Privacy Policy

Last updated: 26 July 2026

Protecting personal data matters to us. Below we explain which personal data we process, for what purposes and on what legal basis, who we share data with, and what rights you have.

Scope

This privacy policy covers two separate offerings. Part A concerns our website surv-ai.com, including the demo booking form. Part B concerns the SurvAI platform at app.surv-ai.com, which we provide as software-as-a-service for market research and survey analysis. Part C contains information that applies to both.

Data Controller

SurvAI by A+R UG (haftungsbeschränkt) Nerostraße 18 65183 Wiesbaden Germany Email: info@surv-ai.com

A. Website surv-ai.com

Hosting and server log files

Our website is hosted by Hetzner Online GmbH; the servers are located in Germany. When you visit the website, technical access data is automatically processed in server log files, in particular IP address, date and time of access, page requested, volume of data transferred, referrer, and browser and operating system identifiers. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure, stable and uninterrupted operation of the website and in defending against attacks. A data processing agreement under Art. 28 GDPR is in place with Hetzner.

Demo booking form

On the website we collect personal data only when you voluntarily provide it through our demo booking form. The following data is processed:

  • Name
  • email address
  • company
  • preferred appointment
  • language
  • optional message

We use this data solely to arrange and hold the demo appointment and to respond to your enquiry. The legal basis is Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract).

Google Calendar API

We use the Google Calendar API provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for appointment scheduling. Your appointment details (name, company, preferred time) are transmitted to Google in order to create the entry in our calendar. The legal basis is Art. 6(1)(b) GDPR. Processing by Google LLC in the United States cannot be ruled out; see the section “International data transfers” for details. Google's privacy notice is available at policies.google.com/privacy.

Demo booking confirmation emails

After a demo booking we send you a confirmation email with a calendar entry and notify our team. We use the Brevo service to send these emails. Your name, email address and the content of the message are transmitted to Brevo. The legal basis is Art. 6(1)(b) GDPR. According to Brevo, the data is processed in data centres within the EU. We do not send newsletters or other marketing emails via this channel.

Cookies, local storage and tracking

Our website does not use cookies for analytics, profiling or advertising. We use no web analytics, tracking pixels, ad networks or social media plugins. We only store two technically necessary entries in your browser's local storage: your dark-mode preference and the acknowledgement of our notice banner. These entries never leave your device and are not transmitted to us. The legal basis is Section 25(2) no. 2 TDDDG (strictly necessary storage) in conjunction with Art. 6(1)(f) GDPR.

B. SurvAI platform (app.surv-ai.com)

The SurvAI platform is a paid service for companies and market research institutes. Our customers upload open-ended survey responses and associated metadata and have them categorised, analysed and exported with the help of AI.

Roles: controller and processor

For our customers' own data — account, usage and billing data — we are the controller within the meaning of Art. 4(7) GDPR. For the survey, response and respondent data that our customers upload to the platform, we act solely as a processor under Art. 28 GDPR; the respective customer is the controller. We process this data only to deliver the contractually agreed service and in accordance with the customer's instructions.

A data processing agreement (DPA) is available on request at info@surv-ai.com. Our customers are responsible for ensuring that they are permitted to collect the uploaded data and transfer it to us, that the individuals concerned have been informed accordingly, and that respondent data is anonymised as far as possible — or at least pseudonymised — before it is uploaded.

Account, sign-in and sessions

A user account is required to use the platform. We process the email address, display name, role and permission details, a normalised form of the email address to prevent duplicate accounts, and timestamps for registration, sign-in and email verification. User management and authentication are handled by Zitadel, an open-source identity solution that we operate ourselves on our own servers hosted by Hetzner in Germany (auth.surv-ai.com); no data is transferred to an external identity provider. Your password is stored there only, and only as a cryptographic hash. Your session is held server-side in our database; we additionally store the session's IP address and browser identifier to protect against misuse, and the access tokens in encrypted form. A technically necessary session cookie is set in your browser for this purpose (valid for 7 days), along with a cookie storing your chosen language. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(f) GDPR for securing the session.

Usage and billing data

For billing, cost control and quality assurance we record, per account, which AI analyses were carried out. We log the model used, the tokens consumed, the resulting cost, the associated credit balance and technical identifiers of the survey, question or evaluation concerned. We also record aggregated events to improve the product, such as whether and how often AI suggestions were corrected manually. Response content is not stored as part of this. The legal basis is Art. 6(1)(b) GDPR for billing and Art. 6(1)(f) GDPR for quality assurance and further development of the service.

