Eatpol Tester Privacy Policy

Version: 2.0  |  Effective Date: 07/10/2026  |  Company: Eatpol B.V.  |  Contact: info@eatpol.com  |  Tester Terms & Conditions

This Privacy Policy explains how Eatpol B.V. collects, uses, stores, shares, and deletes personal data relating to members of the Eatpol tester panel who sign up through the Eatpol app or otherwise participate in Eatpol-managed tester studies.

This Privacy Policy applies to testers. It does not by itself describe every data flow in studies where participants are recruited or managed directly on a client's instructions outside the Eatpol tester panel model.

The information below is intended to be clear, transparent, and specific as to purposes, categories of data, and key processing operations, in line with the principles of transparency, purpose limitation, minimisation, and storage limitation.

Table of Contents

1. Who we are

Eatpol B.V. ("Eatpol", "we", "us" or "our") operates the Eatpol tester panel and related research platform.

The controller of your personal data for the Eatpol tester panel is: Eatpol B.V., Bronland 10, Wageningen, 6708WH, The Netherlands
Privacy contact: info@eatpol.com

2. What data we collect

Depending on how you use the Platform and which studies you join, we may collect the following categories of personal data.

2.1 Account and sign-up data

2.2 Device and app data

2.3 Profile data

Food allergy information is health-related information and is treated with additional care. Eatpol seeks to minimise collection and sharing of such information and not to disclose it to clients unless strictly necessary for the relevant study setup.

2.4 Study participation data

2.5 Interview data

Because interviews are open-ended, transcripts may contain information that you volunteer spontaneously, including information that was not specifically requested.

2.6 Video data

In some studies, we collect short participant-recorded videos showing product use at home.

For such studies, we may hold:

We use face masking as a privacy measure. Face masking may not work with 100% accuracy in every situation, especially if the participant records from a side angle, under poor lighting, or in other challenging conditions. For that reason, participants may be instructed to record front-facing video where feasible.

We do not use these videos for facial recognition and do not create facial templates to identify participants. The mere collection of video does not by itself make the processing biometric identification; biometric processing requires additional technical extraction and matching for unique identification.

2.7 Payment and reward data

2.8 Panel responses, poll answers and support communications

3. How we collect your data

We collect personal data:

4. Why we use your data

We use personal data for the following purposes.

4.1 Operating the tester panel

4.2 Fraud prevention and security

4.3 Study management and research execution

We may also combine your answers with those of other participants to create de-identified example profiles ("personas") that the study team may explore with AI. A persona is not your profile and does not show your name or contact details.

4.4 Handling video submissions

4.5 Rewards and accounting

4.6 Support and communications

4.7 Optional AI training and model improvement

If you separately opt in before a recording, we may use the relevant study video and related labels or annotations to develop, train, test and improve AI models and related technology used to analyse consumer behaviour and consumer-product interactions. This optional use is separate from participation in the study itself.

This training is for computer-vision models that recognise consumer actions in video, such as opening a pack, pouring, taking a bite, chewing or taking a sip. Your interview transcripts and survey answers are not used for it.

For this optional AI training purpose, Eatpol uses the masked version of the relevant video rather than the raw source video. However, face masking is automated and is not 100% accurate in every case. In some situations, including certain recording angles, lighting conditions or movement, the masked version may still contain occasional unmasked frames or other imperfect masking. This training use therefore still involves personal data.

A video is used for this training only if you have opted in and the client that commissioned the study has also agreed. Training runs on Eatpol's own infrastructure in the EU, and your videos are not sent to an external AI model provider for training.

Eatpol may use models trained through this optional programme in its internal tools and in commercial products or services provided to business customers.

This use is limited by the scope of the permission requested. It is distinct from the core study itself and is not a condition for study participation or reward eligibility.

Eatpol does not use this process to identify you, perform facial recognition, or conduct emotion recognition.

4.8 Aggregated benchmarks and published insights

To combine study responses and daily poll answers into aggregated statistics, benchmark datasets and insight materials that are designed not to identify any individual tester.

4.9 Use of aggregated insights for product development and marketing

To use the aggregated statistics, benchmarks and insight materials described above for improving our services, developing our products, creating market insights, and producing business-facing publications, case studies, sales materials and other marketing content. These materials are not intended to identify you personally.

4.10 Optional use of video clips in Eatpol marketing

If you separately opt in before a recording, we may use face-masked clips or still images from the relevant study video in Eatpol's own marketing, such as LinkedIn and other social media, our website, case studies, sales presentations, newsletters and events. We may edit clips, for example by trimming, cropping, adding captions or music, or blurring backgrounds.

We use only the masked version of the video, do not show your name, username, contact details or location, and remove your original voice unless you separately agree. A clip is used only if the client that commissioned the study has approved it. Marketing content is public and, because face masking is not 100% accurate, you may occasionally be recognisable.

This use is based on your consent. It is optional, requested separately from the AI-training opt-in, and does not affect your participation or rewards. See Sections 7.4, 9.3 and 10.

6. What clients see

Eatpol's clients do not receive your ordinary account identifiers such as your name, email address, postal address, or phone number in ordinary client reports.

Clients generally receive:

Where participant videos or transcripts are made available to a client, they are made available only through controlled access and not as unrestricted downloads. Eatpol applies masking and/or redaction measures designed to reduce the risk of direct identification. Such materials remain personal data in pseudonymised form rather than anonymous data.

