Data Processing Agreement
(DPA)
Data Processing Addendum
Last Updated: 7/29/2026
This Data Processing Agreement ("DPA") forms part of the Customer Terms of Service found at TheySaid Terms of Use between TheySaid, Inc. ("TheySaid") and you, the customer ("Customer"), unless Customer has entered into a superseding written master subscription agreement with TheySaid, in which case it forms part of such written agreement (in either case, the "Agreement"). Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of its Controller Affiliates (defined below). All capitalized terms not defined herein shall have the meaning set forth in the Agreement.In the course of providing access to the Platform and Services under the Agreement, TheySaid may Process certain Personal Data on behalf of Customer, and where TheySaid Processes such Personal Data on behalf of Customer the parties agree to comply with the terms of this DPA.
1. Definitions(a)
"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. "Control" means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
"Controller Affiliate" means any of Customer's Affiliate(s) that are (i) subject to applicable Data Protection Laws of the EU, EEA, Switzerland and/or United Kingdom, and (ii) permitted to use the Services pursuant to the Agreement, but have not signed their own Order Form.
"Customer Data" means any content or information submitted by Customer to the Services, including survey questions, responses, voice recordings, video recordings, transcriptions, and AI-generated outputs."Data Protection Laws" means all applicable laws relating to privacy, data protection, data security, breach notification, or the Processing of personal data, including without limitation: the General Data Protection Regulation (EU) 2016/679 ("GDPR"); the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act ("CCPA") as amended; and other applicable US state and federal laws.
"Data Subject" means the identified or identifiable person to whom Personal Data relates.
"Europe" means the European Union, EEA, Switzerland and the United Kingdom.
"Personal Data" means any Customer Data that relates to an identified or identifiable natural person, to the extent protected as personal data under applicable Data Protection Laws.
"Processing" means any operation performed upon Personal Data, including collection, recording, storage, adaptation, retrieval, use, disclosure, combination, restriction, erasure or destruction.
"Security Incident" means any confirmed breach of security resulting in the accidental or unlawful acquisition, destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
"Standard Contractual Clauses" or "EU SCCs" means the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
"Sub-processor" means any entity engaged by TheySaid to Process Personal Data in connection with the Services.
The terms "Controller," "Processor," and "Service Provider" are as defined in applicable Data Protection Laws.
2. Processing of Personal Data
Roles of the Parties
To the extent Customer is the Controller of Personal Data, TheySaid is its Processor. To the extent Customer is a Processor, TheySaid is its Sub-processor.
Customer's Processing of Personal DataCustomer shall Process Personal Data in accordance with applicable Data Protection Laws and shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which it was acquired.
3. Personal Data Processing Requirements
(a) Restrictions on Processing. TheySaid will:
- not retain, use, or disclose Personal Data outside of the direct business relationship between Customer and TheySaid, or for any purpose (including any commercial purpose) not set forth in this DPA or the Agreement;
- not “sell” or “share” any Personal Data, or use Personal Data for purposes of “targeted advertising,” as such terms are defined in Data Protection Laws; and
- comply with applicable restrictions under the CCPA on combining Personal Data received from or on behalf of another person.
(b) Confidentiality. TheySaid will ensure that the persons Processing the Personal Data have are bound by obligations of confidentiality no less protective than those set forth in the Agreement or are under an appropriate statutory obligation of confidentiality.
(c) Assistance. TheySaid will provide Customer with reasonable assistance: (i) in implementing appropriate technical and organizational measures for the fulfillment of Customer's obligations to respond to Data Subject rights requests; and (ii) in performing any required data protection impact assessments and consulting with regulatory authorities in relation to Processing of Personal Data.
(d) Notice Regarding Compliance. TheySaid will promptly notify Customer if it determines it can no longer meet its obligations under Data Protection Laws, or if it believes Customer's instructions violate Data Protection Laws.
(e) Automated Decision-Making. TheySaid's Services generate AI-assisted insights, themes, sentiment analysis and other outputs as decision-support tools only. TheySaid does not make solely automated decisions that produce legal or similarly significant effects on Data Subjects within the meaning of Article 22 GDPR. Customer, as Controller, acknowledges that outputs generated by the Services are for informational purposes only and are not intended to be used as the sole basis for decisions with legal or similarly significant effects on Data Subjects. Where Customer uses TheySaid's outputs as input to any such decision, Customer is solely responsible for ensuring that:
- meaningful human review is applied before any such decision is made;
- Data Subjects are provided with rights required under Article 22 GDPR, including the right to obtain human intervention, express their point of view, and contest the decision;
- Customer otherwise complies with its obligations under applicable Data Protection Laws with respect to automated decision-making and profiling.
