GDPR Compliance
Last updated: June 2026
Insight Squid is built and hosted in the UK with EU users in mind. We take data protection seriously and comply with the UK GDPR and EU GDPR. This page explains how we handle personal data, your rights, and how we support your compliance obligations.
1. Our Role
When you use Insight Squid to collect and process participant data:
You are the Data Controller. You decide what data to collect, why you need it, and how long to keep it.
We are the Data Processor. We process data on your instructions and only to provide the platform.
We have a Data Processing Agreement (DPA) in place. If you need a copy, contact us at legal@insightsquid.com.
2. What Data We Process
| Data type | Why we process it | Lawful basis |
|---|---|---|
| Account details (name, email, company) | To provide access, billing, and support | Contract |
| Researcher and observer data | To manage team access and permissions | Contract |
| Participant contact details (surname, email, phone) | To facilitate recruitment, scheduling, and on-platform messaging. Full contact details are hidden from researchers. Researchers see only first name and first letter of surname for identification in the platform. | Your instructions (we rely on your lawful basis) |
| Participant recordings and transcripts | To deliver the research tools you have requested | Your instructions (we rely on your lawful basis) |
| Screener responses | To help researchers select suitable participants for a study | Your instructions (we rely on your lawful basis) |
| Usage logs and analytics | To maintain security, fix bugs, and improve the platform | Legitimate interests |
| Payment information | To process subscriptions | Contract |
Data minimisation: No other identifiable information is captured about participants. For participants recruited through the platform, their full surname, email address, and contact number are hidden from researchers. Researchers see only the participant's first name and first letter of their surname for identification within the platform. In any reporting, participants are referred to by a number (e.g., Participant 1). All communication happens via the platform's built-in messaging system.
Participant identification: Within the researcher platform, participants are identified by their first name and first letter of their surname. Full contact details (surname, email, mobile number) remain hidden from researchers and are visible only to the participant themselves. In exported reports and insight stories, participants are referred to by a sequential number (e.g., Participant 1) to ensure anonymity. This data is used internally solely for the purpose of communicating with the participant in relation to study invitations and the studies in which they are scheduled or participating.
NDA breach disclosures: The only circumstance under which the platform will release identifiable information is if there is a strong belief that a participant has breached a non-disclosure agreement. In such cases, we are obligated to provide the participant's name, IP address, and email address to the relevant authorities.
3. How We Protect Data
Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
Access controls: Role-based permissions, SSO (SAML 2.0 / OAuth), and optional domain lock.
Infrastructure: Hosted on EU-based cloud providers with ISO 27001-aligned practices.
Backups: Encrypted, geographically separated, and tested regularly.
Staff access: Only authorised engineers can access production systems, and only for support or maintenance with logging.
4. AI and Data Protection
We use AI providers (Speechmatics, Together.ai) to deliver transcription, summarisation, and thematic analysis. We have contractual agreements in place that prohibit these providers from using your research data to train, fine-tune, or improve their AI models. Your recordings, transcripts, and research content are processed solely to generate outputs for your project and are never retained or used for model training.
5. International Transfers
Our primary infrastructure is in the UK and EU. Some supporting services (e.g., AI transcription providers) may process data outside the EEA. Where this happens, we ensure adequate safeguards are in place, such as:
Standard Contractual Clauses (SCCs) with additional technical and organisational measures.
Using providers certified under recognised adequacy decisions where possible.
6. Retention and Deletion
Video recordings and transcripts are stored for a maximum of 12 months. You can delete them earlier at any time.
Participant contact details (surname, email, phone) are retained for as long as needed to facilitate recruitment and communication, or until the participant deletes their account.
Screener responses are retained only for the duration of the study and are deleted once the study is complete.
Account and billing data is kept for 6 years after closure to meet UK tax and legal obligations. Reward transaction records, including associated email addresses, are retained for 6 years for tax auditing purposes.
You can delete individual sessions, projects, or your entire account from the platform. Deletion is permanent and cannot be undone.
7. Your Rights (and Your Participants' Rights)
Under GDPR, individuals have the right to:
Access their personal data.
Rectify inaccurate or incomplete data.
Erasure ("right to be forgotten") in certain circumstances.
Restrict processing.
Data portability – receive data in a structured, machine-readable format.
Object to processing based on legitimate interests.
Withdraw consent at any time.
Because you are the controller for participant data, participant requests should generally come to you first. We will assist you in fulfilling these requests where we hold the data on your behalf.
8. Data Breaches
We have internal breach detection and response procedures. If we become aware of a personal data breach that affects your data, we will notify you without undue delay and within 72 hours where feasible. You are responsible for assessing whether you need to notify your participants or a supervisory authority.
9. Sub-processors
We use the following sub-processors to deliver the platform:
Stripe – payment processing
Together.ai – AI summarisation and thematic analysis
Speechmatics – speech-to-text transcription
Browserless – browser automation for session recording and testing tasks
Tremendous – participant reward distribution
Respondent, Prolific, Testing Time – participant sourcing and recruitment
We review their security and contractual compliance before engagement and keep this list up to date.
10. Contact and Supervisory Authority
For data protection questions, contact our team at legal@insightsquid.com.
If you are in the UK, the supervisory authority is the Information Commissioner's Office (ICO). If you are in the EU, you can contact your local data protection authority.