Data processing agreement
Last updated 1 September 2026.
Need this countersigned?
Email [email protected] with your institution's details and we will return an executed copy, with the Standard Contractual Clauses and the annexes below completed for your studies. If your institution prefers its own template, send it and we will review it.
This agreement applies where you use VibeMyExpt to process personal data and data protection law applies to you. It supplements the terms of service. In it, "controller" and "processor" have the meanings given in the GDPR.
1. Roles
You — the researcher and your institution — are the controller for personal data your studies collect. ALPHAKHOJ LLP is your processor for that data and processes it only on your documented instructions, which consist of these terms, your configuration of the service, and any further written instruction you give us.
We are an independent controller for the account, wallet, billing and service-communication data described in our privacy policy. This agreement does not cover that processing.
If we consider an instruction to breach data protection law, we will tell you and may pause that processing until it is resolved.
2. Our obligations
- Process personal data only on your instructions, including for transfers.
- Ensure everyone we authorise to process it is bound by confidentiality.
- Apply the technical and organisational measures set out in Annex B.
- Engage subprocessors only under Section 3.
- Assist you, taking account of the nature of processing, in responding to data subject requests. In practice: participants are pseudonymous to you, we surface each participant's consent record, and you can delete selected runs and their recordings yourself from the Data tab.
- Assist you with your obligations on security, breach notification, data protection impact assessments and prior consultation.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own notifications.
- On termination, delete or return your data at your choice, except where we must retain it by law.
- Make available the information needed to demonstrate compliance and allow audits — see Section 6.
3. Subprocessors
You give general authorisation for the subprocessors listed on our subprocessors page, which is incorporated into this agreement. We are putting back-to-back data protection terms in place with each of them, no less protective than those in this agreement, and we remain liable to you for their performance regardless. We will confirm the position for any specific subprocessor on request.
We will update that page before a new subprocessor begins processing, and will notify you in advance if you have asked to be on the notification list. If you reasonably object on data protection grounds, tell us within 30 days and we will work with you on an alternative; if none is workable, you may terminate the affected service.
4. International transfers
ALPHAKHOJ LLP is established in India, which does not benefit from a European Commission adequacy decision. Where you transfer EEA or UK personal data to us, the transfer is made under the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914):
- Module Two (controller to processor) where you are the controller, which is the normal case.
- Module Three (processor to processor) where you are yourself acting as a processor for another controller.
For UK transfers, the UK International Data Transfer Addendum applies to those clauses. Docking clause: optional. Clause 9: Option 2, general written authorisation, with 30 days' notice. Clause 11: the optional independent dispute resolution body is not used. Clause 17: the law of Ireland. Clause 18(b): the courts of Ireland.
A transfer impact assessment covering Indian law, including the Digital Personal Data Protection Act 2023 and government access powers, is available to institutions on request.
If your policy does not permit the transfer at all: we are open to running a dedicated instance inside the EEA or the United States, with storage, database, email and AI inference pinned to that region, or to a self-hosted installation on your own infrastructure so that no participant data reaches us. Both are arranged as part of an institutional agreement. Tell us what your policy requires and we will scope it with you — see the security overview.
5. Security and breach
Our measures are described in Annex B and in the security overview, which states plainly which controls are in place and which are not. We may update them as the service evolves, provided the level of protection is not reduced.
6. Audit
We will respond to reasonable questionnaires — including a completed HECVAT — and provide documentation on request. Where that is not sufficient for your obligations, you may audit once in any twelve months on 30 days' notice, during business hours, without disrupting the service and subject to confidentiality. We may charge reasonable costs for audits beyond that.
Annex A — Details of processing
- Subject matter and duration
- Hosting and delivery of online behavioural studies, for as long as your account is active or you keep data on the platform.
- Nature and purpose
- Collecting, storing, structuring and making available participant responses so you can run and analyse your research; delivering study materials to participants; making rewards payable.
- Categories of data subject
- Participants you recruit, and collaborators you add to your studies.
- Categories of personal data
- Pseudonymous participant identifiers; responses and timings; browser and device details (browser, operating system, screen and window size, timezone, language); consent records including any typed signature; voice or video recordings where your study collects them; anything further your own study materials request.
- Special category data
- Only where your study design collects it and your ethics approval and Article 9 condition cover it. We do not accept protected health information under HIPAA.
- Frequency
- Continuous for the duration of data collection.
- Retention
- As you configure per study. Where you set no period, until you delete it. Generated exports are deleted after 7 days.
Annex B — Technical and organisational measures
- Encryption in transit (TLS 1.2/1.3, HSTS) and at rest for the database and object storage.
- Pseudonymisation: researchers see a random participant identifier, never a name or email address, on any screen or export.
- Role-based access control, with raw participant data restricted to data-viewer role and above.
- Passwords hashed with bcrypt; sessions in httpOnly cookies with server-side revocation.
- Rate limiting that fails closed, and cross-site request forgery protection by origin allowlist.
- Sandboxed, separate-origin execution of experiment and analysis code.
- Append-only audit logging of exports, deletions, publishes and code changes.
- Version pinning and per-participant consent snapshots for research integrity.
- Automated deletion: per-study retention windows, and 7-day expiry of generated exports.
- Private object storage with public access blocked and time-limited signed URLs.
Measures not currently in place, stated for completeness: multi-factor authentication, an independent penetration test, and SOC 2 / ISO 27001 certification.
Annex C — Subprocessors
| Provider | Purpose | Processed in |
|---|---|---|
| Amazon Web Services (S3, SES) | File storage, stimuli, recordings, exports, outbound email | India (ap-south-1) |
| MongoDB Atlas | Primary database | India |
| Cloudflare | DNS, TLS termination, DDoS protection | Global edge network |
| Google Cloud (Vertex AI) | AI experiment building and analysis assistance | United States |
| Anthropic | AI experiment building and analysis assistance | United States |
| Google (OAuth sign-in) | Optional "Sign in with Google" | United States |
| Google Analytics | Website usage statistics on marketing pages only | United States |
| Razorpay / RazorpayX | Payments in, participant reward payouts | India |