Skip to content

Data Processing Agreement

DRAFT — for counsel review, not legal advice. This document is first-pass content produced as part of the Canadian legal compliance program. Review with legal counsel before relying on it.

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Ideas Builder user (“Controller”) and Ideas Builder (“Processor”) for the processing of personal information that the Controller collects through the Service — primarily survey respondent data, audience panel data, and imported contacts.

  • Controller — you, the user: you decide the purposes and means of processing respondent/panel data you collect through the Service.
  • Processor — Ideas Builder: we process that data only on your documented instructions.

We process personal information only to provide the Service: storing responses, delivering surveys, generating analysis, and managing contacts. We will never use your respondent data for our own purposes, nor sell, rent, or reuse it across organizations. We will not process it for incompatible purposes.

The Controller agrees we may engage the sub-processors listed in the Privacy Policy (section 4): Tencent Cloud (hosting), Cloudflare, Stripe/Lemon Squeezy, SurveyMonkey, Brevo, and LLM providers used for analysis. Each is bound by contract to protect the data and process it only for the stated purpose. A current list is available on request from legal@idea-builder.org.

Data may be processed in mainland China, the United States, and other locations of our sub-processors. For transfers from Canada we rely on contractual safeguards (data-processing terms with each sub-processor, and appropriate technical measures).

We apply appropriate technical and organizational measures: encryption in transit (TLS), encrypted credentials storage, per-user access controls, admin access auditing, and a documented incident response process (see the breach runbook).

We will assist the Controller in responding to access, correction, deletion, and portability requests from respondents, within legal timeframes and at no extra cost where feasible.

We delete or anonymize respondent data per the retention windows in the Privacy Policy (365 days for survey responses, 730 days for imported contacts). On Controller’s account deletion we delete or anonymize the associated data, subject to legal holds.

We will notify the Controller without undue delay upon becoming aware of a personal information breach affecting Controller data, with the information reasonably available, consistent with our obligations under PIPEDA and Quebec Law 25.

The Controller may request reasonable information demonstrating our compliance with this DPA. This does not extend to access to other users’ data.

This DPA continues with the Terms of Service and terminates with the Controller’s account. On termination we delete or anonymize Controller data per section 7.

Last updated: 2026-08-09 (version 2026-08-09-v1).

Was this page helpful?