Open Lab

Legal

Data Processing Agreement

How Open Lab processes participant study data on your behalf, as your processor under Article 28 GDPR. Incorporated into the Terms of Service. Last updated June 2026.

For help, visit Support or check the documentation.
This Data Processing Agreement ("DPA") governs the processing of personal data by Open Lab Online UG (haftungsbeschränkt) on behalf of the researcher in connection with the Open Lab platform. It is incorporated by reference into, and forms an integral part of, the Open Lab Terms of Service (the "Terms"). By accepting the Terms at signup, or by using the platform to collect study data, you enter into this DPA. Where this DPA and the Terms conflict on data-protection matters, this DPA prevails.
Processor: Open Lab Online UG (haftungsbeschränkt), Friedrichstrasse 6b, 78464 Konstanz, Germany; info@open-lab.online; Managing Director Yury Shevchenko ("Open Lab", "we").
Controller: the researcher who registers for and uses Open Lab, and/or the institution on whose behalf they act where that institution is the controller of the study data ("you").

Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "special categories of personal data" and "personal data breach" have the meanings given in the GDPR (Regulation (EU) 2016/679). "Study Data" means the personal data you collect from participants through a study — responses, screening answers, paradata, completion and timing data, and any files your study collects — which Open Lab hosts and processes on your behalf. "Applicable Data Protection Law" includes the GDPR and the German Federal Data Protection Act (BDSG).
Open Lab hosts, stores and processes Study Data so that you can design and run online studies and collect, store and analyse participant responses. We process Study Data solely to provide the platform: receiving responses, storing them in encrypted form, making them available for export and analysis, applying your configured retention and deletion settings, and operating the supporting infrastructure (authentication, access control, backups, security). We do not process Study Data for our own purposes. Processing lasts for the term of your use of the platform and ends per Section 11. Further detail is in Annex 1.
The data subjects are the participants in your studies. The types of personal data are determined by you through your study design and configuration, and may include identifiers and contact details (where collected), demographic and screening information, survey and free-text responses, behavioural/paradata, and completion data. Participant IP addresses are stored only as a salted hash.

