Data Processing Agreement

Our standard controller-to-processor terms for customers whose review teams require a DPA.

Version 1.0 · Effective 22 July 2026

Need a signed copy?

These are ValidateThat's standard data-processing terms and form part of your agreement with us when you use the Services. If your organisation requires a countersigned copy naming your entity, or needs us to sign your own DPA form instead, email support@validatethat.io and we will turn it around promptly.

Related: Privacy Policy · Security · Terms of Use

This Data Processing Agreement ("DPA") forms part of the agreement for the supply of services (the "Agreement") between HourlyRate Inc, the operator of ValidateThat ("ValidateThat", "we", "us", the "Processor"), and the customer that has accepted this DPA or uses the Services (the "Customer", "you", the "Controller"). Each a "Party" and together the "Parties". This DPA is effective from the date the Customer first accepts it or begins using the Services (the "Effective Date").

1. Definitions

Terms not defined here have the meanings given in the Agreement or in applicable Data Protection Laws.

  • "Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
  • "Personal Data", "Controller", "Processor", "Data Subject", "Processing" and "Supervisory Authority" have the meanings given in the EU GDPR. Where CCPA/CPRA applies, "Personal Data" also includes "Personal Information" as defined there, "Controller" corresponds to "Business", and "Processor" corresponds to "Service Provider".
  • "Customer Personal Data" means Personal Data that the Processor processes on behalf of the Controller in connection with the Services, as described in Annex I.
  • "Services" means ValidateThat's online user-research platform, including card sorting, tree testing, surveys, and prototype-testing studies, and related account and export functionality.
  • "Sub-processor" means any third party engaged by the Processor to process Customer Personal Data.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

2. Roles and Scope

2.1 The Parties acknowledge that, for the purposes of the Data Protection Laws, the Controller is the controller and the Processor is the processor with respect to Customer Personal Data.

2.2 This DPA applies only to the Processing of Customer Personal Data by the Processor on behalf of the Controller. It does not apply to Personal Data for which the Processor is an independent controller (for example, the Processor's own account, billing, and business-contact records), which is governed by the Processor's Privacy Policy.

2.3 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I.

3. Processor Obligations

The Processor shall:

3.1 Process only on documented instructions. Process Customer Personal Data only on the Controller's documented instructions, including with regard to international transfers, unless required to do otherwise by law that applies to the Processor; in which case the Processor shall inform the Controller of that legal requirement before Processing, unless the law prohibits such information on important grounds of public interest. The Agreement, this DPA, and the Controller's use and configuration of the Services constitute the Controller's complete and final documented instructions.

3.2 Notify unlawful instructions. Immediately inform the Controller if, in its opinion, an instruction infringes the Data Protection Laws.

3.3 Confidentiality. Ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality.

3.4 Security. Implement the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, to ensure a level of security appropriate to the risk.

3.5 Assist the Controller. Taking into account the nature of the Processing and the information available to it, provide reasonable assistance to the Controller, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Controller's obligations to: (a) respond to requests from Data Subjects exercising their rights; (b) ensure security of Processing (Article 32 GDPR); (c) notify Personal Data Breaches and communicate them to Data Subjects (Articles 33 and 34 GDPR); and (d) carry out data protection impact assessments and prior consultations with Supervisory Authorities (Articles 35 and 36 GDPR).

3.6 Data subject requests. Promptly notify the Controller if the Processor receives a request from a Data Subject relating to Customer Personal Data, and not respond to that request itself except on the Controller's documented instructions or as required by law. The Services also allow the Controller to access, correct, export (CSV), and delete Customer Personal Data directly.

4. CCPA/CPRA Terms (where applicable)

4.1 To the extent the Processor processes Personal Information subject to the CCPA/CPRA, the Processor acts as a Service Provider. The Processor shall not: (a) sell or share such Personal Information; (b) retain, use, or disclose it for any purpose other than performing the Services, or otherwise outside the direct business relationship with the Controller; (c) combine it with Personal Information obtained from other sources, except as permitted by the CCPA/CPRA for a Service Provider.

