Data Processing Agreement
Draft version 2026-09-12-draft — this text is engineering scaffolding, not final, reviewed legal copy. Do not rely on it as binding until Legal replaces it.
1. Roles & Scope
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer ("Controller") and Askdepth ("Processor") governing Askdepth's processing of personal data on the Controller's behalf in the course of providing the platform.
2. Documented Instructions
Askdepth processes personal data only on the Controller's documented instructions, including as necessary to operate interviews, surveys, and analysis the Controller configures, unless required to do otherwise by applicable law.
3. Subprocessors
Askdepth engages the subprocessors listed at /legal/subprocessors. The Controller may object to a new subprocessor by contacting privacy@askdepth.com within a reasonable period of notice.
4. Security Measures
Askdepth maintains technical and organizational measures appropriate to the risk, including encryption of respondent PII at rest, access controls scoped by organization, and the retention/anonymization lifecycle described in the Respondent Privacy Notice.
5. Breach Notification
Askdepth will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data.
6. Assistance with Data Subject Requests
Askdepth provides a self-service Data Subject Request portal and will assist the Controller with requests it cannot resolve directly.
7. Organization Acceptance
To accept this Data Processing Agreement on behalf of your organization, sign in to your Askdepth workspace. Only an organization owner can record acceptance.
Open DPA Acceptance in Workspace