#Data Processing Agreement

Last updated: April 13, 2026

This Data Processing Agreement ("DPA") is a standard, publicly available agreement that governs the processing of Personal Data by Voicepanel, Inc. ("Provider") on behalf of its customers (each, a "Customer"). This DPA is incorporated by reference into, and forms part of, the agreement governing Customer’s use of the Voicepanel services (the "Agreement").

By accessing or using the Service, Customer agrees to this DPA.


#1. Structure of this DPA

This DPA consists of:

  1. These Key Terms, which apply to all Customers; and
  2. The Common Paper Data Processing Agreement – Standard Terms, Version 1.1 (the "DPA Standard Terms"), available at:

https://commonpaper.com/standards/data-processing-agreement/1.1

The DPA Standard Terms are incorporated by reference. If there is any conflict between these Key Terms and the DPA Standard Terms, these Key Terms control.

Capitalized terms not defined here have the meanings given in the DPA Standard Terms or the Agreement. If a highlighted term is not defined, it is deemed not applicable, and the corresponding provision does not apply.


#2. Key Terms

#2.1 Agreement

This DPA supplements the agreement between Customer and Provider governing use of the Service, including any master services agreement, subscription agreement, order form, or online terms.


#2.2 Roles of the Parties

For purposes of Applicable Data Protection Laws:

  • Customer acts as a Controller with respect to Customer Personal Data.
  • Provider acts as a Processor (and, where applicable, a service provider under the CCPA/CPRA).

Customer determines the purposes and means of processing Customer Personal Data. Provider processes Customer Personal Data solely on Customer’s documented instructions as reflected in the Agreement and this DPA.


#2.3 Service Provider Relationship (CCPA / CPRA)

To the extent the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. ("CCPA"), as amended by the CPRA, applies:

  • Provider acts as a service provider or processor to Customer.
  • Provider receives Personal Data solely to provide the Service for Customer, which constitutes a limited and specified business purpose.
  • Provider will not sell or share Customer Personal Data.
  • Provider will not use Customer Personal Data to train or improve AI models.
  • Provider will not retain, use, or disclose Customer Personal Data except:
    • as necessary to provide the Service;
    • as permitted by the Agreement; or
    • as permitted by Applicable Data Protection Laws.

Provider certifies that it understands and will comply with these restrictions and will notify Customer if it can no longer meet its obligations under the CCPA.


#2.4 Approved Subprocessors

A current list of approved subprocessors is available at:

https://voicepanel.com/privacy/subprocessors

Provider will provide notice of material changes to subprocessors in accordance with the DPA Standard Terms.


#2.5 Provider Security Contact

Email: privacy@voicepanel.com


#2.6 Security Policy

Provider will use commercially reasonable efforts to secure the Service against unauthorized access, alteration, use, or unlawful tampering.

Provider maintains the following security assurances:

  • Annual SOC 2 Type II reports
  • Regular penetration testing

#2.7 Restricted Transfers

EEA Transfers – Governing Member State: Ireland
UK Transfers – Governing Law: England and Wales


#3. Annex I(A): List of Parties

#Data Exporter

  • Entity: Customer using the Service
  • Role: Controller

#Data Importer

  • Entity: Voicepanel, Inc.
  • Address: 2261 Market Street, Suite 5823, San Francisco, CA 94114, USA
  • Contact: Asa Schachar, CTO & Co-Founder
  • Role: Processor

#4. Annex I(B): Description of Transfer and Processing Activities

#Service Description

The Service is a customer research and survey platform that enables Customers to design, administer, and analyze projects, including unmoderated projects conducted via text, voice, or video.

Customer Personal Data includes:

  • data provided by Users (such as researchers, administrators, and collaborators); and
  • data provided by Respondents at the direction of Customer through the Service.

Respondent Data may include text, audio (voice), and video recordings, as well as transcripts, annotations, analytical outputs, and associated metadata generated as part of the Service.

