PRIVACY POLICY
Last updated: [DATE OF PUBLICATION]
Your privacy is important to us, and so is being transparent about how we collect, use, and share information about you.
This Privacy Policy (“Policy”) describes how Discuss.io, Inc., Groupe Voxco Inc., Language Logic, LLC (doing business as Ascribe), Voxco GmbH, and Voxco SARL, together with their respective affiliates and subsidiaries (collectively, “Discuss,” “Voxco,” “Ascribe,” “we,” “our,” or “us”), collect, use, disclose, and protect personal data when you visit our websites, use our platforms and products — including the Discuss platform, Voxco Online, Voxco CATI, Voxco Dialer, Voxco Analytics, Voxco Audience, Voxco Panel & Portal, and Ascribe Text Analytics — or otherwise interact with us (collectively, the “Services”), unless a different policy is displayed.
Where we provide the Services under contract with a customer, researcher, or organization (for example, your employer or the organization commissioning research), that organization controls and determines the processing of personal data for research activities hosted on its account, for which we act as a processor. Other users of our Services, such as moderators, translators, and observers, may provide personal data that we process as a controller, as described below. For participants in research activities hosted on the platform, the organization or researcher contracting with us controls and determines the processing of personal data.
This Policy applies to all Discuss, Voxco, and Ascribe legal entities and operating locations, and covers your interactions with us as a customer, participant, website visitor, job applicant, or other type of user.
2. Our Role in Handling Your Information
We may act as a Controller or Processor of personal data depending on the specific context. Our approach is informed by the controller/processor framework under the EU GDPR and equivalent concepts under other data protection laws.
Controller (we determine the purposes and means of processing)
• When interacting directly with customers, prospects, website visitors, vendors, and partners through our website, sales, and marketing activities.
• When we initiate a market research study that collects personal data directly from individuals using our own sample or sources.
• For our own recruiting, human resources, accounting, operations, and other internal business processes.
• When you visit our offices or otherwise interact with us directly as an individual, rather than as a participant in a customer’s research.
Processor (we process data on behalf of customers per their instructions)
• When contracted by a customer, researcher, or organization to collect personal data from individuals using that customer’s sample and sources.
• When providing self-service Services that allow contracted customers to collect personal data directly from individuals; the customer determines the purposes and means as Controller.
• When conducting market research activities as contracted by a customer using its own sample sources.
• When storing, organizing, analyzing, transcribing, or translating personal data from contracted research activities per the customer’s instructions.
• When transferring personal data or recordings to contracted customers after research activities conclude.
If you participated in a research activity from one of our customers, the invitation, survey, or interview may indicate it is “powered by Voxco,” “powered by Discuss,” or similar, and the data may be hosted in our environment. Regardless, the customer is solely responsible for decisions about the personal data it collects from you. For information on how a specific customer intends to use your data, please contact that customer directly.
Where personal data involves special categories of data (such as data revealing health, racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic or biometric data, or data concerning sex life or sexual orientation), we process such data only on the customer’s documented instructions and as necessary to provide the Services; the customer is responsible for determining the lawful basis for that processing and for obtaining any required consent.
3. Information We Collect
We process or collect information to provide, build, protect, improve, and promote our Services. The categories of information we collect or process include:
• Account Information: your name, email address, password, job title/role, and other details you provide when you sign up for an account.
• Billing and Payment Information: for paying customers, billing address, payment method, and transaction history, including any credit card or banking information you provide to process payment.
• Log Data and Device Information: IP address or other device identifier, browser type and version, internet speed, time zone setting and location, and operating system and platform.
• Sales and Support Data: information you provide when interacting with our sales and support teams.
• User Content or Interview Data: quote form details, documents, video and audio recordings, discussion guides, screeners, survey responses, meeting room data, clips, labels, transcripts, reports, or other content uploaded or transmitted via the Services, or generated as part of a contracted research project, including any derivatives of that data.
