SurveyRock
BlogResourcesSupportPricingLog inStart free

Data Processing Agreement

Document status: Approved v1.0 (2026-07-21) Effective date: 2026-07-21


This Data Processing Agreement (“DPA”) forms part of the Terms of Service (“Terms”) between Oak Mountain Digital LLC (“SurveyRock”, “Processor”) and the Customer (defined in the Terms) (“Customer”, “Controller”) for the use of the SurveyRock Service.

This DPA reflects the parties’ agreement on the processing of Personal Information when Customer’s use of the Service involves processing Personal Information subject to the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK Data Protection Act 2018 (“UK GDPR”), the California Consumer Privacy Act (“CCPA”), or other applicable data protection laws.

If there is any conflict between this DPA and the Terms, this DPA prevails with respect to the processing of Personal Information.


1. Definitions

Capitalized terms used but not defined here have the meaning given in the Terms or GDPR.

  • “Customer Personal Information” means Personal Information of Respondents and other individuals collected, stored, or processed through Customer’s use of the Service.
  • “Data Subject” means an identified or identifiable natural person whose Personal Information is processed.
  • “EEA” means the European Economic Area.
  • “Personal Information” / “Personal Data” has the meaning given in GDPR Article 4(1).
  • “Sub-processor” means any third party engaged by SurveyRock to process Customer Personal Information.
  • “Standard Contractual Clauses” or “SCCs” means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), or replacement mechanisms in effect from time to time.

2. Roles and scope

2.1 Roles

  • The Customer is the Controller of Customer Personal Information processed through the Service.
  • SurveyRock is the Processor acting on behalf of the Customer with respect to Customer Personal Information.
  • SurveyRock is the Controller of certain account, billing, and operational data described in our Privacy Policy.

2.2 Scope of processing

Element Details
Subject matter Provision of the SurveyRock Service to Customer
Duration The term of the Terms, plus the retention periods in our Privacy Policy
Nature of processing Hosting, storage, transmission, organization, retrieval, display, analysis (where Customer uses analytical features), deletion of Customer Personal Information
Purpose of processing Solely to provide the Service to Customer in accordance with the Terms and Customer’s documented instructions
Types of Personal Information As described in Section 3 below
Categories of Data Subjects Respondents to Customer’s surveys; Customer’s Authorized Users; contacts in Customer’s lists

2.3 Customer’s documented instructions

The Customer’s instructions for processing Customer Personal Information are documented in:

  • The Terms
  • This DPA
  • The Customer’s configuration of the Service
  • Written instructions provided by Customer (e.g., support tickets, account configuration)

SurveyRock processes Customer Personal Information only in accordance with these documented instructions, except as required by applicable law (in which case SurveyRock will inform Customer before processing unless prohibited by law).


3. Types of Personal Information and Data Subjects

3.1 Types of Personal Information

The Service may involve processing the following categories of Customer Personal Information, depending on how Customer configures their surveys:

  • Identifying data: name, email address, phone number (if Customer collects)
  • Demographic data: age, gender, location, occupation (if Customer collects)
  • Survey response data: answers to questions Customer asks (which may include any category above plus opinions, preferences, and other content)
  • Technical data: IP address (truncated by default), browser type, device type
  • Behavioral data: response timing, completion patterns
  • Special categories (if Customer chooses to collect): health information, racial/ethnic origin, political opinions, religious beliefs, trade union membership, biometric data, etc.

Customer is responsible for ensuring lawful basis and any additional safeguards for processing special categories of Personal Information.

