Last Updated: July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Use between the Contracting Entity (as defined in the Terms of Use: Motives Inc. for US-based customers, and BTRT Ltd for all other customers), trading as Motives ("Processor"), and the Customer ("Controller") who has executed an Service Agreement incorporating this DPA by reference.
Terms not defined herein shall have the meanings set forth in the Terms of Use. In this DPA:
"Data Protection Laws" means the UK GDPR, EU GDPR (where applicable), and any other applicable data protection legislation.
"Personal Data" means any personal data processed by Processor on behalf of Controller under the Agreement.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
"Processing" has the meaning given in Data Protection Laws.
"Sub-processor" means any third party engaged by Processor to process Personal Data.
Processor shall process Personal Data only on documented instructions from Controller, except where required by applicable law. The processing details are:
Categories of Data Subjects: Research interview participants, survey respondents, and other individuals whose data is collected through the Services
Types of Personal Data: Voice recordings, video recordings, transcripts, demographic information, contact details, and survey responses
Purpose: To provide AI-powered consumer research and market research services
Duration: For the term of the Agreement plus 60 days
Processor shall:
a) Process Personal Data only on Controller's written instructions;
b) Ensure that all persons authorised to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality and receive appropriate training regarding the handling of Personal Data;
c) Implement appropriate technical and organizational measures to ensure security of Personal Data, including measures to prevent unauthorized access, disclosure, alteration, or destruction;
d) Not transfer Personal Data outside the UK/EEA except (i) to a Sub-processor authorised under Section 3, or (ii) with Controller's prior consent, and in each case subject to the appropriate safeguards described in Section 8;
e) Taking into account the nature of the processing, assist Controller in ensuring compliance with Articles 32–36 GDPR, including security obligations, Personal Data Breach notifications, Data Protection Impact Assessments and consultations with supervisory authorities;
f) Delete or return all Personal Data within 60 days after termination, except where retention is required by law, and certify such deletion to Controller on request;
g) Make available information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 5;
h) Immediately inform Controller if, in Processor's opinion, an instruction infringes applicable Data Protection Laws;
i) Maintain records of the Processing activities carried out on behalf of Controller as required by Article 30(2) UK GDPR or EU GDPR, as applicable, and make such records available to Controller or a supervisory authority on request.
Processor shall not, and shall procure that its Sub-processors do not, use Personal Data — or any recordings, transcripts, analyses or other outputs derived from it — to train, fine-tune, develop or otherwise improve any artificial intelligence or machine-learning model. Processor does not train, fine-tune or develop its own foundation models.
Where Processor engages a Sub-processor to provide artificial intelligence or machine-learning services, Processor shall ensure that such Sub-processor is engaged under terms that contractually prohibit the use of Personal Data submitted through the Services to train, fine-tune or improve that Sub-processor's models.
Nothing in this clause restricts Processor from Processing Personal Data at inference solely to provide the Services in accordance with Controller's documented instructions.
Controller acknowledges and agrees that Processor may engage Sub-processors in the following categories to deliver the Services:
Specific Sub-processors within these categories are listed at www.motives.ai/subprocessors.
Processor maintains a current list of Sub-processors at www.motives.ai/subprocessors and offers a mechanism for Controller to subscribe to notifications of changes. Processor shall give Controller prior notice of the addition or replacement of any Sub-processor (including within the authorized categories) by updating that list and notifying subscribed Controllers. For Sub-processors in categories not listed in Section 3.1, Processor shall give at least 30 days' prior notice. Controller may object to a new Sub-processor on reasonable data-protection grounds within 14 days of notice, and the parties shall work in good faith to resolve the objection; where it cannot be resolved, Controller may terminate the affected Services.
Processor shall ensure Sub-processors are bound by data protection obligations no less protective than this DPA. Where a Sub-processor fails to fulfil its data protection obligations, Processor shall remain fully liable to Controller for the performance of that Sub-processor's obligations.
Processor maintains security measures including:
Further detail is set out in Annex B (Technical and Organisational Measures).
