Who processes the data
The personal data operator is (hereinafter — the operator). The operator provides a platform for organizational diagnostics: launching surveys, collecting responses, analyzing open-ended text, working with found growth points, and re-checking changes.
Compliance with user rights when processing their data, including the protection of privacy, is a mandatory condition for the service's operation. For any questions regarding data processing, you can contact the operator using the contacts listed on the website. The full details of the operator are provided at the end of this policy.
If an organization uses the service for its employees or respondents, it independently bears responsibility for the legality of launching the survey, the composition of invited participants, and the availability of necessary grounds for processing their data.
What data is processed
The composition of the data depends on the scenario: registration, launching a survey, participating in a survey, analyzing results, payment, support, or requesting a demo. The operator may process the following categories of data:
- account data — last name, first name, patronymic, email address, phone number;
- organization data — name, roles, teams, invitations, access settings;
- survey content — answers to questions, open-ended comments, found growth points, and recommendations;
- payment details — data on the tariff, invoices, and payment status; details of payment means are processed by payment providers and are not stored by the operator;
- technical data — IP address, information about the browser and device, cookies, action logs;
- requests — correspondence with support and data transferred through the demo request form.
The operator does not request more data than necessary for diagnostics and the operation of the service, and does not allow redundancy of the processed data in relation to the stated purposes.
Why the data is used
The data is needed to create an account and provide access to the service, grant access to the organization, conduct a survey, collect responses, show results by roles, form anonymized summaries, find growth points, prepare recommendations, and respond to user requests.
Certain technical data is used for service stability, protection against abuse, error diagnostics, action logging, execution of the contract with the organization, and fulfillment of duties established by applicable personal data legislation.
Legal grounds for processing
The operator processes data on one or more grounds: user consent; execution of a contract to which the user is a party or beneficiary, or the conclusion of such a contract at their initiative; legitimate interests of the operator or third parties, provided that user rights are not violated; fulfillment of duties imposed on the operator by applicable legislation.
The user may withdraw their consent to data processing or demand the cessation of processing at any time — the procedure is described in the rights section. After the withdrawal of consent, the operator has the right to continue processing only if there is another legal ground.
Processing principles
Processing is carried out on a lawful and fair basis and is limited to achieving specific, predefined purposes. Only data that meets these purposes is subject to processing; the combination of databases processed for incompatible purposes is not allowed.
The operator maintains the accuracy and relevance of the data: incomplete or inaccurate data is clarified or deleted. Data is stored in a form that allows identifying the user for no longer than required by the purposes of processing, after which it is destroyed or anonymized.
Responses, anonymity, and summaries
Controlled anonymization is one of the service’s core strengths. The manager works with processed summaries and found growth points, not the raw response text as ordinary management material.
The anonymity mode is selected when the survey is launched. Sensitive breakdowns are only disclosed when there are enough responses; if the sample size is too small, the service limits visibility to avoid creating a false sense of security.
The operator does not publicly disclose the diagnostic results of the user, or of the organization or brand the user represents, without their consent.
Absolute anonymity is impossible when the context of the response itself reveals the respondent. Therefore, the service reduces the risk of deanonymization through technical and product rules, and the organization must run surveys with a clear context and an appropriate audience.
AI analysis and service providers
AI helps parse open-ended responses, group topics, and prepare summaries and recommendation options. It does not make management decisions and does not replace the responsibility of the manager or organization.
External service providers may be engaged for infrastructure operations, email delivery, payment processing, and text analysis. They are only provided with the amount of data necessary to deliver the specific service, based on executed contracts or agreements.
Information collected by third-party services—including payment systems and communication tools—is stored and processed by them in accordance with their own user agreements and privacy policies.
Data transfer to third parties
Personal data is not transferred to third parties, except in three cases: when transfer is required by applicable law; when the user has given consent; when transfer is necessary for a service provider to fulfill contractual obligations, as described above.
If the operation of the service requires transferring data to the territory of another country, the operator follows the procedures required by applicable law for such transfer, including providing necessary notifications and verifying the data protection conditions on the receiving side.
The operator and other persons who have access to personal data are obligated not to disclose them to third parties and not to distribute them without the user's consent, unless otherwise provided by applicable law.
Storage and security
Data is hosted in the country or jurisdiction where the specific service instance is launched and is processed in accordance with local personal data legislation. Security is ensured through legal, organizational, and technical measures: role-based access, visibility minimization, technical logs, anonymity settings, and restrictions on displaying sensitive breakdowns.
These measures protect data from unauthorized or accidental access, destruction, modification, blocking, copying, disclosure, and dissemination. The approach to the visibility matrix, storage, and service providers is described in more detail in the Trust Center.
Retention periods, export, and deletion
The processing period is determined by the achievement of the purposes for which the data was collected, unless a different period is specified by the contract or applicable law. Organizational data is stored as long as the account and contractual relationship are active, or longer if required for legal obligations, security, settlements, or dispute resolution.
Upon achieving the purposes of processing, withdrawal of consent, a user's request to cease processing, or detection of unlawful processing, the data is destroyed or anonymized. The organization administrator may request the export or deletion of organizational data; backups are deleted according to the retention policy, and technical logs are retained only for as long as necessary for security and service obligations.
User rights and request procedure
The user has the right to receive information about the processing of their data; to request its rectification, blocking, or destruction if the data is incomplete, outdated, inaccurate, obtained unlawfully, or no longer necessary for the stated purpose; to withdraw consent to processing; to demand cessation of processing; and to appeal the operator’s actions or inactions to the competent authority for the protection of the rights of personal data subjects or to a court.
Requests should be sent to the operator using the contacts listed on the website: for data clarification — with the subject line "Updating Personal Data", for withdrawal of consent — with the subject line "Withdrawal of Consent to the Processing of Personal Data". Upon receiving a deletion request, the operator deletes the user's data; responses are provided within the timeframes established by applicable law.
If the request concerns data within an organization, the service may forward it to that organization’s administrator or process it jointly. Users, in turn, must provide accurate personal data and notify of any changes; the person who provides inaccurate information or another person’s data without consent bears responsibility.
Policy changes
All changes to the policy are reflected in this document. The policy is effective indefinitely until replaced by a new version; the current version is always available at http://nanodepo.net/privacy.