(f) Children's Data. Customer shall not use the Services to conduct surveys, collect feedback, or otherwise process Personal Data from individuals under the age of 18 ("Minors") without having first:
- obtained verifiable parental or guardian consent as required by applicable law;
- implemented age-appropriate design safeguards in accordance with applicable law; and
- ensured an appropriate legal basis exists for such processing under applicable Data Protection Laws. Customer is solely responsible for determining whether any Data Subjects are Minors and for complying with all applicable laws relating to processing of children's personal data, including the UK Age Appropriate Design Code, COPPA, and any other applicable children's data protection legislation. TheySaid accepts no liability for Customer's failure to comply with this obligation.
4. Sub-processors
(a) Appointment of Sub-processors. Customer acknowledges and agrees that TheySaid's Affiliates may be retained as Sub-processors and that TheySaid may engage third-party Sub-processors in connection with the Services. TheySaid will enter into a written agreement with each Sub-processor containing data protection obligations that provide at least the same level of protection as this DPA.
(b) List of Current Sub-processors and Notification. The current list of Sub-processors is set out in Exhibit A. Customer may receive notifications of new Sub-processors by contacting security@theysaid.iowith the subject line "Subprocessor List". TheySaid will notify Customer of new Sub-processors before authorizing them to Process Personal Data in connection with the Services.
(c) Objection Right for New Sub-processors. Customer may reasonably object to TheySaid's use of a new Subprocessor by notifying TheySaid in writing within ten (10) business days of receiving notice. TheySaid will use commercially reasonable efforts to make available a change in the Services to avoid Processing by the objectedto Sub-processor.
(d) Liability. TheySaid shall be liable for the acts and omissions of its Sub-processors to the same extent it would be liable if performing the Services directly.
5. Security Incident
(a) Notice. TheySaid will notify Customer of any Security Incident without undue delay, or within the time period required under Data Protection Laws (and in any event within 48 hours of becoming aware). Notification will include, to the extent available: (i) the nature of the Security Incident and categories and approximate number of Data Subjects and Personal Data records concerned; (ii) likely consequences of the Security Incident; and (iii) measures taken or proposed to address the Security Incident. TheySaid will provide periodic updates as additional information becomes available.
(b) Responsibilities. TheySaid will comply with its Security Incident obligations under Data Protection Laws and will assist Customer in its compliance. Nothing in this DPA requires TheySaid to violate or delay compliance with any legal obligation relating to Security Incidents.
6. Data Transfers
(a) Authorization. Customer authorizes TheySaid and its Sub-processors to make international transfers of Personal Data in accordance with this DPA and applicable Data Protection Laws.
(b) Order of Precedence. Where a transfer is covered by more than one transfer mechanism, the following order of precedence applies: (i) the EU-US Data Privacy Framework (DPF) or UK Extension to the DPF, where applicable; (ii) the EU SCCs and/or UK Addendum as set out in this Section; and (iii) any alternative mechanism agreed by the parties in good faith.
(c) Data Privacy Frameworks. To the extent TheySaid processes Personal Data from the EEA, United Kingdom, or Switzerland and is certified under the applicable Data Privacy Framework, TheySaid will adhere to the Data Privacy Principles for such transfers.
(d) EU SCCs. To the extent legally required, by entering into this DPA the parties are deemed to have signed the EU SCCs, completed as follows: (i) Module 2 applies to transfers from Customer as Controller to TheySaid as Processor; Module 3 applies to transfers from Customer as Processor to TheySaid as Sub-processor; (ii) Clause 7 (optional docking clause) is not included; (iii) Clause 9 (sub-processors): Option 2 (general written authorization) applies, time period per Section 4(b); (iv) Clause 11 (redress): optional language does not apply; (v) Clause 17: the law of Ireland applies; (vi) Clause 18: the courts of Ireland have jurisdiction.
(e) UK Addendum. To the extent legally required, the parties are deemed to have signed the UK Addendum, which takes precedence over this DPA as set out in the UK Addendum. Table 4: either party may end this DPA as set out in Section 19 of the UK Addendum.
(f) Swiss Data. For transfers subject to the FADP, the EU SCCs apply with the following modifications: (i) references to GDPR are to the FADP where transfers are exclusively subject to the FADP; (ii) "member state" is interpreted to allow Swiss data subjects to sue in Switzerland; and (iii) the Swiss Federal Data Protection and Information Commissioner is the relevant supervisory authority.
