Privacy Policy
Source: https://www.responsly.com/terms-and-policies/privacy-policy/
Contents
- 1. Who we are
- 2. When we are a controller and when we are a processor
- 3. What we process, why, on what legal basis and for how long
- 4. Respondent data
- 5. AI Features
- 6. Recipients of personal data
- 7. International transfers
- 8. Your rights
- 9. Whether you must provide your data
- 10. Automated decision-making
- 11. Cookies and similar technologies
- 12. Security
- 13. Use of Google APIs
- 14. Changes to this Privacy Policy
This Privacy Policy explains how we process personal data in connection with the Responsly website, the Responsly platform and our communications, and what rights you have. Capitalised terms not defined here have the meanings given in the Terms of Service available at https://www.responsly.com/terms-and-policies/.
This Privacy Policy is an information document. It does not form part of the agreement with Customers.
1. Who we are
1.1. The controller of your personal data is sixpoints – Jędrzej Koronowicz, a sole proprietorship registered in the Polish Central Registration and Information on Business (CEIDG), Grunwaldzka 472, 80-309 Gdańsk, Poland, VAT ID PL5842612410, which provides Responsly (we, us, our).
1.2. You can contact us:
- by email: help@responsly.com;
- by post: sixpoints – Jędrzej Koronowicz, Grunwaldzka 472, 80-309 Gdańsk, Poland.
1.3. In all matters relating to the processing of personal data and the exercise of your rights, you can contact us at gdpr@responsly.com.
2. When we are a controller and when we are a processor
2.1. We are the controller of personal data that we process for our own purposes, in particular data of:
- Customers’ representatives and Users who have an Account;
- visitors to the Website;
- people who contact us, request a demonstration or submit a complaint;
- people who submit notices of illegal content;
- recipients of our marketing communications and participants in our own satisfaction surveys.
2.2. We are a processor of personal data contained in Content, including Respondents’ personal data and the content of Surveys. We process such data on behalf of our Customers and in accordance with their instructions, under the Data Processing Agreement available at https://www.responsly.com/terms-and-policies/data-processing-addendum/. The Customer that created the Survey decides why and how the data is processed and is responsible for informing Respondents.
2.3. If you are a Respondent, please contact the organisation that created the Survey to learn how your data is used or to exercise your rights. If you contact us, we will pass your request on to that organisation where we can identify it. We will not respond to the substance of the request ourselves unless the organisation instructs us to do so or the law requires it.
2.4. In limited cases we process certain data relating to Surveys and Respondents as a controller for our own purposes: to secure the Service, to prevent abuse such as phishing Surveys, to handle notices of illegal content and to comply with legal obligations. These purposes are described in Section 3.
3. What we process, why, on what legal basis and for how long
3.1. The table below describes the processing we carry out as a controller. Legal bases refer to Article 6(1) of the General Data Protection Regulation (EU) 2016/679 (GDPR).
