Privacy Policy
1. Who we are
SurveySpire is provided by Swedish company Dynamic Visions AB, registration number 559385-1784. This policy explains how we handle personal data under the EU General Data Protection Regulation ("GDPR"). You can reach us via our contact page.
2. Received a survey through SurveySpire?
If you received a survey through SurveySpire, for example by email or SMS, the organization that sent it decides why and how your personal data is used — that organization is the data controller, and we process your data only on its behalf, as described in our Data Processing Agreement. Questions about why you were contacted, or requests to access or delete your data, are best directed to the organization that sent the survey. Every survey also includes an opt-out link you can use to stop receiving further surveys from that organization. You can always contact us as well, and we will assist or forward your request.
3. Personal data we store
- Survey recipient data: information about survey recipients that the sending organization provides, which can include names, email addresses, mobile numbers and custom attributes, together with survey responses, which may contain personal data depending on the questions asked and the answers given. We store this on behalf of the organization that sent the survey, which decides what recipient information to provide and is responsible for it (see section 2).
- Account data: your name, email address and password (stored hashed) when you create a SurveySpire account. If you are invited to an organization, we store the email address the invitation was sent to, even before you have an account.
- Usage and security data: login timestamps, session data and technical logs, including IP addresses.
- Agreement records: when you accept our Terms of Service or Data Processing Agreement we record who accepted, when, from which IP address and which document version.
- Communication: messages you send us, for example support requests.
- Website statistics: aggregated website usage statistics collected using a privacy-focused, cookieless analytics service (see sections 4 and 5).
4. Why we process it and on what legal basis
For survey recipient data we act as a processor on behalf of the organization that sent the survey, which is responsible for its own legal basis (see section 2). The purposes and legal bases below concern the processing we carry out as a controller.
- Providing the service (account management, authentication, organization membership) — performance of a contract, Article 6(1)(b) GDPR.
- Security and abuse prevention (logs, IP addresses, session handling) — our legitimate interest in keeping the service secure, Article 6(1)(f) GDPR.
- Demonstrating agreement acceptance (acceptance records) — our legitimate interest in being able to evidence concluded agreements, Article 6(1)(f) GDPR.
- Understanding how our website is used — we use a privacy-focused, cookieless analytics service that does not track you across sites and only provides us with aggregated statistics; IP addresses are processed transiently to produce these statistics and are not stored — our legitimate interest in understanding how the service is used so we can improve it, Article 6(1)(f) GDPR.
- Complying with legal obligations such as accounting rules — Article 6(1)(c) GDPR.
5. Cookies
We only use cookies that are strictly necessary for the service to function: a session cookie and a security (CSRF) cookie, and a cookie to keep you logged in if you choose "remember me". We do not use advertising cookies, and our analytics works entirely without cookies.
6. How long we keep personal data
Survey recipient data is stored on behalf of the organization that sent the survey, and is kept in accordance with that organization's choices and retention settings in the service. SurveySpire account data is kept for as long as your account exists. When your account is deleted, or when an organization is deleted, we delete the associated personal data within 90 days, except where a longer retention period is required by law (for example accounting records) or necessary to establish, exercise or defend legal claims — this includes agreement acceptance records, which we retain for as long as necessary to evidence the agreement. Deleted data may remain in encrypted backups until they are rotated out, no later than 120 days after deletion.
7. Who we share personal data with
We do not sell personal data. We share it only with the service providers listed on our subprocessors page (for example hosting and survey delivery), with a privacy-focused analytics provider for cookieless website statistics — who all process personal data on our behalf and under our instructions — and with authorities where the law requires it.
8. Where personal data is processed
Personal data is stored and processed within the EU/EEA. If a transfer outside the EU/EEA ever becomes necessary, we will ensure appropriate safeguards under Chapter V GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses. We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss and misuse.
9. Your rights
You have the right to request access to, rectification or erasure of your personal data, to restrict or object to its processing, and to receive it in a portable format. Where processing is based on our legitimate interest, you may object on grounds relating to your particular situation. To exercise your rights, contact us via our contact page. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), or with the supervisory authority in your country of residence.
10. Changes to this policy
We may update this policy as the service evolves. The current version is always available at this page, and material changes will be communicated in the service or by email.