Privacy

Privacy policy

How Pindrop handles account data and employee-respondent data.

Last reviewed: 21 August 2026

1. Who we are

Pindrop is an employee-listening service at employeeexperience.ai. It is provided by PEOPLE WORK LIFE LIMITED (Companies House 16547876).

Registered office: 26 Cromwell Road, Ascot, England, SL5 9DG

Privacy contact: rob@peopleworklife.com

We do not name a Data Protection Officer. Privacy requests go to rob@peopleworklife.com. We are not listing an ICO registration number.

2. Two roles, said plainly

For staff and client-user accounts (ADMIN, DESIGNER, and CLIENT): PEOPLE WORK LIFE LIMITED is the controller.

For employee-respondent data (answers, comments, and related survey records): the customer organisation is the controller. We are their processor. We act on their documented instructions. We do not use respondent answers to market to those employees, and we do not treat The EX Institute as a party to that processing.

Employees who answer a survey are not Pindrop users. They are respondent records reached by a token link. They do not create an account.

If you were invited to a survey, the organisation that invited you decides why it is run and how long the answers are kept. Ask them first. We will help them respond to a rights request that concerns data we hold.

3. The service this policy covers

Pindrop lets a customer design listening strategies, generate questionnaire items with AI, run pulse and census surveys, view dashboards, and export PowerPoint and PDF reports. Respondents answer on a public token link. Customers can send invitations and reminders by email, and — where they have connected Microsoft Teams — as Teams chats. Accounts support two-factor authentication and passkeys. Customers may share dashboards, reports, and client portals with people they choose.

4. Personal data we process

4.1 Account data (we are controller)

For ADMIN, DESIGNER, and CLIENT users:

  • Name and email address
  • Organisation / workspace membership and role
  • Authentication credentials (password, passkey, or two-factor, as used)
  • Billing contact details you give us, and records of plan and trial status
  • Support messages you send us
  • Security and diagnostic logs needed to run the service (sign-in events, error reports)

4.2 Respondent and survey data (customer is controller; we are processor)

  • Invitation identifiers (typically work email, and a Teams identity where the customer uses Teams)
  • Survey answers, including free-text comments
  • Optional demographic or segment fields the customer chooses to collect
  • Technical data needed to deliver the survey (for example, that a link was opened)

A customer can run a wave as IDENTIFIED, ANONYMOUS, or HYBRID. That choice is theirs.

4.3 Data we do not collect on purpose

We do not require special-category data. A customer might still receive it in free-text comments. That remains the customer's responsibility to minimise and handle lawfully. We do not use those comments to infer health, trade-union membership, or similar categories for our own purposes.

5. Why we use it

These bases are a working draft, not a determination.

PurposeTypical basis (UK GDPR)
Create and administer accounts, authenticate users, provide the productContract (Art. 6(1)(b))
Host and process surveys on a customer's instructionsContract with the customer; we rely on the customer to have a basis for their employees
Send service email (invites, reminders, password reset, operational notices)Contract; PECR soft-opt-in does not cover marketing — see §9
Take payment for a paid planContract; processed by Stripe
Security, abuse prevention, debuggingLegitimate interests (Art. 6(1)(f))
Improve the product using aggregated, non-identifying usageLegitimate interests — not respondent verbatims
Legal and accounting obligationsLegal obligation (Art. 6(1)(c))

We do not sell personal data.

6. Anonymity and exports

The default anonymity threshold is 5. Customers can change it. Waves can be IDENTIFIED, ANONYMOUS, or HYBRID.

We do not promise that every view, dashboard, or export is k-anonymous. A small team, a tight filter, or a distinctive comment can still identify someone. Customers must not re-identify respondents and must set thresholds that fit their workforce.

7. Processors we use

We use other organisations to run the service. Only processors we can evidence are named here. The published Trust & data list is the spine.

ProcessorRole
VercelHosting the web application, scheduled jobs, and file storage. Compute region is not claimed. File-storage region is not claimed. Vercel Web Analytics records page views; it does not use cookies and does not identify visitors.
NeonHosted PostgreSQL in AWS eu-west-2 (London), as stated on Trust & data. Shared infrastructure, also used by Portraits — not a dedicated Pindrop database.
ResendTransactional email (invitations, reminders, account mail)
StripePayments
SentryError monitoring (EU ingest). Tracing is present on the live HTML.
UpstashRate limiting
CloudConvertPresentation rendering
SupabaseAskEX / semantic search, AWS eu-west-1 (Ireland)
AnthropicAI features via the Claude API (questionnaire design, theme analysis, report drafting). API inputs are not used to train Anthropic's models. Organisations can bring their own Anthropic key or gateway (BYOK).
Microsoft (Teams / Entra / Azure Bot)Personal-scope Teams bot: invitations and reminders as chats, with email fallback, when a customer enables it.

Optional customer connections, only if the organisation turns them on: Qualtrics, SurveyMonkey, Typeform, Notion.

We do not claim that all of this processing stays in the United Kingdom.

8. International transfers

Several processors above are US organisations or may store data outside the United Kingdom. We do not name a transfer mechanism on this page. We do not claim UK-only or EU-only residency, and we do not claim UK compute.

9. Email, Teams, and PECR

Service messages (survey invitations, reminders, security and account mail) are sent because the customer asked us to send them, or because you have an account. That is not marketing.

We will not send marketing email about Pindrop without a PECR-compliant consent or another lawful PECR route. Unsubscribing from marketing does not stop survey invitations that a customer has instructed us to send; the respondent should ask that organisation to stop inviting them.

Where a customer uses Teams, the bot is personal-scope. Invitations and reminders go as chats, with email as fallback if Teams delivery fails. Answering inside a Teams card is not the main path. Anonymous in-card answering is gated off.

10. Cookies and similar technology

The signed-in product uses an essential authentication cookie named ee-session-token. There is no cookie banner and no separate cookie policy. Sentry tracing is present on the live HTML. Vercel Web Analytics records page views; it does not set cookies and does not identify visitors. We have not completed a full cookie inventory, so we do not claim “essential cookies only”.

11. How long we keep data

  • Account and workspace records: while the workspace is open, then 12 months after closure, except invoices and accounting records kept 6 years
  • Survey and respondent records (as processor): deleted from the live database within 30 days of the customer deleting the campaign or closing the workspace; backups no more than 90 days, unless the law requires longer
  • Security logs: kept only as long as needed for security and debugging

12. Your rights

If we are the controller (account holders and our own contacts), you can ask us to access, correct, delete, or restrict your data, object to legitimate-interest processing, or receive a copy in a portable form, as UK GDPR allows. You can complain to the Information Commissioner's Office (ico.org.uk).

If we are the processor (survey respondents), contact the organisation that ran the survey. We will support them.

13. Children

Pindrop is built for workplace listening. It is not aimed at children. We do not knowingly create accounts for anyone under 16.

14. The EX Institute

The EX Institute is a separate, editorially independent professional body. Recognition of Pindrop as a practice platform does not make the Institute a controller or processor of your Pindrop data, and this policy is not an Institute privacy notice.

15. Changes

We will update this page when the facts change. Material changes will be dated here.