3.2 Categories of Data Subjects

  • Respondents (the primary category)
  • Customer’s authorized users of the Service
  • Contacts in Customer’s contact lists
  • Other individuals whose data Customer chooses to process via the Service

4. SurveyRock’s obligations

4.1 Processing limited to instructions

SurveyRock processes Customer Personal Information only:

  • To provide the Service per Customer’s documented instructions
  • To comply with applicable law (notifying Customer in advance where permitted)
  • To exercise rights under the Terms

4.2 Confidentiality

SurveyRock ensures that personnel authorized to process Customer Personal Information:

  • Are bound by appropriate confidentiality obligations
  • Receive appropriate data protection training
  • Have access only on a need-to-know basis

4.3 Security

SurveyRock implements appropriate technical and organizational measures to protect Customer Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include those described in Annex II — Technical and Organizational Measures to this DPA.

4.4 Sub-processors

4.4.1 General authorization

Customer provides general authorization for SurveyRock to engage Sub-processors to process Customer Personal Information, provided that SurveyRock complies with the requirements below.

4.4.2 List of Sub-processors

The current list of Sub-processors is available at our Sub-processor List. SurveyRock will:

  • Maintain an up-to-date list
  • Notify Customer at least 30 days in advance of adding or replacing a Sub-processor
  • Allow Customer to object to a new Sub-processor on reasonable data protection grounds within 30 days of notice

4.4.3 Right to object

If Customer reasonably objects to a new Sub-processor:

  • SurveyRock will work in good faith to address the concern
  • If SurveyRock cannot accommodate the objection within 30 days, Customer may terminate the affected service with proportionate refund of prepaid fees

4.4.4 Sub-processor obligations

SurveyRock requires each Sub-processor by written agreement to:

  • Provide at least the same level of data protection as required of SurveyRock under this DPA
  • Process Personal Information only as instructed by SurveyRock
  • Maintain appropriate technical and organizational security measures
  • Cooperate with audits as required

SurveyRock remains liable to Customer for the acts and omissions of its Sub-processors.

4.5 Data Subject rights

SurveyRock will assist Customer in fulfilling Customer’s obligations to respond to Data Subject rights requests under GDPR (access, rectification, erasure, restriction, portability, objection). Assistance includes:

  • Providing technical features within the Service that enable Customer to honor requests directly (export, deletion)
  • Forwarding to Customer any Data Subject request received by SurveyRock that relates to Customer Personal Information
  • Providing reasonable technical assistance where Customer requires it to fulfill a request

If SurveyRock receives a Data Subject request directly:

  • SurveyRock will forward the request to Customer without undue delay (within 5 business days)
  • SurveyRock will not respond to the Data Subject directly except to confirm receipt and identify Customer as the Controller
  • Customer is responsible for the substantive response

4.6 Personal Data Breach notification

In the event of a Personal Data Breach affecting Customer Personal Information, SurveyRock will:

  • Notify Customer without undue delay, and in any event within 72 hours of becoming aware
  • Provide information available at the time, including: nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, measures taken or proposed
  • Update Customer as additional information becomes available
  • Cooperate with Customer’s investigation and notification obligations

4.7 Data Protection Impact Assessments

SurveyRock will provide reasonable assistance to Customer in conducting Data Protection Impact Assessments (DPIAs) and consultations with supervisory authorities under GDPR Articles 35-36, taking into account the nature of processing and the information available to SurveyRock.

4.8 Audit rights

4.8.1 Customer’s right to audit

Customer has the right to audit SurveyRock’s compliance with this DPA. Audits may be conducted:

  • No more than once per year unless triggered by a material change in circumstances (e.g., post-incident review)
  • On at least 30 days’ written notice unless required sooner by supervisory authority order
  • During SurveyRock’s normal business hours
  • In a manner that does not unreasonably disrupt SurveyRock’s operations

4.8.2 Customer’s audit options

Customer may satisfy audit rights through:

  1. Reviewing SurveyRock’s compliance documentation (SOC 2 report when available, security questionnaire responses, current audit certifications)
  2. A questionnaire-based audit conducted by Customer or a third party Customer designates
  3. An on-site or remote audit by Customer or a third party Customer designates (subject to reasonable confidentiality and scope agreements; SurveyRock may require the auditor to be qualified and not a competitor)

4.8.3 Costs

Customer bears its own audit costs. If an audit reveals material non-compliance by SurveyRock, SurveyRock bears reasonable costs of the audit and any required remediation.

