← Back to Sensorama

Data Processing Agreement

Last updated: 26 August 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Data Controller” or “Controller”) and The Origin Institute® (“Data Processor” or “Processor”) for the use of the Sensorama™ platform (“Service”).

This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and sets out the terms under which the Processor processes personal data on behalf of the Controller.

This DPA applies automatically to all customers of the Sensorama platform who collect personal data from panelists or other data subjects through the Service. By using the Service to process personal data, the Controller agrees to the terms of this DPA.

1. Definitions

2. Scope and Duration

2.1 Subject Matter

The Processor provides the Sensorama platform, a sensory science SaaS application that enables the Controller to design and conduct sensory evaluation studies, manage sensory panels, collect evaluation data from panelists, and analyse results. In the course of providing the Service, the Processor processes Personal Data on behalf of the Controller.

2.2 Duration

This DPA shall remain in effect for the duration of the Main Agreement. Processing shall cease upon termination of the Main Agreement, subject to the data deletion provisions in Section 10.

2.3 Nature and Purpose of Processing

The Processor processes Personal Data for the following purposes:

3. Types of Personal Data Processed

CategoryData Types
Identity data First name, last name, panelist code/ID
Contact data Email address, phone number
Demographic data Date of birth, gender, age group
Health-related data Dietary restrictions, food allergies (where collected by Controller for safety purposes)
Preference data Taste preferences, sensitivity profiles, food consumption habits
Research data Sensory evaluation responses, scores, rankings, free-text comments

4. Categories of Data Subjects

5. Obligations of the Processor

Per GDPR Article 28(3)

5.1 Lawful Processing

The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Union or Member State law. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

5.2 Confidentiality

The Processor shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.3 Security Measures

The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by GDPR Article 32. These measures are detailed in Annex A of this DPA.

5.4 Sub-processors

The Processor may engage sub-processors to assist in providing the Service. The current list of sub-processors is:

Sub-processorPurposeLocationTransfer Mechanism
Cloudflare, Inc. CDN, DDoS protection, SSL/TLS, DNS, analytics Global (US-headquartered) EU-US Data Privacy Framework
Google LLC (Gmail) Outbound email delivery Global (US-headquartered) EU-US Data Privacy Framework

The Processor shall:

The Controller may object to a new sub-processor within 30 days of notification. If the objection is not resolved, the Controller may terminate the Main Agreement.

Customer-selected AI providers (bring-your-own-key). The Service’s AI interpretation features are disabled by default. They operate only when the Controller supplies its own API key for an AI provider of its choice and enables the feature. The providers currently supported are Anthropic (Claude), OpenAI, xAI (Grok), Perplexity, Groq (hosting Meta Llama and other open models), Google (Gemini) and Mistral. When the feature is enabled, analysis inputs and result tables — which may include response data and pseudonymous panelist codes — are transmitted from the Service directly to the selected provider under the Controller’s own account and on the Controller’s instruction. Such a provider is engaged by the Controller, not by the Processor, and is therefore not a sub-processor of the Processor under this DPA; the Controller is responsible for its own agreement, lawful basis and international-transfer mechanism with that provider. The Processor stores the Controller’s API key encrypted per organisation, uses it solely to perform the interpretation the Controller requests, and does not itself supply, resell or route AI services under its own keys.

5.5 Assistance with Data Subject Rights

The Processor shall assist the Controller in responding to requests from Data Subjects exercising their rights under GDPR Articles 15–22, taking into account the nature of the processing. This includes providing technical means to fulfil access, rectification, erasure, restriction, and portability requests.

5.6 Data Protection Impact Assessments

The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to GDPR Articles 35 and 36 (data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to the Processor.

5.7 Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Data Breach involving Personal Data processed on behalf of the Controller. The notification shall include:

6. Obligations of the Controller

The Controller shall:

7. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

8. International Transfers

The Processor shall not transfer Personal Data outside the European Economic Area (EEA) unless:

Currently, limited data may transit through Cloudflare and Google infrastructure outside the EEA. Both services are certified under the EU-US Data Privacy Framework. The Processor maintains Standard Contractual Clauses with these sub-processors as an additional safeguard. Where the Controller enables AI interpretation with its own API key (Section 5.4), any transfer to the selected AI provider is a transfer made by the Controller under its own arrangements with that provider.

9. Technical and Organisational Measures (Annex A)

Per GDPR Article 32

The Processor implements the following measures to protect Personal Data:

9.1 Encryption

9.2 Access Control

9.3 Data Isolation

9.4 Backup and Recovery

9.5 Network Security

9.6 Monitoring and Logging

9.7 Personnel

10. Data Deletion and Return

Upon termination of the Main Agreement:

11. Liability and Indemnification

12. Governing Law and Jurisdiction

This DPA is governed by the laws of the Netherlands. Any disputes arising from or in connection with this DPA shall be submitted to the competent courts in the Netherlands (District Court of Gelderland, Arnhem location).

13. Amendments

This DPA may be amended by the Processor to reflect changes in data protection law or practice. Material changes will be communicated to the Controller at least 30 days before they take effect. The Controller may object to material changes and terminate the Main Agreement if the changes are unacceptable.

14. Contact

Data Processor:
The Origin Institute®
Wageningen, Netherlands
Email: [email protected]
Website: www.sensoramaai.com
KvK: 97905682
VAT: NL868283496B01