Courtesy translation. In case of any discrepancy, the Spanish version at `/legal` prevails.
Contractual document between the Client (Data Controller) and Camaleonic Survey (Data Processor), pursuant to art. 28 GDPR.
Last updated: 20 July 2026
0. Brief summary (read first)
In plain language, these Data Processing Terms govern the following:
- Who is who. When an organisation (the Client) creates a survey and collects responses from individuals (the respondents or participants), the Client decides what is asked, of whom, and for what purpose. Accordingly, with respect to respondent data, the Client is the Data Controller and Camaleonic Survey is the Data Processor: Camaleonic Survey processes such data on behalf of the Client and in accordance with its instructions.
- What this document covers. Only the personal data of respondents processed through the Camaleonic Survey platform. It does not cover the Client's own account data (registration, subscription, billing), with respect to which Camaleonic Survey acts as an independent Controller and which is governed by the Privacy Policy, not by these Data Processing Terms.
- What Camaleonic Survey commits to do. Process data only in accordance with the Client's instructions; require confidentiality from its personnel; apply security measures; use only the listed providers (sub-processors) and inform the Client if they change; assist the Client in responding to respondents who exercise their rights; assist the Client in the event of a security breach; and, upon termination, delete or return the data as the Client chooses.
- Where the data is (honestly). The primary storage of responses takes place in the European Union: the managed database (Supabase) is hosted in the EU. The application runs on Amazon Web Services (AWS) compute infrastructure. When the Client uses AI or machine translation features, the necessary content is transmitted on an ad hoc basis to providers that may process it in the United States (Groq, Anthropic, translation engines), and anti-bot protection (Cloudflare Turnstile) has global scope. Therefore, there are international transfers that require a legal mechanism (clause 7). It is not claimed that "everything is in the EU."
- On pseudonymisation (honestly). A hash is applied to the IP address, user-agent, and device identifier. This is pseudonymisation (a security measure that reduces risk), not anonymisation: it is not claimed that the result is "irreversible" or "anonymous."
- On AI. The service incorporates active artificial intelligence features applied to responses (for example, summaries, analysis, and machine translation), supported by inference providers acting as sub-processors: Groq (main provider, United States), Anthropic (multi-survey analysis and brand palette extraction from an image, United States), and machine translation engines (MyMemory and/or LibreTranslate). The safeguards of clause 9 apply, including the corresponding international transfer mechanism. AI outputs and Client content belong to the Client.
The full legal detail is set out in the following clauses. In case of interpretive doubt, the text of the clauses prevails over this summary.
1. Parties and identification
These Data Processing Terms (hereinafter, the "Data Processing Terms" or the "Terms") are entered into between:
- The Data Controller (hereinafter, the "Client" or "Controller"): the natural or legal person who contracts the Camaleonic Survey service, creates surveys, and determines the purposes and means of processing respondent data.
- The Client is identified by means of the electronic acceptance of these Data Processing Terms during the sign-up (onboarding) process and by the identifying data associated with its account (company or individual name, NIF/CIF, registered address, and representative). Such acceptance, recorded with a timestamp, perfects the Client's consent to these Terms and to the general authorisation of sub-processors under clause 5.4.
- The Data Processor (hereinafter, "Camaleonic Survey" or "Processor"): Camaleonic ads 2020 S.L., a Spanish company operating the service under the trade name Camaleonic Survey.
- General contact and data protection contact: [email protected].
Hereinafter, collectively, the "Parties".