| Purpose | Personal data | Legal basis | Retention |
|---|---|---|---|
| Providing the Service: creating and maintaining Accounts, signing in (including with a Google account or single sign-on), managing Teams, and sending service messages such as purchase confirmations, security alerts, notices of service interruptions and notices of changes to the Terms or subprocessors | Name, email address, password (not stored in plain text), company name, role, phone number if provided, Account and Plan settings, activity logs, IP address, browser and device data | Art. 6(1)(b) – performance of the agreement, where you are the Customer; Art. 6(1)(f) – our legitimate interest in performing the agreement with the Customer you represent or whose Team you belong to | For as long as the Account exists; after the Account is deleted, 60 days, then deletion from production systems; backups are deleted within 12 months |
| Payments, invoicing and accounting | Billing name, company name, address, VAT ID, email address, Plan, amounts, invoices, transaction identifiers and payment status received from payment providers | Art. 6(1)(b) or (f) – processing payments for the Service; Art. 6(1)(c) – compliance with tax and accounting obligations | For the period required by Polish tax and accounting law, generally 5 years from the end of the calendar year in which the tax payment deadline expired |
| Customer support, enquiries, demonstration requests and complaints, including through the chat on the Website | Name, email address, company name, Account details, content of messages and attachments, chat conversation data | Art. 6(1)(f) – responding to enquiries and handling complaints; Art. 6(1)(b) – where the request concerns the agreement or steps taken before concluding it | 12 months after the matter is closed, unless a longer period is needed for legal claims |
| Security, abuse prevention and stability of the Service | IP addresses, server and application logs, browser and device data, Account activity, error reports, information about suspicious activity | Art. 6(1)(f) – securing the Service and preventing fraud and abuse | As a rule no longer than 12 months, unless needed longer to investigate a specific incident or for legal claims |
| Handling notices of illegal content, appeals and orders of authorities under the Digital Services Act | Notifier’s name and email address, content of the notice, URLs, correspondence, decision and statement of reasons, data of the Customer concerned | Art. 6(1)(c) – obligations under Regulation (EU) 2022/2065 (Digital Services Act) | For the time needed to handle the notice or appeal, then until the limitation period for related claims expires |
| Establishing, exercising or defending legal claims | Data relevant to the claim, such as correspondence, Account and payment history | Art. 6(1)(f) – protecting our legal interests | Until the limitation period expires (under Polish law, generally 3 years for claims related to business activity and 6 years for other claims, ending on the last day of a calendar year) and, if proceedings are pending, until they are finally concluded |
| Handling requests to exercise data protection rights | Identification data, content of the request, correspondence | Art. 6(1)(c) – obligations under Articles 12 to 22 GDPR | Until the limitation period for related claims expires |
| Satisfaction and product feedback surveys sent to Users | Email address, Account details, answers | Art. 6(1)(f) – understanding Users’ needs and improving the Service | 12 months after you complete the survey, after which answers are deleted or anonymised |
| Product analytics in the Platform | Usage events (such as features used), Account and User identifiers, browser and device data | Art. 6(1)(f) – understanding how the Platform is used and improving it; Art. 6(1)(a) – consent, where storing or accessing information on your device requires it | For as long as the Account exists, after which data is deleted or anonymised |
| Marketing communications, such as newsletters, product news and offers | Name, email address, company name, role, communication preferences, interactions with our messages (such as opens and clicks) | Art. 6(1)(a) – consent, where the law requires consent for electronic marketing, including under the Polish Electronic Communications Law; Art. 6(1)(f) – direct marketing, where the law permits it without consent | Until you withdraw consent or object; after that, we keep a record of your opt-out so that we can respect it |
| Cookies and similar technologies on the Website for analytics, advertising measurement and personalisation | Cookie identifiers, IP address, pages visited, referring page, browser and device data, approximate location (country), advertising click identifiers | Art. 6(1)(a) – consent | Until you withdraw consent or the cookie expires (Section 11); data held in the tools is kept for the period configured in those tools |
| Strictly necessary cookies and records of cookie choices | Cookie choices, country code, technical identifiers | Art. 6(1)(f) – operating the Website securely and demonstrating compliance with consent requirements | As set out in Section 11 |
3.2. We do not sell personal data. We do not use personal data for purposes incompatible with those described above.
4. Respondent data
4.1. When a Customer uses Responsly to collect responses, we process the following data on the Customer’s behalf, depending on the Survey and its settings:
- technical data collected when a Survey is opened, such as the IP address, a visitor ID, browser language, device type, operating system and its version;
- visitor attributes passed by the Customer, for example in the Survey link or through an integration;
- the email address or phone number of a Respondent to whom the Customer sends an invitation by email, SMS or WhatsApp;
- responses, including any personal data that the Respondent enters, and the time of responding.