4.9 Return or deletion of Customer Personal Information

Upon termination of the Service or upon Customer’s written request:

  • SurveyRock will, at Customer’s choice, return or delete all Customer Personal Information in SurveyRock’s possession
  • Deletion will occur within 30 days of Customer’s instruction unless retention is required by law (in which case SurveyRock will inform Customer of the legal basis for retention)
  • Backups containing Customer Personal Information will be deleted in accordance with SurveyRock’s backup retention policy (currently 90 days), after which the data is purged

5. International transfers

5.1 Transfers from the EEA, UK, and Switzerland

When Customer Personal Information is transferred from the EEA, UK, or Switzerland to a country not recognized as providing adequate protection:

  • The transfer is subject to the Standard Contractual Clauses (Module 2: Controller-to-Processor) attached as Annex III to this DPA, which are incorporated by reference
  • For UK transfers, the UK International Data Transfer Addendum to the SCCs applies (also in Annex III)
  • For Swiss transfers, equivalent SCCs with Swiss-specific amendments apply

5.2 Supplementary measures

In light of Schrems II and subsequent guidance:

  • Customer Personal Information is encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • SurveyRock implements organizational measures (access controls, audit logging, personnel training) described in Annex II
  • SurveyRock will challenge any government access request that is not legally compliant
  • SurveyRock will inform Customer of any government access request affecting Customer Personal Information, unless legally prohibited

5.3 Adequacy decisions

If the European Commission, UK Government, or Swiss authority issues an adequacy decision covering a relevant transfer, the transfer may rely on that decision in lieu of SCCs.


6. Customer’s obligations

Customer:

  • Is responsible for the lawfulness of processing under applicable law, including establishing a lawful basis under GDPR Article 6 and any additional basis required for special categories under Article 9
  • Provides notices and obtains consents required from Data Subjects
  • Configures the Service appropriately for the data Customer processes
  • Honors Data Subject rights requests in a timely manner
  • Notifies SurveyRock if Customer’s use of the Service may trigger high-risk processing under GDPR Article 35 or EU AI Act obligations
  • Complies with the Acceptable Use Policy

7. Term and termination

This DPA remains in effect for the duration of the Terms. The obligations of SurveyRock relating to confidentiality, security, audit rights, and return/deletion of Customer Personal Information survive termination of the Terms for as long as SurveyRock retains any Customer Personal Information.


8. Liability

The liability of each party under this DPA is subject to the limitations and exclusions in the Terms. For clarity, the limitation of liability in the Terms applies to claims under this DPA.


9. General

9.1 Order of precedence

In case of conflict: SCCs > this DPA > Terms.

9.2 Severability

If any provision of this DPA is found unenforceable, the rest remains in effect.

9.3 Governing law

This DPA is governed by the same law as the Terms, except where applicable data protection law mandates a different governing law.

9.4 Counterparts and execution

This DPA may be executed electronically. Customer’s acceptance of the Terms constitutes acceptance of this DPA where applicable to Customer’s processing.


Annex I — Description of Processing

Already covered in Section 2.2 above.

Annex II — Technical and Organizational Measures

SurveyRock implements the following Technical and Organizational Measures (“TOMs”) to protect Customer Personal Information:

Access control

  • Identity management: All personnel access requires unique credentials
  • Multi-factor authentication: Required for production access and admin functions
  • Role-based access control: Least-privilege principle; access is reviewed when personnel or vendor changes occur
  • Authentication strength: Strong password requirements; SSO supported
  • Session management: Automatic timeout; secure session token handling
  • Access logging: All access to Customer Personal Information is logged

Encryption

  • In transit: TLS 1.2 or higher for all connections
  • At rest: AES-256 for databases and storage
  • Key management: AWS KMS with rotation policies
  • Backups: Encrypted with separate key material