1.1 Framework of the (hybrid) role model
Camaleonic Survey operates a hybrid role model, which should be clearly delimited to avoid confusion:
| Data set | Role of Camaleonic Survey | Applicable instrument |
|---|---|---|
| Respondent responses (subject matter of these Data Processing Terms) | Processor (on behalf of the Client) | These Data Processing Terms |
| Client account and billing data (registration, subscription, billing, support) | Controller | Camaleonic Survey Privacy Policy (not these Data Processing Terms) |
| Aggregated and anonymised analytics produced by Camaleonic Survey (statistical results that do not allow any person to be identified or any individual response to be reconstructed) | Controller | Outside the scope of these Data Processing Terms |
The complete processing chain is as follows: the respondent (data subject) provides their responses to the Client that created the survey (the Controller); the Client relies on Camaleonic Survey (the Processor); and Camaleonic Survey relies, in turn, on the sub-processors listed in Annex III (database and infrastructure, AI inference, machine translation and, for account data, payments). Each link in the chain is contractually bound to the previous one with equivalent data protection obligations. Camaleonic Survey is Controller only of its clients' account and billing data and of aggregated and anonymised analytics; respondents' personal data is never sold or commercialised.
These Data Processing Terms exclusively govern the relationship between the Client (Controller) and Camaleonic Survey (Processor) with respect to respondent data. They constitute a contractual instrument between the Client and Camaleonic Survey.
2. Subject matter, nature, purpose, and duration of processing (art. 28.3 GDPR)
2.1 Subject matter
The subject matter of these Data Processing Terms is to authorise Camaleonic Survey to process, on behalf of and in accordance with the Client's instructions, the personal data of respondents collected and processed through the Camaleonic Survey platform, for the sole purpose of providing the contracted service.
2.2 Nature of the processing
Processing operations (among others): collection, recording, structuring, storage, organisation, consultation, pseudonymisation, disclosure to the sub-processors strictly necessary for the service, restriction (logical deletion), and erasure (automatic purge). Processing is carried out by automated means.
2.3 Purpose
To provide the survey creation, distribution, collection, and processing service, including the presentation of results to the Client and associated operational functions (e.g., sending invitations, anti-bot protection, aggregation of responses). Camaleonic Survey will not process respondent data for its own purposes other than providing the service, with the sole exception of the preparation of aggregated and anonymised statistics expressly authorised in the Terms of Use and described in the Privacy Policy. The specific purposes of each processing activity are those determined by the Client (Controller) when configuring its surveys.
2.4 Duration
Processing will continue for as long as the service relationship between the Parties remains in force. Upon termination, clause 5.7 (erasure or return) will apply, and data will be retained only for the time legally required to address liabilities, prior to its erasure. Additionally, during the term, the technical retention periods described in Annex I apply: the Client may configure a per-survey retention period, upon expiry of which responses are automatically purged by a daily process, and, following the logical deletion of a response, the definitive automatic purge after 30 days applies.
The 30-day automatic purge period constitutes a standard technical measure of the service. The prior logical deletion is executed in accordance with the Client's instructions (clause 4) and is documented in the platform's activity log. The Processor does not apply additional retention periods on its own initiative; the retention periods legally required of the Client as Controller are determined and instructed by the Client.
3. Type of personal data and categories of data subjects (art. 28.3 GDPR)
3.1 Categories of data subjects
- Respondents / participants: natural persons who respond to the surveys created by the Client.
3.2 Types of personal data
Whenever processed:
- Responses to the survey questions.
- Language used to complete the survey.
- Duration of the response session.
- Timestamps.
- Technical data pseudonymised via hash: IP address, user-agent, and device identifier (device ID).
In surveys configured as anonymous, no direct identifiers of the respondent are collected, although pseudonymised technical identifiers (hashes of IP, browser, and device) may be processed for security and anti-abuse purposes; those hashes remain pseudonymised personal data and are protected as such.
As configured by the Client for each survey (optional):
- Email address of the respondent, when collected by the Client for optional purposes it determines (e.g., sending communications or marketing, subsequent contact, participation in a prize draw, or other purposes decided by the Client).
- Demographic data: age, gender, city.