4.2. When a Customer embeds a Survey on its website or application, the Responsly script may store a visitor ID in the browser for Survey delivery, for example to recognise that a Survey has already been shown or completed. We do not use cookies to target Respondents with advertising. The Customer is responsible for obtaining any consent required for such storage on its website or application.
4.3. IP addresses may be used to deliver Surveys and to protect the Service, for example by blocking malicious traffic. We do not store the precise geographic location of Respondents.
4.4. The Customer decides how long responses are kept and may delete them at any time. After the Customer’s Account is deleted or the agreement ends, Content, including Respondent data, is retained for 60 days, then deleted from production systems, and deleted from backups within 12 months.
4.5. We do not use Respondent data for our own marketing and do not use it to train AI models.
5. AI Features
5.1. Responsly offers optional AI Features, for example to generate Surveys from a description, analyse open-ended responses, identify themes and sentiment, and prepare summaries, reports and recommendations.
5.2. AI Features process data only when a Customer or a User uses or enables them. In that case, the data needed to perform the task, such as instructions entered by a User, Survey questions and selected responses, is sent to providers of language models. These providers act as our subprocessors and are listed on the subprocessors page referred to in Section 6. For customers in the EEA the contracting entity is established in Ireland; data may be further transferred to companies in the USA. Transfers are made on the basis described in Section 7.
5.3. Where AI Features process Content, we act as a processor on behalf of the Customer, who decides whether to use them and is responsible for informing Respondents where required by law.
5.4. We do not use Content to train AI models. Language model providers process the data we send under terms that do not permit them to use it to train their models. They may retain inputs and outputs for a limited period to monitor abuse and comply with the law, in accordance with their terms.
5.5. We do not use outputs of AI Features to take decisions about Users or Respondents.
6. Recipients of personal data
6.1. We share personal data only to the extent necessary for the purposes described in this Privacy Policy, with the following categories of recipients:
- providers of hosting and data storage in the European Union, and of content delivery, network security and DNS services;
- providers of email, SMS and WhatsApp delivery, and of language models for AI Features;
- providers of error monitoring, uptime monitoring, product analytics, customer support and messaging tools;
- our payment provider (Stripe), which may also act as an independent controller, for example to prevent fraud;
- Google, in connection with sign-in with a Google account, translation, analytics and the tags described in Section 11;
- professional advisers bound by confidentiality, such as lawyers and accountants;
- public authorities and courts, where the law requires disclosure;
- an entity taking over our business, if the business is transferred.
6.2. The current list of our subprocessors, with their purpose, location and the basis for any transfer outside the European Economic Area, is available at https://www.responsly.com/terms-and-policies/subprocessors/.
6.3. If you are a User in a Customer’s Team, the Customer and the Users it authorises can see your name, email address and activity in the Account. If a Customer enables an integration, data is sent to the third-party service chosen by the Customer, in accordance with the Customer’s instructions.
7. International transfers
7.1. We host the data of the Service in data centres located in the European Union. Some of our service providers are located outside the European Economic Area, in particular in the USA and Canada, and providers of content delivery and network security services operate global networks.
7.2. Transfers to the USA are based on:
- the European Commission’s adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, for recipients certified under that framework; or
- standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), together with supplementary measures where needed, for recipients that are not certified or where the Data Privacy Framework does not apply.
7.3. Transfers to Canada are based on the European Commission’s adequacy decision for Canada, which covers organisations subject to Canadian federal private-sector data protection law.
7.4. The basis for the transfer to each subprocessor is shown on the subprocessors page. You can obtain a copy of the relevant safeguards by writing to gdpr@responsly.com.
8. Your rights
8.1. Under the GDPR, you have the right to:
- access your personal data and receive a copy of it;
- rectification of inaccurate or incomplete data;
- erasure of your data, for example where it is no longer needed for the purposes for which it was collected;
- restriction of processing, for example while the accuracy of the data is being verified;
- data portability, where processing is based on consent or on an agreement and is carried out by automated means;
- object to processing based on our legitimate interests, on grounds relating to your particular situation, and to object at any time to processing for direct marketing;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal;
- lodge a complaint with a supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl/. You may also lodge a complaint with the supervisory authority in the Member State of your habitual residence or place of work.
