Ethics template pack

Wording you can copy when your organisation has to approve a study before it starts.


Universities, and many public bodies, charities and evaluation teams, will not let a study start until someone has approved it. For interviews that is usually a research ethics committee, a data protection officer, or both. They ask for some or all of these documents:

  • an ethics application or protocol, which describes the method, the risks to participants and how you will reduce them
  • a participant information sheet and consent form, which people read before they agree to take part
  • a data protection impact assessment (DPIA), a form recording what personal data you collect, where it is stored, who can see it and how it is protected

Below is draft text for each, based on how Qualia works today.

If nobody has to approve your study, you can skip most of this page. Every Qualia interview opens with a consent screen, though, so the Participant information section still applies.

A committee checks that a study will not harm the people in it. It is also worth asking what they gain, because interviews can easily take people’s stories and give nothing back. At the least, tell participants what the study is for and where to find the results, and let them have their answers deleted; the information sheet below does both. Qualia lets participants answer by voice in their own language, which brings in people a written survey would miss.

How to use it:

  • Copy the blocks you need and replace everything in [square brackets].
  • Check the wording against your own institution’s forms and policies. You are the data controller for your research data (the organisation legally responsible for it), so the final text is yours.
  • Where a block depends on a setting, choose the setting first. The most important is the EU-only option, which keeps interview data, and the AI that processes it, inside the European Union.
  • If anything here disagrees with the Compliance section of the Qualia help, the help is correct.

If your committee asks a question this page does not answer, email hello@causalmap.app. We will probably add the answer here.

Describing the method

For the methods section of an ethics application or protocol:

Interviews will be conducted using QualiaInterviews, a web-based platform provided by Causal Map Ltd (UK). Participants open a link in their browser and take part in a conversation with an AI interviewer, by typing or by speaking. The AI interviewer follows an interview guide written by the research team, asks the questions in the guide, and asks follow-up questions based on what the participant says. Participants are told before they start that they will be talking to an AI and not to a person. Participants do not install software or log in. Transcripts are stored on the platform and downloaded by the research team for analysis. The interview guide was tested before launch using the platform’s test panel [and simulated respondents].

If you will use Qualia’s AI-generated summaries or reports in your analysis, say so and say how the team will check them against the transcripts.

Participant information

Put this in the interview’s Description, which participants must accept on a consent screen before the interview starts. See The Description.

About this interview

This interview is part of [project name], run by [organisation]. We want to understand [topic] so that we can [purpose]. You will be able to see what we found [at [link] / at a meeting] from [date].

You will be talking to an AI interviewer, not a person. It will ask you some questions and may ask follow-up questions about your answers. You can type or speak[, in your own language]. It usually takes about [N] minutes.

Taking part is voluntary. You can skip any question, and you can stop at any time by closing this page.

[If anonymous:] This interview is anonymous. Please do not give your name, or the names of other people, or other details that could identify anyone, such as addresses, phone numbers or email addresses.

What you write or say is stored securely by our service provider, Causal Map Ltd, [inside the European Union / in the USA], and processed by an AI model to run the conversation. It is not used to train AI models. Only the research team can read the transcripts. [We will keep them until [date], then delete them.]

You can ask us to delete your answers at any time [until [date]]. For that, or any questions, contact [name, email][, quoting the code in your interview link].

By clicking the button below you agree to take part.

Two settings go with this text:

  • Turn Anonymous on if you promise anonymity. Qualia then shows the anonymity notice and the warning not to share names and contact details. See Anonymity.
  • Turn Respondent can download transcript on if you want to give participants a copy of their own interview. See Respondent can download transcript.

Data storage and processing

For the data management section. Pick the version that matches your region setting.

With the EU-only option on:

Interview data is stored on servers in Amsterdam, the Netherlands, and encrypted at rest and in transit. The AI interviewer and audio transcription are provided by Google Cloud (Vertex AI Gemini and Speech-to-Text) in European Union locations; requests that do not name an EU location are refused by the platform. Google does not use this data to train its models. It may cache data for up to 24 hours, and its automated abuse monitoring can flag a request for review by Google staff for safety purposes only. Causal Map Ltd acts as data processor under its standard Data Processing Addendum; [institution] is the data controller.