When the Client collects the email address or other data for its own optional purposes (commercial or marketing communications, prize draws, subsequent contact), it is for the Client, as Controller, to: (i) determine and demonstrate the legal basis for each purpose (generally, consent under art. 6.1.a GDPR, obtained separately, specifically, and on an informed basis); and (ii) comply with the requirements for commercial communications by electronic means under art. 21 of Ley 34/2002 (LSSI-CE) (Spanish Information Society Services and E-Commerce Act) and the ePrivacy regulations (Directive 2002/58/EC and any rule replacing it). When Camaleonic Survey sends such communications on behalf of the Client (through the email-sending provider listed, where applicable, in Annex III), it will also act as Processor with respect to those purposes, in accordance with the Client's documented instructions.
3.3 Special categories of data (art. 9 GDPR)
The platform is not designed to collect special categories of data (health, ideology, religion, sexual orientation, biometric/genetic data, etc.). However, the Client, by freely drafting the questions, could induce the collection of such data.
- The Client undertakes not to configure surveys that collect special categories of data under art. 9 GDPR or data of minors without having the appropriate legal basis and having informed Camaleonic Survey.
- It is contractually prohibited to configure surveys aimed at collecting special categories of data (art. 9 GDPR) or data of minors, unless the Client: (i) has a valid legal basis (in particular, explicit consent under art. 9.2.a GDPR or, in the case of minors, the consent of the holder of parental authority or guardianship where applicable under art. 8 GDPR and art. 7 of LO 3/2018 (Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights)); (ii) has carried out, where required, the corresponding data protection impact assessment (art. 35 GDPR); and (iii) has given prior written notice thereof to Camaleonic Survey. Verification of age and of the existence of parental consent is the responsibility of the Client as Controller.
3.4 Notice regarding free-form content
Since the content of the questions is determined by the Client, the Client is solely responsible for the lawfulness, minimisation, and proportionality of the data it requests from respondents (arts. 5, 6, and, where applicable, 9 GDPR).
4. Instructions from the Controller
4.1 Documented instructions
The Client's instructions are documented by: (i) these Data Processing Terms and their Annexes; (ii) the configuration the Client performs on the platform (questions, audiences, collection options, deadlines); and (iii) any additional written instructions agreed by the Parties.
4.2 Processing not instructed
Camaleonic Survey will process data solely in accordance with such documented instructions, unless required to do otherwise by Union or Member State law applicable to it; in such case, Camaleonic Survey will inform the Client of that legal requirement before processing, unless such law prohibits this on important grounds of public interest (art. 28.3.a GDPR).
4.3 Instructions that infringe the regulations
Camaleonic Survey will immediately inform the Client if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions (art. 28.3, second paragraph, GDPR).
5. Obligations of the Processor (art. 28.3 GDPR)
5.1 (a) Processing in accordance with instructions
Process personal data only on documented instructions from the Controller, including those relating to international transfers, on the terms set out in clause 4 (art. 28.3.a GDPR).
5.2 (b) Personnel confidentiality
Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to personnel who need it to provide the service (art. 28.3.b GDPR).
5.3 (c) Security of processing (art. 32 GDPR)
Apply the appropriate technical and organisational measures to ensure a level of security appropriate to the risk, pursuant to art. 32 GDPR (art. 28.3.c GDPR). The measures already implemented are described in Annex II and include, among others:
- Encryption in transit (TLS) and encryption at rest.
- Isolation by organisation through Row-Level Security (RLS).
- Pseudonymisation via hashing of IP address, user-agent, and device ID. (Pseudonymisation, not anonymisation.)
- Configurable per-survey retention with daily automatic purge, logical deletion of responses, and definitive automatic purge after 30 days.
5.4 (d) Sub-processors (arts. 28.2 and 28.4 GDPR)
- General prior authorisation. The Client grants Camaleonic Survey a general written authorisation to engage other processors (sub-processors), pursuant to art. 28.2 GDPR.
- Published list. Camaleonic Survey maintains the updated list of sub-processors in Annex III (and, where applicable, on an equivalent public page).