4.2 The Processor certifies that it understands and will comply with these restrictions.

5. Sub-processors

5.1 The Controller provides general authorisation for the Processor to engage the Sub-processors listed in Annex III.

5.2 The Processor shall impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, in particular regarding security of Processing.

5.3 The Processor shall give the Controller reasonable prior notice of the addition or replacement of any Sub-processor (which may be given by updating Annex III or a public sub-processor list and notifying the Controller by email). The Controller may object on reasonable data-protection grounds within fourteen (14) days; the Parties will work in good faith to resolve the objection, and if it cannot be resolved the Controller may terminate the affected Services.

5.4 The Processor remains liable to the Controller for the performance of each Sub-processor's data protection obligations.

6. International Transfers

6.1 The Processor shall not transfer Customer Personal Data to a country outside the country of origin unless it has taken measures necessary to ensure the transfer is compliant with the Data Protection Laws.

6.2 Where such a transfer involves Personal Data subject to the EU GDPR or UK GDPR to a country without an adequacy decision, the Parties agree that the relevant Standard Contractual Clauses (and, for UK data, the UK International Data Transfer Addendum) are incorporated into this DPA by reference and completed with the information in the Annexes, with the Processor as "data importer" and the Controller as "data exporter".

7. Personal Data Breach

7.1 The Processor shall notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

7.2 The notification shall, to the extent known, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Where information is not available at the time of notification, it may be provided in phases without undue further delay.

8. Audit and Information

8.1 The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, including the security documentation published at validatethat.io/security and any Sub-processor certifications referenced in Annex III.

8.2 The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, no more than once per twelve (12) month period (except where required by a Supervisory Authority or following a Personal Data Breach), on reasonable prior written notice, during normal business hours, subject to confidentiality obligations, and in a manner that does not disrupt the Processor's operations. The Parties will first seek to satisfy audit requests through the provision of existing documentation and Sub-processor attestations.

9. Deletion and Return

9.1 Upon termination or expiry of the Agreement, or earlier at the Controller's written request, the Processor shall, at the Controller's choice, delete or return all Customer Personal Data, and delete existing copies, unless retention is required by law.

9.2 The Controller may export Customer Personal Data in CSV format through the Services at any time before deletion. Residual copies in routine backups are deleted in the ordinary course of the backup rotation.

9.3 Retention periods. The Processor applies the following retention:

DataRetention
Study responses (participant data)Until the Controller deletes the study or closes the account; deletion from primary storage is immediate.
Account and study data after account closureDeleted within 30 days.
Rate-limit identifiers (HMAC-hashed IP)1 minute to 1 hour, per endpoint window. Raw IP addresses are not stored.
Platform request / edge logsRetained by Vercel per its current platform log-retention policy; not used by the Processor for analytics.
BackupsMaximum 3 days (rolling daily backup rotation).
Billing recordsRetained by Stripe as required by statutory financial record-keeping obligations.

10. Data Location

Customer Personal Data is stored using the infrastructure described in Annex III. The primary storage region is the United States. The Processor will not change the primary storage region in a way that introduces a new international transfer without notifying the Controller.

11. Liability

Each Party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA does not limit any rights a Data Subject may have under the Data Protection Laws.

12. General

12.1 Term. This DPA takes effect on the Effective Date and continues for so long as the Processor processes Customer Personal Data on behalf of the Controller.

12.2 Precedence. In the event of a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

12.3 Changes in law. If a change in Data Protection Laws requires amendment of this DPA, the Parties will negotiate the necessary amendments in good faith.

12.4 Governing law. This DPA is governed by the law and subject to the jurisdiction specified in the Agreement.

12.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions continue in full force.


Annex I — Details of Processing

Subject matter: The Processor's provision of the Services to the Controller.

Duration: For the term of the Agreement, plus the period until Customer Personal Data is deleted in accordance with Section 9.