Processor shall notify Controller without undue delay, and in any event within 72 hours where feasible, after becoming aware of a Personal Data Breach affecting Controller's Personal Data. The notification shall describe, to the extent known, the nature of the breach (including the categories and approximate number of data subjects and records concerned), the likely consequences, and the measures taken or proposed to address it, and shall provide sufficient information for Controller to meet its regulatory obligations.
Processor will make available to Controller the information reasonably necessary to demonstrate compliance with this DPA and with Article 28 UK GDPR. In addition to such documentation, Controller (or an independent auditor mandated by Controller and reasonably acceptable to Processor) may conduct an audit, including an on-site inspection, no more than once in any twelve-month period, on at least 30 days' prior written notice, during normal business hours and without unreasonable disruption to Processor's operations. Further audits may be conducted where required by a supervisory authority or following a Personal Data Breach affecting Controller's Personal Data. Controller shall bear its own audit costs and Processor's reasonable costs (including professional services time) for audits requiring significant resources beyond standard compliance documentation.
Taking into account the nature of the processing, Processor shall assist Controller in responding to data subject requests by:
Liability under this DPA is subject to the limitation of liability provisions in the Terms of Use. Each party shall indemnify the other against regulatory fines or third-party claims resulting from the indemnifying party's breach of Data Protection Laws.
Where Personal Data is transferred outside the UK/EEA, Processor shall ensure appropriate safeguards are in place, including as applicable:
Controller's authorisation of the Sub-processors under Section 3 constitutes its consent to the related transfers, subject to these safeguards.
Where the EU Standard Contractual Clauses or UK IDTA/Addendum apply, their annexes shall be deemed completed with the processing details set out in Section 2.1, the Sub-processor list referenced in Section 3, and the technical and organisational measures set out in Annex B.
This DPA continues for the duration of the Agreement. Obligations regarding security, confidentiality, and return/deletion of Personal Data survive termination.
In the event of any conflict between this DPA and the Terms of Use or any Service Agreement, this DPA shall prevail with respect to the Processing of Personal Data and matters of data protection.
This DPA is governed by the same law, and subject to the same jurisdiction provisions, as the Terms of Use.
Current Sub-processors: Available at www.motives.ai/subprocessors
Contact for Data Protection Matters: privacy@motives.ai
Processor implements and maintains the following technical and organisational measures to protect Personal Data:
1. Encryption. Personal Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
2. Access control. Role-based access controls on a least-privilege basis; access to Personal Data is limited to personnel who require it to provide the Services. Multi-factor authentication is enforced for systems processing Personal Data.
3. Logging and monitoring. Access to production systems is logged and monitored for anomalous activity.
4. Vulnerability management. Regular vulnerability scanning and patching; penetration testing conducted at least annually.
5. Personnel. All personnel with access to Personal Data are bound by confidentiality obligations and receive security awareness training.
6. Data minimisation and segregation. Customer data is logically segregated; Personal Data is retained only as long as necessary to provide the Services and in accordance with Section 2.2(f).
7. Business continuity. Documented disaster recovery and backup procedures, tested periodically.
8. Sub-processor security. Sub-processors are assessed for security posture before engagement and bound by obligations per Section 3.3.
This Annex applies where Motives Inc. is the contracting entity for a Controller subject to US state privacy laws, including the California Consumer Privacy Act as amended by the CPRA ("US State Privacy Laws"). Terms such as "business," "service provider," "sell," "share," and "personal information" have the meanings given under the applicable US State Privacy Laws.
1. Roles. Controller is the "business" and Processor is a "service provider" processing personal information solely to provide the Services.
2. Restrictions on use. Processor shall not: (a) sell or share personal information; (b) retain, use, or disclose personal information for any purpose other than performing the Services, or as otherwise permitted by US State Privacy Laws; (c) retain, use, or disclose personal information outside the direct business relationship between the parties; or (d) combine personal information with information received from other sources, except as permitted under US State Privacy Laws.
3. Certification. Processor certifies that it understands and will comply with these restrictions.
4. Assistance. Processor shall assist Controller in responding to verifiable consumer requests (access, deletion, correction, and opt-out) to the extent required by US State Privacy Laws.
5. Sub-processors. Processor shall impose these obligations on any Sub-processor that processes personal information on Controller's behalf.