LEGAL & TRUST
Data processing agreement
Last updated 2 August 2026
This public DPA is a standard starting point and does not become a negotiated enterprise agreement unless accepted with the applicable Surveyor order or subscription terms. Obtain legal review for your organisation and study.
Parties and scope
This DPA applies where a Surveyor customer is a controller or processor of personal data placed in a workspace and Surveyor processes that data on the customer’s behalf. The customer is the controller or engaging processor; Surveyor provides the contracted processing service. Account, billing, security, and direct support data that Surveyor determines how to use remains covered by the Privacy Policy.
Customer instructions
Surveyor will process customer data to provide hosting, authentication, survey delivery, response collection, analytics, exports, support, security, billing, and deletion services described in the agreement and customer configuration. Additional lawful written instructions may be agreed where technically feasible. Surveyor will inform the customer if an instruction appears to violate applicable data-protection law unless prohibited from doing so.
Processing details
Subjects may include workspace members, survey respondents, enumerators, customers, employees, students, beneficiaries, patients, citizens, applicants, or other people selected by the customer. Data may include identifiers, contact details, survey answers, consent records, technical metadata, optional coordinates, workspace activity, and any sensitive information the customer chooses to collect. Processing lasts for the subscription and approved retention or deletion period.
Customer obligations
The customer will provide lawful instructions, notices, and rights mechanisms; establish a lawful basis; minimise data; secure member access and exports; conduct impact or ethics assessments where required; configure appropriate retention; and avoid using Surveyor where the study requires safeguards the service or agreement does not provide.
Confidentiality and personnel
Surveyor will limit customer-data access to authorised personnel and contractors who need it for the service, security, or support and who are bound by appropriate confidentiality duties. Access may be logged and reviewed according to operational controls.
Security measures
Surveyor applies measures appropriate to the service, including authenticated access, role and workspace checks, row-level database controls, encrypted provider transport and storage capabilities, request and payload controls, signed webhook verification, audit records, secure secret handling, and tested recovery and build processes. Measures may evolve without materially reducing overall protection.
Service providers
Surveyor may use contracted infrastructure, payment, authentication, and email providers to deliver the service. Surveyor remains responsible for selecting providers with appropriate security, confidentiality, and data-protection commitments. Customers with provider-specific requirements should record them in an order form before use.
International transfers
Where customer data is transferred across borders, the parties will use a lawful mechanism and appropriate safeguards required by the Nigeria Data Protection Act 2023 and any other applicable transfer law. The customer is responsible for identifying restrictions arising from participant locations, sector rules, or its own instructions.
Data-subject assistance
Taking account of the nature of processing, Surveyor will provide reasonable technical and organisational assistance for verified access, correction, restriction, portability, objection, and deletion requests. The customer remains responsible for evaluating and answering requests as controller. Assistance beyond standard product functionality may be subject to reasonable cost where permitted.
Security incidents
Surveyor will investigate a confirmed breach of customer personal data and notify the customer without undue delay after becoming aware, providing available information about nature, affected data, likely consequences, mitigation, and contact points. The customer is responsible for regulator and participant notifications unless law directly requires Surveyor to notify.
Deletion and return
During service, authorised owners may export available customer data. At termination or on valid instruction, Surveyor will delete or return customer data unless law requires retention. Residual backup copies are protected and age out under provider cycles; if restored for recovery, applicable deletion instructions will be reapplied.
Audit information
Surveyor will provide information reasonably necessary to demonstrate compliance, such as current security and service disclosures. Any additional audit must protect other customers, security, confidentiality, and service availability, be reasonably scoped and scheduled, and use existing independent reports first when available.
Contact
Privacy and DPA requests: privacy@surveyor.ng. Contract questions: legal@surveyor.ng. Enterprise arrangements: sales@surveyor.ng.