Privacy
Privacy policy
How Pindrop handles account data and employee-respondent data.
Last reviewed: 21 August 2026
1. Who we are
Pindrop is an employee-listening service at employeeexperience.ai. It is provided by PEOPLE WORK LIFE LIMITED (Companies House 16547876).
Registered office: 26 Cromwell Road, Ascot, England, SL5 9DG
Privacy contact: rob@peopleworklife.com
We do not name a Data Protection Officer. Privacy requests go to rob@peopleworklife.com. We are not listing an ICO registration number.
2. Two roles, said plainly
For staff and client-user accounts (ADMIN, DESIGNER, and CLIENT): PEOPLE WORK LIFE LIMITED is the controller.
For employee-respondent data (answers, comments, and related survey records): the customer organisation is the controller. We are their processor. We act on their documented instructions. We do not use respondent answers to market to those employees, and we do not treat The EX Institute as a party to that processing.
Employees who answer a survey are not Pindrop users. They are respondent records reached by a token link. They do not create an account.
If you were invited to a survey, the organisation that invited you decides why it is run and how long the answers are kept. Ask them first. We will help them respond to a rights request that concerns data we hold.
3. The service this policy covers
Pindrop lets a customer design listening strategies, generate questionnaire items with AI, run pulse and census surveys, view dashboards, and export PowerPoint and PDF reports. Respondents answer on a public token link. Customers can send invitations and reminders by email, and — where they have connected Microsoft Teams — as Teams chats. Accounts support two-factor authentication and passkeys. Customers may share dashboards, reports, and client portals with people they choose.
4. Personal data we process
4.1 Account data (we are controller)
For ADMIN, DESIGNER, and CLIENT users:
- Name and email address
- Organisation / workspace membership and role
- Authentication credentials (password, passkey, or two-factor, as used)
- Billing contact details you give us, and records of plan and trial status
- Support messages you send us
- Security and diagnostic logs needed to run the service (sign-in events, error reports)
4.2 Respondent and survey data (customer is controller; we are processor)
- Invitation identifiers (typically work email, and a Teams identity where the customer uses Teams)
- Survey answers, including free-text comments
- Optional demographic or segment fields the customer chooses to collect
- Technical data needed to deliver the survey (for example, that a link was opened)
A customer can run a wave as IDENTIFIED, ANONYMOUS, or HYBRID. That choice is theirs.
4.3 Data we do not collect on purpose
We do not require special-category data. A customer might still receive it in free-text comments. That remains the customer's responsibility to minimise and handle lawfully. We do not use those comments to infer health, trade-union membership, or similar categories for our own purposes.
5. Why we use it
These bases are a working draft, not a determination.
| Purpose | Typical basis (UK GDPR) |
|---|---|
| Create and administer accounts, authenticate users, provide the product | Contract (Art. 6(1)(b)) |
| Host and process surveys on a customer's instructions | Contract with the customer; we rely on the customer to have a basis for their employees |
| Send service email (invites, reminders, password reset, operational notices) | Contract; PECR soft-opt-in does not cover marketing — see §9 |
| Take payment for a paid plan | Contract; processed by Stripe |
| Security, abuse prevention, debugging | Legitimate interests (Art. 6(1)(f)) |
| Improve the product using aggregated, non-identifying usage | Legitimate interests — not respondent verbatims |
| Legal and accounting obligations | Legal obligation (Art. 6(1)(c)) |
We do not sell personal data.
6. Anonymity and exports
The default anonymity threshold is 5. Customers can change it. Waves can be IDENTIFIED, ANONYMOUS, or HYBRID.
We do not promise that every view, dashboard, or export is k-anonymous. A small team, a tight filter, or a distinctive comment can still identify someone. Customers must not re-identify respondents and must set thresholds that fit their workforce.
7. Processors we use
We use other organisations to run the service. Only processors we can evidence are named here. The published Trust & data list is the spine.
| Processor | Role |
|---|---|
| Vercel | Hosting the web application, scheduled jobs, and file storage. Compute region is not claimed. File-storage region is not claimed. Vercel Web Analytics records page views; it does not use cookies and does not identify visitors. |
| Neon | Hosted PostgreSQL in AWS eu-west-2 (London), as stated on Trust & data. Shared infrastructure, also used by Portraits — not a dedicated Pindrop database. |
| Resend | Transactional email (invitations, reminders, account mail) |
| Stripe | Payments |
| Sentry | Error monitoring (EU ingest). Tracing is present on the live HTML. |
| Upstash | Rate limiting |
| CloudConvert | Presentation rendering |
| Supabase | AskEX / semantic search, AWS eu-west-1 (Ireland) |
| Anthropic | AI features via the Claude API (questionnaire design, theme analysis, report drafting). API inputs are not used to train Anthropic's models. Organisations can bring their own Anthropic key or gateway (BYOK). |
| Microsoft (Teams / Entra / Azure Bot) | Personal-scope Teams bot: invitations and reminders as chats, with email fallback, when a customer enables it. |
Optional customer connections, only if the organisation turns them on: Qualtrics, SurveyMonkey, Typeform, Notion.
We do not claim that all of this processing stays in the United Kingdom.
8. International transfers
Several processors above are US organisations or may store data outside the United Kingdom. We do not name a transfer mechanism on this page. We do not claim UK-only or EU-only residency, and we do not claim UK compute.
9. Email, Teams, and PECR
Service messages (survey invitations, reminders, security and account mail) are sent because the customer asked us to send them, or because you have an account. That is not marketing.
We will not send marketing email about Pindrop without a PECR-compliant consent or another lawful PECR route. Unsubscribing from marketing does not stop survey invitations that a customer has instructed us to send; the respondent should ask that organisation to stop inviting them.
Where a customer uses Teams, the bot is personal-scope. Invitations and reminders go as chats, with email as fallback if Teams delivery fails. Answering inside a Teams card is not the main path. Anonymous in-card answering is gated off.
10. Cookies and similar technology
The signed-in product uses an essential authentication cookie named ee-session-token. There is no cookie banner and no separate cookie policy. Sentry tracing is present on the live HTML. Vercel Web Analytics records page views; it does not set cookies and does not identify visitors. We have not completed a full cookie inventory, so we do not claim “essential cookies only”.
11. How long we keep data
- Account and workspace records: while the workspace is open, then 12 months after closure, except invoices and accounting records kept 6 years
- Survey and respondent records (as processor): deleted from the live database within 30 days of the customer deleting the campaign or closing the workspace; backups no more than 90 days, unless the law requires longer
- Security logs: kept only as long as needed for security and debugging
12. Your rights
If we are the controller (account holders and our own contacts), you can ask us to access, correct, delete, or restrict your data, object to legitimate-interest processing, or receive a copy in a portable form, as UK GDPR allows. You can complain to the Information Commissioner's Office (ico.org.uk).
If we are the processor (survey respondents), contact the organisation that ran the survey. We will support them.
13. Children
Pindrop is built for workplace listening. It is not aimed at children. We do not knowingly create accounts for anyone under 16.
14. The EX Institute
The EX Institute is a separate, editorially independent professional body. Recognition of Pindrop as a practice platform does not make the Institute a controller or processor of your Pindrop data, and this policy is not an Institute privacy notice.
15. Changes
We will update this page when the facts change. Material changes will be dated here.