Data Processing Policy
This policy summarizes how SierraTec processes Customer Personal Data, including processor obligations, subprocessors, security, data-subject requests, international transfers, and deletion.
1. Purpose and Scope
This Data Processing Policy describes SierraTec’s public-facing approach to processing Customer Personal Data through SierraTec Survey. Where applicable law requires a processor contract, SierraTec and the Customer must enter into or incorporate an applicable Data Processing Agreement (DPA). This public Policy does not replace the mandatory terms of that DPA.
2. Roles
For Customer survey-response data, the Customer generally determines the purposes and essential means of processing and SierraTec generally acts as processor or service provider. For SierraTec’s own account, billing, security, support, fraud-prevention, and legal-compliance activities, SierraTec may act as an independent controller or business.
3. Customer Instructions
Where SierraTec acts as processor, SierraTec processes Customer Personal Data according to documented Customer instructions contained in the agreement, configuration, feature use, support request, or other authorized instruction, unless law requires different processing.
4. Processing Details
- Subject matter: hosting and operating SierraTec Survey and enabled features.
- Duration: the subscription term plus applicable retrieval, deletion, backup, legal, or contract periods.
- Nature: collection, storage, organization, transmission, analysis, reporting, export, deletion, and other processing needed to provide the Service.
- Purposes: survey creation, response collection, analytics, collaboration, support, security, integrations, AI features when enabled, and related functionality.
- Data subjects: respondents, Customer personnel, invitees, research participants, students, employees, consumers, patients, or other individuals selected by the Customer.
- Data categories: survey responses, contact information, identifiers, demographics, uploaded files, research data, and other Customer-selected information.
5. Confidentiality
SierraTec will limit access to Customer Personal Data to personnel and authorized providers who require access for permitted purposes and are subject to appropriate confidentiality obligations.
6. Security Measures
SierraTec will implement technical and organizational safeguards appropriate to the nature of the processing and associated risks. Customer-facing details are summarized in the Security Policy and may be supplemented by Enterprise security documentation.
7. Subprocessors
SierraTec may use subprocessors for hosting, storage, authentication, communications, support, analytics, AI, security, payment, and other infrastructure. Where required, SierraTec will maintain appropriate contractual protections and provide required authorization or notice mechanisms.
8. Data Subject Requests
Where SierraTec acts as processor, SierraTec will provide reasonable assistance to the Customer with applicable data-subject requests, taking into account the nature of processing and functionality available in the Service.
9. Personal Data Breaches
SierraTec will maintain procedures to detect, investigate, contain, document, and respond to personal-data breaches. Where SierraTec acts as processor, it will notify the applicable controller without undue delay as required by the DPA and applicable law.
10. DPIAs and Regulatory Assistance
Where legally required and reasonably related to SierraTec’s processing, SierraTec will provide information and assistance reasonably necessary for Customer DPIAs, consultations, or compliance assessments, subject to the applicable agreement.
11. International Transfers
Customer Personal Data may be processed in the United States and other countries where SierraTec or its authorized providers operate. Where restricted transfers apply, SierraTec will use appropriate transfer mechanisms, such as applicable adequacy arrangements, Standard Contractual Clauses, UK transfer mechanisms, or other legally recognized safeguards.
12. Return and Deletion
At the end of the applicable service relationship, SierraTec will return, make available for export, delete, or de-identify Customer Personal Data according to the applicable agreement, plan, retention configuration, backup schedule, and legal requirements.
13. Audits and Compliance Information
Where required by a DPA, SierraTec may provide information reasonably necessary to demonstrate compliance, such as security documentation, independent assessments where available, subprocessor information, or responses to reasonable audit inquiries. Audit rights and procedures are governed by the applicable DPA or Enterprise agreement.
14. Records of Processing
SierraTec will maintain records of processing activities to the extent required by applicable data-protection law.
15. Customer Responsibilities
- Provide lawful instructions.
- Give required privacy notices.
- Establish an appropriate legal basis for Customer processing.
- Avoid collecting unnecessary information.
- Configure access, retention, sharing, and integrations appropriately.
- Respond to respondents and data subjects as required.
- Conduct DPIAs, assessments, or consultations where required for the Customer’s use case.
16. Special Categories and Regulated Data
Customers must not assume every plan or feature supports special-category, sensitive, HIPAA-regulated, FERPA-regulated, financial, biometric, government, or other regulated data. Additional contractual and technical requirements may apply.
17. AI Processing
AI features are optional and may involve additional processors. Customers should not submit highly sensitive or regulated data to AI functionality unless SierraTec has expressly approved the configuration and relevant provider chain for that purpose.
18. Relationship to the DPA
If this Policy conflicts with an applicable DPA, the DPA controls for Customer Personal Data covered by that DPA. If an Enterprise order form or BAA contains more specific processing requirements, that agreement controls for its subject matter.
19. Contact
Data-processing questions may be sent to info@sierratecsecure.com.