With the EU-only option off:

Interview data is stored on servers in Virginia, USA, and encrypted at rest and in transit. The AI interviewer is provided by [OpenAI / Anthropic, depending on the model chosen], and audio is transcribed by OpenAI. These providers do not use API data to train their models. OpenAI retains API data for up to 30 days for compliance purposes. Causal Map Ltd acts as data processor under its standard Data Processing Addendum; [institution] is the data controller. Transfers outside the UK or EU rely on [your transfer mechanism, for example the UK International Data Transfer Addendum].

Research needing UK or EU data residency, or on sensitive topics, should normally use the EU-only option. See EU-only interviews.

Identifiability and anonymity

Participants do not create an account or log in, and the platform does not ask for their name or contact details. [Interviews are anonymous.] [To link responses to our sampling list, each participant receives a link containing a code. The list linking codes to people is held only by the research team, on [institution] systems, and is not shared with the platform provider. It will be destroyed on [date].]

The AI interviewer asks participants not to share names or other identifying details, and warns them if they start to do so. [We have also switched on the platform’s automatic removal of personal details, which replaces names, contact details and ID numbers with labels such as [NAME] before anything is stored.]

The relevant settings are personalised keys and Remove personal details before storing. Automatic removal is done by an AI model, which can miss a detail or remove one it should have kept, so describe it as an extra safeguard rather than a guarantee.

Risks and mitigations

Risk Mitigation
A participant becomes distressed, or discloses that they or someone else is at risk The AI interviewer is instructed to respond to safeguarding concerns and to tell the participant that the research team will be told. The owner and editors of the interview get an email alert (with no interview content) within minutes. [Named person] reviews alerts [daily] and follows [institution]’s safeguarding procedure. The information sheet gives a contact for support.
A participant shares identifying details about themselves or others Warning on the consent screen; the interviewer asks them to stop; [automatic removal of personal details]; transcripts are checked and any remaining identifiers removed before analysis.
Participants do not realise they are talking to an AI The information sheet and consent screen say so plainly before the interview starts.
The AI misunderstands a participant or asks a leading question The guide was tested with the test panel and simulated respondents before launch. [The interviewer summarises the participant’s main points at the end so they can correct them.] The team reads a sample of early transcripts and adjusts the guide if needed.
People without internet access, or with low literacy or confidence online, are excluded Participants can speak instead of typing, and can answer in their own language. [Alternative: a human interview on request.]
Data is accessed without authorisation Encrypted storage and transport; research team accounts use [two-factor] authentication; only named team members are added as editors.

For safeguarding alerts to reach the right people, make them owner or editor of the interview. See Safeguarding / Flagging the interview. You can also add safeguarding instructions to the guide, such as a helpline for the interviewer to mention.

Withdrawal and data rights

Participants can stop at any point by closing the page. [Because interviews are anonymous, we cannot identify an individual’s answers after they have finished, so answers cannot be withdrawn once submitted.] [Participants who want their answers deleted can contact [name] within [N] weeks, quoting the code in their link; we will delete their transcript from the platform and from our own files.]

Deleted transcripts leave the platform’s backups within 89 days.

Data protection impact assessment (DPIA)

What a DPIA usually asks for, with sources:

  • Roles: you are the data controller for the research data; Causal Map Ltd is the data processor. See Data Controller and Data Processor.
  • Data Processing Addendum: a standard UK GDPR addendum is published at the end of the Compliance section. Email us if your institution needs to sign its own.
  • Hosting: Railway, in Amsterdam (EU-only) or Virginia, USA.
  • Sub-processors: Railway (hosting), Google Firebase (researcher sign-in), and the AI provider for the model you choose (Google in the EU region, including for Claude models; OpenAI or Anthropic otherwise).
  • Security: encryption at rest; TLS for all traffic, including TLS 1.3 between the application, its database and the AI services; the database is not reachable from the internet.
  • Retention: you decide how long to keep data and can delete transcripts at any time. Backups are kept for up to 89 days.
  • Training: interview data is not used to train our models or the AI providers’ models.
  • Lawful basis: yours to choose, usually public task or legitimate interests for research, with consent as the ethical basis for taking part.