Privacy Policy

Last updated: July 20, 2026

At Durvey.org, we take privacy seriously. Whether you're a survey creator, participant, or visitor, this policy explains what data we collect, how we use it, and how you remain in control of your personal information.

Welcome to Durvey.org, a service operated by Beleo Labs GmbH ("Durvey.org", "we", "us", or "our"). We respect your privacy and are committed to protecting the personal data of our users and survey participants. This Privacy Policy explains how we collect, process, and protect personal data in connection with the use of our platform and services.

This policy applies to:

  • Registered users of Durvey.org
  • Survey respondents participating in panels or studies created via our platform
  • Visitors to our website

This Privacy Policy also explains how we use analytics to understand how users interact with our services and to continuously improve our features and user experience.

For questions, contact us at: [email protected]

1. Roles under Data Protection Law

Durvey.org acts in two distinct roles depending on the data concerned.

a) As Data Processor (Art. 28 GDPR)

For personal data we process on behalf of and under the documented instructions of our users, in particular:

  • survey and panel content created by users;
  • participant responses and associated metadata;
  • participant email addresses used to deliver invitations.

For this data, the user is the Data Controller and determines the purposes, content, and legal basis of the processing.

b) As Data Controller (Art. 4(7) GDPR)

For personal data we process for our own purposes, in particular:

  • account, registration and billing data of our users;
  • support communications;
  • data of website visitors, cookies set on durvey.org, and product/usage analytics;
  • security, fraud prevention, and aggregated benchmarking/marketing.

For this data, Durvey.org determines the purposes and means and is the responsible controller.

Throughout this policy we indicate, where relevant, in which role we act.

Controller Responsibility for Study Design

Where we act as processor, the user (Controller) alone designs and controls the surveys, panels, and studies created via the platform. This includes deciding which data are collected, how questions are framed, whether direct or indirect identifiers are requested, and whether responses are collected in anonymized, pseudonymized, or identifiable form.

Durvey.org provides technical features that support data minimization and pseudonymization (for example, the option to disable IP collection or to analyze responses in pseudonymized form), but we have no control over, and no visibility into, the substantive design of a study or the content a Controller chooses to collect. Accordingly, the Controller is solely responsible for designing and conducting each study in compliance with applicable law, including establishing a valid legal basis and applying appropriate anonymization or pseudonymization. This responsibility applies with particular force to any special categories of data within the meaning of Art. 9 GDPR.

2. Data We Process

We process the following categories of data:

Data You Provide

  • Account registration details (name, email, password)
  • Organization or billing details (if applicable)
  • Your intended use/interest in our platform
  • Support requests or communication history
  • Survey and panel content you create

Data from Survey Participants

  • Survey answers (text, choices, media)
  • Metadata (timestamp, device, language)
  • IP address (if not disabled by the user)
  • Consent status (if consent forms are used)

Automatically Collected Data

  • Access logs, browser type, OS, and activity (for security and analytics)
  • Cookies (see Section 9)
  • Device identifiers, screen resolution, time spent per page or action
  • User interaction patterns (clicks, hovers, scrolls) via first- and third-party tools

Email Delivery Data (on behalf of users)

When survey creators send invitation emails to participants via Durvey.org, we process the recipients' email addresses and message metadata (such as timestamp, delivery status, and bounce information) solely for the purpose of delivering the invitation.

Durvey.org processes these data as a Data Processor on behalf of the survey creator (Data Controller). We do not use participant email addresses for any purpose other than email delivery or troubleshooting delivery issues.

3. Legal Bases for Processing

We process personal data based on:

  • Art. 6(1)(b) GDPR – Performance of a contract (e.g., account setup, platform use)
  • Art. 6(1)(c) GDPR – Legal obligations (e.g., invoicing, tax law)
  • Art. 6(1)(f) GDPR – Legitimate interests (e.g., platform security, fraud detection)
  • Art. 6(1)(a) GDPR – Consent (e.g., participation in surveys, cookies, marketing)

As a Data Controller, you must ensure that you have a valid legal basis for any data collected via surveys.

4. Purposes of Processing

We use personal data for the following purposes:

  • Provision of our platform and services
  • Account administration and user authentication
  • Technical support and communication
  • Survey creation, distribution, and analysis
  • Compliance with legal obligations
  • Prevention of abuse or misuse of our services
  • Analytics and product improvement (on an aggregated, pseudonymized basis)
  • Analytics and product improvement, including detailed behavioral usage tracking (e.g., feature adoption, interaction trends, performance diagnostics), based on aggregated or pseudonymized data where possible

Important: We do not submit survey responses to any AI or machine-learning service, and no third-party AI provider receives survey content. We never use your data or your participants' responses to train AI models, and we never sell user data to third parties.

