Data Processing Agreement
Last updated: August 14, 2026
Reference translationThis English translation is provided for convenience only. TheJapanese version is the authoritative version. If there is any inconsistency or discrepancy between the Japanese version and this translation, the Japanese version will prevail.
1. Scope and parties
This Data Processing Agreement (the "DPA") applies between Jumpei Takiyasu, a sole proprietor based in Japan ("we", "us"), and you as a customer of the Service, whenever we process personal data on your behalf. This DPA forms part of the Terms of Service.
For the response data collected through surveys you create, you determine the purposes and means of processing. Accordingly you act as the controller, or — where you use the Service on behalf of a third party (for example as an agency or consultancy) — as that third party's processor; and we act as your processor or subprocessor respectively. References in this DPA to our obligations as a processor apply equally where we act as a subprocessor. If you use the Service on behalf of a third party, you represent and warrant that you have the necessary authorization from that party.
For processing where we determine the purposes ourselves — account data and similar — we are the controller, and the Privacy Policy applies instead of this DPA. Providers we use as a controller are not subprocessors under this DPA (see section 2 of theSubprocessors page).
The purpose of this DPA is to set out the matters required by Article 28(3) of the GDPR where the EU or UK GDPR applies to your processing. Where this DPA and the Terms of Service conflict, this DPA prevails in respect of the processing of personal data.
2. Details of processing
As required by Article 28(3) GDPR:
| Subject matter and duration | For as long as you use the Service, and until the deletion described in section 9 is complete |
|---|---|
| Nature and purpose | Delivering surveys; receiving, storing, aggregating, analyzing and exporting responses; providing the AI features you explicitly invoke; and operations incidental to providing the Service |
| Categories of personal data | The fields your survey collects (name, email address, phone number, address, free-text answers and so on — this depends on how you design the survey), together with associated data such as timestamps, invitation token state, and acquisition parameters |
| Categories of data subjects | Respondents to your surveys (your customers, employees, event attendees, and similar) |
You will not collect special categories of personal data or other highly regulated information through the Service unless we have expressly stated that we support that use (see section 5 of theTerms of Service).
3. Processing on documented instructions
We treat this DPA, the Terms of Service, and the configuration and operations you carry out through the Service's features as your documented instructions, and we process personal data only in accordance with them.
This does not apply where processing is required by a law to which we are subject. In that case we will inform you before processing, unless that law prohibits such information on important grounds of public interest.
If we consider that an instruction infringes applicable data protection law, we will inform you without delay.
4. Confidentiality
We ensure that persons involved in processing personal data are bound by confidentiality obligations, or are under an appropriate statutory obligation of confidentiality.
5. Security
We implement appropriate technical and organizational measures having regard to the risk (Article 32 GDPR), including encryption in transit, authentication and authorization, tenant isolation, access control, monitoring, and backups. Specific measures may change as technology evolves, provided the level of protection is not reduced.
6. Subprocessors
You give general authorization for us to engage the providers listed in section 1 of ourSubprocessors page as subprocessors. The providers in section 2 of that page are ones we use as a controller and are not subprocessors under this section.
We will normally give at least 30 days' notice before adding or changing a subprocessor. You may object on reasonable grounds, and if we cannot offer an alternative within a reasonable period you may terminate the affected part of the Service.
For AI features, our direct subprocessor is OpenRouter, Inc.. Individual AI model providers are subprocessors of OpenRouter, Inc. and are not covered by the advance notice above. Where you select a model or its provider at run time, that selection is treated as your specific instruction and authorization for processing by that provider.
We impose on each subprocessor, by contract, obligations substantially equivalent to those we owe under this DPA. Where a subprocessor fails to fulfil its obligations, we remain liable to you.
7. Assistance with data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to data subject requests. The Service provides features to view, export, and delete response data, so you can handle most requests yourself.
If we receive a request directly from a data subject, we will not respond to it ourselves — except where we are legally required to do so — and will forward it to you without undue delay.
