How Tellet protects your research data and your participants' data, and how we support your GDPR obligations.
Under GDPR, you (our customer) are the data controller for the data collected in your studies, and Tellet is the data processor. We process participant data on your behalf and only to provide the service.
Data Processing Agreement (DPA)
Data Protection Impact Assessment (DPIA)
Record of Processing Activities (RoPA)
List of sub-processors
Email [email protected] to request any of these.
Application: Tellet runs on DigitalOcean in Amsterdam, the Netherlands.
Database, sign-in and files: your studies, transcripts and recordings are stored with Supabase, North EU region (Stockholm).
Tellet uses AI models to run interviews, transcribe voice and video answers, translate, and analyse results. You can choose the AI provider for each study in its settings.
OpenAI models run through Microsoft Azure OpenAI, not OpenAI directly. Data is processed in EU (Sweden), however, specific location might change depending on capacity.
Google Gemini models run through Google Cloud Vertex AI. Recordings sent to Gemini are stored only briefly while they're processed, then deleted.
Your data isn't used to train AI models.
Sign in with email and password, Google, or Microsoft.
Passwords must be at least 8 characters, with upper and lower case letters, a number and a symbol.
Two-factor authentication with an authenticator app is available for every account. Set it up in Account settings.
Single sign-on (SAML) isn't available yet.
Every organisation's data is kept separate from other organisations, and automated security tests check that data can't leak between them.
Access within your organisation depends on each member's role. See Member management.
A small number of Tellet staff can access customer data, using Tellet accounts, to provide support and keep the service running.
Tellet keeps a log of key actions, such as creating or deleting studies, adding or removing members, and new interviews, with who did them and when.
All data is encrypted in transit using HTTPS/TLS. Recordings and files are stored privately and can only be opened through links that expire.
If you connect an AI assistant such as Claude or ChatGPT to Tellet, it works as you, with the same access you have. It can't publish, delete, invite people or change settings. You can remove its access at any time. See Connect an AI assistant (MCP).
Every participant must agree to a consent statement before the interview starts. They consent to being recorded and to the recording being shared with you for research purposes. The consent statement is fixed and can't be edited, so every study meets the same standard.
Because you're the data controller, participants should be able to read your privacy policy before they start. Add your privacy policy links in Organisational settings and choose one for each study. It's shown on the consent screen next to Tellet's Interview Terms.
Participants don't create an account or give their name to Tellet. Tellet stores:
their answers, including any voice and video recordings and their transcripts
the language they chose
any variables included in their interview link, such as a panel participant ID
A cookie on the participant's device lets them resume an unfinished interview. Cookies are currently stored for about 3 years.
Session recordings for error monitoring are stored for 90 days (Sentry) and 30 days (Posthog). Both are stored in the European Region.
Tellet doesn't automatically redact or pseudonymise personal details that participants mention in their answers.
Minimum participant age is 16 years old.
Transcripts can be archived, which removes them from your results and analysis. To permanently delete transcripts, email [email protected].
Draft studies can be deleted from the study menu. Published studies can't be deleted from the platform: contact support.
Deleted accounts, workspaces and studies are kept for 60 days in case of mistakes, then permanently deleted.
For security or privacy questions, email [email protected]. For data protection requests, email [email protected].