Skip to content

Data Processing Addendum

Effective September 18, 2026 · Last updated

For customers subject to GDPR and similar laws: this addendum sets out how HumanPanel handles personal data in your surveys on your behalf. It applies automatically when you accept our Terms.

1. Scope and roles

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Customer”) and HumanPanel (“HumanPanel”). It applies when HumanPanel processes personal data contained in Customer's survey content or Results (“Customer Personal Data”) on Customer's behalf, in connection with data protection laws such as the EU and UK GDPR.

For Customer Personal Data, Customer is the controller and HumanPanel is the processor. For account, security and billing data about Customer's own users, HumanPanel is an independent controller as described in the Privacy Policy.

2. Details of processing

Subject matterProviding the HumanPanel Service: generating simulated survey respondents, answers, statistics and summaries.
DurationFor the term of the Terms, plus the deletion period in section 9.
Nature and purposeStorage, transmission to subprocessors, generation and display of Results, solely to provide the Service.
Types of personal dataAny personal data Customer chooses to include in surveys, such as names or descriptions of people. The Service does not require personal data in survey content.
Data subjectsIndividuals who Customer references in survey content.
Special categoriesNone intended. Customer must not include special category data unless it has a lawful basis and has told us in advance.

3. Customer instructions

HumanPanel processes Customer Personal Data only on Customer's documented instructions, which are the Terms, this DPA and Customer's use of the Service, unless required by law, in which case we will inform Customer unless the law prohibits it. We will tell Customer if we believe an instruction infringes data protection law. We do not use Customer Personal Data to train AI models or for any other purpose of our own.

4. Confidentiality

Personnel authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide, secure and support the Service.

5. Security measures

HumanPanel maintains appropriate technical and organizational measures, including:

  • encryption of data in transit using TLS;
  • email one-time-code authentication, with codes and session tokens stored only as hashes;
  • rate limits on sign-in attempts and verification of signed payment webhooks;
  • account-level authorization on every request, so customers can access only their own data;
  • least-privilege access to production systems for our team;
  • use of reputable infrastructure and service providers with their own security programs.

6. Subprocessors

Customer authorizes HumanPanel to use the following subprocessors:

SubprocessorPurpose
AI model providers (OpenAI and/or Anthropic)Generating worlds, simulated respondents, answers and summaries
Google (Gmail API)Sending service emails, such as run notifications
Cloud hosting and database providersHosting the Service and storing data

HumanPanel imposes data protection obligations on subprocessors that are no less protective than this DPA and remains responsible for their performance. We will update this list before adding or replacing a subprocessor. Customer may object on reasonable data protection grounds by emailing contact@humanpanel.ai within 30 days of the update; if we cannot reasonably accommodate the objection, Customer may stop using the Service and receive a refund of unused wallet funds.

7. Data subject requests and assistance

Taking into account the nature of the processing, HumanPanel will assist Customer by appropriate measures in responding to requests from data subjects and, where required, with data protection impact assessments and consultations with supervisory authorities. If we receive a request directly from a data subject about Customer Personal Data, we will refer it to Customer.

8. Personal data breaches

HumanPanel will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include the information reasonably available to us to help Customer meet its own obligations, and we will take reasonable steps to contain and remediate the breach.

9. Deletion

Customer can delete surveys, together with their runs and Results, in the Service at any time. When the Terms end, or on Customer's request, HumanPanel will delete Customer Personal Data within 30 days, unless law requires us to keep it. Data in backups is overwritten on our normal backup cycle.

10. Audits

HumanPanel will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including written responses to reasonable security questionnaires no more than once a year, unless a supervisory authority requires more.

11. International transfers

Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the parties agree to the European Commission's Standard Contractual Clauses (Module Two, controller to processor, and Module Three where applicable), the UK International Data Transfer Addendum and equivalent Swiss adjustments, which are incorporated into this DPA by reference.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms, except where law does not permit it. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data.

This DPA applies automatically when Customer accepts the Terms. If Customer needs a countersigned copy, email contact@humanpanel.ai.