Legal reference
Data Processing Agreement
This public reference explains how Fred processes customer research data, which roles apply, and where buyers can review security, privacy, and sub-processor information.
- Last updated
- Legal entity
- Fred The User Research Shepherd SRL
- Core hosting
- Europe, with AWS and database layer in Frankfurt
Signed customer agreements, order forms, or executed DPAs can supplement or override this public reference where they apply.
At a glance
The agreement follows the research data lifecycle.
European data residency
Core Fred application servers and customer data are hosted in Europe, with AWS infrastructure and the database layer in Frankfurt, Germany.
Research data scope
Covers workspace data, study data, participant responses, recordings, transcripts, behavioral signals, reports, and related evidence processed for customers.
Controller and processor roles
Customers decide why and how their research is run. Fred processes customer workspace data to provide the service and may act separately as controller for website, billing, and business records.
Sub-processor transparency
Fred maintains a public sub-processor list so customers can review the infrastructure and service providers involved in platform delivery.
External recording boundary
Where a customer uploads recordings or participant material outside Fred's native notice flow, the customer remains responsible for the required notice, consent, and attestation path.
Security and assistance
The DPA reference explains access controls, confidentiality, incident assistance, data subject request support, and deletion expectations.
Processing summary
Purpose
Provide Fred's research workspace, study setup, participant workflows, scheduling support, evidence storage, AI-assisted analysis, reporting, collaboration, support, billing, security, and service administration.
Data subjects
Customer users, workspace members, invited participants, study respondents, research session guests, customer contacts, and other people whose data is included in customer research materials.
Personal data
Account details, workspace metadata, study responses, survey answers, session recordings, video or audio, transcripts, interaction events, gaze or attention signals where enabled, AI-assisted indicators, reports, tags, comments, billing records, support messages, and technical logs.
Special handling
Fred uses in-product acceptance flows where applicable for tester registration, recordings, AI-assisted analysis, attention or gaze-related indicators, and related behavioral features. External uploads collected outside Fred's native flow remain subject to customer attestation and notice responsibility.
Data residency
Core Fred application servers and customer data are hosted in Europe. Current AWS infrastructure and the Supabase/Postgres database layer are configured in Frankfurt, Germany.
Duration
For the customer relationship and any retention period required by the service, customer instructions, legal obligations, security needs, billing records, or an applicable written agreement.
1. Scope and roles
This page summarizes Fred's standard data processing position for B2B customers using Fred to run research, manage participants, analyze evidence, and create reports. It is intended to support customer evaluation and contract incorporation. If a signed order form, enterprise agreement, or separately executed DPA applies, that document controls where it conflicts with this public reference.
Fred The User Research Shepherd SRL acts as a processor when it processes customer workspace data on a customer's documented instructions. Fred may act as an independent controller for public website visitors, sales activity, billing administration, security logs, legal records, and other processing described in the Privacy Policy.
2. Processing details
Fred processes customer data to provide a connected research workflow: study creation, participant management, moderated or unmoderated sessions, analysis, repository organization, reporting, collaboration, and support.
AI-assisted features are used to support synthesis and review. They should not be treated as definitive statements about a person's feelings, intent, identity, health, legal status, or future behavior.
3. Fred obligations
Fred will process customer personal data only to provide and protect the service, follow documented customer instructions, comply with applicable law, support customer-requested workflows, or satisfy security and legal obligations.
Fred applies appropriate technical and organizational measures for the sensitivity of research data, including controlled access, infrastructure safeguards, confidentiality expectations, privacy-aware workflows, and security monitoring.
Personnel and contractors with access to customer personal data are expected to handle it under confidentiality obligations and only for authorized business purposes.
4. Customer obligations
Fred provides in-product acceptance and consent flows where applicable, including for tester registration, recordings, AI-assisted analysis, emotion analysis, eye tracking, and related behavioral features. Customers remain responsible for the research purpose, study configuration, participant selection, and any customer-side legal notices or lawful basis decisions that sit outside Fred's product flow.
If a customer uploads or imports external recordings, transcripts, or similar participant material that was collected outside Fred's native notice and acceptance flow, the customer must ensure that the collection, upload, and requested analysis are lawful and appropriately disclosed. Fred may require attestation or supporting context before enabling a sensitive workflow.
Customers must ensure that material they upload, import, request, or instruct Fred to process is lawful and appropriate for the research purpose. Customers must not upload or process illegal, pornographic, exploitative, abusive, discriminatory, infringing, or otherwise prohibited material, or material that violates applicable law, human rights, participant rights, confidentiality duties, intellectual property rights, or other third-party rights.
Customers should not upload unnecessary sensitive data, secrets, production credentials, or participant material that is unrelated to the research purpose. Fred is designed to support evidence-based work, but customers remain responsible for the research design and for the materials they choose to provide or request through the platform.
5. Sub-processors
Fred may use sub-processors and service providers to host the platform, secure traffic, process payments, provide authentication or integrations, monitor reliability, support customers, and measure product usage where permitted.
The current public list is maintained on the Sub-processors page. Material changes will be reflected there, and enterprise agreements may include additional notice or objection mechanics.
6. International transfers
Fred is based in Italy. Core application infrastructure and customer data are hosted in Europe, with current AWS infrastructure and the Supabase/Postgres database layer configured in Frankfurt, Germany.
Fred uses European contracting entities where applicable, including for AWS and Google services. If a limited service component or provider configuration requires an international transfer mechanism for operational metadata, Fred expects to rely on appropriate contractual protections, provider data processing terms, Standard Contractual Clauses where applicable, and supplementary safeguards aligned with the nature of the processing.
7. Data subject requests and incidents
If Fred receives a data subject request that relates to customer-controlled research data, Fred will direct the requester to the customer where appropriate and provide reasonable assistance so the customer can respond.
If Fred becomes aware of a confirmed personal data breach affecting customer personal data, Fred will notify affected customers without undue delay and provide information reasonably available to support legal, operational, and participant communication obligations.
Fred may use security logs, diagnostics, and operational records to investigate incidents, prevent abuse, and protect the platform, customers, and participants.
8. Return and deletion
Customers can request deletion or export of customer-controlled data according to the product capabilities, customer agreement, and applicable law. Fred may retain limited records where required for billing, legal obligations, security, auditability, dispute resolution, or backup integrity.
Fred's retention expectations should be read together with the Privacy Policy and any written customer agreement that specifies retention, export, or deletion requirements.
Annex A: Technical and organizational measures
Fred's safeguards are organized around the realities of research data: participant context, evidence files, recordings, analysis artifacts, reports, and team access.
Access control
Role-aware workspace access, limited administrative access, and controlled operational workflows for customer support and platform maintenance.
Infrastructure protection
Reviewed AWS architecture foundations, Frankfurt-hosted AWS and Supabase/Postgres infrastructure, Cloudflare edge protection, service monitoring, and separation of public website and application responsibilities.
Data minimization
Research features are designed to collect evidence needed for the study purpose, with special attention to recordings, camera access, eye tracking, and AI-assisted behavioral indicators.
Confidentiality
People authorized to access customer data are expected to use it only for legitimate service, support, security, legal, or business purposes.
Incident response
Operational processes support investigation, containment, customer communication, and remediation when a security or privacy incident affects customer data.
Review support
Enterprise evaluations can include security review, procurement questions, architecture discussion, and workflow governance planning.
Contact
For DPA execution, procurement review, security questionnaires, or privacy questions, contact Fred at [email protected].