This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Terms") between Highline Beta Inc. ("Highline Beta", "we", "us"), which provides Candor (the "Service"), and the customer that accepts those Terms ("Customer", "you"). It applies automatically whenever we process personal data on your behalf through the Service. You don’t need to sign anything for it to apply. If your organization needs a countersigned copy, email ben@highlinebeta.com.
1. Definitions
- Data Protection Law means every law that applies to our processing of Customer Personal Data, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, Canada’s PIPEDA and provincial privacy laws, the California Consumer Privacy Act ("CCPA"), and Japan’s Act on the Protection of Personal Information.
- Customer Personal Data means personal data contained in the content you or your users submit to the Service for research, and in the outputs the Service generates from it, that we process on your behalf. It does not include the data we control ourselves under section 2.
- Subprocessor means a third party we engage that processes Customer Personal Data.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Standard Contractual Clauses means the clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
"Controller", "processor", "data subject", "personal data" and "processing" have the meanings given in the GDPR.
2. Roles and scope
You are the controller of Customer Personal Data, or a processor acting for your own clients. We are your processor, or your subprocessor. Annex 1 describes the processing: whose data, what data, and why.
Some data we process as a controller in our own right, not on your behalf, and this DPA does not cover it:
- account and billing details for you and your users;
- records of how the Service is used, such as logs, sign-in and audit records, and session recordings made when a user has accepted analytics cookies (a recording can show workspace content that was on screen);
- conversations with the in-app help assistant;
- answers to our feedback questions.
Our Privacy Policy explains how we use that data.
3. How we process Customer Personal Data
We process Customer Personal Data only on your documented instructions. Those instructions are the Terms, this DPA, and the way you use and configure the Service. Together they let us process Customer Personal Data to provide, support, secure and improve the Service for you, as the Terms describe. We’ll tell you if we believe an instruction breaks Data Protection Law. We don’t process Customer Personal Data for any other purpose unless a law requires it, and where the law allows, we’ll tell you before we do.
We will not:
- sell or share Customer Personal Data, as the CCPA uses those words;
- use Customer Personal Data to train AI models, or allow any Subprocessor to do so;
- combine Customer Personal Data with personal data from other customers or sources, except as needed to provide the Service.
4. Your responsibilities
You’re responsible for having a lawful basis for the data you submit and for giving people any notice the law requires. The Service is not built for special categories of personal data (such as health data or data revealing ethnic origin), government identifiers, financial account numbers, or data about children. Don’t submit that kind of data unless we have agreed in writing to accept it. Where you can, remove or anonymize personal details before you upload research material.
5. Our people
Only staff who need access to operate or support the Service can reach Customer Personal Data, and each of them is bound by a duty of confidentiality.
6. Security
We maintain the technical and organizational measures in Annex 2, and we may improve them over time. We won’t reduce the overall level of protection they provide during the term of the Terms.
7. Subprocessors
You authorize us to use the Subprocessors listed on our subprocessors page. We only use a Subprocessor under written terms that include data protection obligations, and we remain responsible to you for the obligations in this DPA when a Subprocessor carries out processing for us. What each one receives is listed on that page.
We’ll give you at least 30 days’ notice by email before adding a new Subprocessor. You may object on reasonable data protection grounds within that window by emailing ben@highlinebeta.com. We’ll work with you in good faith to resolve the objection. If we can’t, you may close your account before the new Subprocessor starts processing your data, and we won’t charge you for any period after that.
8. International transfers
Highline Beta is based in Canada, and the Service is hosted in the United States. Our Subprocessors’ locations are listed on the subprocessors page. Where Customer Personal Data moves from the European Economic Area to a country without an adequacy decision, the Standard Contractual Clauses apply and are incorporated into this DPA by reference, as follows:
- Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) applies where you are a processor. You are the data exporter and we are the data importer.
- Clause 7 (the docking clause) applies.
- Under Clause 9, Option 2 (general written authorization) applies, with the notice period in section 7 of this DPA.
- The optional wording in Clause 11 does not apply.
- Under Clause 13, the competent supervisory authority is the one set by that clause for your situation. Where no other authority applies, it is the Irish Data Protection Commission.
- Under Clauses 17 and 18, the clauses are governed by the law of Ireland, and disputes go to the courts of Ireland.
- Annex I of the clauses is completed by Annex 1 of this DPA, Annex II by Annex 2, and Annex III by the subprocessors page.
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the Standard Contractual Clauses (version B1.0) applies, completed with the information above and in the annexes. For transfers from Switzerland, the Standard Contractual Clauses apply with the changes Swiss law requires: the Swiss Federal Data Protection and Information Commissioner is the competent authority, and references to Member States include Switzerland.
If the Standard Contractual Clauses conflict with the rest of this DPA or the Terms, the clauses win.
