DATA PROTECTION & COMPLIANCE

Even a one-question survey makes you responsible for the data.

Everything a GDPR-compliant survey needs — in every plan, including the free one.

If you collect personal data, you are the one legally responsible for it. Nuvopoll does not take that responsibility from you. It lets you do what is required and keep a record of having done it.

These tools are in every plan; data protection is not a paid extra.

Who is responsible for what?

You make the decisions; Nuvopoll keeps the record.

You · Data Controller

You decide what is collected: anonymous or identified, which notice is shown, how long data is kept, and whether participants get a request form.

Nuvopoll · Data Processor

Applies your decision and keeps the record. Collects, stores, and permanently deletes data according to your instructions with sealed audit logs.

FOUR STAGES

Data protection at every stage of research.

Preparing, collecting, sharing, and deleting.

1Preparing: One setting, consistent outcome

  • Anonymous or identified: One setting decides whether the IP is stored, whether a participant request link appears, and how interviewer and answer relate.
  • Notice text is versioned: Changing notice text creates a new version; the record of what previous participants agreed to is never erased.
  • Separate legal translation: Privacy notices in multilingual surveys are not auto-translated; they undergo separate verification.

2Collecting: Never collect more than required

  • Sealed consent records: Which version of which notice the participant agreed to is sealed and recorded. Sensitive data and audio consent are kept separately.
  • Real anonymous mode: The participant's real IP address is never stored; only a coarse, masked IP identifying no one is retained.
  • Location strictly refused: Neither participant nor interviewer location is collected; the system rejects location data outright.
  • Transcript-only audio: If selected, raw audio recordings are permanently deleted the exact second they are transcribed to text.

3Sharing: Granular audience control

  • Custom access control: On live survey results, publish headline figures publicly while locking demographic breakdowns behind a password.
  • Small cell suppression: In measurement models, breakdowns with fewer than 15 people are hidden to prevent deanonymization.

4Deleting: Irreversible deletion on retention expiry

  • Retention period & alerts: Countdown begins upon study completion. Automatic reminders sent 30, 7, and 1 day prior to permanent deletion.
  • Consent evidence remains: If you delete a study, answers and audio go; the sealed record of who consented to what stays.
  • Data subject request portal: Participants can request data deletion or access directly through the embedded form in identified surveys.

Team permissions, encryption, and audit logs.

AES-256 & Daily Backups

Data is encrypted at rest and in transit, with automated daily backups across EU facilities.

Raw Answers Never Sent to AI

Participants' raw answers are never sent to AI models. AI is strictly utilized for questionnaire drafting and translation.

Transparent Audit Logs

Exports, deletions, and setting changes are logged with user and timestamp. Platform administrative maintenance is tagged under its own label.

Written Breach Notification

If a security breach is detected, we notify you without delay of affected data categories and headcount as a contractually binding obligation.

Where is the data? Inside the European Union.

Data is stored inside the European Union, on servers in Belgium. All third-party subprocessors are named in our contracts.

A Data Processing Addendum (DPA) is provided as standard. Read exactly what we cover and what we exclude in our Scope page.

Do not leave survey compliance to chance.

All compliance features are active across all plans, including the free tier.

    GDPR-compliant surveys: consent, retention, EU hosting | Nuvopoll