VeySurVeySur

VeySurVeySur
PricingFAQ
Log inGet Started

Data Processing Agreement

Last Updated: 26 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between VeySur Limited ("VeySur", "we", "us", "our") and you (the "Customer", "you", "your") for the use of the VeySur survey platform (the "Services").

This DPA applies where and only to the extent that VeySur processes Personal Data on your behalf in the course of providing the Services, and such processing is subject to the GDPR ("Data Protection Laws").

Effective Date: This DPA is effective from the date you first use the Services.


1. Definitions and Interpretation

1.1 Defined Terms

In this DPA, the following terms have the meanings set out below:

  • "Agreement" means the Terms of Service between you and VeySur, of which this DPA forms part.
  • "Controller" means the natural or legal person which determines the purposes and means of the Processing of Personal Data. In the context of the Services, you (the Customer) are the Controller.
  • "Data Subject" means an identified or identifiable natural person about whom Personal Data relates. In the context of the Services, Data Subjects are typically survey participants.
  • "Personal Data" means any information relating to an identified or identifiable natural person as defined in the Data Protection Laws.
  • "Processing" (and "Process", "Processes", "Processed") means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • "Processor" means a natural or legal person which Processes Personal Data on behalf of the Controller. In the context of the Services, VeySur is the Processor.
  • "Services" means the VeySur survey platform and related services provided by VeySur to you under the Terms of Service.
  • "Sub-processor" means any Processor engaged by VeySur to Process Personal Data in connection with the Services.
  • "Supervisory Authority" means the relevant independent public authority of an EU Member State responsible for monitoring the application of the GDPR in accordance with Article 51.
  • "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
  • "EU Representative" means the representative appointed by VeySur in accordance with Article 27 GDPR to act on behalf of VeySur with regard to VeySur's obligations under the GDPR within the European Union.
  • "EU Data Act Representative" means the representative appointed by VeySur in accordance with Article 37 EU Data Act to act on behalf of VeySur with regard to VeySur's obligations under the EU Data Act within the European Union.

1.2 Interpretation

References to "you", "your", and "Customer" refer to the Controller. References to "we", "us", "our", and "VeySur" refer to the Processor. Terms not defined in this DPA have the meanings given in the Terms of Service or the Data Protection Laws.


2. Scope and Applicability

2.1 Subject Matter of Processing

This DPA governs the Processing of Personal Data of survey participants collected through the VeySur platform on your behalf.

2.2 Duration of Processing

Processing under this DPA continues for as long as your account is Active or Suspended. If your account enters Terminated status, Processing continues for up to 1 month (or until earlier deletion), subject to Section 11 (Deletion and Return of Data).

2.3 Nature and Purpose of Processing

The nature and purpose of Processing includes:

  • Collection of survey responses submitted by participants
  • Storage and organisation of survey data
  • Retrieval and display of survey results
  • Analysis and aggregation of survey data for reporting purposes
  • Enabling data export and download functionality
  • Deletion of survey data upon your instruction

2.4 Types of Personal Data

The types of Personal Data Processed depend entirely on the survey questions you create and may include: contact information (names, email addresses), demographic data, survey responses and opinion data, location data, uploaded files, IP addresses, device information, and timestamps.

2.5 Categories of Data Subjects

Data Subjects are survey participants who complete surveys that you create and distribute using the Services.


3. Roles and Responsibilities

3.1 Your Role as Controller

You are the Controller of the Personal Data collected through your surveys. As Controller, you:

  • Determine the purposes and means of Processing Personal Data
  • Are responsible for ensuring you have a lawful basis for Processing under Data Protection Laws
  • Must provide appropriate privacy notices to Data Subjects
  • Must obtain any necessary consents from Data Subjects
  • Are responsible for ensuring your instructions to us comply with Data Protection Laws
  • Must respond to Data Subject requests (with our assistance as set out in Section 8)

3.2 Our Role as Processor

We are the Processor of the Personal Data you collect through the Services. As Processor, we:

  • Process Personal Data only on your documented instructions
  • Implement appropriate technical and organisational security measures
  • Assist you in responding to Data Subject rights requests
  • Notify you of Personal Data breaches
  • Engage Sub-processors in accordance with this DPA
  • Make available information necessary to demonstrate compliance with this DPA

3.3 Independent Controllers

For certain Personal Data, we may act as an independent Controller:

  • Account Data: Your name, email, billing information, and account settings (covered by our Privacy Policy)
  • Usage Data: Aggregated and anonymised platform usage statistics for our own business purposes

This DPA does not apply where we act as an independent Controller.

