Customer directs data protection matters, including matters relating to the performance of this DPA, to the Provider at gdpr@responsly.com.
5. Subprocessors
- The Customer gives the Provider general authorisation to engage subprocessors and to entrust them with the processing of Personal Data for the purpose of providing the Service, including the subprocessors listed on the date this DPA is concluded.
- The current list of subprocessors, describing their purpose, location and transfer mechanism, is published at https://www.responsly.com/terms-and-policies/subprocessors/ and constitutes Annex 3 to this DPA.
- The Provider shall give notice of any intended addition or replacement of a subprocessor at least 14 days before the change takes effect, by email to the Account owner.
- Within 14 days of receiving the notice, the Customer may submit a reasoned objection to gdpr@responsly.com. The Parties shall seek a solution in good faith. If the Parties do not reach agreement within 30 days of the objection, the Customer may terminate the agreement for the Service with immediate effect. If no objection is submitted within that period, the Customer is deemed to have accepted the change. The Customer acknowledges that an objection may prevent it from using features of the Service that depend on the subprocessor concerned. Termination on this ground does not entitle the Customer to a refund, as set out in the Terms of Service.
- In exceptional cases, where a change of subprocessor is urgently needed to ensure the continuity or security of the Service, the Provider may make the change earlier. In that case the Provider shall inform the Customer without delay, and the Customer may object in accordance with Section 5.4.
- The Provider shall enter into an agreement with each subprocessor that imposes data protection obligations at least equivalent to those in this DPA (Article 28(4) GDPR), and remains liable to the Customer for the performance of those obligations by the subprocessor. A provider of a service to which the Customer itself sends data through an integration or similar connection chosen by the Customer is not the Provider’s subprocessor.
- Personal Data is transferred to a third country only in compliance with Chapter V GDPR, on the basis of a European Commission adequacy decision (including the EU-US Data Privacy Framework for certified organisations) or standard contractual clauses adopted by the European Commission.
- To the extent permitted by law, the Provider shall notify the Customer of a legally binding request by an authority to disclose Personal Data, unless the law prohibits such notice. The Provider is not required to challenge the request. The Customer may challenge it at its own expense. If notifying the Customer is legally prohibited, the Provider shall, where legally permitted, inform the Customer that it can no longer follow the Customer’s instructions without providing further details.
6. Audit
- The Customer has the right to verify whether the Provider processes Personal Data in accordance with this DPA (an “Audit”). An Audit is carried out in the first instance by the Provider making information and documents available and answering the Customer’s questions sent to gdpr@responsly.com.
- If the information under Section 6.1 is not sufficient, the Customer may carry out an Audit at the Provider’s place of business, either itself or through an independent auditor who has entered into a confidentiality agreement with the Provider and does not compete with the Provider.
- An Audit:
- covers only the Personal Data processed under this DPA,
- takes place no more than once a year, unless required by a supervisory authority or carried out after a material personal data breach affecting the Customer’s Personal Data has been identified,
- is announced at least 14 days before the planned date,
- lasts no longer than 2 working days, takes place during the Provider’s business hours and does not disrupt the Provider’s operations or the security of other customers,
- does not include access to other customers’ data, the Provider’s trade secrets or subprocessors’ systems (for subprocessors, the Provider makes available the subprocessors’ reports and certifications that are available to it).
- The Customer bears the costs of an Audit, unless the Audit reveals a material breach of this DPA by the Provider.
- The Customer shall provide the Provider with the Audit report. The report is the Provider’s confidential information.
7. Deletion of Personal Data
- While using the Service, the Customer may export and delete Personal Data at any time using the functions of the Service.
- After the Account is deleted or the provision of the Service ends, Personal Data is retained for 60 days solely to allow the Account to be reactivated. During that period, the Provider performs no operations on the Personal Data other than storage. The Customer may export Personal Data during that period. Making Personal Data available for export through the functions of the Service, including during the period in Section 7.2, constitutes return of the data within the meaning of Article 28(3)(g) GDPR. The Provider is not required to return Personal Data in any other form or on any other medium.
- After the period in Section 7.2, the Personal Data is deleted from production systems. Personal Data contained in backups is deleted as part of the backup rotation cycle, within 12 months at the latest. Until then, backups are stored in encrypted form and are not used for any purpose other than restoring the Service after a failure.
- Sections 7.2–7.3 do not apply to data that the Provider is required to retain by Union or Member State law.
- At the Customer’s request made before the end of the period in Section 7.2, the Provider shall delete Personal Data from production systems earlier. After that period, the Provider has no obligation to return or further store Personal Data, subject to Section 7.4.
8. Liability
- The Parties’ liability under this DPA is subject to the limitations set out in the Terms of Service. The limit of liability in the Terms of Service is an aggregate limit covering all claims under the Terms of Service and this DPA.
- The limitations of liability do not apply to damage caused intentionally.
