Last updated: 27 July 2026
This Privacy Policy explains how The Origin Institute® (“we”, “us”, or “our”) collects, uses, stores, and protects personal data when you use Sensorama™ (“the Service”). We are committed to protecting your privacy and complying with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws.
The Origin Institute® is a Wageningen-based company that develops and operates Sensorama™, an AI-powered platform for sensory evaluation, panel management, and predictive modelling in food and consumer science. We act as:
| Data Type | Examples | Purpose |
|---|---|---|
| Identity information | First name, last name | Account management, communication |
| Contact information | Email address, phone number | Account access, notifications, support |
| Organisation information | Company name, role, department | Account setup, licence management |
| Authentication data | Login codes (hashed), session tokens | Secure access to the Service |
| Billing information | Invoicing address, VAT number | Payment processing, invoicing |
When our customers use Sensorama to conduct sensory evaluation studies, they may collect the following data from their panelists. The customer is the data controller for this data; we process it on their behalf.
| Data Type | Examples | Purpose |
|---|---|---|
| Identity information | First name, last name, panelist code | Panelist identification and session management |
| Contact information | Email address, phone number | Session invitations, communication |
| Demographic data | Date of birth, gender, age group | Study design, panelist selection, statistical analysis |
| Dietary information | Dietary restrictions, allergies, food preferences | Study eligibility screening, safety |
| Taste preferences | Taste sensitivity scores, preference profiles | Panelist profiling, study calibration |
| Sensory responses | Evaluation scores, rankings, descriptive analysis data | Sensory research and analysis |
| Data Type | Examples | Purpose |
|---|---|---|
| Contact form submissions | Name, email, phone, company, message | Responding to your inquiry |
| Analytics data | Page views, visit duration, referrer (aggregated, no PII) | Website improvement |
| Technical data | IP address (processed by Cloudflare, not stored by us), browser type | Security, DDoS protection |
We process personal data under the following legal bases:
| Legal Basis | GDPR Article | Applies To |
|---|---|---|
| Performance of a contract | Art. 6(1)(b) | Account data, billing data, providing the Service |
| Legitimate interest | Art. 6(1)(f) | Website analytics, security, fraud prevention, service improvement |
| Consent | Art. 6(1)(a) | Marketing communications (if applicable), panelist consent for studies (managed by the customer as data controller) |
| Legal obligation | Art. 6(1)(c) | Tax records, regulatory compliance |
For panelist data, the customer (data controller) is responsible for establishing the appropriate legal basis. We recommend that customers obtain explicit consent from panelists (GDPR Art. 7). We provide a template consent form to assist with this.
We use personal data for the following purposes:
We will never:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account data | Duration of contract + 2 years | Contract performance, post-termination support and disputes |
| Panelist data | As configured by the customer (data controller) | Customer controls retention; deleted upon request or account termination |
| Billing and invoice data | 7 years after the transaction | Dutch tax law (Algemene wet inzake rijksbelastingen) |
| Contact form submissions | Until inquiry is resolved, then archived | Legitimate interest in communication |
| Website analytics | 30 days (aggregated) | Cloudflare Web Analytics rolling window |
| Security logs | 90 days | Security monitoring and incident response |
When data reaches the end of its retention period, it is securely deleted or anonymised. We never delete data without archiving it first (our “no-delete” policy means data is archived/junked rather than hard-deleted, ensuring recoverability within the retention period).
