← Back to Sensorama
Data Processing Agreement
Last updated: 26 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Data Controller” or “Controller”) and The Origin Institute® (“Data Processor” or “Processor”) for the use of the Sensorama™ platform (“Service”).
This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and sets out the terms under which the Processor processes personal data on behalf of the Controller.
This DPA applies automatically to all customers of the Sensorama platform who collect personal data from panelists or other data subjects through the Service. By using the Service to process personal data, the Controller agrees to the terms of this DPA.
1. Definitions
- “Personal Data” means any information relating to an identified or identifiable natural person, as defined in GDPR Art. 4(1).
- “Processing” means any operation performed on Personal Data, as defined in GDPR Art. 4(2).
- “Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
- “Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- “Main Agreement” means the Terms of Service and any associated subscription agreement between the Controller and the Processor.
2. Scope and Duration
2.1 Subject Matter
The Processor provides the Sensorama platform, a sensory science SaaS application that enables the Controller to design and conduct sensory evaluation studies, manage sensory panels, collect evaluation data from panelists, and analyse results. In the course of providing the Service, the Processor processes Personal Data on behalf of the Controller.
2.2 Duration
This DPA shall remain in effect for the duration of the Main Agreement. Processing shall cease upon termination of the Main Agreement, subject to the data deletion provisions in Section 10.
2.3 Nature and Purpose of Processing
The Processor processes Personal Data for the following purposes:
- Hosting and storing panelist data in the Controller’s isolated database.
- Facilitating sensory evaluation sessions (booth access, sample presentation, data collection).
- Sending email notifications and session invitations to panelists on behalf of the Controller.
- Generating reports and statistical analyses based on collected data.
- Providing technical support when requested by the Controller.
3. Types of Personal Data Processed
| Category | Data Types |
| Identity data |
First name, last name, panelist code/ID |
| Contact data |
Email address, phone number |
| Demographic data |
Date of birth, gender, age group |
| Health-related data |
Dietary restrictions, food allergies (where collected by Controller for safety purposes) |
| Preference data |
Taste preferences, sensitivity profiles, food consumption habits |
| Research data |
Sensory evaluation responses, scores, rankings, free-text comments |
4. Categories of Data Subjects
- Panelists: Trained or untrained individuals participating in sensory evaluation sessions.
- Consumers: Individuals participating in consumer tests or market research studies conducted through the Service.
- Employees of the Controller: Staff members who use the Service for panel management or study design.
5. Obligations of the Processor
Per GDPR Article 28(3)
5.1 Lawful Processing
The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Union or Member State law. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
5.2 Confidentiality
The Processor shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.3 Security Measures
The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by GDPR Article 32. These measures are detailed in Annex A of this DPA.
5.4 Sub-processors
The Processor may engage sub-processors to assist in providing the Service. The current list of sub-processors is:
| Sub-processor | Purpose | Location | Transfer Mechanism |
| Cloudflare, Inc. |
CDN, DDoS protection, SSL/TLS, DNS, analytics |
Global (US-headquartered) |
EU-US Data Privacy Framework |
| Google LLC (Gmail) |
Outbound email delivery |
Global (US-headquartered) |
EU-US Data Privacy Framework |
The Processor shall:
- Inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object.
- Impose the same data protection obligations on sub-processors as set out in this DPA by way of a contract.
- Remain fully liable for the performance of its sub-processors.
The Controller may object to a new sub-processor within 30 days of notification. If the objection is not resolved, the Controller may terminate the Main Agreement.
Customer-selected AI providers (bring-your-own-key). The Service’s AI interpretation features are disabled by default. They operate only when the Controller supplies its own API key for an AI provider of its choice and enables the feature. The providers currently supported are Anthropic (Claude), OpenAI, xAI (Grok), Perplexity, Groq (hosting Meta Llama and other open models), Google (Gemini) and Mistral. When the feature is enabled, analysis inputs and result tables — which may include response data and pseudonymous panelist codes — are transmitted from the Service directly to the selected provider under the Controller’s own account and on the Controller’s instruction. Such a provider is engaged by the Controller, not by the Processor, and is therefore not a sub-processor of the Processor under this DPA; the Controller is responsible for its own agreement, lawful basis and international-transfer mechanism with that provider. The Processor stores the Controller’s API key encrypted per organisation, uses it solely to perform the interpretation the Controller requests, and does not itself supply, resell or route AI services under its own keys.
5.5 Assistance with Data Subject Rights
The Processor shall assist the Controller in responding to requests from Data Subjects exercising their rights under GDPR Articles 15–22, taking into account the nature of the processing. This includes providing technical means to fulfil access, rectification, erasure, restriction, and portability requests.
5.6 Data Protection Impact Assessments
The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to GDPR Articles 35 and 36 (data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to the Processor.
5.7 Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Data Breach involving Personal Data processed on behalf of the Controller. The notification shall include:
- A description of the nature of the breach, including the categories and approximate number of Data Subjects and records concerned.
