Privacy & AI transparency notice
1. Controller and contact
Pronoia is a Delphi research service operated by Metodix Ltd. When a study is run by a client organisation (e.g. a university), the client is the data controller and Metodix Ltd the processor. In Metodix's own studies, Metodix Ltd is the controller. Contact: info@metodix.fi.
2. What data we process
For panelists we process: name and email address (for invitations), responses and comments (research material), expertise classifications (panel matrix), and sign-in data (a personal invite link — no password; the link is valid for a limited time and the facilitator can renew or revoke it). Other panelists see your responses only under a neutral word pseudonym (e.g. Vega), and the facilitator under a pseudonymous code (e.g. P-17).
3. Data about the research team
For facilitators and administrators we also process: email address and name (the account), a hash of the password, session data (browser identifier, IP address, times of use), and an access history recording who granted or removed whose access rights and when. If two-factor authentication is in use, we store its key and hashes of the backup codes. Of failed sign-in attempts we keep only a count and the time of the most recent one — no log of individual attempts and no IP addresses for them. This data is processed for the security of the service and for investigating misuse; the access history is retained after an account is deleted, without the deleted email address. None of this is collected about you as a panelist.
4. Purpose and legal basis
Data is processed to conduct the Delphi study. The legal basis is stated by the study's data controller, which is the organisation running the study; you will see it in the study's own consent view before you reach any material. In Metodix Ltd's own studies the legal basis is scientific research in the public interest (GDPR Art. 6(1)(e) and section 4(3) of the Finnish Data Protection Act). Taking part is always voluntary, and we ask for your consent before you see any of the study's material — this is research-ethics consent to participate, not the legal basis for processing your personal data, unless the controller has expressly chosen consent as the basis. You can answer at your own pace: one question at a time, finishing later from the same link. You may also withdraw from the study entirely by contacting the study's contact person — these are two different things, and what withdrawal means for answers already given is stated in the study's own consent text.
5. AI notice (EU AI Act, Art. 50)
Studies may include AI panelists — synthetic perspectives that take part in responses and dialogue. Their presence is disclosed before you respond, and AI-generated content is always marked: an AI panelist's name always takes the form AI · role, and the views also show the 🤖 indicator. AI content is kept separate from human responses in the analysis and in data exports (machine-readable ai_generated marking). In addition, your open responses may be processed by AI features (e.g. summaries) via Anthropic's Claude API. This always happens without your name and contact details, and the material is not used to train AI models.
6. Retention and anonymization
The service runs on a server located in the EU. When the study ends, the facilitator anonymizes it: names, emails and invite links are permanently deleted, and the remaining material is anonymous research data that cannot be linked to you. Backups are retained for at most 30 days.
7. Your rights
You have the right to access and rectify your data. Where the legal basis is scientific research in the public interest, you have the right to object to the processing on grounds relating to your particular situation, and the right to erasure may be limited in so far as erasure would prevent the research from being carried out. If the controller has chosen consent as the basis, you may withdraw it at any time. During the study, requests are handled through the facilitator; an erasure request permanently unlinks your responses from you. The supervisory authority is the Finnish Data Protection Ombudsman (tietosuoja.fi).
8. Sub-processors
Hetzner Online GmbH (server infrastructure, EU) · Anthropic (AI processing; transfers outside the EU protected by standard contractual clauses; material is not used for model training) · Resend, Inc. (delivery of invitation, password-reset and panel messages; messages are sent from the EU, but their metadata and content are stored in the United States for 30 days; transfers protected by standard contractual clauses and EU–U.S. Data Privacy Framework certification) · backup storage within the EU. Data processing agreements are in place with all of them.