- Notification of changes and right to object. Camaleonic Survey will inform the Client of any addition or replacement of sub-processors with at least 30 calendar days' notice, by communication to the email address associated with the Client's account and/or publication on the dashboard or on the public sub-processor page. The Client may object on reasoned grounds within that period. If Camaleonic Survey cannot offer a reasonable alternative that addresses the objection, the Client may, as its sole remedy, terminate the affected service without penalty.
- Same obligations. Camaleonic Survey will impose on each sub-processor, by contract, the same data protection obligations as those set out in these Data Processing Terms, in particular sufficient guarantees of implementing appropriate technical and organisational measures (art. 28.4 GDPR).
- Liability. Where a sub-processor fails to fulfil its data protection obligations, Camaleonic Survey will remain fully liable to the Client for the performance of that sub-processor's obligations (art. 28.4 GDPR).
5.5 (e) Assistance with data subject rights (Chapter III GDPR)
Assist the Controller, by appropriate technical and organisational measures, insofar as this is possible, so that it can respond to requests for the exercise of rights by respondents provided for in Chapter III of the GDPR (arts. 15 to 22: access, rectification, erasure, restriction, portability, objection) (art. 28.3.e GDPR).
- If a request from a respondent is addressed directly to Camaleonic Survey, it will forward it to the Client without undue delay and will not respond to it itself, unless instructed by the Client.
- The referral to the Client will take place without undue delay and, in any event, within five (5) business days of receipt of the request. Assistance beyond the standard functions available on the platform may be billed in accordance with the rates in force and the main service agreement, subject to prior notice to the Client of its estimated cost.
5.6 (f) Assistance with security, breaches, and DPIAs (arts. 32 to 36 GDPR)
Assist the Controller in ensuring compliance with the obligations under arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available (art. 28.3.f GDPR). In particular:
- Security (art. 32): maintain the measures set out in Annex II and cooperate in their assessment.
- Notification of security breaches (arts. 33 and 34): Camaleonic Survey will notify the Client without undue delay and, at the latest, within 48 hours of becoming aware of the incident involving a personal data breach. The notification will include, to the extent the information is available: the nature of the breach and the categories and approximate number of data subjects and records concerned; its likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point where more information can be obtained. Where it is not possible to provide the information simultaneously, it will be provided in phases without undue further delay, so that the Client can comply with its duties to notify the supervisory authority (art. 33 GDPR, which imposes on the Controller a maximum period of 72 hours) and to communicate with data subjects (art. 34 GDPR).
- Data protection impact assessment (DPIA) and prior consultation (arts. 35 and 36): provide the Controller with the information necessary about the processing carried out by Camaleonic Survey so that it can prepare, where applicable, the data protection impact assessment and, if appropriate, the prior consultation with the supervisory authority.
5.7 (g) Erasure or return upon termination (art. 28.3.g GDPR)
At the Controller's choice, delete or return all personal data once the provision of processing services ends, and delete existing copies, unless Union or Member State law requires their retention.
- Upon termination of the service, the Client will have a period of 30 calendar days to request the return of the data, which will be delivered in a structured, commonly used, and machine-readable format (e.g., CSV or JSON) by export from the platform. Once this period has elapsed without the Client requesting return, Camaleonic Survey will delete the data and its copies within a maximum period of 90 calendar days, unless there is a legal obligation to retain it. At the Client's request, Camaleonic Survey will certify the deletion by means of written certification.
5.8 (h) Information to demonstrate compliance and audits (art. 28.3.h GDPR)
Make available to the Controller all information necessary to demonstrate compliance with the obligations under art. 28 GDPR and to allow for and contribute to audits, including inspections, conducted by the Controller or an auditor authorised by the Controller.