Under the GDPR, you have the following rights regarding your personal data:
| Right | GDPR Article | Description |
|---|---|---|
| Right of access | Art. 15 | You can request a copy of all personal data we hold about you. |
| Right to rectification | Art. 16 | You can ask us to correct inaccurate or incomplete personal data. |
| Right to erasure | Art. 17 | You can ask us to delete your personal data (“right to be forgotten”). |
| Right to restrict processing | Art. 18 | You can ask us to limit how we process your data. |
| Right to data portability | Art. 20 | You can request your data in a structured, machine-readable format. |
| Right to object | Art. 21 | You can object to processing based on legitimate interest. |
| Right to withdraw consent | Art. 7(3) | Where processing is based on consent, you can withdraw it at any time. |
| Right to lodge a complaint | Art. 77 | You can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). |
To exercise any of these rights, please contact us at:
We will respond to your request within 30 days (GDPR Art. 12(3)). If the request is complex or we receive a high volume of requests, we may extend this by up to 60 additional days, and we will inform you of any such extension. We may ask you to verify your identity before processing your request.
There is no fee for exercising your rights, unless requests are manifestly unfounded or excessive (GDPR Art. 12(5)).
If you are a panelist whose data was collected through Sensorama by a research organisation, please first contact the organisation that invited you to participate. They are the data controller for your data. If you cannot reach them, or if your request relates to our platform specifically, you may contact us directly.
We use essential cookies only. We do not use advertising cookies, tracking pixels, or third-party analytics services that collect personal data.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
_streamlit_xsrf |
Cross-site request forgery protection for the analyst dashboard and booth | Essential | Session |
__cf_bm |
Cloudflare bot management — protects against automated attacks | Essential (third-party) | 30 minutes |
sensorama_cookie_ok |
Remembers that you acknowledged this cookie notice | Preference (localStorage) | Persistent |
Cloudflare Web Analytics is used for basic website analytics. It is privacy-preserving: it does not use cookies, does not collect personal identifiable information (PII), and does not track individual users. Data is aggregated and retained for 30 days.
No consent is required for strictly necessary cookies under GDPR Article 6(1)(f) and the ePrivacy Directive. For full details, see our Cookie Policy.
We use a limited number of third-party services (“sub-processors”) to operate the Service. Each sub-processor is bound by data processing obligations consistent with GDPR requirements.
| Sub-Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Cloudflare, Inc. | CDN, DDoS protection, SSL/TLS termination, DNS, web analytics | IP address (transient), page views (aggregated) | Global (EU-US Data Privacy Framework certified) |
| Google LLC (Gmail/SMTP) | Outbound email delivery (notifications, invitations) | Email addresses, email content | Global (EU-US Data Privacy Framework certified) |
We do not use Google Analytics, Facebook Pixel, Hotjar, or any other tracking or advertising service.
We will notify customers of any changes to sub-processors. Customers who object to a new sub-processor may terminate their agreement in accordance with our Terms of Service.
Your data is primarily stored and processed within the European Economic Area (EEA). Where data is transferred outside the EEA (for example, when using Cloudflare or Google services), we rely on the following transfer mechanisms:
We conduct transfer impact assessments for any international data transfers to ensure adequate protection of personal data.
We implement appropriate technical and organisational measures to protect personal data, including:
In the event of a personal data breach:
Sensorama is a professional B2B platform designed for use by organisations conducting sensory science research. We do not knowingly collect personal data from children under the age of 16. If we become aware that we have inadvertently collected data from a child under 16, we will take immediate steps to delete it.
If a customer wishes to include minors aged 16–17 in sensory panels, the customer is responsible for obtaining parental or guardian consent in accordance with applicable law.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on individuals (GDPR Art. 22). Our platform provides analytical tools, but all decisions based on sensory data are made by the human researchers using the Service.
For all privacy-related inquiries, please contact our Data Protection Officer:
You have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
Bezuidenhoutseweg 30
2594 AV Den Haag
autoriteitpersoonsgegevens.nl
Phone: +31 70 888 8500
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. We will notify you of material changes at least 30 days before they take effect by email or through the Service. The “last updated” date at the top reflects the most recent revision.
We encourage you to review this Privacy Policy periodically. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
The Origin Institute®
Wageningen, Netherlands
General inquiries: [email protected]
Data protection: [email protected]
Website: www.sensoramaai.com
KvK: 97905682
VAT: NL868283496B01