• Usage Data: details on how you and your devices interact with the Services, including service selections, clicks, pages visited, analytics, entry/exit pages, and usage metrics.
• Research Participant Data: from research participants (“panelists,” “respondents,” or “participants”), contact details, demographic information, survey responses, and interview-derived data such as video and/or audio recordings, collected only after explicit consent has been obtained in accordance with the customer’s instructions.
• Human Resources and Recruitment Data: for employees, contractors, and job applicants, including identification and contact details, employment and contractual information, application and recruitment data, HR and performance records, and payroll and tax information.
• Cookie Information and Other Identifiers: to enable our systems to recognize your browser or device and provide, protect, and improve our products. See Section 11 (Cookies) below.
• Third-Party Information: data about organizations, industries, or website visitors from affiliates, partners, or other sources we use to make our information better or more useful.
• AI-Generated Data and AI-Processed Content: data generated through AI-enabled features and AI-processed content and responses. See Section 4 (Use of Artificial Intelligence) below.
• Other Information: additional personal information you choose to submit through surveys, registration forms, or beta programs.
We do not request the disclosure of special categories of personal data or sensitive data unless otherwise instructed by a customer or by you, and only after explicit consent has been obtained where required.
4. Use of Artificial Intelligence
We integrate artificial intelligence services to enhance platform capabilities, including but not limited to: AI-enabled question types that generate real-time follow-up questions based on respondent input; document processing for survey and questionnaire creation; translation services for multi-language support; and response analysis and interpretation features.
AI processing occurs only where a customer deliberately enables AI-powered question types or features in its questionnaire design, or where you actively use AI-powered platform features yourself. We do not use fine-tuning or model training on customer or participant data, and all AI behavior is controlled through prompt engineering and retrieval-based context rather than persistent training on your data.
Legal Basis for AI Processing (GDPR)
Our use of AI services is based on one of the following:
• Legitimate interest in improving platform functionality, response quality, and user experience;
• Explicit consent, where applicable; or
• Performance of a contract to deliver requested platform features.
You retain the rights described in Section 8 (Exercising Your Data Rights) with respect to data processed through AI-enabled features, subject to the controller/processor allocation described in Section 2.
5. How We Use Information We Collect
We use personal data for specified, explicit, and legitimate purposes, including to:
• Deliver the Services in connection with the projects, research, and transactions you or a customer initiate;
• Provide customer support, technical assistance, and account-related services;
• Verify your identity and help secure your account;
• Invite you to participate in surveys, interviews, focus groups, and other market research activities;
• Send insights, updates, and information about market research, our Services, and industry trends;
• Personalize your experience with relevant content, recommendations, and features;
• Analyze usage patterns and performance data to improve and optimize our platform;
• Monitor and protect our systems, infrastructure, and confidential data through cybersecurity measures;
• Detect, investigate, and prevent fraud, misuse, or other unauthorized activity;
• Comply with applicable legal, regulatory, and contractual obligations;
• Aggregate or de-identify data for analytics, reporting, and other legitimate business purposes (see Section 6); and
• Retain personal data as long as your account remains active, or longer where legally required (see Section 7).
We use both automated and manual processing techniques for these purposes, including artificial intelligence as described in Section 4. Our manual review processes frequently work in conjunction with, and support, our automated methods.
6. How We Disclose Information We Collect
We want our platform to be easy, collaborative, and accessible for research teams, which means disclosing information through the Services and to certain third parties, as described below. We are not a data broker, and we do not sell personal information for monetary consideration. Information collected through third-party cookies, pixels, tags, or similar tracking technologies for cross-context behavioral advertising purposes may nonetheless be considered a “sale” or “share” under certain US state laws; see Section 10.C.
Disclosing to other Service users
• Collaboration: you may share content containing information about you based on account permissions (for example, a saved moment displays your name to other authorized users).
• Managed accounts: if you register using your employer’s domain, your name, contact information, content, and account use may become accessible to your organization’s administrators and other authorized users on that domain.