8.2. To exercise your rights, write to gdpr@responsly.com. We may ask for information needed to confirm your identity. We respond within one month; where necessary because of the complexity or number of requests, this period may be extended by two further months, of which we will inform you within the first month. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.
8.3. Users can view and update most of their Account data in the Account settings.
8.4. If you are a Respondent, requests concerning your responses should be sent to the organisation that created the Survey (Section 2.3).
9. Whether you must provide your data
9.1. Providing personal data is voluntary, but some data is necessary:
- the data requested at registration, to create an Account and conclude the agreement;
- billing data, which tax law requires us to process, to purchase a paid Plan;
- contact details and a description of the matter, to handle a support request or complaint;
- your name and email address, for a notice of illegal content to be complete under the Digital Services Act, except for notices concerning child sexual abuse offences, which may be anonymous.
9.2. Consent to marketing communications and to non-essential cookies is voluntary. Refusing it does not affect your ability to use the Service.
9.3. If you are a Respondent, the organisation that created the Survey decides which questions require an answer.
10. Automated decision-making
10.1. We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
10.2. We use automated tools to protect the Service, for example to block traffic that appears malicious, and to analyse the use of the Website and the Platform. If you believe that you have been blocked in error, please contact help@responsly.com.
11. Cookies and similar technologies
11.1. What we use. The Website uses cookies and similar technologies, such as browser local storage and tags. Some of them are strictly necessary for the Website to work. Others are used for analytics, advertising measurement and personalisation, and are used only with your consent where consent is required by law.
11.2. Cookie banner. When you first visit the Website, we check your approximate location (country) based on your IP address, using a lookup service on our domain. Where the law requires consent, a cookie banner is displayed and non-essential technologies remain disabled until you make a choice. In the banner you can accept all categories, reject all non-essential categories, or choose individual categories in the settings. The categories are:
- Strictly necessary – required for the Website to function and to keep it secure, including storing your cookie choices. They are always active and cannot be disabled.
- Analytics – help us understand how visitors use the Website.
- Advertising – used to measure the performance of our advertising and to show relevant ads.
- Personalisation – remember your preferences to personalise content.
11.3. Google Tag Manager and Google Consent Mode. We use Google Tag Manager to load analytics and advertising measurement tags on the Website. Your choices are passed to these tags through Google Consent Mode as signals for analytics storage, advertising storage, use of data for advertising, ad personalisation and personalisation storage. Without your consent for a category, the tags do not store or read cookies for that purpose but may send limited information without cookies, such as the fact that a page was viewed. If advertising storage is not permitted, advertising data is redacted and ad click information may be passed in page addresses instead of cookies. Information on how Google uses such data is available at https://policies.google.com/technologies/partner-sites.
11.4. Cookies and storage on the Website.
| Name | Set by | Purpose | Duration |
|---|---|---|---|
| cookie_consent_v2 (cookie and local storage entry) | Responsly | Stores your cookie choices | 180 days (cookie); the local storage entry remains until you clear it |
| cookie_consent_required | Responsly | Records whether the cookie banner needs to be shown in your country | 30 days |
| cf_country | Responsly | Stores the country code determined from your IP address, used to decide whether to show the banner and passed to Google Tag Manager | 30 days |
| ResponslyFirstVisitedUrl | Responsly | Stores the address of the first page of the Website you visited, so that we can tell which page a sign-up started from | 30 days |
| Cookies of tags loaded through Google Tag Manager | Analytics and advertising measurement, depending on your choices | As set by Google | |
| Help Scout Beacon cookies and local storage | Help Scout | Operating the chat after you open it | As set by Help Scout |
11.5. Chat. The chat on the Website is provided by Help Scout. It is loaded only when you click the chat button. When loaded, Help Scout receives your IP address, browser data and the messages you send. When you send a message through the chat, we record in Google Tag Manager that a message was sent, together with a conversation identifier, but not its content.
