SurveysAI / Trust
Privacy Policy
How i-dotazník s.r.o. handles account data, customer content, Google data, analytics, and service providers across SurveysAI services.
Current version:
Version 1.0 — effective 30 July 2026.
This policy applies to the SurveysAI website and to every online service operated by i-dotazník s.r.o. that links to it, including For Google Forms, CrossChat, Open-End Response Analyser, Qualitative Analysis Workflow, and Transkripce i-dotazník (together, the Services). A new service is covered when it links to this policy and its data use fits the activities described here.
1. Who is responsible
The operator is:
- i-dotazník s.r.o.
- Business ID (IČO): 08689784
- Registered office: Burdova 407/33, Kyje, 198 00 Praha 9, Czech Republic
- Registered in the Commercial Register kept by the Municipal Court in Prague, file C 323320
- Email: info@surveysai.com
For account, payment, support, security, and website data, we are the data controller.
When a customer submits content containing personal data for processing, the customer normally decides why and how that data is used and is the controller; we act as its processor solely to provide the requested Service. The data-processing terms in our Terms of Service apply to that processing.
2. Data we handle
Depending on the Service, we may handle:
- account and contact data, such as email address, name, authentication identifiers, and support messages;
- order and billing data, such as purchased product, price, currency, payment status, and invoice details;
- technical and security data, such as IP address, device/browser information, timestamps, and server logs;
- optional analytics data after consent, such as page views and product interactions;
- customer content submitted to a Service, such as questionnaire instructions, prompts, open-ended answers, transcripts, field notes, recordings, and generated outputs;
- Google account identity and authorization data when a user connects For Google Forms.
We do not receive or store full payment-card numbers; Stripe handles card details.
3. Why we use the data
We use data to:
- create and operate accounts and deliver requested features;
- process orders, provide access, keep accounting records, and handle support;
- secure, diagnose, and improve the Services;
- create forms or other outputs requested by the user;
- transcribe, analyse, classify, or otherwise process customer content as instructed by the user;
- measure use of a Service where the user has consented to non-essential analytics;
- meet legal obligations and establish or defend legal claims.
Our legal bases are performance of a contract, compliance with legal obligations, our legitimate interests in secure and reliable operation, and consent where required. For customer content processed on behalf of a customer, that customer is responsible for identifying its own legal basis.
4. Customer content and data minimisation
The Services are designed for research and productive work, not for building identity databases. Before submitting research material, remove names, contact details, direct identifiers, and details that are not needed for the task. Do not intentionally submit special-category data or other sensitive personal data unless the relevant Service expressly supports that use and you have a valid legal basis.
A passing name or isolated detail is not treated by us as a reason to inspect or profile a person. Nevertheless, information can be personal data when a person is identifiable from the material or from information reasonably available to the customer. You are responsible for determining whether submitted content contains personal data and for processing it lawfully. We do not proactively scan customer content for personal data, but we treat personal data that reaches a Service according to this policy and the data-processing terms.
We process customer content only to provide the requested Service, maintain security, and resolve a support issue when the customer asks us to. We do not sell customer content and do not use Google user data or customer research content for advertising.
5. Google user data
For Google Forms uses Google OAuth. Depending on the sign-in flow, it receives basic Google account identity (openid, email, and profile) and requests https://www.googleapis.com/auth/forms.body to create or update the forms the user asks it to create or update. An authorization token may be stored in encrypted form so the connection works between sessions.
Google user data is used only to provide or improve the user-facing functionality requested by the user. It is not sold, used for advertising, or used to train general-purpose AI models. Human access is limited to user-approved support, security investigation, or legal necessity.
Users can disconnect the integration in the product where that option is available or revoke access in their Google Account permissions.
Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
6. Service providers and international transfers
We use suppliers only where needed to run a Service. Depending on the product and options selected, these may include:
- Railway for application hosting and managed databases;
- Neon or managed PostgreSQL for database services;
- Stripe for payments;
- Resend for transactional email;
- Google for OAuth, Google Forms, Gemini, Speech-to-Text, and consented analytics;
- OpenAI, Soniox, Deepgram, AssemblyAI, and ElevenLabs for selected transcription or AI processing;
- OpenRouter and the model provider selected through it for selected AI processing;
- PostHog for consented product analytics and feedback;
- GitHub for technical issue tracking when feedback is escalated.
Only the provider needed for a requested workflow receives the relevant data. Some providers may process data outside the European Economic Area. Where GDPR requires it, we rely on an adequacy decision, approved contractual safeguards, or another lawful transfer mechanism.
The list reflects the portfolio as a whole; an individual Service normally uses only a subset. We will update this page when a material new category of provider is introduced.
7. Retention
We keep data only for the time needed for the stated purpose, security, support, or legal obligations. The current portfolio defaults are:
- account data: while the account is active and normally up to 30 days after closure;
- uploaded content and generated outputs: normally no longer than 90 days unless the user deletes them earlier or a Service clearly states a shorter period;
- uploaded audio and video in Transkripce: normally no longer than 30 days;
- operational logs: normally up to 90 days;
- backups: normally up to 30 days before rotation;
- accounting and tax records: for the period required by Czech law.
Some third-party providers keep limited operational records under their own documented retention settings. A deletion request does not override records we must retain by law.
8. Analytics, cookies, and local storage
Essential cookies or local storage may be used for login, security, and saving service settings. The SurveysAI hub loads Google Analytics 4 and PostHog only after the visitor allows analytics. Session recording is disabled on the hub, and research content, prompts, recordings, transcripts, and uploaded file names are not intentionally included in analytics events.
Other Services must provide their own in-product consent control before loading non-essential analytics. Declining analytics does not prevent use of the core Service.
9. Security
We use proportionate technical and organisational measures, including HTTPS encryption in transit, access controls, separation of application secrets from source code, and encrypted storage for Google authorization tokens. No online system is risk-free, but access to customer content is limited to what is needed to operate and support the Services.
10. Your rights
Where GDPR applies, you may request access, correction, erasure, restriction, portability, or object to processing, and you may withdraw consent without affecting earlier lawful processing. Send requests to info@surveysai.com.
If a customer submitted your data, that customer is normally the controller and should decide your request. We will assist the customer where required.
You may complain to the Czech Office for Personal Data Protection (ÚOOÚ) or another competent supervisory authority.
11. Children, automated decisions, and changes
The Services are intended for adults and are not directed to children. AI outputs support the user’s work and are intended for human review; we do not use them to make our own decisions producing legal or similarly significant effects about research participants.
We may update this policy as the Services evolve. The version and effective date above identify the current text. Material changes will be announced through an appropriate channel.