- This DPA does not limit the rights of data subjects under Article 82 GDPR. If a Party pays compensation for any part of the damage for which the other Party is responsible, it may claim that amount back from the other Party.
- The Customer is liable for damage resulting from processing Personal Data without a legal basis or on the Customer’s unlawful instructions, and shall indemnify the Provider against third-party claims to that extent, on the terms set out in the Terms of Service.
9. Final provisions
- The Provider’s remuneration for performing this DPA is included in the fee for the Service. During a free trial, this DPA is performed free of charge.
- This DPA remains in force for as long as the Service is provided, and its provisions on the retention and deletion of Personal Data and on confidentiality remain in force until the Personal Data is deleted in accordance with Section 7.
- This DPA replaces any earlier standard data processing agreements concluded by the Parties in connection with the Service, including the Data Processing Addendum last updated on 5 March 2024. A data processing agreement issued on the then-current standard template, including where it was signed without changes to its wording, is a standard agreement for this purpose. It does not replace individually negotiated data processing agreements, unless the Parties agree otherwise.
- The Provider may amend this DPA in accordance with the rules for amending the Terms of Service, by notifying the Customer at least 14 days before the changes take effect. The Customer may terminate the agreement for the Service before that date.
- Communications concerning this DPA are made electronically: to the Provider at gdpr@responsly.com, and to the Customer at the Account owner’s email address.
- In matters of personal data protection, this DPA prevails over the Terms of Service. Matters not governed by this DPA are governed by the Terms of Service, the GDPR and Polish law.
- This DPA was published on 16 September 2026 and is effective from 1 October 2026. Earlier texts of the DPA are available on request.
10. Other data protection laws
Where the UK GDPR or the Swiss Federal Act on Data Protection applies to the processing of Personal Data, references in this DPA to the GDPR and its provisions include the corresponding provisions of those laws, and references to Union or Member State law include the law of the United Kingdom or Switzerland, as applicable. Where required for transfers of Personal Data subject to those laws, the corresponding safeguards apply: the International Data Transfer Addendum to the European Commission’s standard contractual clauses issued under the UK GDPR, or the standard contractual clauses adopted by the European Commission as adapted for Switzerland.
Where US state privacy laws, such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), apply to Personal Data (including “personal information” as defined in those laws), the Provider acts as a “service provider” or “contractor” within the meaning of those laws and shall not:
- “sell” or “share” Personal Data, as those terms are defined in those laws,
- retain, use or disclose Personal Data for any purpose other than providing the Service, including for any commercial purpose other than providing the Service,
- retain, use or disclose Personal Data outside the direct business relationship between the Customer and the Provider,
- combine Personal Data with personal data it receives from or on behalf of another person, or collects from its own interactions with individuals, except as permitted by those laws.
The Provider certifies that it understands these restrictions and will comply with them.
Annex 1. Description of processing
Purpose of processing. Providing the Service to the Customer: creating and distributing Surveys (including forms, quizzes, tests and polls), sending invitations, collecting, storing and analysing responses, including with AI Features where the Customer uses them, and integrations enabled by the Customer.
Nature of processing. Automated processing in the IT systems of the Service. Operations: collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission (including to integrations designated by the Customer), alignment, restriction, erasure and backup. The Provider does not contact data subjects on behalf of the Customer other than through mailings the Customer orders in the Service.
Duration of processing. For as long as the Service is provided and for the periods set out in Section 7 of this DPA.
Categories of data subjects.
- Respondents — individuals who complete the Customer’s Surveys.
- Contacts — individuals whose data the Customer imports or collects in the Service and to whom the Customer sends invitations, such as customers, prospective customers, employees, job applicants, event participants, members of organisations and contact persons at the Customer’s business partners.
- Other individuals whose data the Customer includes in the content of Surveys or in messages sent through the Service.
Categories of personal data.
- Response content — data within the scope defined by the Customer in Survey questions, including uploaded files.
- Contact and identification data — email address, phone number, first and last name, and other attributes added by the Customer (such as job title, department, workplace, address details, gender, age, and hidden variables passed in the link).
- Respondents’ technical data — IP address, visitor identifier, browser language, device type and operating system, referring page address, and date and time of completion.
- Mailing data — delivery, open and click status of invitations.
- Personal data contained in the content of messages sent by the Customer through the Service.
Special categories of data. Not anticipated. If the Customer decides to collect them, Section 2.4 of this DPA applies.
Annex 2. Technical and organisational measures
The description of technical and organisational measures is published at https://www.responsly.com/terms-and-policies/data-processing-addendum/security-measures/ and constitutes Annex 2 to this DPA. The Provider updates it in accordance with Section 4.1.
Annex 3. Subprocessors
The current list of subprocessors is published at https://www.responsly.com/terms-and-policies/subprocessors/ and is updated in accordance with Section 5 of this DPA.