11.6. Fonts. When a page of the Website loads, your browser downloads fonts from Adobe Fonts, which receives your IP address and browser data. We use this service, based on our legitimate interest, to display the Website correctly.
11.7. The Platform. The Platform uses cookies that are strictly necessary for signing in and keeping your session secure. Product analytics in the Platform is described in Section 3.
11.8. Changing your choices. You can change or withdraw your consent at any time by deleting the cookie_consent_v2 cookie and the site data for responsly.com in your browser settings. The banner will then be displayed again on your next visit, where it applies in your country. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. You can also block or delete cookies in your browser:
- Google Chrome: https://support.google.com/chrome/answer/95647
- Mozilla Firefox: https://support.mozilla.org/kb/clear-cookies-and-site-data-firefox
- Apple Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac
- Microsoft Edge: https://support.microsoft.com/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
Blocking strictly necessary cookies may prevent parts of the Website or the Platform from working.
12. Security
12.1. We apply technical and organisational measures appropriate to the risk, including:
- encryption of data in transit using TLS 1.2 or higher, and encryption of stored data using AES-256;
- hosting of the data of the Service in data centres located in the European Union;
- role-based permissions in the Account, two-factor authentication and, on the Enterprise Plan, single sign-on (SSO/SAML);
- access to personal data limited to authorised persons bound by confidentiality;
- internal information security policies, including on access control, cryptography, change management, incident response and business continuity.
12.2. Payment card details are handled by our payment providers and are not stored in our databases.
12.3. If a personal data breach occurs, we notify the supervisory authority and the persons affected where required by the GDPR. We notify Customers of breaches concerning their Content without undue delay and no later than 48 hours after becoming aware of the breach, as set out in the Data Processing Agreement.
12.4. We never ask for passwords by email. Please report suspected security vulnerabilities to help@responsly.com. More information about our security measures is available at https://www.responsly.com/security/.
13. Use of Google APIs
13.1. Responsly uses Google APIs to allow Users to sign in with a Google account and to connect Google services to their Account, for example to send responses to Google Sheets. We request access only to the data needed for the feature selected by the User.
13.2. Responsly’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, available at https://developers.google.com/terms/api-services-user-data-policy, including the Limited Use requirements.
13.3. In particular:
- we use data received from Google APIs only to provide or improve the features that the User has chosen and that are visible in the Platform;
- we do not transfer such data to third parties, except as necessary to provide or improve those features, to comply with the law, to protect the security of the Service, or as part of a merger, acquisition or sale of assets with notice to Users;
- we do not use such data for advertising, including personalised, retargeted or interest-based advertising;
- we do not allow people to read such data, unless the User has given consent for specific data, it is necessary for security purposes such as investigating abuse, it is required by law, or the data has been aggregated and anonymised for internal operations;
- we do not sell such data;
- we do not use data obtained from Google Workspace APIs to develop, improve or train generalised artificial intelligence or machine learning models.
13.4. Data received from Google APIs is stored securely and is accessible only to authorised persons. A User can revoke Responsly’s access at any time by disconnecting the integration in the Platform or in the Google Account settings at https://myaccount.google.com/permissions. Data received through the integration is then deleted in accordance with the retention periods described in this Privacy Policy.
14. Changes to this Privacy Policy
14.1. We may update this Privacy Policy, for example when our processing or the law changes. We publish each updated Privacy Policy on the Website with its effective date before it takes effect and inform Account owners of material changes by email or in the Platform.
14.2. This Privacy Policy was published on 16 September 2026 and is effective from 1 October 2026. The previous Privacy Policy is available on request sent to help@responsly.com.