7. Audits
(a) Standard Audit Process. TheySaid will make available documentation, certifications, reports and records ("Records") relating to Processing of Personal Data to demonstrate compliance with this DPA, at Customer's sole expense, upon fourteen (14) days' prior written notice, no more than once annually (except following a Security Incident).
(b) Written Requests and Inspections. If Records are insufficient to demonstrate compliance, Customer may: (i) submit written requests, to which TheySaid will respond within a reasonable period; and (ii) where written responses remain insufficient, request access to TheySaid's premises, systems and staff upon twenty-one (21) days' prior written notice, subject to mutual agreement on scope, timing, auditor, and costs (all borne by Customer). Inspections are permitted no more than once annually, except following a Security Incident.
8. Data Retention and Deletion
Return and Deletion of Personal Data. Upon deletion of Customer's organization account within the Services, whether initiated by Customer or at Customer's written request, TheySaid shall action deletion as follows:
(a) Primary Data. Customer's primary data, including database records and identity provider data, will be permanently deleted within 48 hours of organization deletion. A grace period of 48 hours applies to allow recovery from accidental deletion, during which data remains accessible to Customer.
(b) Operational Monitoring Data. Operational data held in error monitoring, observability and product analytics systems including error monitoring, observability and product analytics systems will be permanently deleted within one year of the organization deletion date. Such data is retained during this period solely for the purposes of security incident investigation, abuse detection and legal claim defense.
(c) Self-Service Deletion. Customer may self-service delete their organization account and all associated data at any time via the platform. Customers whose subscription has lapsed but whose organization account has not been deleted retain access to the platform for the purposes of viewing their data and initiating self-service deletion.
(d) Inactive Organizations. Where Customer's subscription has lapsed and the organization account has notbeen deleted, TheySaid will retain Customer's data as follows:
- Where Customer has provided explicit consent to AI model training use under Section 8(g): data is retained indefinitely until Customer withdraws consent or deletes their organization account.
- Where Customer has NOT provided AI model training consent: data is retained until the earlier of
(i) Customer deleting their organization account; or
(ii) three (3) years of account inactivity. For the purposes of this Section, "account inactivity" means no authenticated login by any active user on the Customer's account during the applicable period. TheySaid will permanently delete all Customer data upon expiry of this three-year inactivity period without further notice to Customer.
(e) Return of Data. Upon Customer's written request prior to organization deletion, TheySaid will make available an export of Customer's Personal Data in a commonly used electronic format. Depending on the Service plan, access to export functionality may require purchase of a Service upgrade.
(f) Residual Copies. TheySaid may retain residual copies of Personal Data in automated backup systems for up to 30 days following the applicable deletion date, after which such data will be permanently deleted in the ordinary course of backup expiry. TheySaid will continue to comply with this DPA in respect of any residual copies until deleted.
(g) AI Model Training Data. TheySaid may use Customer's organization data for AI model training purposes on the basis of its legitimate interests unless Customer exercises its right to object via account settings. Where Customer objects, TheySaid will cease using Customer's data for model training from the date of objection. Objection does not require deletion of data already incorporated into trained models prior to objection. The right to object may only be exercised by organization owners or administrators.
(h) Legal Holds. Nothing in this Section requires TheySaid to delete Personal Data where retention is required by applicable law, regulation, or legal process. TheySaid will notify Customer of any such requirement to the extent permitted by law.
- references to the GDPR in the EU SCCs are to be understood as references to the FADP insofar as the data transfers are subject exclusively to the FADP and not to the GDPR;
- the term “member state” in EU SCCs shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs; and
- the relevant supervisory authority is the Swiss Federal Data Protection and Information Commissioner (for transfers subject to the FADP and not the GDPR), or both such Commissioner and the supervisory authority identified in the EU SCCs (where the FADP and GDPR apply, respectively).
9. Controller Affiliates
(a) Contractual Relationship. By executing this DPA, Customer enters into it on behalf of itself and its Controller Affiliates, establishing a separate DPA between TheySaid and each such Affiliate. Each Controller Affiliate is bound by the obligations under this DPA. A Controller Affiliate is not a party to the Agreement itself.
(b) Communication. The Customer contracting party to the Agreement is responsible for coordinating all communication with TheySaid under this DPA on behalf of its Controller Affiliates.
(c) Rights of Controller Affiliates. Where applicable Data Protection Laws permit, the Customer contracting party shall exercise rights under this DPA on behalf of its Controller Affiliates collectively, not separately for each Affiliate individually.
