Learn what makes Survicate a GDPR-compliant product, where we store your data, what personal data we collect from respondents, and how we ensure the right to be forgotten.
GDPR (General Data Processing Regulation), officially entered into application on 18 May 2018, is an EU regulation on protecting personal data and privacy for individuals in the EU.
GDPR applies to any Survicate Customer processing data in the EU or processing data of EU citizens.
Within the scope of this regulation, any entity processing personal data must clearly state the purpose of the data to be processed, their legal basis, how long the data is kept, and whether it is shared with any third party or outside the European Economic Area (EEA). Data subjects have the right to request a copy of their stored data at any time and the deletion of their personal data under certain conditions.
Yes, Survicate is fully GDPR compliant. Our headquarters are located in Warsaw, Poland. As a business operating within the EU, we are subject to GDPR and all additional EU data protection amendments.
By choosing Survicate, you will meet your obligations under Article 28 of the GDPR to work with a Data Processor that executes appropriate technical and organizational measures and pseudonymization techniques to ensure the protection of the rights of the data subject. We assist you in meeting your obligations under the GDPR, such as deleting personal data or gathering and storing proof of consent.
Survicate acts as both Data Controller and Data Processor under the provisions of GDPR compliance:
When you create a Survicate account, you agree to adhere to our Terms of Service, Privacy Policy, and Data Processing Agreement.
Our data centers are located in Ireland (EU), Amazon AWS Cloud, an ISO 27001 and SOC2 certified data center. Under the provisions of GDPR, entities transferring personal data outside the EU and European Economic Area (EEA), should take the necessary technical and institutional measures to implement data protection principles and pseudonymization techniques. By working with a company that has its data centers inside the EU, you will eliminate many risks associated with transcontinental data transfers.
Development and maintenance of our product is ISO 27001 certified as well.
In Survicate, we take the protection of Personally Identifiable Information (PII) very seriously, and we understand it's a matter which should be handled delicately. Therefore, in Survicate, you can choose to keep your responses anonymous (without collecting any PII) or only obtain personal data when the data subject is willing to share their information. We also give you the possibility to collect the personal information of your respondents at all times. If you are collecting the personal data of your respondents in any way, you might need to obtain consent to process the personal data of your respondent or modify how you currently obtain that consent.
In order to help you handle your obligations under the GDPR Right to Erasure requests, Survicate allows you to delete personal data stored in survey responses conveniently.
You may delete:
The measures we have taken to ensure GDPR compliance:
The procedures we follow
We carry out an analysis of the risks, and we have strict procedures in place. Here are some of them:
ISO 27001 Certified
Global Privacy Frameworks
PCI DSS & HIPAA
© 2026 Survicate S.A. With ♥ from Poland