- The Controller may audit compliance with the obligations under art. 28 GDPR once a year, with a minimum of 30 calendar days' prior notice, during business hours, without interrupting the service, and under a duty of confidentiality; an additional audit may be carried out in the event of a demonstrated security incident or a request from a supervisory authority. Prior to an on-site inspection, Camaleonic Survey may demonstrate compliance by means of valid third-party certifications or audit reports (e.g., ISO/IEC 27001 or SOC 2), which the Controller will accept as sufficient evidence where they reasonably cover the audited scope. The costs of the audit will be borne by the Controller, unless a material breach attributable to Camaleonic Survey is established.
6. Obligations of the Controller (Client)
The Client, as Controller, undertakes to:
- Determine and ensure the legal basis for processing (art. 6 and, where applicable, art. 9 GDPR) and the information provided to respondents (arts. 13-14 GDPR).
- Configure surveys in compliance with the principles of lawfulness, data minimisation, and proportionality (art. 5 GDPR).
- Issue lawful instructions and keep the processing configuration up to date.
- Not collect data for which it lacks a legal basis, including special categories or data of minors, without the required safeguards (see clause 3.3).
7. International data transfers (Chapter V GDPR)
Where data is stored and where it may be processed (honestly). The primary storage of surveys and respondent responses takes place in the European Union: the managed database (Supabase) is hosted in the EU. The application runs on Amazon Web Services (AWS) compute infrastructure. When the Client uses artificial intelligence or machine translation features, the strictly necessary content is transmitted on an ad hoc basis to the relevant providers (Groq, Anthropic, translation engines), which may process it in the United States; such ad hoc transmission does not change the place of storage. Anti-bot protection (Cloudflare Turnstile) has global scope. Therefore, international transfers of personal data subject to Chapter V of the GDPR (arts. 44 to 49) do exist where those features are used or where a sub-processor located outside the European Economic Area is involved.
International transfers to sub-processors located outside the European Economic Area are based on the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), together with any supplementary measures appropriate following the corresponding transfer impact assessment (TIA). In particular:
- Module 2 (Controller to Processor) will apply between the Client and Camaleonic Survey, and Module 3 (Processor to Sub-processor) will apply between Camaleonic Survey and each sub-processor, as appropriate to each data flow.
- Where a sub-processor is certified under an adequacy framework recognised by the European Commission (art. 45 GDPR), the transfer will be based on that adequacy decision.
- The applicable Standard Contractual Clauses are deemed incorporated by reference into these Data Processing Terms and remain available to the Client.
Camaleonic Survey will only carry out international transfers on the Controller's instructions and on the basis of one of the above mechanisms.
8. Liability and service level
- Each Party is liable for damage caused by its failure to comply with the obligations that the GDPR imposes specifically on processors or that pertain to it in its capacity as Controller or Processor (art. 82 GDPR).
- Camaleonic Survey is liable to the Client on the terms of clause 5.4 with respect to sub-processors.
- Liability regime. The contractual liability of each Party will be governed by the main service agreement and by Spanish law. Except in cases where the law does not permit limitation (in particular, wilful misconduct (dolo), gross negligence, personal injury, and liability towards data subjects under art. 82 GDPR, which cannot be excluded), the aggregate liability of each Party towards the other for all matters arising from these Terms will be limited to the amounts actually paid by the Client for the service during the twelve (12) months preceding the event giving rise to liability. Indirect damages, loss of profit, and loss of business not directly attributable to the breaching Party are excluded. Each Party will indemnify the other against third-party claims arising from the breach of the obligations corresponding to it in its respective capacity as Controller or Processor.
- Service level. Camaleonic Survey will provide the service using reasonable professional diligence, but does not guarantee uninterrupted or error-free availability. Downtime due to maintenance, updates, force majeure, or third-party provider failures will not give rise to liability, without prejudice to any service level commitments expressly agreed, where applicable, in the main service agreement.