• Administrators: if you are an administrator, we may disclose your contact information to facilitate platform-related requests from other users.
Disclosing to third parties
• Service Providers / Sub-processors: we use companies such as Amazon Web Services to provide, protect, promote, and improve our products. These providers are bound by contract to use your data only as we instruct. Current sub-processor lists are available for Voxco and Ascribe Services and for Discuss Services (see Section 14).
• Legal/Regulatory Entities: we may share data with law enforcement, government agencies, or regulators where reasonably necessary to comply with law, legal process, or a legitimate governmental request.
• Business Transactions: in a merger, acquisition, bankruptcy, or other corporate transaction, your data may be transferred to the acquiring organization.
• Affiliates: we may share personal data among our affiliated entities for the purposes described in this Policy.
• Your Consent: we may share your data with other third parties where you give explicit consent.
Aggregated and de-identified data
We may create aggregated or de-identified data derived from the information we collect, for purposes such as analytics, reporting, and improving our Services. Once information has been aggregated or de-identified such that it can no longer reasonably be used to identify you, it is no longer considered personal data under this Policy. We do not attempt to re-identify such data and maintain reasonable measures designed to prevent re-identification.
7. Data Security and Retention
We use a combination of technical, physical, and logical safeguards to protect your data, including encryption of data in transit and at rest, access controls to restrict unauthorized personnel, secure network configuration and monitoring (including intrusion detection/prevention), data transfer restrictions, staff security training and confidentiality agreements, and regular third-party audits and penetration testing.
Discuss.io, Inc. is ISO/IEC 27001 certified. Groupe Voxco Inc., Language Logic, LLC, Voxco GmbH, and Voxco SARL have completed a SOC 2 Type II audit. Certification and audit scope vary by entity and product; current certifications and audit reports are available through our respective Trust Centers (see Section 14).
We retain personal data only as long as needed to fulfill the purposes described in this Policy, unless a longer period is required by law. Retention considerations include the duration of your account and use of the Services, applicable statutes of limitations, contractual obligations with customers, and legal holds required for litigation or investigations. When we no longer require personal data, we securely delete or anonymize it, and we regularly review our data inventories to retain only what is still needed for business purposes.
8. Exercising Your Data Rights
Subject to local data protection laws, you may have the right to: be informed of the purposes of processing; access your personal data; correct incomplete or inaccurate personal data; erase your personal data, to the extent permitted by other legal obligations; restrict our future processing; transfer your data to another controller where possible; and object to processing carried out on the basis of our legitimate interests.
• Request a Personal Data Report: submit an access request through our support channels (see Section 14).
• Correct or Update Your Data: update your name, email address, and language preference through your account settings, or contact support.
• Stop Marketing Processing: use the “unsubscribe” link in marketing emails, or request account deletion to stop all processing of your personal information.
• Delete Your Data: request deletion of your personal information by deleting your account or contacting us. If your account is managed by your employer or another organization, contact that organization’s administrator; for enterprise accounts, the organization controls the account and associated personal data.
• Move Your Data: download interview data stored in your account through the applicable export functionality, or contact support.
• Lodge a Complaint: if you are based in the EEA, Switzerland, or the UK, you have the right to lodge a complaint with your local supervisory authority. See Section 10.A.
We will respond to requests within 30 days unless an extension is required or permitted by law. We may need to verify your identity before fulfilling a request.
9. International Transfers of Data
We collect information globally and operate in multiple countries, including the United States, Canada, the European Economic Area, the United Kingdom, and Australia. We may transfer, process, and store your information outside your country of residence to wherever we or our service providers operate, in order to provide the Services. Any such transfer is carried out in compliance with applicable law.
For transfers of personal data protected by EEA, Swiss, or UK data protection law to a jurisdiction that has not received an adequacy decision or similar determination, we ensure the transfer is subject to an appropriate transfer mechanism, as described below.
