Data Processing Agreement (DPA)

Last updated: 30 June 2026.

This Data Processing Agreement ("DPA") forms part of the agreement between The Future Mill LLC operating SortedResearch ("Processor", "we", "us") and the customer identified in the applicable order or account ("Customer", "Controller", "you") for use of the SortedResearch card-sorting platform (the "Service"). It governs our processing of participant study data on your behalf.

Where the Terms of Service and this DPA conflict regarding the processing of personal data, this DPA controls.


1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in the GDPR and UK GDPR. "Applicable Data Protection Law" means the GDPR, UK GDPR, and any other privacy or data protection law applicable to the processing, including the CCPA/CPRA. "Sub-processor" means a third party engaged by the Processor to process personal data.


2. Roles of the parties

  • For participant study data collected through your studies, you are the Controller and SortedResearch is the Processor.
  • SortedResearch is a separate, independent controller for researcher account, billing, usage, and support data, which is governed by our Privacy Policy, not this DPA.

For CCPA/CPRA purposes, SortedResearch acts as a service provider and will not sell or share personal information, nor retain, use, or disclose it except to provide the Service.


3. Subject matter and duration

The subject matter is the provision of the Service. The duration of processing is the term of your agreement with us, plus any post-termination period required to return or delete data (Section 12).


4. Nature and purpose of processing

We process participant study data solely to provide and support the Service in accordance with your documented instructions, including hosting, storing, displaying, analyzing, and enabling AI-assisted features on the data you collect.


5. Categories of data subjects and personal data

  • Data subjects: study participants (and any individuals identified in screener answers, if the Controller chooses to collect such data).
  • Categories of personal data:
    • Card placements and group names created by participants.
    • Screener question answers (only those the Controller configures).
    • Timing and quality metadata.
    • Any identifying information only if the Controller deliberately adds a screener question requesting it. Participants are otherwise anonymous by default.
  • Special category data: not intended to be collected. The Controller must not collect special category data via screeners without ensuring an appropriate lawful basis and safeguards.

6. Controller obligations

You will:

  • Ensure you have a lawful basis and any required consents/notices for the data you collect.
  • Issue only lawful instructions for processing.
  • Be responsible for the accuracy and lawfulness of the data you collect, including not collecting children's data without proper consent.

7. Processor obligations

We will:

  • Process personal data only on your documented instructions (including those in this DPA and the Service configuration), unless required by law (in which case we will notify you unless prohibited).
  • Ensure persons authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (Annex A).
  • Assist you, taking into account the nature of processing, with data-subject requests and your obligations regarding security, breach notification, and data protection impact assessments.
  • Make available information reasonably necessary to demonstrate compliance, and allow for audits (Section 11).

8. Confidentiality

We will keep personal data confidential and ensure our personnel and sub-processors are subject to appropriate confidentiality obligations.


9. Sub-processors

You provide general authorization for us to engage the sub-processors listed in Annex B. We will impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.

We will give you prior notice of any intended addition or replacement of a sub-processor (by email or a sub-processors page, with at least 30 days' notice). If you reasonably object on data protection grounds, the parties will work in good faith to resolve it; if unresolved, you may terminate the affected Service.


10. Data-subject requests and breach notification

  • Data-subject requests: If we receive a request from a participant relating to your data, we will, where legally permitted, direct them to you and assist you in responding.
  • Personal data breach: We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably available to help you meet your own notification obligations.

11. Audit rights

We will make available information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by you or an independent auditor you mandate, on reasonable prior notice, no more than once per year (except where required by a supervisory authority or following a breach), subject to confidentiality and minimizing disruption. We may satisfy audit requests by providing relevant certifications or third-party reports where available.


12. International transfers

Personal data is processed in the United States. For transfers from the EEA, UK, or Switzerland, the parties incorporate the EU Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum, which apply to such transfers under this DPA. The relevant SCC module is Module Two (Controller-to-Processor).


13. Deletion or return on termination

On termination or expiry of the Service, we will, at your choice, delete or return the personal data we process on your behalf, and delete existing copies, unless retention is required by law. You may export your data during the 30-day grace period before deletion (see the Terms and Privacy Policy).


14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.


Annex A: Technical and Organizational Security Measures

  • Encryption in transit (TLS) and encryption at rest.
  • Row-level security scoping each customer's data so customers can only access their own data.
  • Access controls: role-based, least-privilege internal access on a need-to-know basis; authentication managed via Supabase Auth with hashed passwords.
  • Network and infrastructure security through reputable hosting providers (Supabase, Vercel).
  • Logging and monitoring of application errors and system activity.
  • Automated backups and resilience through our database provider, with regular retention.
  • Incident response process for detecting, handling, and notifying breaches.
  • Vendor management of sub-processors with appropriate data protection terms.

Annex B: Sub-processors

Sub-processor Purpose Location
Supabase Database, authentication, hosting US
Vercel Application hosting US
Anthropic Powers the Graham AI assistant and AI features US
Stripe Payment processing US
Resend Transactional and support email US

International transfers to these sub-processors (EU/UK → US) are covered by SCCs and the UK Addendum.


How this DPA is entered into

This DPA is incorporated into the Terms of Service and applies to paid customers who act as controllers of participant data. A countersigned copy for your records is available on request at privacy@sortedresearch.com.