10. Survival; Amendments
The provisions of this DPA survive the termination or expiration of the Agreement for so long as TheySaid or its Subprocessors Process Personal Data. TheySaid may amend this DPA in order to comply with Data Protection Laws and will notify Customer of such changes. By continuing to use the Services after the DPA has been updated, Customer is deemed to have agreed to the updated DPA.
Exhibit B
Annex I and II to EU SCCs
Annex I — List of Parties
Data exporter(s):
- Name: Customer, as identified in the Agreement.
- Address: As provided in the Agreement.
- Contact person: As provided in the Agreement.
- Activities relevant to the data transferred: Customer receives access to TheySaid's Services pursuant to the Agreement.
- Signature and date: Execution of the Agreement constitutes execution of these EU SCCs by both parties.
- Role: Controller or Processor, as applicable.
Data importer(s):
- Name: TheySaid, Inc.
- Address: As provided in the Agreement.
- Contact person: Security & Privacy Lead, security@theysaid.io.
- Activities relevant to the data transferred: TheySaid provides the Services to Customer pursuant to the Agreement.
- Signature and date: Execution of the Agreement constitutes execution of these EU SCCs by both parties
- Role: Processor or Sub-processor, as applicable.
B. Description of Transfer
Categories of Data Subjects
The categories of data subjects whose Personal Data is transferred are determined by Customer as data exporter. In the normal course of the Services, categories may include: survey respondents and end-users of Customer's services; Customer's personnel, customers, service providers and business partners.
Categories of Personal Data Transferred
The categories of Personal Data transferred are determined by Customer as data exporter. In the normal course of the Services, categories may include: text survey responses; voice and video recordings of survey responses; transcriptions of audio/video content; AI-generated insights, themes and sentiment analysis; and other feedback data submitted by survey respondents. Personal data may include name, contact details, and any other information submitted by Data Subjects in connection with their use of the Services.
Sensitive Data
Sensitive or special category data is not intentionally collected. Survey respondents may incidentally disclose special category data in open-ended responses. Customer is responsible for establishing an appropriate Article 9(2) GDPR condition (typically explicit consent) before conducting surveys designed or expected to elicit such data. TheySaid offers PII redaction functionality to assist Customer in managing such disclosures.
Frequency of Transfer
Continuous, in the course of providing the Services
Nature of Processing
Collection, storage, transcription, AI-based analysis (theme extraction, sentiment analysis, redaction), generation of insights, semantic search via vector embeddings, and provision of analytics outputs to Customer.
Purpose of Transfer
Provision of the TheySaid AI survey and analytics platform, including conversational AI surveys, transcription, theme generation, sentiment analysis, and insight delivery, as described in the Agreement.
Retention Period
As set out in Section 8 of this DPA: indefinite while organization account exists; primary data deleted within 48 hours of organization deletion; operational monitoring data deleted within one year of organization deletion; backup copies deleted within 30 days of applicable deletion date.
Sub-processors
As set out in Exhibit A.
Annex II — Technical and Organizational Security Measures
TheySaid implements the following technical and organizational measures to protect Personal Data:
- Encryption at rest: AES-256 encryption for all data stored in AlloyDB and Cloud Storage
- Encryption in transit: TLS 1.2+ for all data transmitted between systems and to/from the platform
- Access controls: Role-based access control (RBAC) with Owner, Admin and Member roles; principle of least privilege enforced
- Authentication: Single sign-on (SSO) via WorkOS with multi-factor authentication (MFA) required for all staff access to production systems
- Infrastructure: Google Cloud Platform (GCP), multi-zone GKE deployment, automated failover, RTO ≤ 4 hours, RPO ≤ 1 hour
- Backup and recovery: AlloyDB automated daily backups with 30-day retention; quarterly backup restoration testing
- Monitoring and logging: GCP Cloud Logging for audit trails; Sentry for error monitoring; Langfuse (selfhosted) for AI observability
- Sub-processor controls: All Sub-processors required to maintain equivalent data protection standards; Sub-processor agreements in place with all parties listed in Exhibit A
- Security assessments: Annual SOC 2 Type II audit; regular internal security reviews
- Incident response: Documented Security Incident Response procedure; Customer notification within 48 hours of confirmed Security Incident
- Personnel: All staff with access to Personal Data bound by confidentiality obligations; mandatory privacy and security training
- PII redaction: Customer-controlled PII redaction functionality to minimize sensitive data exposure in AI processing pipelines
Test experiences with real users, faster and smarter, using AI.






.avif)