Network security

  • Network segmentation: Production application and data tiers isolated in a VPC with security-group allowlists (default deny between tiers)
  • Traffic capture: VPC Flow Logs enabled
  • DDoS protection: AWS Shield Standard (network/transport layer, included on all AWS endpoints)
  • Web application firewall and managed intrusion detection (AWS WAF, GuardDuty): on our security roadmap; not yet deployed

Personnel

  • Access: Production access is limited to named personnel under confidentiality obligations; any contractors are bound by equivalent written confidentiality and data protection terms; access is reviewed when personnel or vendor changes occur

Physical security

  • All processing occurs on AWS infrastructure, which maintains physical security certifications (SOC 1, SOC 2, ISO 27001) for its data centers
  • No SurveyRock office-based access to Customer Personal Information

Availability and resilience

  • Backups: Daily automated backups with 90-day retention; restore procedures documented
  • Multi-AZ deployment: Production database deployed across multiple availability zones, with a read replica
  • Disaster recovery: Documented runbook
  • Uptime monitoring: Continuous synthetic monitoring; alerting to operations

Security testing

  • Dependency and vulnerability monitoring: Automated dependency scanning in CI; blocking security-test gate on every deploy
  • Code review: Required for all production changes
  • Penetration testing: Not yet commissioned; planned post-launch
  • Security incident response: Documented procedures; on-call rotation

Data lifecycle

  • Data minimization: Customer controls what data is collected
  • Pseudonymization: Applied to analytics data
  • Retention: Per Privacy Policy
  • Deletion: Verified deletion within 30 days of Customer instruction (90 days for backup purge)

Sub-processor management

  • Vetting: Each Sub-processor reviewed for security and compliance posture before engagement
  • Contractual safeguards: Each Sub-processor bound by DPA equivalent to this one
  • Ongoing monitoring: Sub-processor compliance reviewed annually
  • Notification: 30-day advance notice of changes

Certifications and audits

  • SOC 2 Type II: on our roadmap (planned to begin in the months following the 2026 relaunch); not yet certified
  • ISO 27001: not currently pursued

Annex III — Standard Contractual Clauses

The European Commission Standard Contractual Clauses (Module 2: Controller-to-Processor) of 4 June 2021 are hereby incorporated by reference, with the following completions:

Module: Module 2 (Controller to Processor)

Docking clause: Enabled

Annex I.A — List of Parties:

  • Data exporter: Customer (as identified in the Terms)
  • Data importer: Oak Mountain Digital LLC

Annex I.B — Description of transfer: As described in Section 2.2 and Section 3 of this DPA.

Annex I.C — Competent supervisory authority: The supervisory authority of the EU Member State in which the data exporter (Customer) is established

Clause 7 (Docking clause): Enabled

Clause 9(a) (sub-processor authorization): General written authorization, with notification of changes at least 30 days in advance.

Clause 11(a) (independent dispute resolution): Not offered

Clause 17 (Governing law): Ireland

Clause 18 (Jurisdiction): Courts of Ireland

Annex II: As set out in Annex II of this DPA above.

Annex III (sub-processors): As set out in the Sub-processor List referenced in Section 4.4.

UK Addendum: The UK International Data Transfer Addendum is incorporated for UK transfers, with completions matching those above.


Annex IV — Contact

Data Protection contact: privacy@surveyrock.com Data Protection Officer: Not designated; contact privacy@surveyrock.com

SurveyRock

Surveys that turn answers into decisions. Operating since 2012.

Product

PricingTemplatesFree toolsEnterprise

Company

Our storyBlogBrand & pressContact

Resources

Resource hubGlossaryHelp center

Trust & legal

Trust centerGDPRAI & data governance

Compare

vs SurveyMonkeyvs Typeformvs Jotformvs Google Formsvs SurveySparrow

© 2026 SurveyRock

PrivacyTermsCookiesAcceptable UseDPASub-processorsAccessibility