Nature and purpose of Processing: Hosting, storage, and processing of user-research studies and their responses so that the Controller can create, run, and analyse card sorting, tree testing, survey, and prototype-testing studies, including generating analytics and exports.

Categories of Data Subjects

  • The Controller's authorised users (account holders and collaborators).
  • Participants in the Controller's studies (which may include the Controller's employees, recruited testers, or members of the public, as determined by the Controller).

Categories of Customer Personal Data

  • Account data: name and email address of the Controller's authorised users.
  • Study configuration content submitted by the Controller (for example card labels, category names, task and survey text), which the Controller controls and should not populate with unnecessary Personal Data.
  • Participant response data: card sortings, tree-test paths, survey answers, prototype-test interactions, timestamps, and technical data such as IP address and browser/device information.
  • Any additional participant Personal Data the Controller chooses to collect through pre-study or survey questions (for example a participant email address), as configured by the Controller.

Special categories of Personal Data: None is required by the Services. The Controller shall not use the Services to collect special-category data unless it has a lawful basis and has notified the Processor.

Frequency of Processing: Continuous, for the duration of the Agreement.


Annex II — Technical and Organisational Measures

The Processor maintains the following measures. The current published version is at validatethat.io/security.

Encryption

  • All traffic to validatethat.io is encrypted in transit using TLS 1.2 or higher; HTTP requests are redirected to HTTPS.
  • Data at rest is encrypted by the database provider (Upstash). The Processor does not store unencrypted exports outside the database.

Access control and authentication

  • User sessions use HTTP-only, secure cookies scoped to validatethat.io and its subdomains.
  • Account passwords are stored as bcrypt hashes; plaintext passwords are never written to logs, the database, or any persistent store.
  • Password resets use time-limited, single-use tokens delivered by email.
  • API tokens are generated server-side from 32 bytes of CSPRNG entropy, shown once at creation, and stored only as a SHA-256 hash; the raw token is never persisted server-side and is transmitted only over HTTPS.
  • Administrative access to production systems is limited to authorised personnel.

Infrastructure security

  • Application hosting on Vercel (SOC 2 Type 2, ISO 27001).
  • Database and cache on Upstash Redis (SOC 2 Type 2), with regular backups.
  • Payments processed by Stripe (PCI DSS Level 1); the Processor does not store cardholder or banking data.
  • Transactional and broadcast email via Resend.

Operational security

  • A published coordinated vulnerability-disclosure process (security@validatethat.io), with acknowledgement targeted within 24 to 48 hours and critical issues patched ahead of public disclosure.
  • Monitoring for suspicious activity.
  • Participant response data is stored per study and is accessible only to the study's owning account.

Note on scale: ValidateThat is operated as a small engineering operation and is not separately certified to SOC 2, ISO 27001, or HITRUST. It relies on the certified infrastructure providers listed above and in Annex III.


Annex III — List of Sub-processors

Sub-processorPurposeLocationRelevant certifications
Vercel Inc.Application hosting and content deliveryUnited StatesSOC 2 Type 2, ISO 27001
Upstash Inc.Database and cache (study data, responses)United StatesSOC 2 Type 2
Resend (Plus Five Five, Inc.)Transactional and broadcast emailUnited States
Stripe, Inc.Payment processing and billingUnited StatesPCI DSS Level 1
Anthropic, PBCAI features (study/task generation and analysis). Content submitted by the Controller is not used to train models.United StatesSOC 2 Type 2
Prolific (Prolific Academic Ltd.)Optional participant recruitment, where the Controller chooses to recruit via ProlificUnited KingdomUK GDPR
Strapi (CMS host)Content management for marketing pages; does not process participant response dataEuropean Union

Payment card data is submitted by the payer directly to Stripe and is processed by Stripe as an independent controller for that purpose; the Processor does not receive or store cardholder data.

Questions about this DPA?

For a countersigned copy, to sign your own form, or with any data-processing questions, get in touch and we will respond quickly.