Is Tellet GDPR compliant?
Yes. Tellet is fully GDPR compliant. You (the client) are the data controller. Tellet is the data processor. Tellet processes data on your behalf and at your direction. All data is hosted on Microsoft Azure within the EU.
Who is the data controller and who is the processor?
Under GDPR, you (the client) are the data controller. Tellet is the data processor. Because you are the controller, you must include a link to your own privacy policy when setting up a discussion guide. Participants are shown your privacy policy link before starting the interview.
How long is data stored?
If no deletion request is made, data is retained for up to three years and then automatically deleted. You can delete data at any time: it is removed from primary systems immediately and from backups within a set period. Customer SaaS data is retained for up to 6 years after contract termination, or as required by law.
Can I delete data?
Yes. You can delete individual conversations from the Transcripts tab, or contact [email protected] to request deletion of all project data. Deletion from primary systems is immediate. Removal from backups occurs within a set period.
Can I request custom data retention terms?
No. Custom retention terms are not currently available.
With whom is personal data shared?
Personal data is not shared with any third parties outside your Tellet account. Only you and users you explicitly invite have access to your data. A sub-processor list is available upon request.
Who are Tellet's sub-processors?
Digital Ocean (cloud hosting, EU Netherlands), Azure OpenAI (AI engine, EU Sweden), HubSpot (CRM, EU), Google Workspace (email and docs, EU), Slack (team communications, USA), GitHub (code repository, EU), S3 (object storage, EU), Jira (project management, EU), Confluence (documentation, EU).
Is the consent form customisable?
No. The consent form is a fixed legal document and cannot be modified. All participants must provide consent before starting an interview. This is because most interviews involve collecting PII (voice and video responses). Even text-only interviews require consent for participant safety and compliance.
Can data collected through Tellet be quoted for publication?
Yes. Text quotes and insights from Tellet interviews are suitable for publication. Audio and video recordings contain personally identifiable information and should not be published.
Do you conduct penetration tests and security audits?
Yes. Tellet conducts regular security audits and penetration testing. Cyber insurance is also in place.
Can I request a DPIA?
Yes. Contact [email protected] to request a copy of Tellet's Data Protection Impact Assessment.
Can I request a custom DPA template?
Yes. Email [email protected] to request a custom Data Processing Agreement template.
Can I request a copy of the RoPA?
Yes. Contact [email protected].
Can I choose the data storage location (EU vs US)?
No. All data is stored and processed in the EU only. This cannot be changed.
Does Tellet support participants under 16?
No. The Tellet platform is for participants aged 16 and above. Children's consent forms are not supported.
Do you offer pseudonymisation or automatic data redaction?
No. Neither is currently supported. Consent is collected from every participant before an interview begins.
Do you support single sign-on (SSO)?
Not yet. Multi-factor authentication (2FA) is available. SSO is on the roadmap and coming soon.