8. Breach notification and further assistance
If we become aware of a personal data breach affecting personal data we process for you, we will notify you without undue delay and provide, to the extent known, the nature of the breach, the categories of data affected, and the measures taken or proposed.
Taking into account the nature of processing and the information available to us, we assist you in complying with your obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessment, prior consultation).
9. Deletion or return on termination
You can export (return) personal data using the Service's features before termination. After termination we will, at your choice, return or delete the personal data and delete existing copies, unless storage is required by law.
Personal data in the production environment is deleted within the period technically required to complete deletion, up to a maximum of 90 days. That period is a technical ceiling for completing deletion, not a general retention policy.
Personal data contained in backups persists only for the duration of our normal backup rotation. During that period we do not access it through ordinary means and do not use it for any new processing, and we do not restore it except where required by law or for disaster recovery. It is deleted when the rotation completes.
10. Information and audits
We make available to you, on reasonable request, the information necessary to demonstrate compliance with our obligations under this section.
You may carry out audits to the extent required by applicable law. Audits will normally take place no more than once per year, on at least 30 days' written notice, during our normal business hours, and in a manner that minimizes disruption to our operations. The auditor must be an independent auditor, must not be a competitor of ours, and must be bound by a confidentiality agreement. Audits do not extend to other customers' data, our source code, or credentials. For our trade secrets and other confidential information we will not refuse verification outright: we make compliance with this DPA verifiable by alternative means, such as redacted documentation, a screen-sharing walkthrough with us present, or third-party audit reports. Costs are borne by you.
Where we hold third-party audit reports or similar documentation, we may first offer that documentation in place of an audit; where it satisfies your legitimate audit purpose, you will not request a separate audit. The frequency limit above does not apply where required by law or following a personal data breach.
Where assistance with data subject requests, data protection impact assessments, or similar requires manual work beyond the ordinary scope, we may charge a reasonable fee to the extent permitted by applicable law.
11. International transfers
There are two separate legs, and they rest on different grounds. Do not conflate them.
(1) From EEA and UK customers to us
We are established in Japan, and Japan holds adequacy decisions from the European Commission and the United Kingdom. As a personal information handling business operator under the Japanese Act on the Protection of Personal Information, we comply with the Supplementary Rules issued by the Personal Information Protection Commission for personal data received from the EEA or the UK. Standard contractual clauses are therefore not required for this leg.
If an adequacy decision is withdrawn or suspended, or ceases to cover such a transfer, we will rely on the standard contractual clauses adopted by the European Commission (including the UK Addendum for UK transfers). The module used in that case is Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are yourself a processor.
(2) From us to subprocessors outside Japan
For each subprocessor listed in section 1 of theSubprocessors page — including those established in the United States — we put in place the lawful transfer mechanism required for that onward transfer. Because we engage them as a processor, where standard contractual clauses are used, Module Three (processor to processor) applies. The same holds where we act as a subprocessor.
Where adequacy ceases to be available, or standard contractual clauses are otherwise required for leg (1), the parties, the supervisory authority, the governing law, and the matters corresponding to the annexes are supplemented by this DPA and by theSubprocessors page; on request we will enter into the necessary standard contractual clauses with you.
For leg (2), we put in place the necessary standard contractual clauses or other lawful transfer mechanism with each subprocessor. The parties to those clauses are us and that subprocessor; you are not a party to them. On reasonable request we will provide information showing that such a mechanism is in place, within the limits of applicable law and our confidentiality obligations.
12. Liability
Our liability under this DPA is subject to the limitation of liability in theTerms of Service, except for liability that cannot be limited under applicable data protection law.
13. Governing law
This DPA is governed by the laws of Japan, without prejudice to the mandatory provisions of applicable data protection law, which prevail.
14. Contact
Questions about this DPA, or requests for a signed copy: contact form.
15. Authoritative version
The authoritative version of this DPA is the Japanese version. Translations into other languages are provided for convenience; if there is any discrepancy with the Japanese version, the Japanese version prevails.