9. Requests from individuals
The Service lets your users export their data and delete their accounts from their settings, and lets a workspace Owner delete the workspace. If we receive a request from an individual about Customer Personal Data, we’ll pass it to you and won’t answer it ourselves unless you ask us to. Requests about the data we control under section 2 we answer ourselves, as the Privacy Policy describes. We’ll give you reasonable help to respond to requests you can’t handle through the Service.
10. Other help we provide
We’ll give you reasonable help with data protection impact assessments and consultations with supervisory authorities, to the extent they concern our processing and you can’t get the information elsewhere.
11. Security Incidents
We’ll notify you without undue delay, and in any case within 72 hours, after we become aware of a Security Incident affecting your Customer Personal Data. We’ll tell you what we know about its nature and likely effects, the steps we are taking to contain it, and a contact for more information. We send the notice to your workspace Owners by email. A notice is not an admission of fault.
12. Audits
On request, we’ll provide the information you reasonably need to show that we comply with this DPA. That includes answering a security questionnaire once a year and passing on our Subprocessors’ security reports where their terms allow. If that information is not enough to meet a legal requirement, or after a Security Incident, you may audit our processing yourself or through an independent auditor. An audit needs 30 days’ written notice, takes place during business hours, happens no more than once in any 12 months unless a regulator requires it, is at your cost, and is subject to confidentiality.
13. Deletion and return
You can export and delete your data through the Service at any time. When the Terms end, we’ll delete Customer Personal Data within 30 days, unless a law requires us to keep it. Copies in our hosting provider’s backups are removed as those backups expire. Copies held by our AI and search Subprocessors follow each provider’s own retention terms. Data we control under section 2 is kept as the Privacy Policy describes. We’ll confirm deletion in writing if you ask.
14. Liability and order of precedence
Each party’s liability under this DPA is subject to the limitation of liability in the Terms, except where the Standard Contractual Clauses or Data Protection Law do not allow it. If this DPA conflicts with the Terms, this DPA wins on data protection matters.
15. Governing law and changes
This DPA is governed by the same law as the Terms, except for the Standard Contractual Clauses, which follow section 8. We may update this DPA to reflect changes in law or in the Service. If a change reduces your protection in a material way, we’ll give you notice as the Terms describe before it takes effect.
Annex 1: Details of the processing
- Data exporter: the Customer, contactable through the email address of its workspace Owner. Role: controller, or processor for its own clients.
- Data importer: Highline Beta Inc., 372 Bay St., Suite 200, Toronto, ON M5H 2W9, Canada, ben@highlinebeta.com. Role: processor, or subprocessor.
- Data subjects: any people whose personal data you include in study inputs or uploaded material, such as your customers, prospects, employees or authorized users. The synthetic participants the Service generates are not real people.
- Categories of data: whatever personal data you choose to include in the content you submit (study descriptions, research objectives, concepts to test and uploaded documents) and in the outputs generated from it (synthetic participants, interview transcripts and reports).
- Special categories of data: none intended. Section 4 applies.
- Frequency: continuous, for as long as you use the Service.
- Nature and purpose: hosting and storing your content; analyzing it with AI models and web research to generate synthetic participants, simulated interviews and reports; and support.
- Duration and retention: for the term of the Terms, then deleted as section 13 describes.
- Transfers to Subprocessors: as listed on the subprocessors page, for the purposes shown there.
Annex 2: Security measures
- Encryption: data is encrypted in transit with TLS and encrypted at rest by our hosting providers.
- Separation and access control: every record belongs to one workspace, and the Service checks a user’s workspace membership and role (Owner, Admin, Editor or Viewer) before reading or writing workspace data. Database row-level security is switched on for every table. Uploaded research documents sit in private storage and are reached only through time-limited signed links.
- Sign-in: passwords of at least 12 characters, with known breached passwords rejected everywhere a password is set; optional authenticator-app two-factor authentication, which workspace Owners can make mandatory; optional Google sign-in; a bot check and rate limits on sign-up, and our authentication provider’s rate limits on sign-in.
- Staff access: only platform administrators can view a workspace they are not invited to. They must use two-factor authentication, must verify again before sensitive actions, and every view is logged. A record of who holds administrator access is taken monthly for review.
- Logging: an append-only audit log records who did what, when, and from which IP address. Nobody can edit or delete an entry. If a user or workspace is deleted, its entries stay, but the link to that user or workspace is removed.
- Error monitoring: request bodies, query strings, cookies and sign-in headers are removed from error reports before they leave the Service.
- Application protection: security headers that prevent the Service being framed by other sites, and a check that refuses web addresses pointing to internal networks when the Service fetches a page you give it.
- Vendors: we only use Subprocessors under written terms, and the AI providers are barred from training on the data they receive.
Questions about this DPA? Email ben@highlinebeta.com.