Data Processing Agreement
1. Background and parties
This Data Processing Agreement (the "DPA") is entered into between the customer organization using SurveySpire (the "Controller") and Dynamic Visions AB, a Swedish limited liability company with registration number 559385-1784 (the "Processor"). It forms part of the Terms of Service and governs the Processor's processing of personal data on behalf of the Controller, as required by Article 28(3) of Regulation (EU) 2016/679 (the "GDPR").
The DPA is accepted on the Controller's behalf by an owner of the Controller's organization account, who confirms that they are authorized to do so. It applies for as long as the Processor processes personal data on the Controller's behalf.
2. Subject matter, nature and purpose of the processing
The Processor provides a survey platform through which the Controller creates surveys, distributes them to its recipients through channels such as email and SMS, and collects and analyzes responses. The processing consists of storing, transmitting, organizing and displaying the personal data the Controller submits to the Service and the responses submitted by its recipients, solely for the purpose of providing and supporting the Service.
3. Categories of data subjects and personal data
- Data subjects: the Controller's survey recipients, and the Controller's own users of the Service.
- Personal data: recipient names, email addresses, mobile numbers and custom attributes provided by the Controller; survey responses; user account details (name, email address); and technical log data relating to survey delivery, authentication and use of the Service.
The Service is not intended for special categories of personal data (Article 9 GDPR). The Controller agrees not to include such data in survey content, recipient attributes or free-text collection without a separate written agreement with the Processor.
4. Instructions and controller responsibilities
The Processor processes personal data only on the Controller's documented instructions, unless required to do otherwise by EU or Swedish law, in which case the Processor will inform the Controller before processing unless that law prohibits it. The Controller's use of the Service constitutes its instruction to process personal data as described in this DPA. The Processor will immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable EU or Member State data protection law. The Controller is responsible for having a lawful basis for the processing and for the accuracy and lawfulness of the personal data it submits.
5. Confidentiality
The Processor ensures that all persons authorized to process the personal data are bound by confidentiality obligations, by contract or by law.
6. Security
The Processor implements and maintains appropriate technical and organizational measures pursuant to Article 32 GDPR throughout the term of this DPA, taking into account the state of the art and the risks of the processing, and reviews them regularly. These measures include, as appropriate:
- encryption of data in transit;
- access controls and role-based permissions limiting access to personal data;
- logical separation of each customer organization's data;
- regular backups and the ability to restore availability after an incident;
- logging of survey delivery and account activity.
7. Subprocessors
The Controller grants the Processor a general written authorization to engage subprocessors for the processing described in this DPA. The subprocessors currently engaged are listed at https://surveyspire.com/legal/subprocessors.
The Processor will notify the Controller by email at least 30 days before adding or replacing a subprocessor. If the Controller objects on reasonable data protection grounds, the parties will seek a solution in good faith; if none is found, the Controller may terminate the affected Service. The Processor imposes data protection obligations on each subprocessor equivalent to those in this DPA and remains fully liable to the Controller for the subprocessor's performance.
8. Data location and international transfers
Personal data is stored and processed within the EU/EEA. The Processor will not transfer personal data to a country outside the EU/EEA without ensuring appropriate safeguards under Chapter V GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses, and will inform the Controller of any such transfer through the subprocessor list.
9. Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organizational measures in fulfilling the Controller's obligations to respond to data subject requests (Chapter III GDPR), and in ensuring compliance with the Controller's obligations regarding security, breach notification, data protection impact assessments and prior consultation (Articles 32–36 GDPR). Assistance beyond the standard functionality of the Service may be subject to reasonable charges.
10. Personal data breaches
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information reasonably required for the Controller to meet its obligations under Articles 33–34 GDPR.
11. Deletion and return of data
Upon termination of the Service, the Processor will delete all personal data processed on the Controller's behalf within 90 days, unless the Controller requests return of the data within 30 days of termination, or EU or Swedish law requires continued storage. Deleted data may remain in encrypted backups until they are rotated out, no later than 120 days after deletion from the live systems.
12. Audits
The Processor will make available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, provided the auditor is not a competitor of the Processor and is bound by confidentiality obligations. Audits require 30 days' written notice, may be conducted at most once per year unless a supervisory authority requires otherwise or a breach has occurred, and are carried out at the Controller's expense.
13. Amendments
The Processor may propose updates to this DPA when required by law or when changes to the Service require it. Material changes take effect when the Controller accepts the new version in the Service. Changes to the subprocessor list are handled as described in Section 7 and do not require re-acceptance of this DPA.
14. Governing law
This DPA is governed by Swedish law. In case of conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.
15. Contact
Privacy-related questions and data subject requests can be sent to us using the contact details published on our website's contact page.