9. Artificial Intelligence
The service incorporates active artificial intelligence features that may operate on respondent data (for example, generation of summaries, classification, quality and sentiment analysis of responses, multi-survey analysis, and machine translation). New capabilities are activated gradually, as they become available. These features are subject to the following safeguards:
- Inference providers (sub-processors). The main AI inference provider is Groq (United States); the specific model may vary within that provider's offering. Anthropic (United States) is involved in specific features: multi-survey analysis and brand palette extraction from an image. When the Client uses machine translation, the survey text is sent to the translation engine (MyMemory and/or LibreTranslate). All of them are listed as sub-processors in Annex III and are subject to the regime of clause 5.4.
- Transfers. The use of providers located outside the European Economic Area entails ad hoc international transfers, based on the mechanism of clause 7. The data remains stored in the EU; the transmission to the provider is limited to the content necessary to provide the requested feature.
- Roles. When AI features operate on respondent data, the chain of roles is the general one under these Terms: the Client is the Controller, Camaleonic Survey acts as Processor, and the AI and translation providers act as Sub-processors of Camaleonic Survey, with the obligations of clause 5.4. Camaleonic Survey is Controller only of its clients' account and billing data and of aggregated and anonymised analytics, areas outside the scope of these Terms.
- Automated decisions. The service does not make automated individual decisions with legal or similarly significant effects on respondents within the meaning of art. 22 GDPR; should such decisions be introduced, the Client, as Controller, must ensure the safeguards required under that provision.
- Prohibition on training. Respondent data will not be used to train, retrain, or improve models of Camaleonic Survey, and Camaleonic Survey will not authorise its use for training by the inference providers, except upon the Client's express written instruction. In particular, the sub-processor Groq is subject to an express contractual commitment not to use client data to train models. In the case of the machine translation engines, the survey text is sent to the engine only when the Client uses the translation feature.
- Assessments and AI regulation. Camaleonic Survey assesses the need for a data protection impact assessment (art. 35 GDPR) and alignment with Regulation (EU) 2024/1689 (the Artificial Intelligence Act) to the extent applicable to each feature.
- Ownership of outputs. The content provided by the Client and the results generated by the AI features from that content (outputs) belong to the Client. Camaleonic Survey does not claim any ownership over them and will process them solely to provide the service, in compliance with applicable intellectual property law (Real Decreto Legislativo 1/1996, approving the consolidated text of the Spanish Intellectual Property Act (Ley de Propiedad Intelectual)).
10. Final provisions
- Precedence. In the event of a conflict between these Data Processing Terms and the main service agreement on data protection matters, these Data Processing Terms will prevail.
- Amendments. Updates arising from regulatory changes or changes to sub-processors will be handled in accordance with clauses 5.4 and 7.
- Governing law and jurisdiction. These Terms are governed by Spanish law. For any questions arising as to their interpretation or performance, the Parties submit to the courts and tribunals of the registered office of Camaleonic ads 2020 S.L., except where mandatory law provides otherwise, in particular the law applicable to consumers and users.
- Language. The Spanish-language text prevails for all purposes.
- Acceptance and entry into force. These Terms are accepted by electronic means during the sign-up process and enter into force on the date of such acceptance, remaining in effect for as long as the service relationship continues.
- Relationship with other documents. These Terms supplement the main service agreement and the Privacy Policy; with respect to the processing of respondent data on behalf of the Client, they prevail over those documents in the event of conflict.
