Skip to main content

Signal and Noise

GDPR & Data Protection

Protecting data. Preserving Trust.

Every research project involves a responsibility that extends beyond collecting data. It involves protecting the people behind it.

At Signal & Noise, data protection is integrated into every stage of the research process, from study design and participant recruitment to data storage, analysis and final reporting.

While our work complies with the General Data Protection Regulation (GDPR) where applicable, our approach is guided by broader principles of responsible data stewardship. We apply these standards across all research projects, regardless of where they are conducted, because protecting participants is a professional responsibility, not simply a legal obligation.

Our data protection practices are informed by the ICC/ESOMAR International Code on Market, Opinion and Social Research and Data Analytics and ESOMAR guidance on primary data collection, duty of care and data protection.

Privacy by design

Privacy is considered before data collection begins, not afterwards.

Every project is designed to collect only the information necessary to achieve its research objectives. Before fieldwork starts, we evaluate what personal information is required, why it is needed, who will have access to it, how long it will be retained and how it will be protected throughout its lifecycle.

Data protection is therefore built into the design of our research rather than added as a final compliance step.

Data Minimisation

We collect only the information that is necessary for the research.

Wherever possible, personal identifiers are avoided, removed or separated from research data. Information is never collected “just in case” it might become useful later.

This principle reduces privacy risks while helping maintain participant trust.

Lawful and Transparent Processing

Participants have the right to understand how their information will be used.

Before taking part in a study, participants receive clear information about:

  • the purpose of the research;
  • the type of information being collected;
  • how their data will be processed;
  • who is responsible for the research;
  • long data will be retained;
  • they can exercise their rights.

Depending on the nature of the project and applicable legislation, personal data is processed on an appropriate lawful basis, including informed consent or other legal grounds recognised under applicable data protection laws.

Confidentiality

Research data is not marketing data.

Information collected for research purposes is used exclusively for research and statistical analysis. We do not use participant data for direct marketing, sales activities or individual profiling outside the agreed research purpose.

Unless explicitly authorised or legally required, participant identities are never disclosed to clients.

Whenever possible, research findings are reported in aggregated or anonymised form so that individuals cannot be identified.

Data Security

Protecting research data requires both technology and disciplined processes.

Depending on the project, appropriate technical and organisational safeguards may include:

  • secure data transfer;
  • encrypted storage where appropriate;
  • controlled access based on project responsibilities;
  • password-protected research environments;
  • secure research platforms and technology providers;
  • regular review of access permissions;
  • secure deletion or anonymisation once personal data is no longer required.

Access to research data is limited to authorised personnel involved in the project.

Working with Partners

Some research projects involve trusted external suppliers, such as sample providers, recruitment agencies or specialist technology platforms.

When external partners process personal data on our behalf, we expect them to maintain data protection standards consistent with applicable legislation and recognised professional research practices.

Where required, appropriate contractual safeguards are established before any data is shared.

Only the minimum amount of personal information necessary to perform the agreed services is disclosed.

International Research

Many research projects involve participants, suppliers or clients located in different countries.

Where personal data is transferred across jurisdictions, we take appropriate measures to ensure that transfers comply with applicable legal requirements and that participant information continues to receive an appropriate level of protection.

Participant Rights

We respect the rights of every participant whose personal information we process.

Subject to applicable legislation and the specific circumstances of a research project, participants may have the right to:

  • access their personal information;
  • request correction of inaccurate data;
  • request deletion where legally applicable;
  • restrict or object to certain forms of processing;
  • withdraw consent where consent is the legal basis for processing;
  • raise concerns regarding the handling of their personal information.

Requests are handled promptly and in accordance with applicable data protection requirements.

Accountability

Protecting personal data is a shared responsibility across every stage of the research process.

Our internal procedures are designed to ensure that data protection considerations remain part of project planning, fieldwork, analysis and reporting, not separate from them.

We regularly review our practices as technology, legislation and professional standards evolve.

Our Commitment

Good research depends on trust.

Participants trust researchers with their opinions, experiences and, in some cases, sensitive personal information. Clients trust researchers to protect that information while producing reliable evidence.

We take both responsibilities seriously.

Protecting personal data is not simply about regulatory compliance, it is essential to conducting research that people are willing to participate in and organisations are willing to rely upon.

INFORMATION FOR MARKET RESEARCH PARTICIPANTS

I. PRIVACY POLICY

(Last updated: 23.04.2026)

1. Data Controller

The data controller for the research activities carried out by Signal & Noise is SC Resolvo SRL, a Romanian company registered under no. J2018003427225, VAT code RO40300023, with registered office at Str. Buzescu nr 7, Iasi, Romania.

For any questions regarding the processing of personal data, you can reach us at dpo@signalandnoise.eu.

2. What Data We Collect

Depending on the project, we may collect:

  • contact details (name, email, phone number);
  • demographic data relevant to the study (age, gender, occupation, etc.);
  • responses and opinions shared during the research;
  • biometric or physiological data, where the methodology includes eye tracking, EEG, facial coding or GSR (for example eye movements, electrodermal signal, facial expressions);
  • audio/video recordings, only if part of the study protocol and with your explicit consent.
3. Purposes of Processing

Data is collected solely for carrying out the study you are taking part in: running the session, analysing results and reporting to the client in aggregated or anonymised form. We do not use participant data for direct marketing purposes.

4. Legal Basis

Processing is based, depending on the case, on your explicit consent, obtained before the study begins, or on Signal & Noise’s legitimate interest in conducting the research, while respecting your rights.

5. Retention Period

We keep your data only for as long as necessary for the purpose of the study and to meet contractual or legal obligations (for example tax record keeping). Once this period expires, data is deleted or anonymised.

6. Your Rights

You have the right to request access to your data, its rectification or deletion, restriction of processing, objection to processing, and, where processing is based on consent, withdrawal of that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal. You can exercise these rights at dpo@signalandnoise.eu.

7. Data Transfers

Data is stored and processed in Romania or within the European Economic Area. Should a transfer outside the EEA become necessary, we ensure that the safeguards required by law are applied (for example standard contractual clauses).

8. Complaints

If you believe your rights have not been respected, you can file a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), anspdcp@dataprotection.ro, www.dataprotection.ro.

✓ 15+ years in research

✓ Qual, Quant & Neuroscience

✓ In-Lab & Remote capabilities

✓ ESOMAR-aligned standards