We rely on legitimate interests (Art. 6(1)(f) GDPR) for strictly necessary and low-impact analytics, and on explicit consent (Art. 6(1)(a)) where required under GDPR or local ePrivacy laws (e.g., for advanced tracking or cross-site analysis).

We may also use aggregated, pseudonymized, or anonymized data for internal research, statistical reporting, benchmarking, and marketing purposes — for example, to communicate general trends (e.g., "150 projects are currently active in the US") or to improve our product by identifying usage patterns and feature adoption rates.

Such processing is carried out without identifying individual users or participants and is based on our legitimate interest in improving our services, developing new features, and promoting platform effectiveness in line with Art. 6(1)(f) GDPR.

5. Data Sharing and Subprocessors

Where your data is hosted

Survey content, participant responses, uploaded files and the associated database are stored exclusively on infrastructure operated by Hetzner Online GmbH in data centres located in Germany. Hetzner is the only processor that holds the complete dataset, and that data is processed solely within the European Union. Backups are likewise stored within the EU.

No other service provider receives the full dataset. Every remaining provider is scoped to a narrow, clearly defined slice of data required for one specific function, and none of them has access to the survey database.

Beyond hosting, we engage a small number of carefully selected service providers to operate the platform. Because the composition of this list changes over time as we adapt our infrastructure, we describe the categories of recipients here rather than naming individual companies, and maintain a current, named list separately (see below).

Category of recipientData concernedOur roleProcessing location
Hosting and database infrastructureThe complete survey, participant and account datasetProcessor (on behalf of users)Germany (EU) only
Application delivery and content distributionRequest metadata in transit (e.g. IP address, user agent). No survey content is storedProcessor (on behalf of users)EU, provider subject to US jurisdiction
Transactional email deliveryRecipient addresses and the content of invitation emails, plus delivery metadataProcessor (on behalf of users)EU, provider subject to US jurisdiction
Payment and invoicingBilling data of paying customers. No participant or survey dataController (our own purposes)EU/US
Error monitoring and diagnosticsTechnical error reports in pseudonymized formController (our own purposes)EU/US
Website and product analyticsUsage data of website visitors. No survey content or participant responsesController (our own purposes)EU/US

Data is only shared with these providers under binding agreements in compliance with Art. 28 GDPR. We do not sell personal data, and we do not share it with advertisers. Our analytics tooling is configured with IP anonymization, so that IP addresses are truncated before being stored or processed. The specific third-party services that may set cookies in your browser are named individually in Section 9 and in our Consent Manager.

Transfers to providers subject to US jurisdiction

Survey and participant data does not leave the EU. Where a provider in one of the categories above is a US company or a European subsidiary of one, all such providers we currently engage are certified under the EU–U.S. Data Privacy Framework (DPF). Transfers therefore take place on the basis of the European Commission's adequacy decision pursuant to Art. 45 GDPR. As an additional safeguard, we have also concluded EU Standard Contractual Clauses (Art. 46 GDPR) with these providers, which continue to apply should the adequacy decision cease to be available.

Current list of subprocessors

We maintain an up-to-date list of all active subprocessors, including their company names, processing locations and the transfer mechanism relied upon. You can obtain the current version at any time by emailing [email protected]. Where we act as processor for a user, we inform that user of any intended addition or replacement of a subprocessor in advance, giving them the opportunity to object, in accordance with Art. 28(2) GDPR and the terms of the applicable Data Processing Agreement.

For email delivery, Durvey.org may temporarily process participant email addresses on behalf of the survey creator. These addresses are automatically deleted or anonymized once the delivery process and related logs (e.g., delivery confirmation or bounce handling) are complete. Where a participant has requested not to be contacted again, a minimal hashed record may be retained solely to honor that suppression, in accordance with the Controller's instructions.

6. International Data Transfers

If any service provider we engage operates outside the EU/EEA, we ensure protection of your data through:

  • Adequacy decisions by the European Commission — in particular the EU–U.S. Data Privacy Framework, in which all of our current US-based providers participate (Art. 45 GDPR), or
  • Standard Contractual Clauses (SCCs) as approved by the EU Commission, which we additionally conclude as a fallback safeguard (Art. 46 GDPR), and
  • Additional security measures as needed (e.g., encryption, strict access controls, data minimization)

Survey and participant data is not transferred outside the EU/EEA. This data is stored and processed exclusively on Hetzner infrastructure in Germany. The transfer safeguards described in this section are relevant only to the narrowly scoped services listed in Section 5 (application delivery, email dispatch) and to our own controller-side processors, such as payment and analytics providers.