Survey, response and respondent data

In the platform we process the survey data uploaded by our customers: question texts, open-ended and closed responses, a respondent identifier assigned by the customer, respondent metadata imported from files (such as attributes like age, region or segment), and the resulting code frames, categorisations and analyses. Whether this data relates to identifiable individuals depends on what the customer uploads. It is stored in a PostgreSQL database on our servers hosted by Hetzner in Nuremberg, Germany; uploaded files are additionally stored in Hetzner object storage in Falkenstein, Germany. The data is strictly segregated by account at database level. In relation to our customers the legal basis is Art. 6(1)(b) GDPR; towards respondents, the respective customer is the controller.

AI-assisted analysis

The core function of the platform is the automatic categorisation and analysis of open-ended responses using large language models. To this end we transmit the response texts to be analysed, together with the associated question, code frame and instruction details, through our own gateway service (operated on our own servers hosted by Hetzner in Germany) to Microsoft's Azure OpenAI Service. We obtain this service in an EU region; under the deployment type we have chosen, processing takes place within Microsoft's EU data zone. We do not transmit account or billing data. For searching large volumes of responses and for the chat assistant, response texts are also stored temporarily at the provider; we delete these records as soon as the corresponding survey or evaluation is deleted. Job data held by our gateway service (request and response) additionally remains in a queue on our own servers for a maximum of one hour, or a maximum of 24 hours in the event of an error. The legal basis is Art. 6(1)(b) GDPR.

We do not use survey, response or respondent data to train or improve AI models, and we do not share it for that purpose. Under Microsoft's terms for the Azure OpenAI Service, customer content is used neither to train the underlying models nor to improve third-party products. According to Microsoft, inputs and outputs may be retained for a limited period of up to 30 days to detect misuse, unless an exemption has been agreed for the resource used.

Analysis sandbox (code interpreter)

For advanced analyses, customers can use an analysis sandbox in the chat: an isolated, short-lived container environment in which Python code is executed against the data of the relevant survey. Files uploaded by the customer are transferred there, as are automatically generated extracts of the survey data — in particular response texts with their categorisations and the associated respondent metadata. The sandbox runs on our own infrastructure hosted by Hetzner in Germany; containers are deleted together with their data once the session ends. The output of the analysis (text and error output, truncated) is returned to the language model so that it can explain the results, and may therefore contain analysed content. The legal basis is Art. 6(1)(b) GDPR.

Payments and credit top-ups

For paid credit top-ups we use the payment service provider Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. We transmit only the payment amount, a payment description and an internal user identifier to Mollie. You enter your payment details, such as card or bank account information, directly with Mollie; we neither receive nor store them. From Mollie we receive only the payment identifier, the payment status and the amount, which we store together with the credited balance. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR in conjunction with statutory commercial and tax retention obligations for keeping payment and accounting records.

Transactional emails

We send emails via the Brevo service to confirm registration, to issue account invitations, to reset passwords, to process feedback and for operational notifications. The recipient address, the display name where applicable, and the content of the message are transmitted. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(f) GDPR for operational notifications. We do not send marketing newsletters through the platform.

Bot protection at sign-up (Cloudflare Turnstile)

On the registration page we use Cloudflare Turnstile to prevent automated bulk sign-ups. A script is loaded from Cloudflare (challenges.cloudflare.com); for this purpose Cloudflare processes your IP address and technical characteristics of your browser and device. When the result is subsequently verified server-side, we transmit your IP address to Cloudflare as well. According to Cloudflare, Turnstile does not use cookies for tracking purposes and is not used for profiling or advertising. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protecting the registration process against automated attacks, mass account creation and the abusive extraction of starting credits. Turnstile is used on the registration page only. Regarding transfers to Cloudflare, Inc. in the United States, see the section “International data transfers”.

Abuse prevention and sign-up limits

To prevent bulk and duplicate sign-ups, we log every registration attempt separately, recording the IP address, a normalised form of the email address, the outcome of the attempt and the time. On this basis we cap the number of registrations per IP address and per email address and detect unusual spikes. These entries are deleted automatically after 30 days. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in preventing abuse and ensuring proper operation of the service. This does not involve automated decision-making producing legal effects within the meaning of Art. 22 GDPR; rejected registrations can be clarified at any time via info@surv-ai.com.

Operational log data

Operating the platform generates technical log data such as IP address, timestamp, endpoint called, status code, response times and error messages. It serves to troubleshoot faults, ensure availability and detect attacks. Logs are overwritten on a rolling basis and are generally kept for no longer than 30 days. The legal basis is Art. 6(1)(f) GDPR. We do not use analytics, tracking or advertising services in the platform; the only third-party script embedded is the bot protection on the registration page described above.