Discuss.io, Inc. participates in and certifies compliance with the EU-U.S. Data Privacy Framework (DPF), the Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF, as administered by the US Department of Commerce. Discuss.io, Inc. remains responsible for personal information shared under the Onward Transfer Principle with third parties for processing on its behalf. Details of the DPF program and our certification are available at dataprivacyframework.gov.
For Restricted Transfers involving any other Discuss, Voxco, or Ascribe entity as data importer, we rely on the Standard Contractual Clauses approved by the European Commission (and, for transfers from the United Kingdom, the UK Addendum issued by the UK Information Commissioner), together with supplementary measures where required.
In compliance with the EU-U.S. DPF and the UK Extension, Discuss.io, Inc. commits to cooperate with the advice of the panel established by the EU data protection authorities and the UK Information Commissioner’s Office regarding unresolved DPF complaints, including those concerning human resources data. Discuss.io, Inc. further commits to refer unresolved DPF complaints to ICDR-AAA, an alternative dispute resolution provider based in the United States, at no cost to you. Discuss.io, Inc. is subject to the investigatory and enforcement powers of the US Federal Trade Commission.
10. Additional Information for Users in Specific Regions
A. European Economic Area, United Kingdom, and Switzerland
The information in this section is specific to our European, Swiss, and UK users.
To reach our Data Protection Officer (as defined under the GDPR), contact dpo@discuss.io.
Legal Basis for Processing
• Performance of a Contract: to provide the Services or communicate with you about them, including taking and handling projects, setting up sessions, and processing payments.
• Our Legitimate Business Interests: and those of our customers, including detecting and preventing fraud and abuse, improving our products, and promoting our paid products to you.
• Your Consent: where we ask for consent to process your personal information for a specific purpose; you may withdraw consent at any time.
• Compliance with a Legal Obligation: for example, collecting identity-verification information required by law.
Information submitted to us will be transferred to, processed, and stored in the United States and around the world, as described in Section 9. If you believe we have not complied with applicable data protection law, you have the right to lodge a complaint with your local supervisory authority.
B. Canada (PIPEDA and Quebec Law 25)
This section applies to users in Canada. Groupe Voxco Inc. is domiciled in Quebec. Where your personal data is subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) or Quebec’s Act respecting the protection of personal information in the private sector (“Law 25”), we process it in accordance with the applicable requirements of those laws, including in our role as a service provider under Law 25 where we process personal data on behalf of a customer.
If we become aware of a confidentiality incident affecting your personal data that we process on a customer’s behalf, we will notify the customer with information sufficient to enable it to assess the incident and make any notifications required under Law 25. Where we act as controller of your personal data (see Section 2), we will notify affected individuals and the Commission d’acces a l’information du Quebec where required.
C. California and Other US State Privacy Laws
This information supplements this Policy and applies to residents of California and other US states that have enacted comprehensive consumer privacy laws, which as of this Policy’s last update include Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Indiana, Kentucky, Rhode Island, and other states with comparable laws then in effect.
Subject to applicable state law, you may request that we:
• Provide access to and a copy of certain information we hold about you;
• Provide a summary of the categories of personal information collected or disclosed about you in the preceding twelve months, the categories of sources, the business or commercial purpose for collecting or selling such information, and the categories of third parties with whom it was shared;
• Delete your personal data;
• Correct inaccurate personal data; and
• Not be discriminated against for exercising your privacy rights.
California Civil Code Section 1798.83 permits California residents to request information regarding our disclosure of personal data to third parties for their direct marketing purposes. California residents under 18 who are registered users may request removal of content they have publicly posted, under California Business and Professions Code Section 22581. To make a request under the CCPA or other applicable state privacy law, contact us as described in Section 14.
D. Brazil
This information supplements this Policy and applies to residents of Brazil. Subject to Brazil’s Lei Geral de Protecao de Dados (LGPD), you may request access to, correction of, and deletion of your personal data, and you have the right not to be discriminated against for exercising your privacy rights.