3.4 EU Representative

As VeySur is established in the United Kingdom and not in the European Union, we are required under Article 27 GDPR to appoint a representative in the European Union. Our EU Representative is:

Name: Prighter EU Rep GmbH Address: Schellinggasse 3/10, 1010 Vienna, Austria Data Subject Rights Portal: https://app.prighter.com/portal/16325015152

You may contact our EU Representative regarding any matters relating to the processing of your Personal Data and the exercise of your rights under the GDPR.

3.5 EU Data Act Representative

As VeySur is established in the United Kingdom and not in the European Union, we are required under Article 37 EU Data Act to designate a legal representative in the European Union for matters relating to our obligations under Regulation (EU) 2023/2854 (the Data Act). Our EU Data Act Representative is:

Name: Prighter EU Rep GmbH Address: Schellinggasse 3/10, 1010 Vienna, Austria Portal: https://app.prighter.com/portal/16325015152

Our EU Data Act Representative serves as the addressee for competent authorities, users, and other stakeholders in the European Union on all matters related to the Data Act.


4. Processing Instructions

You instruct us to Process Personal Data as necessary to provide the Services, including: hosting and displaying surveys, collecting and storing responses, providing access to data and analytics, enabling export/download/deletion, performing backups, and providing customer support.

You may issue additional written instructions via support requests (support@veysur.com), account settings, or other agreed written communication.

If we believe any instruction violates Data Protection Laws, we will inform you immediately and may suspend performance until you confirm or modify it. We will not Process Personal Data for any purpose other than as instructed by you or as required by applicable law. If required by law to Process beyond your instructions, we will inform you beforehand (unless the law prohibits such notice).


5. Confidentiality

We ensure that all persons authorised to Process Personal Data are subject to confidentiality obligations (by contract or statutory duty) and receive regular training on data protection principles and security practices. Access to Personal Data is granted only on a need-to-know basis and only to the extent necessary to perform the Services.


6. Security Measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of Processing Personal Data, including encryption (TLS/HTTPS for data in transit, encryption at rest for sensitive data), access controls (multi-factor authentication, role-based access), system resilience (backups, redundancy), security monitoring and testing, and physical security measures at our data centres.

While we implement industry-standard security measures, no system is completely secure. We commit to maintaining measures appropriate to the risk level and promptly addressing any identified vulnerabilities.

Detailed Security Measures: For comprehensive information on our technical and organisational security measures, see Appendix A.

Security Documentation: Upon reasonable request, we will provide summary documentation of our security measures, subject to confidentiality obligations.


7. Sub-Processors

7.1 General Authorisation

You provide general authorisation for us to engage Sub-processors to Process Personal Data on your behalf, provided we comply with the requirements of this Section 7.

7.2 Current Sub-Processors

As of the date of this DPA, we engage the following Sub-processors:

Sub-processor Service Provided Location Data Processed
EU data centre provider Data storage and infrastructure hosting European Union (EEA) All personal data categories (Stream A and Stream B)
Stripe, Inc. Payment processing United States Cardholder data only (not survey response data) (EU-US Data Privacy Framework adequacy decision)
Zoho Corporation Pvt. Ltd. Customer service email (support inbox) European Union (EEA) Identity data (name, email address, support ticket content)
Google LLC (Google Analytics) Website analytics (marketing and account management sites only) United States Analytics data (page views, session data, device/browser type, referral source) (EU-US Data Privacy Framework adequacy decision)

7.3 Sub-Processor Notification and Objection

We will notify you of any intended changes to our Sub-processors (addition or replacement) at least 1 month in advance via email and/or account dashboard notice. You may object on reasonable grounds relating to Data Protection Laws by notifying us in writing within 1 month. If you object, we will use reasonable efforts to provide a commercially reasonable alternative. If we cannot, you may suspend or terminate the affected Services.

7.4 Sub-Processor Obligations

We impose data protection obligations on all Sub-processors equivalent to those in this DPA via written contract, ensuring they: Process Personal Data only on our instructions (which reflect yours), implement appropriate security measures, maintain confidentiality, assist with Data Subject rights requests and breach notification, and delete or return Personal Data upon termination.

7.5 Liability for Sub-Processors

We remain fully liable for the performance of any Sub-processor's obligations under this DPA.

7.6 Updated Sub-Processor List

An updated list of current Sub-processors is available upon request by contacting support@veysur.com.


