Participant Consent

When you run interviews through UserTold, you are the data controller for your participants' data and UserTold is your processor. That means obtaining a valid legal basis — usually consent — from each participant before recording is your responsibility, not ours. This is practical guidance, not legal advice; when in doubt, consult a lawyer in your jurisdiction.

Why this matters

A recording captured without a valid basis is unlawful to process — and the exposure is yours, because you decide who to interview and why. A clear disclosure plus an affirmative action is enough in most cases, and the widget captures it.

What every participant must be told before recording

Disclose, in plain language, before capture begins:

  • That the session is recorded — audio, and screen if your study enables screen capture.
  • Who is recording — your company name (you, the study owner), and that UserTold processes the recording on your behalf.
  • What it's used for — that an AI conducts the interview and UserTold processes the recording into transcripts, evidence, and summaries for your team to review.
  • That it's voluntary — they can stop any time by closing the widget.
  • Your privacy information — the controller contact and other information required in the participant's jurisdiction, available through your normal privacy surface.

UserTold's widget shows a short built-in recording disclosure above the microphone-permission prompt, and the participant's Allow recording and start click is their affirmative action; that built-in copy is versioned. The line covers the recording itself and links to UserTold's processing notice. Your company still determines the research purpose and should make its identity, that purpose, voluntariness, and legally required privacy information available through the host product's normal privacy surface or invitation. UserTold does not require a separate customer privacy-policy URL or a new disclosure step before the widget opens.

GDPR (EU/EEA participants)

You need a lawful basis under GDPR Art. 6 to record. In practice:

  • Consent (Art. 6(1)(a)) is the cleanest basis for voluntary research interviews. It must be freely given, specific, informed, and unambiguous — a pre-ticked box or silence is not consent.
  • Participants can withdraw consent at any time; honour it and stop processing going forward.
  • Before collecting data, provide the applicable GDPR Art. 13 information through the host product's existing privacy surface or invitation. This includes, as applicable, controller and DPO contact details, purposes and legal basis, recipients and international transfers, retention, participant rights (including withdrawal when consent is the basis), the right to complain to a supervisory authority, and automated decision-making. Do not bury it. UserTold does not require you to duplicate that information in a new policy or URL.

Special-category data (Art. 9)

Open-ended interviews can surface health, beliefs, political opinions, or other special-category data that a participant volunteers. If your interview design predictably elicits this, you need an Art. 9(2) condition — almost always explicit consent. Collect that explicit consent in the host product or another appropriate flow before opening the widget, and avoid prompting for sensitive topics you don't need.

US recording law is set by state:

  • One-party-consent states (the majority): one party's consent is enough — with clear notice, that party can be you, the recorder.
  • All-party ("two-party") consent states — including California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, and Washington — require every participant to consent to being recorded.
  • When participants are in different states, the strictest standard generally applies; California's rule has been held to reach any session to or from California.

Practical rule: always show a clear "this session is recorded" disclosure and require the affirmative Allow recording and start click. If you interview US consumers, treat all-party consent as your default so you're covered everywhere.

Minors

Don't deploy the widget to audiences likely to include children below the applicable digital-consent age — 14 in Spain (LOPDGDD Art. 7), 13 under US COPPA, and 13–16 across the EU depending on the Member State. If minors are in scope, you need verifiable parental consent and should design for it explicitly.

How to configure disclosure around UserTold

  1. Keep your identity, purpose, voluntariness, and legally required privacy information available through the host product's existing privacy surface or participation invitation. UserTold requires no separate privacy-policy URL.
  2. For studies that may surface special-category data, collect explicit consent before opening the widget.
  3. Leave the widget's default recording disclosure and Allow recording and start action in place; that copy is versioned.
  4. Use an Intake for qualification questions when needed. The current widget does not display an Intake's consent text; consent comes from the widget's own recording notice and the Allow recording and start click, plus whatever you disclose in the host product.

A UserTold recruitment URL is a shareable campaign entrypoint, not consent and not participant identity. Put no email, name, eligibility answer, or other personal data in the link. UserTold's widget observes only its opaque ut_research parameter, does not capture the full host query string, and does not request permissions or begin recording on arrival. The participant must still review the Invitation and explicitly choose Start, then complete Intake and permission steps where configured.

Sample host-product disclosure

[Your Company] invites you to a voluntary product-research interview run with UserTold. We use the recording to create transcripts, evidence, and summaries for our team to review. You can stop at any time. Our usual privacy information explains how to contact us, our legal basis, recipients, retention, and your rights.

The widget separately shows its recording notice, links to UserTold's processing and privacy information, and requires the participant to choose Allow recording and start before recording begins.

Deletion requests

If a participant asks to delete their recording, you (the study owner) can delete the interview from your dashboard. If a participant contacts UserTold directly, we route the request to you. Build a quick internal process to honour these within a reasonable time — GDPR expects a response within one month.

Quick checklist

  • Host product's existing privacy surface or invitation provides the study owner's identity, purpose, voluntariness, and legally required privacy information
  • Explicit consent collected before opening the widget for studies that may surface Art. 9 data
  • Built-in recording disclosure and Allow recording and start action remain in place
  • All-party-consent default if interviewing US participants
  • Not targeting audiences likely to include minors below the consent age
  • A process to action participant deletion requests

For how UserTold handles the data once captured, see the Privacy Policy and the Data Processing Agreement.