E. Biometric Data (United States)
This section applies where the Services process biometric identifiers (such as a voiceprint or faceprint) of individuals in the United States, including under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, the Washington biometric privacy law, and comparable provisions of other state privacy laws. Photographs and audio or video recordings are not biometric data unless a biometric identifier is extracted from them.
F. Other Jurisdictions
Where your personal data is subject to the data protection law of another jurisdiction not addressed above, we comply with the obligations applicable to our role under that law. We will add jurisdiction-specific provisions to this Policy where our processing involves a material volume of personal data subject to such a law.
11. Cookies
A cookie is a small text file that a website saves on your computer or mobile device when you visit the site, enabling the site to remember your actions and preferences over time. We use session cookies (erased when you close your browser) and permanent cookies to recognize repeat visits, which helps us improve your browsing experience and evaluate website behavior in the aggregate. Some of our service providers may also use their own cookies, over which we do not have control, including for analytics, advertising, social media features, and live chat.
You can modify your browser settings to decline or control cookies. If you do not accept cookies, you may not experience full functionality of our website. For information about Google Analytics and how to opt out, see Google’s Analytics Terms of Use and Privacy Policy, or install the Google Analytics Opt-out Browser Add-on.
12. Minors and Children
We do not knowingly allow children under the age of 13, or children considered “Minors” under the laws of the jurisdiction in which they reside (which may set a higher age, such as 16), to use the Services without the consent of a parent or legal guardian required by applicable law. If you believe we might have information from or about a Minor that was collected without proper consent, please contact us using the details in Section 14.
13. Changes to This Policy
We may occasionally update this Policy to reflect changes in our personal data practices or applicable legal requirements. When we post changes, we will revise the “Last Updated” date at the top of this Policy. If we make significant changes, we will provide prominent notice on our website or send a notification. We encourage you to periodically review this page. Your continued use of the Services confirms your acceptance of the updated Policy.
14. Contact Information
You can contact us with questions about this Policy as follows:
Discuss Services
• Email: privacy@discuss.io
• Support ticket: discussio.zendesk.com
• Trust Center / Sub-processor list: trust.discuss.io
Voxco and Ascribe Services
• Email: privacy@voxco.com
• Sub-processor list: voxco.com/data-processing-agreement
European Data Protection Officer
• Email: dpo@discuss.io (see decision note in Section 10.A)
15. Definitions
In this Policy, “personal data” includes:
• Under the laws of the United States, any “non-public personal information” as defined in the Gramm-Leach-Bliley Act (15 U.S.C. Subchapter I, Section 6809(4)), and “protected health information” as defined in HIPAA (45 CFR Section 160.103);
• Under the laws of the European Economic Area, the meaning given in the General Data Protection Regulation (“GDPR”);
• Under the laws of Australia, information or an opinion about an identified individual or an individual who is reasonably identifiable, whether true or not, and whether recorded in material form or not;
• Under the laws of California, any “personal information” as defined in the California Consumer Privacy Act (“CCPA”), Section 1798.140(o); and
• Under the laws of Brazil, the meaning given in the Lei Geral de Protecao de Dados (“LGPD”).
“Applicable State Privacy Laws” means, as applicable, the CCPA and other comprehensive US state consumer privacy laws then in effect, including but not limited to those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Indiana, Kentucky, and Rhode Island, together with their implementing regulations.
For Applicable State Privacy Laws, terms such as “business,” “consumer,” “controller,” “personal data,” “personal information,” “process,” “processing,” “sale(s),” and “sell” have the meanings given in those laws.
“Deidentified Data” means data that is “deidentified” as defined by the CCPA and “de-identified data” as defined by other Applicable State Privacy Laws, when disclosed by one party to another.
“CCPA” means the California Consumer Privacy Act of 2018, as amended, including by the California Privacy Rights Act of 2020, together with its implementing regulations.
“Data controller” means the party that determines the purposes or means of the processing of personal data.
“Data processor” means the party that processes personal data on behalf of the data controller.
“Personal information” generally means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.