8. Data Subject Rights Assistance

We will assist you in responding to Data Subject requests by providing functionality to:

  • Access and Data Portability: Export survey response data in machine-readable formats (CSV, JSON)
  • Rectification: Edit and correct survey response data via the Services interface
  • Erasure: Delete specific responses or entire surveys
  • Restriction: Control access to and visibility of survey data
  • Right to Object: Manage consent and opt-out preferences

Request Procedures: If we receive a Data Subject request directly, we will promptly forward it to you. You remain responsible for responding within the required timeframes (generally one month). We will respond to your reasonable requests for assistance within 10 business days.

Charges: Assistance is provided at no additional charge, unless the request requires substantial resources beyond the functionality provided in the Services, in which case we may charge a reasonable fee.


9. Security Incident and Breach Notification

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data breach affecting your Personal Data. Our notification will include (to the extent known): the nature of the breach, categories and approximate number of Data Subjects affected, our data protection contact details (privacy@veysur.com), likely consequences, and measures taken or proposed to address the breach. If information is not immediately available, we will provide updates in phases.

You remain responsible for determining whether the breach must be notified to the Supervisory Authority (generally within 72 hours) and to affected Data Subjects (where there is a high risk to their rights and freedoms).

We will provide reasonable cooperation and assistance, including providing additional information, preserving evidence, mitigating harm, and coordinating on communications and remediation. We will conduct a prompt investigation and take steps to remediate the cause and prevent recurrence.


10. Compliance Assistance

We will provide reasonable assistance to help you comply with your Data Protection Law obligations, including:

  • Security of Processing: Implementing and maintaining the security measures described in Section 6 and Appendix A
  • Data Protection Impact Assessments (DPIAs): Providing information about our Processing activities to support your DPIA where required
  • Prior Consultation: Providing information to support consultation with the Supervisory Authority where required
  • Other Obligations: Such other assistance as you may reasonably request

Charges: Assistance is provided at no additional charge, except where your request requires substantial resources beyond the scope of the Services, in which case we may charge a reasonable fee agreed in advance.


11. Deletion and Return of Data

11.1 Data Export and Deletion During Service

You may export or delete Personal Data at any time via the Services, including individual responses, entire surveys, or all account data. Exports are provided in machine-readable format (CSV or JSON), either immediately through the Services or within 10 business days if requested via support@veysur.com. Deletion is immediate and irreversible.

11.2 Account Suspension

We may suspend your account where necessary to:

  • Investigate suspected Terms of Service violations or fraud
  • Comply with legal obligations or court orders
  • Establish, exercise, or defend legal claims
  • Protect the security and integrity of the Services

Legal Basis: Suspension relies on GDPR Article 17(3) (legal claims and legal obligations) and Article 6(1)(f) (legitimate interests in fraud prevention and security).

During suspension, you cannot access the Services or Personal Data. Personal Data is retained but not deleted, and we only Process it as necessary for the investigation or legal requirement.

We will notify you of the reason and expected duration, unless prohibited by law or notification would undermine the investigation. Suspensions are reviewed regularly and resolved as promptly as possible. You may contact privacy@veysur.com to challenge a suspension.

We may reinstate your account if the investigation concludes in your favour, terminate your account if warranted, or continue periodic reviews where legally required to maintain suspension.

Your right to erasure is temporarily restricted during suspension under GDPR Article 17(3)(b) (legal obligations) or Article 17(3)(e) (legal claims). We will honour your erasure request once the investigation concludes and no legal obligation to retain data remains.

11.3 Account Termination

Termination Initiated by You:

  • You may immediately and permanently delete your account at any time through the Services
  • You may request account termination via support@veysur.com, which places your account in Terminated status with a 1-month export period

Termination Initiated by VeySur: If we terminate your account (due to Terms of Service violation, legal requirement, or other reason), your account will be placed in Terminated status. We will provide notice and reason where legally permitted.

During Terminated Status (1-month Export Period):

  • You may log in to export Personal Data in machine-readable formats (CSV or JSON)
  • You may request immediate deletion at any time during this period
  • After 1 month, all Personal Data will be permanently deleted from active systems

Deletion Process: Upon deletion (whether immediate or after the 1-month export period), we will delete or anonymise all Personal Data in active systems without undue delay and from backups within 3 months. We will provide written certification of deletion upon request, including confirmation of active system deletion, backup deletion timeline, and any data retained under legal obligations.

11.4 Right to Erasure Under Data Protection Laws

You may exercise your right to erasure at any time by deleting your account through the Services (immediate deletion) or submitting a written request to privacy@veysur.com. We will comply with erasure requests without undue delay and in accordance with Data Protection Laws, subject to Section 11.5 (Legal Retention Requirements).