- The name and contact details of the Processor’s data protection contact.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
6. Obligations of the Controller
The Controller shall:
- Ensure that there is a lawful basis for the processing of Personal Data by the Processor under this DPA.
- Provide clear documented instructions for the processing of Personal Data.
- Obtain necessary consents from Data Subjects where consent is the lawful basis for processing (see our template consent form).
- Inform panelists about the processing of their personal data through the Service, including the involvement of the Processor as a sub-processor.
- Ensure that the Personal Data provided to the Processor is accurate and up to date.
- Comply with all applicable data protection laws in connection with the use of the Service.
7. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
- Audits shall be conducted with reasonable prior notice (at least 30 days), during normal business hours.
- The Controller shall bear the costs of any audit, unless the audit reveals material non-compliance by the Processor.
- The Processor may satisfy audit requests by providing relevant certifications, audit reports, or other evidence of compliance.
- The Controller shall not have access to other customers’ data during any audit.
8. International Transfers
The Processor shall not transfer Personal Data outside the European Economic Area (EEA) unless:
- The transfer is to a country that the European Commission has determined provides an adequate level of protection.
- Appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
- The transfer is covered by the EU-US Data Privacy Framework (for transfers to certified US companies).
- The Controller has given prior written consent to the transfer.
Currently, limited data may transit through Cloudflare and Google infrastructure outside the EEA. Both services are certified under the EU-US Data Privacy Framework. The Processor maintains Standard Contractual Clauses with these sub-processors as an additional safeguard. Where the Controller enables AI interpretation with its own API key (Section 5.4), any transfer to the selected AI provider is a transfer made by the Controller under its own arrangements with that provider.
9. Technical and Organisational Measures (Annex A)
Per GDPR Article 32
The Processor implements the following measures to protect Personal Data:
9.1 Encryption
- All data in transit is encrypted using HTTPS with TLS 1.3.
- Passwords are hashed using PBKDF2-SHA256 with 260,000 iterations and 256-bit salt.
- Session tokens are signed with HMAC-SHA256.
9.2 Access Control
- Role-based access control (RBAC) with tiered permission levels (admin, analyst, panelist).
- Each customer organisation has an isolated database — no cross-organisation data access is possible.
- Processor staff access to production data is limited to authorised personnel and logged.
- XSRF (cross-site request forgery) protection on all forms and API endpoints.
9.3 Data Isolation
- Each customer’s data is stored in a separate, isolated SQLite database.
- Databases are scoped by organisation ID — all queries are organisation-filtered.
- No shared data stores between customers.
9.4 Backup and Recovery
- Regular automated database backups.
- Backup files are stored securely with restricted access.
- Recovery procedures are tested periodically.
9.5 Network Security
- Cloudflare WAF (Web Application Firewall) for perimeter protection.
- Cloudflare bot management to prevent automated attacks.
- DDoS mitigation through Cloudflare.
- All public endpoints served through Cloudflare tunnels (no direct IP exposure).
9.6 Monitoring and Logging
- Security event logging for authentication, access, and data modifications.
- Anomaly detection for suspicious activity.
- Logs retained for 90 days for security monitoring purposes.
9.7 Personnel
- All Processor staff with access to Personal Data are bound by confidentiality obligations.
- Staff receive data protection awareness training.
- Access to production systems is restricted to essential personnel.
10. Data Deletion and Return
Upon termination of the Main Agreement:
- The Controller may request an export of all Personal Data within 30 days of termination. Data will be provided in a structured, commonly used, and machine-readable format (CSV, JSON, or Excel).
- After the 30-day export period, the Processor shall delete all Personal Data from its systems and confirm the deletion in writing, unless retention is required by Union or Member State law.
- Backup copies containing the Controller’s Personal Data will be overwritten within 90 days of deletion from production systems.
- The Processor will provide written certification of data deletion upon request.
11. Liability and Indemnification
- Each party shall be liable for damages caused by processing that infringes the GDPR, in accordance with GDPR Article 82.
- The Processor shall be liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the lawful instructions of the Controller.
- The Controller shall indemnify the Processor against any claims arising from the Controller’s failure to comply with its obligations as data controller under the GDPR.
- Total liability under this DPA is subject to the limitation of liability provisions in the Main Agreement.
12. Governing Law and Jurisdiction
This DPA is governed by the laws of the Netherlands. Any disputes arising from or in connection with this DPA shall be submitted to the competent courts in the Netherlands (District Court of Gelderland, Arnhem location).
13. Amendments
This DPA may be amended by the Processor to reflect changes in data protection law or practice. Material changes will be communicated to the Controller at least 30 days before they take effect. The Controller may object to material changes and terminate the Main Agreement if the changes are unacceptable.
14. Contact
Data Processor:
The Origin Institute®
Wageningen, Netherlands
Email: [email protected]
Website: www.sensoramaai.com
KvK: 97905682
VAT: NL868283496B01