API keys, exports and webhooks

Customers can generate API keys to access our REST API. We store these keys only as a cryptographic hash, together with a name, a visible prefix, the time of creation and the time of last use. Exports, for example to Excel or CSV, are generated on request and delivered directly to the requesting person; they contain the survey and analysis data of the respective account. Customers may optionally configure webhooks. In that case we transmit status and result information about a job — essentially identifiers, counts and the generated category structure — to the address specified by the customer, and log the delivery. The customer is responsible for the lawfulness of that transfer and for the receiving system.

C. Information applying to both

Service providers we use

We use the following service providers. Data processing agreements under Art. 28 GDPR are in place with every provider that processes personal data on our behalf.

Provider Purpose Place of processing Privacy notice
Hetzner Online GmbH Hosting of the application, database, object storage and backups (website and platform) Germany (Nuremberg, Falkenstein) View
Microsoft (Azure OpenAI Service) AI-assisted analysis of open-ended responses, chat assistant, transcription EU region (Microsoft EU data zone) View
Brevo (Sendinblue GmbH) Sending transactional emails (website and platform) EU (France, Germany) View
Mollie B.V. Payment processing for credit top-ups Netherlands (EU) View
Cloudflare, Inc. (Turnstile) Bot protection on the registration page (Turnstile) EU and USA View
Google Ireland Limited (Calendar API) Calendar entry for demo bookings (website only) EU (Ireland) and USA View

We operate our identity management (Zitadel), our database, our AI gateway service and the analysis sandbox ourselves on servers rented from Hetzner Online GmbH in Germany. These are not additional external service providers. Before engaging a new sub-processor we inform affected customers in good time in accordance with the applicable data processing agreement.

International data transfers

Processing generally takes place within the European Union. For two services a transfer to the United States cannot be ruled out: Cloudflare (bot protection on the platform's registration page) and Google (calendar entries for demo bookings on the website). Both providers are certified under the EU-US Data Privacy Framework; to that extent the transfer is based on the European Commission's adequacy decision of 10 July 2023 pursuant to Art. 45 GDPR. In addition, and for recipients outside that framework, we have agreed the European Commission's Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR with the providers. Despite these safeguards, access by US authorities to transferred data cannot be entirely ruled out, and legal protection equivalent to European standards cannot be guaranteed in every case.

Retention periods

We store personal data only for as long as it is necessary for the purposes described or for as long as statutory retention obligations require:

  • Account and sign-in data: for the duration of the user relationship. After the account is deleted the data is removed unless a statutory retention obligation applies. Sessions expire after 7 days at the latest.
  • Survey, response and analysis data: until deleted by the respective customer, and at the latest after the contract ends and any agreed return period has expired. Customers can delete surveys themselves at any time.
  • Payment, invoicing and accounting data: 10 years pursuant to Section 147 AO and Section 257 HGB (German tax and commercial law).
  • Log of registration attempts (IP address, normalised email address, outcome): 30 days.
  • Server and application logs: rolling, generally no longer than 30 days. Job data in the internal queue: a maximum of 1 hour, or a maximum of 24 hours in the event of an error.
  • Data from the demo booking form: until the appointment has taken place and the enquiry has been dealt with; if no business relationship arises, after 12 months at the latest.

Security of processing (Art. 32 GDPR)

We take technical and organisational measures to protect your data. These include end-to-end transport encryption (TLS/HTTPS) for all connections, strict tenant separation at database level through row-level security so that application access can only ever reach data belonging to the signed-in account, a separate database user with restricted privileges for the application, role-based access control within the application, server-side session management with encrypted storage of access tokens, execution of analysis code exclusively in isolated, short-lived containers without unrestricted network access, and regular backups to storage located within the EU. Access to production systems is limited to a small number of people and takes place exclusively over encrypted, key-based connections.

Your rights

Under the GDPR you have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20), as well as the right to object to processing based on legitimate interests (Art. 21). You may withdraw any consent you have given at any time with effect for the future. To exercise these rights, please contact:

info@surv-ai.com

Note for survey respondents: if you took part in a survey that is analysed using SurvAI, we act solely as a processor in that respect. Please address your request to the company or institute that conducted the survey, which is the controller in relation to you. If your request nevertheless reaches us, we will forward it to the controller without delay, provided the controller is known to us.

Irrespective of the above, you have the right to lodge a complaint about the processing of your personal data with a data protection supervisory authority. The authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit Gustav-Stresemann-Ring 1 65189 Wiesbaden, Germany https://datenschutz.hessen.de

Changes to this privacy policy

We reserve the right to amend this privacy policy to reflect changes in the legal framework or in our services. The current version is always available on this page.

This privacy policy was drafted in German. Translations are provided for information only; in the event of discrepancies, the German version prevails.

Our terms of service apply in addition.