11.5 Legal Retention Requirements and Exceptions to Deletion

We may retain or delay deletion of Personal Data where:

  • Payment Records: Retained for the period required by applicable Member State law for tax and accounting purposes (payment information only, not survey response data)

  • Legal Obligations: We are required by law, regulation, court order, or lawful government request to retain the Personal Data. We will flag your account with a retention notice, process the data only as required, delete it once the obligation is lifted, and notify you (unless prohibited by law) of the retention and expected duration.

  • Legal Claims: Retention is necessary for the establishment, exercise, or defence of legal claims. Personal Data will be deleted once the claim is resolved or the retention period expires.

  • Anonymised Data: Aggregated and anonymised usage statistics that cannot identify you or Data Subjects may be retained indefinitely for our business purposes.

11.6 Subscription Changes

If your paid subscription expires or is cancelled, your account will revert to our free subscription tier. No data deletion occurs immediately as a result of the subscription change.

If your Resource Usage exceeds the free tier's limits, you have 1 month to bring it within those limits. We'll send you email warnings in good time before any action is taken. If your Resource Usage still exceeds the limits after 1 month, we reserve the right to delete Resources (oldest first) as necessary to bring you within the free tier's limits. See our Terms of Service for full details.


12. Audit Rights

We will make available information and documentation reasonably necessary to demonstrate compliance with this DPA and Data Protection Laws, including:

  • Summaries of our security policies and procedures
  • Security certifications, attestations, or third-party audit reports (such as SOC 2 Type II, if available)
  • Descriptions of technical and organisational security measures
  • Sub-processor lists and agreements

We will cooperate with audits and inspections conducted by Supervisory Authorities.


13. International Data Transfers

Data Storage Location: Personal Data is stored on servers in European Economic Area (EEA), which is within the European Economic Area (EEA).

Processing Within the EEA: All primary processing of Personal Data occurs within the EEA. This is not considered an international transfer under the GDPR.

Transfers to Third Countries: If any Sub-processor Processes Personal Data in a country outside the EEA without an EU adequacy decision ("Third Country"), we will ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (2021): The standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914)
  • Binding Corporate Rules (BCRs): Binding corporate rules approved by competent supervisory authorities pursuant to Article 47 GDPR
  • EU Adequacy Decisions: Transfers to countries for which the European Commission has adopted an adequacy decision pursuant to Article 45 GDPR

Transfer Risk Assessments: Where required, we conduct transfer risk assessments to evaluate whether the destination country's laws and practices may impair safeguard effectiveness and, if necessary, implement supplementary measures.

Customer Rights: You may request information about safeguards for international transfers by contacting privacy@veysur.com. We will provide a copy of relevant safeguards (which may be redacted to protect confidential information).


14. Term and Termination

This DPA is effective from the date you first use the Services and continues for as long as we Process Personal Data on your behalf.

This DPA terminates upon the earlier of:

  • 1 month after your account enters Terminated status
  • Expiration or termination of the Terms of Service

Account suspension does not terminate this DPA; it remains in effect during the suspension period.

Upon termination of this DPA:

  • Our obligation to Process Personal Data ceases (except as required by Section 11.7)
  • Section 11 (Deletion and Return of Data) applies
  • You must cease accessing the Services (if not already terminated)

The following provisions survive termination: Section 5 (Confidentiality), Section 11 (Deletion and Return of Data), Section 15 (Liability and Indemnification), Section 16 (Governing Law and Disputes), and any other provisions that by their nature should survive.


15. Liability and Indemnification

Liability for damages arising from Processing of Personal Data is governed by Articles 82-83 of the GDPR. You are liable for damages caused by Processing that violates Controller obligations. We are liable for damages caused by Processing that violates Processor obligations, or where we have acted outside or contrary to your lawful instructions. We are not liable if we prove we are not in any way responsible for the event giving rise to the damage.

Where both parties are involved in the same Processing and both liable, each party shall be held liable for the entire damage to ensure effective compensation of Data Subjects. However, a party that has paid full compensation may claim back from the other party the portion corresponding to their part of responsibility.

Indemnification: We will indemnify you against claims arising from our breach of this DPA, our violation of Data Protection Laws as Processor, or our negligent or wrongful Processing. You will indemnify us against claims arising from your breach of this DPA, your violation of Data Protection Laws as Controller, your unlawful instructions, or your failure to obtain necessary consents or provide required notices to Data Subjects.