Because you choose what to collect, Study Data may include special categories of personal data (Art. 9 GDPR), depending on the study. You are responsible for, and warrant that: you have a valid legal basis under Art. 6 GDPR; where special categories are involved, an Art. 9 condition is met — typically the participant's explicit consent via the in-study consent form, or the scientific-research basis under Art. 9(2)(j) with Art. 89 GDPR and BDSG §27; you have any required ethics-board approval; and you provide participants the information required by Arts. 13–14 GDPR. Open Lab processes Study Data only on your behalf and does not determine the purposes or means of the underlying research.
Open Lab processes Study Data only on your documented instructions, including as to international transfers, unless required otherwise by EU or Member State law (in which case we inform you first, unless the law prohibits it on important public-interest grounds). Your documented instructions comprise this DPA, the Terms, and your configuration of and actions within the platform (study design, fields collected, retention and deletion settings, access and collaborator settings, exports, and erasure actions). We will inform you if, in our opinion, an instruction infringes data-protection law; we are not obliged to legally review your study design and are not responsible for the lawfulness of the underlying research.
Persons authorised to process Study Data are bound by confidentiality (contractually or by statute), and access is limited to personnel who need it to provide the platform. This survives termination. For any study using the default end-to-end encryption (Annex 2), Open Lab personnel cannot in any event read that study's content; for studies you opt out to server-side encryption, confidentiality rests on these obligations and the access controls in Annex 2.
Taking into account the state of the art, costs, and the nature, scope, context and purposes of processing and the risks to data subjects, Open Lab implements appropriate technical and organisational measures (Annex 2). These include end-to-end encryption of study datasets by default — each study's responses are encrypted with a data key wrapped to your own account key (X25519/ECIES + AES-256-GCM), which you unlock with your password (with a one-time recovery code as backup), so Open Lab is zero-knowledge as to that study's content; you may grant project collaborators you authorise the ability to decrypt. For pilot studies, testing, or where you prefer it, you may opt a study out to server-side encryption, where Study Data is encrypted in transit and at rest with keys managed by Open Lab and protected by access controls, but is technically accessible to Open Lab acting as your processor. These sit alongside TLS/HTTPS in transit, encryption at rest and encrypted backups at the hosting layer, salted hashing of participant IPs, role- and item-level access control, and audit logging. We may update these measures provided the level of security is not materially reduced.
You give Open Lab a general written authorisation to engage the sub-processors listed in our Sub-processor list (Annex 3). We impose data-protection obligations on each sub-processor equivalent to those in this DPA, and remain fully liable to you for their performance. We give advance notice of any addition or replacement of a sub-processor that processes Study Data, by updating the published list and emailing account owners, with a 30-day window during which you may reasonably object. If an objection cannot be resolved, you may terminate the affected service as your sole remedy.
Taking into account the nature of processing, Open Lab assists you, by appropriate measures and insofar as possible, in responding to data-subject-rights requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). The platform provides self-service tools — participant data export, account deletion, study withdrawal, and rectification — that help give effect to these rights; we also assist on request. For end-to-end-encrypted studies (the default), we cannot read the content, so requests requiring access to that content are performed by you (you hold the key); for studies you opt out to server-side encryption, we can assist directly. We also assist you with your obligations under Arts. 32–36 GDPR, including DPIAs and prior consultation.
Open Lab notifies you without undue delay after becoming aware of a personal data breach affecting your Study Data or related personal data, describing (to the extent known) the nature of the breach, the categories and approximate numbers affected, likely consequences, and measures taken. We follow our documented incident-response plan. The obligation to notify the supervisory authority and, where required, data subjects under Arts. 33–34 GDPR rests with you, with our assistance under Section 8.
At your choice, Open Lab deletes or returns all Study Data after the end of the services, and deletes existing copies, unless EU or Member State law requires storage. In practice the platform applies automated retention and deletion: study datasets are auto-deleted per plan — free: 12 months; paid: 36 months by default, with a per-study override (0 means indefinite, on paid plans). The lifecycle is a warning 30 days before expiry → soft-delete → hard-delete after a 30-day grace period, including the underlying storage object. On account termination, your data is deleted. You can export (return) Study Data at any time via the platform's tools (you hold the key). Encrypted residual copies in backups are overwritten in the ordinary backup-rotation cycle.
Open Lab makes available the information necessary to demonstrate compliance with Art. 28 GDPR, and allows for and contributes to audits, including inspections, by you or an auditor you mandate. Audits are subject to reasonable conditions: reasonable prior written notice, no more than once per year (save following a breach or where required by a supervisory authority), during normal business hours, minimising disruption, protecting confidentiality and other customers' data, and the auditor's confidentiality commitment. We may satisfy audit requests in whole or part by providing our security documentation, Annex 2, and the sub-processor list.
Core compute, the PostgreSQL database, and Spaces object storage are hosted by DigitalOcean in Frankfurt, Germany (EU), so the primary repositories of Study Data and uploaded files remain in the EEA; analytics, where enabled, is EU-hosted. Transfers outside the EEA arise only via certain US-based sub-processors (billing, email, participant payouts, optional sign-in), for which we rely on the EU–US Data Privacy Framework where the recipient is certified and on Standard Contractual Clauses as a safeguard or fallback. For end-to-end-encrypted studies (the default), their Study Data is unreadable by storage sub-processors. See the sub-processor list for details.
Each party is liable in accordance with Art. 82 GDPR and the liability provisions of the Terms; nothing here limits a data subject's GDPR rights. This DPA takes effect on acceptance of the Terms and remains in force while Open Lab processes Study Data on your behalf, terminating on completion of deletion or return under Section 10; obligations that should survive (including confidentiality and Section 10) survive. This DPA is governed by the laws of the Federal Republic of Germany, excluding its conflict-of-laws rules and the UN CISG; the place of jurisdiction is Konstanz, Germany, to the extent permitted by law.
  • Subject matter: hosting, storage and processing of Study Data so you can run studies and collect/analyse responses.
  • Duration: term of your use of the platform; ends on account termination or expiry of the retention period (Section 10).
  • Nature and purpose: receiving, storing (encrypted), making available for export/analysis, and deleting responses; operating supporting infrastructure. No Open Lab own-purpose use.
  • Types of personal data: determined by your study design; may include special categories (Art. 9). Participant IPs stored only as a salted hash.
  • Data subjects: participants in your studies.
  • Your obligations: lawful basis (Art. 6), Art. 9 condition for special categories, ethics approval where applicable, participant information (Arts. 13–14).
  • End-to-end encryption of study datasets by default: an AES-256-GCM data key is wrapped to your account key via X25519/ECIES; the account key is unlocked by your password with a one-time recovery code as backup, and can be shared to collaborators you authorise — so Open Lab is zero-knowledge as to that study's content. A server-side encryption opt-out is available (data encrypted at rest with keys managed by Open Lab and accessible to Open Lab as your processor) for pilot studies and testing. A self-managed study key option is also available, where you generate and hold your own key file and Open Lab never holds it. Encryption in transit (TLS) and at-rest encryption at the hosting layer apply to all study data.
  • TLS/HTTPS everywhere, including the database connection.
  • Passwords hashed with bcrypt; 2FA secrets encrypted (AES-256-GCM); participant IPs stored only as a salted hash; short-lived (60-second) signed URLs for file access.
  • Role-based and item-level access control; stateless 7-day JWT sessions with secure + SameSite cookies; GraphQL introspection disabled in production; CORS allow-list; security headers; least-privilege admin access.
  • Audit logging of logins, exports, erasures, withdrawals, 2FA events and retention actions (18-month retention); encrypted PostgreSQL backups (7-day + point-in-time recovery), Spaces versioning, and tested restore.
  • Data minimisation, purpose limitation, and retention limits applied across the platform.
Your general written authorisation under Section 7 covers the sub-processors in our Sub-processor list, incorporated into this DPA by reference. That page sets out each sub-processor's purpose, processing location, and transfer safeguard, and the notice-of-change and objection process referenced in Section 7.

Need this for your institution?

If your institution requires a countersigned DPA or has specific clauses, contact us at info@open-lab.online.