Annex I. Processing details
| Element | Detail |
|---|---|
| Categories of data subjects | Respondents / participants (persons who respond to the Client's surveys). |
| Types of data (always) | Responses; language; duration; timestamps; IP, user-agent, and device ID pseudonymised via hash. In anonymous surveys, no direct identifiers are collected, although those pseudonymised technical identifiers may be processed for security and anti-abuse purposes. |
| Types of data (optional, as configured by the Client) | Email address (e.g., communications/marketing, subsequent contact, prize draws, or other optional purposes determined by the Client); demographic data (age, gender, city). |
| Special categories (art. 9) | Not intended by design (see clause 3.3). |
| Nature and purpose | Provision of the survey service (collection, storage, processing, presentation of results). |
| Operations | Collection, recording, structuring, storage, consultation, pseudonymisation, disclosure to necessary sub-processors, restriction (logical deletion), erasure (purge). |
| Duration / retention | For as long as the service relationship lasts. The Client may configure a per-survey retention period, upon expiry of which responses are automatically purged by a daily process; if no period is configured, responses are retained until the Client deletes them. Definitive automatic purge after 30 days following logical deletion, which is executed in accordance with the Client's instructions. The Processor does not apply additional retention periods on its own initiative; those legally required of the Client are determined by the Client as Controller. |
Annex II. Security measures (art. 32 GDPR) already implemented
This list reflects the measures verified as of the date of these Terms. It does not constitute a statement of completeness; the measures may evolve in accordance with art. 32 GDPR.
- Encryption in transit via TLS.
- Encryption at rest of stored data.
- Multi-tenant isolation by organisation through Row-Level Security (RLS).
- Pseudonymisation of IP address, user-agent, and device identifier via hashing. (A risk-reduction measure; it is not equivalent to anonymisation, and its irreversibility is not claimed.)
- Configurable per-survey retention with daily automatic purge, logical deletion of responses, and definitive automatic purge after 30 days.
- Access control based on roles and least privilege, with authentication of authorised personnel accounts.
- Logging of sensitive administrative actions (including support access to client accounts), being progressively strengthened.
- Backups and recovery procedures managed at the database infrastructure level.
- Security incident management and notification procedure in accordance with clause 5.6.
- Confidentiality commitment and training of authorised personnel (clause 5.2).
- Third-party certifications (e.g., ISO/IEC 27001 or SOC 2), where available, may be demonstrated in accordance with clause 5.8.
Annex III. List of sub-processors (subprocessors)
General prior authorisation pursuant to clause 5.4. Camaleonic Survey will notify changes with at least 30 calendar days' prior notice (clause 5.4).
| Sub-processor | Function | Location / region | Processes respondent data |
|---|---|---|---|
| Supabase | Managed database, authentication, and storage | EU | Yes |
| Amazon Web Services (AWS) | Compute infrastructure on which the application runs | International | Yes, as an infrastructure layer; international transfer where applicable (see clause 7) |
| Cloudflare Turnstile | Anti-bot protection | Global | Yes; possible international transfer (see clause 7) |
| Groq | AI inference (main provider of the service's AI features) | United States | Yes, when the Client uses AI features; international transfer (see clauses 7 and 9); commitment not to train on client data |
| Anthropic | AI inference for multi-survey analysis and brand palette extraction from an image | United States | Yes, when the Client uses those features; international transfer (see clauses 7 and 9) |
| MyMemory / LibreTranslate | Machine translation engines for survey content | International | Not as a general rule: they process the survey text when the Client uses translation; international transfer where applicable (see clauses 7 and 9) |
| Stripe | Payments | United States | No, with respect to respondent data: it processes only Client account data (Camaleonic Survey is Controller; outside the scope of these Data Processing Terms) |
Notes on this Annex:
- Storage versus ad hoc processing. The primary storage of surveys and responses takes place in the EU (Supabase). The AI and translation providers process the content on an ad hoc basis, only when the Client uses those features, and may do so from the United States or other countries; such ad hoc processing does not change the place of storage.
- Stripe is included for transparency, but with respect to respondent data it is not a sub-processor for purposes of these Data Processing Terms: it is only involved in the Client's account/billing data, an area in which Camaleonic Survey acts as Controller.
- For each sub-processor located outside the EU, the transfer mechanism is that provided for in clause 7: Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module 2 or 3 depending on the data flow, or an adequacy decision where the provider is certified under a framework recognised by the European Commission. The data processing agreements (DPAs) and Standard Contractual Clauses of each sub-processor remain available to the Client.