These indemnification obligations are subject to liability limitations in the Terms of Service, except where Data Protection Laws prohibit such limitations. The remedies in this Section and in Data Protection Laws are your sole and exclusive remedies for claims related to Processing of Personal Data under this DPA.


16. Governing Law and Disputes

This DPA and any disputes arising from it are governed by the laws of the EU Member State in which you are established. Disputes will be resolved in accordance with the dispute resolution procedures in the Terms of Service.

Jurisdiction: Business customers: the courts of the EU Member State in which you are established have exclusive jurisdiction. Consumer customers: you may bring proceedings in your home courts, and we may only bring proceedings against you in your home courts.

Nothing in this Section affects the rights of Data Subjects or Supervisory Authorities under Data Protection Laws, including the right to lodge complaints with Supervisory Authorities.


17. Changes to This DPA

We may update this DPA to reflect changes in our Processing activities, security practices, applicable laws, regulatory guidance, or industry standards.

Notice: For material changes, we will notify you at least 1 month in advance via email and/or prominent notice within the Services dashboard. Continued use of the Services after the effective date constitutes acceptance. If you do not agree, you may terminate your account within 1 month.

Non-Material Changes: We may make non-material changes (corrections, clarifications, formatting updates) without advance notice. The "Last Updated" date at the top reflects the most recent changes.


18. Contact Information

Data Protection Inquiries: privacy@veysur.com (VeySur Limited does not currently have a designated Data Protection Officer)

General DPA Questions: support@veysur.com

Company Information:

  • Company Name: VeySur Limited
  • Registered Address: c/o DoES Liverpool, 1st Floor, The Tapestry, 68-76 Kempston Street, Liverpool, L3 8HL, United Kingdom
  • Company Registration: England and Wales (United Kingdom), Registration Number: 17297318
  • Website: https://www.veysur.com

Supervisory Authority: You have the right to lodge a complaint with the relevant Data Protection Authority in your EU Member State. The relevant Supervisory Authority depends on your EU Member State of establishment. As VeySur processes data for customers across multiple EU Member States, you may lodge a complaint with the Data Protection Authority in your Member State.

For a list of Data Protection Authorities in EU Member States, please visit: https://edpb.europa.eu/about-edpb/about-edpb/members_en


Appendix A: Technical and Organizational Measures

This appendix provides additional detail on the technical and organisational security measures referenced in Section 6 of this DPA.

A.1 Access Control Measures

  • Unique user accounts for all personnel with access to Personal Data
  • Multi-factor authentication (MFA) for administrative and privileged access
  • Role-based access control (RBAC) with principle of least privilege
  • Regular access reviews and prompt deprovisioning of terminated personnel
  • Strong password policies (minimum complexity)
  • Session timeout and automatic logout mechanisms

A.2 Transmission Control Measures

  • TLS/HTTPS encryption for all data in transit
  • Secure API authentication using API keys and tokens

A.3 Storage and Encryption Measures

  • Encryption at rest for databases containing sensitive Personal Data
  • Encrypted backups
  • Secure key management

A.4 Separation and Pseudonymisation

  • Multi-tenancy architecture ensuring customer data segregation
  • Database-level isolation between customer accounts
  • Pseudonymisation and anonymisation where technically feasible
  • Logical separation of production and development environments

A.5 Availability and Resilience Measures

  • Redundant infrastructure with failover capabilities
  • Regular automated backups
  • Backup testing and restoration procedures

A.6 Incident Detection and Response

  • Documented incident response plan
  • Security incident escalation procedures

A.7 Testing and Evaluation

  • Annual vulnerability assessments and penetration testing
  • Regular security patch management and updates
  • Code security reviews and static analysis
  • Continuous monitoring of security advisories

A.8 Physical Security

  • Environmental controls (fire suppression, cooling, power redundancy)
  • Primary data centre: European Economic Area (EEA)

A.9 Personnel Security

  • Confidentiality agreements with all employees and contractors
  • Data protection and GDPR training for relevant personnel
  • Clear acceptable use and security policies

A.10 Supplier and Sub-Processor Management

  • Due diligence assessments of Sub-processors' security measures
  • Contractual security and data protection requirements
  • Regular review of Sub-processor compliance
  • Sub-processor breach notification obligations

END OF DATA PROCESSING AGREEMENT

VeySurVeySurAsk. Analyse. Act.

Product

ContactDocsBlog

Legal

Legal NoticePrivacy PolicyTerms of ServiceDPA (UK)DPA (EU)EU Data Act

© 2026 VeySur. All rights reserved.