Where videos are shown to clients, Eatpol applies automated face masking designed to reduce the risk of direct identification. However, face masking is not 100% accurate, and a client reviewer may occasionally see unmasked frames of your face.

Client access is limited by contractual and technical controls, and clients are not permitted to use participant materials to try to identify testers.

Eatpol may decide not to share food allergy information or dietary preference data with clients except where strictly necessary for safe and proper study execution.

6.1 Important information about video privacy

If you take part in a video-based study, please remember:

7. Who we share data with

We share tester personal data only where necessary and for defined purposes.

7.1 Service providers

Current service providers may include providers used for:

Where these providers process personal data on our behalf, we require appropriate contractual protections consistent with applicable data protection law.

Where we send personal data to service providers, we seek to limit that data to what is reasonably necessary for the relevant purpose and apply appropriate technical and organisational protections.

7.2 Clients

Eatpol shares study outputs with clients in accordance with the relevant study design and contractual controls, typically in aggregated or otherwise restricted form. Where a study includes personas, clients may also receive or access de-identified example profiles derived from combined participant responses, designed not to identify any individual tester.

7.3 Authorities and legal claims

We may disclose data where required by law, legal process, or to establish, exercise, or defend legal claims.

7.4 Public marketing channels

If you opt in under Section 4.10, face-masked clips of your video may be published on Eatpol's website and on social media platforms such as LinkedIn, Instagram, YouTube and TikTok. Content published there is public. These platforms process it as independent controllers under their own terms and may process it outside the EU/EEA.

8. International transfers

Eatpol seeks to keep tester data within the European Union where possible. However, some providers may involve processing or access outside the EU/EEA.

Where personal data is transferred outside the EU/EEA, Eatpol uses an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, and supplementary measures where appropriate.

Material sent to Anthropic after removal of direct identifiers remains pseudonymised personal data, not anonymous data.

9. Storage and retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, taking into account the nature of the data, the purpose of the processing, legal obligations, dispute handling, and security needs.

If we no longer need personal data for an identifiable purpose, we may delete it, aggregate it or anonymise it.

9.1 Panel profile

Retained while you remain an active tester, unless earlier deleted at your request or otherwise removed.

9.2 Interviews and transcripts

Retained for up to 2 years, unless earlier deleted on account deletion or where longer retention is required for a specific lawful reason already disclosed.

9.3 Video recordings

Retained for up to 5 years, unless deleted earlier due to account deletion, a valid deletion request, withdrawal where applicable, or where a shorter retention period applies operationally.

Where you delete your account, Eatpol may delete associated videos linked to your account rather than waiting for the standard storage expiry.

Marketing clips used under Section 4.10 are kept for up to 3 years from the recording date, or until you withdraw your consent, whichever comes first.

9.4 Payment records

Retained for up to 7 years or such other period as required by applicable accounting or tax obligations. These may not be deleted immediately upon an ordinary deletion request where legal retention is required.

9.5 Superseded file copies

Retained for up to 90 days in line with system handling.

9.6 Sign-up and security logs

Retained only as long as reasonably necessary for anti-fraud, security, troubleshooting, and audit purposes, after which they are deleted or minimised. Verification or confirmation-code logs are retained only for as long as reasonably necessary for security, troubleshooting and fraud-prevention purposes, and then deleted or anonymised.

9.7 Poll answers and panel responses

Poll answers and similar panel-response data may be retained for analytics, benchmarking and service improvement where appropriate safeguards are applied.

9.8 Consent records

Consent records are kept for as long as necessary to demonstrate the consent collected and to manage withdrawals.

10. Account deletion and withdrawal

You may request deletion through the app or through Eatpol's deletion request page.

When you delete your account or make a valid deletion request, Eatpol will delete or de-link relevant account data in accordance with its operational processes, including deletion of associated videos where applicable, while keeping only those records that must lawfully be retained, such as payment records or limited legal-defence records.

If we rely on your consent, you may withdraw that consent at any time. For the optional AI-training consent, you can do this in the app. For the optional marketing consent, you can do this in the app or by emailing info@eatpol.com. Withdrawal does not affect processing already carried out before withdrawal.

If you have separately opted in to AI training use and later withdraw that permission:

If you have separately opted in to marketing use and later withdraw that permission:

11. Security

Eatpol uses technical and organisational measures intended to protect personal data, including encryption in transit and at rest, access logging, cloud security controls, monitoring, and internal access restrictions.

Because no system can guarantee absolute security, Eatpol cannot promise that every measure, including face masking, will work perfectly in every case. Measures are designed to reduce risk materially, not to make identification impossible in every circumstance.

12. Your rights

Subject to applicable law, you may have the right to:

Eatpol will facilitate the exercise of these rights and respond in a concise, transparent, and accessible manner.

To exercise your rights, contact us at info@eatpol.com.

13. Children

The Platform is not intended for testers below the minimum required age. If Eatpol learns that personal data was collected from someone not eligible to participate, Eatpol may delete the account and related data subject to legal retention needs.

14. Changes to this Privacy Policy

Eatpol may update this Privacy Policy from time to time. If the changes are material, Eatpol may notify you through the app, by email, or by another appropriate method.

15. Contact

If you have questions about this policy or want to exercise your privacy rights, contact: Eatpol B.V., Bronland 10, 6708WH Wageningen, The Netherlands
info@eatpol.com