Demographic and survey attribute data may be processed in connection with projects. Such demographic data may:

  • be provided automatically by third-party research panel providers integrated with the Service; and/or
  • be collected directly from Respondents by or on behalf of Customer (including Customer’s own Users), based on Customer-configured project questions and instructions.

Provider processes demographic data solely in accordance with Customer’s instructions and does not independently determine which demographic attributes are collected.


#Categories of Data Subjects

  • Users (e.g., researchers, administrators, collaborators)
  • Respondents

#Categories of Personal Data

  • Identifiers such as name, username, or respondent ID
  • Contact information (email address, phone number)
  • Account and authentication data
  • Respondent Data, including text, audio (voice), and video recordings and transcripts
  • Demographic and survey attribute data (such as age range, gender, education level, household characteristics, or similar attributes defined by Customer)
  • Technical and device data (such as IP address, browser type, operating system, device identifiers, timestamps, and log data)
  • Location information (general location derived from IP address)

#Special Category Data

Is special category data processed? Yes.

Safeguards and limitations:
Special category personal data (as defined in Article 9 of the GDPR), including data revealing racial or ethnic origin, health information, sexual orientation, or biometric characteristics (such as voice or facial features), may be processed where such data is:

  • collected by or on behalf of Customer; or
  • provided by Respondents, including via third-party research panel providers.

Such data is processed solely in accordance with Customer’s instructions and Applicable Data Protection Laws. Customer is responsible for establishing a lawful basis, obtaining any required consents, and providing required notices to data subjects.


#Frequency of Transfer

Continuous


#Nature and Purpose of Processing

  • Collection, access, recording, and entry of data
  • Storage, organization, and structuring
  • Analysis, consultation, testing, automated processing, and profiling as instructed by Customer
  • Transcription, annotation, and generation of analytical outputs
  • Updating, correction, alignment, and combination
  • Protection, encryption, monitoring, and security testing
  • Disclosure and access to authorized users as directed by Customer
  • Export, return, or deletion of data

#Duration of Processing

Provider will process Customer Personal Data only for as long as necessary to:

  1. provide the Service and perform the processing activities instructed under the DPA Standard Terms; or
  2. comply with Applicable Laws.

#5. Annex I(C): Competent Supervisory Authority

The competent supervisory authority will be determined in accordance with Clause 13 of the EU Standard Contractual Clauses or the applicable provision of the UK Addendum.


#6. Annex II: Technical and Organizational Security Measures

Provider maintains technical and organizational measures appropriate to the risk, including but not limited to:

  • Encryption: AES-256 encryption for data at rest; TLS 1.3 or equivalent for data in transit
  • Pseudonymization: Applied where appropriate, including in non-production and testing environments
  • Access Controls: Unique user accounts, role-based access controls, and multi-factor authentication
  • Availability & Resilience: Cloud infrastructure redundancy, monitoring, and failover mechanisms
  • Incident Recovery: Documented backup and disaster recovery procedures with defined recovery objectives
  • Security Testing: Annual SOC 2 Type II audits, penetration testing, vulnerability scanning, and dependency monitoring
  • Logging & Monitoring: Application and system activity logging retained for security monitoring and investigation
  • Configuration Management: Infrastructure-as-code, change management, and environment separation (development, staging, production)
  • Governance: Designated security ownership, documented policies, and periodic internal reviews
  • Data Minimization: Processing limited to what is reasonably necessary to provide the Service
  • Retention Controls: Customer-configurable deletion and documented retention practices
  • Accountability: Controls designed to demonstrate compliance with data protection obligations
  • Portability & Erasure: Data export and deletion capabilities, with propagation to subprocessors where applicable

#7. No Signatures Required

This DPA does not require individual signatures. It becomes legally binding when Customer enters into the Agreement or uses or continues to use the Service.


#8. Standard Terms Reference

The Common Paper Data Processing Agreement – Standard Terms (Version 1.1) are available at:

https://commonpaper.com/standards/data-processing-agreement/1.1

Provider and Customer have not modified the DPA Standard Terms except as expressly set out in this public DPA.