Website analytics and payment processing may involve transfers of personal data to the United States. We rely on the participation of the providers concerned in the EU–U.S. Data Privacy Framework, supported by Standard Contractual Clauses and additional safeguards such as data minimization, encryption and IP anonymization. We keep the certification status of these providers under review; should the Data Privacy Framework cease to apply, the Standard Contractual Clauses already in place remain effective.

7. Data Retention

We retain personal data only as long as necessary for:

  • Providing services to our users
  • Complying with legal retention periods
  • Resolving disputes or enforcing agreements

We retain personal data only as long as necessary and in accordance with data minimization principles. Below are the specific retention periods for different categories of data:

  • Account information: Deleted 30 days after account termination
  • Survey responses: Retained until manually deleted by the user or up to 12 months after project expiration
  • Support tickets and communications: Retained for up to 12 months after resolution
  • Access logs and IP addresses: Retained for a maximum of 90 days
  • Backups: Automatically deleted after 90 days unless required for legal purposes

8. Your Rights as a Data Subject

If you are a survey participant or user from the EU/EEA, you have the following rights under GDPR:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure ("right to be forgotten") (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

How to exercise your rights depends on the role Durvey.org plays in the relevant processing:

  • Survey and participation data — contact the relevant survey organizer, who is the Data Controller for that processing. Durvey.org will forward requests and assist as required under Art. 28(3)(e) GDPR.
  • Account, billing, website, or analytics data — contact Durvey.org directly at [email protected], as we act as Data Controller for this data.

9. Cookies and Tracking

We use cookies to provide basic functions of this site (essential cookies) and - with your consent - to collect anonymous usage statistics and optimize the user experience. You can find details on this in our Consent Manager. There you can change or revoke your selection at any time.

Types of cookies we use:

TypePurposeConsent required
Essential cookiesLogin, CSRF protectionNo
Functional cookiesUser preferences (e.g., language)Yes
Analytics cookiesUsage tracking via Google AnalyticsYes
Marketing cookiesMay be used in the future for retargeting or campaign optimization. Currently disabled.Yes

We currently do not use marketing cookies. If this changes, we will update our cookie banner and request your explicit consent in accordance with applicable laws.

You can manage your preferences in our cookie consent banner at any time or visit our Cookie Settings page to view and change your preferences. We use a Consent Management Platform (CMP) to ensure that data collection complies with applicable data protection laws, including ePrivacy and GDPR.

10. Security Measures

We implement technical and organizational measures (TOMs) in line with Art. 32 GDPR, including:

  • TLS encryption
  • Regular software updates and security patching
  • Role-based access control (RBAC)
  • Audit logs for sensitive system actions
  • Encrypted backups
  • Data minimization principles

All staff and subprocessors are bound by strict confidentiality agreements. Access to personal data by system administrators is strictly limited based on necessity and role. All access is logged and subject to periodic review in line with the principle of least privilege ("need-to-know").

11. Children's Data

Durvey.org is not intended for use by children under the age of 16. If we become aware that we have collected data from a child without appropriate consent, we will delete it promptly.

12. Data Processing Agreement (DPA)

If you require a signed DPA to meet your GDPR obligations, please contact us at [email protected]. A standard template is available upon request. We conduct regular internal privacy and security audits to ensure compliance with applicable regulations and best practices.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via platform notification or email. Continued use of the platform after such changes constitutes your acceptance of the updated policy.

14. Behavioral Analytics Tools

We may use behavioral analytics tools to better understand user interaction patterns (e.g., clicks, scrolling behavior, page navigation) and to improve user experience. These tools may record anonymized session data unless otherwise consented.

We ensure that such tools operate in compliance with applicable data protection laws and are configured to minimize the collection of personal data wherever possible. Consent is obtained where legally required.

15. Use of Aggregated Data and Benchmarks

We reserve the right to analyze and publish aggregated statistics or trends derived from anonymized or pseudonymized usage data. These insights help us:

  • Understand industry benchmarks
  • Improve platform features
  • Communicate market activity (e.g., "Durvey supports over 150 live projects per month across Europe and North America")

Aggregated data does not contain personal information and cannot be linked back to any individual user or survey participant.

16. AI and Automated Processing

Durvey.org does not process survey content with artificial intelligence or machine-learning services.

  • Survey responses are not transmitted to any AI provider, and no AI subprocessor is engaged.
  • No automated decision-making or profiling within the meaning of Art. 22 GDPR is performed.
  • We never use your data or survey responses to train AI models.
  • We never sell user data to third parties.

Should we introduce AI-assisted features in the future, we will update this Privacy Policy, disclose the provider and its processing location in the subprocessor list in Section 5, and notify users in advance in accordance with Section 13.

17. Contact

If you have any questions about this Privacy Policy or how we handle your data, please contact:

Durvey.org
Email: [email protected]