Security and data
Where the data lives, and who can reach it
Written for the person whose job it is to ask. If something here isn't enough, or you need it on your own paper, email support@psychsafety.com and you'll get a person who built this, not a form.
The short version. Respondents give us no name, no email address, no employee ID and no IP address. There is nothing in a team's answers that identifies who gave them — which means, for the survey itself, there is very little personal data for anyone to process, protect or leak.
That is architecture, not policy. It is also the reason most of the questions below have short answers.
Who is the controller, and who is the processor?
This is usually the first question, and the answer is unusual enough to be worth stating carefully.
Your team's answers
A response carries a rating per question; the reasons someone gives for holding back or for speaking up, picked from a fixed list; any comments they choose to write; the date it was submitted; how long it took; and whether every answer was the same, so the report can flag it. Nothing else. No name, no email, no IP address, no device identifier, no time of day. A team's report only exists once the survey has closed and at least four people have answered. Because we never receive identifying information about your employees, we are not processing your employees' personal data on your behalf — there is no identifiable person attached to a response for anyone to act on.
Two honest qualifications, because absolute claims in this area are usually wrong:
- Someone can type a name. Free-text comments are written by people, and a person can write "my manager said…" or name a colleague. We can't prevent that. Comments are shown to the organiser and, once released, to the team — the same people who were in the room. They go nowhere else.
- Our infrastructure providers keep short-lived technical logs that include IP addresses, as every web host does. We don't use them, we can't join them to any response, and retention is set as short as their tooling allows.
Organisers
The person who builds a survey gives us an email address, so we can send them a sign-in code, remind them about an open survey and tell them when their report is ready. We also keep their time zone, so reminders arrive in their morning, and whether they asked for our newsletter. For that, Iterum Ltd is the controller — it's our own relationship with them, not something we do on an employer's instruction.
Organisation licences
For an organisation licence we also hold the email addresses of the people given seats, and whatever the administrator chooses to put in the panel their organisers see: a short introduction, contacts and links.
The self-check
The self-check stores nothing but a count of how many were completed. If someone chooses to contribute their answers to research, those answers are stored with whatever broad context they chose to give (sector, team size, time in the team, seniority, whether they manage others, country), with no link to them.
What this means in practice
Most organisations conclude a data processing agreement isn't needed for the survey data, because there is no personal data to process. If your legal team reaches a different conclusion, say so and we'll work through it rather than argue — we'd rather understand your reasoning than win the point.
An organisation licence is different: the seat holders' email addresses and the panel your administrator writes are personal data we hold on your behalf. We'll sign a data processing agreement for an organisation licence as a matter of course — just ask.
Where it is
| What | Where | Region |
|---|---|---|
| Database and application logic | Supabase (managed PostgreSQL) | EU — Ireland |
| The website itself | Render | Served via CDN |
| Email delivery | SendLayer | United States — organiser emails only (see below) |
| Payments | Stripe | We never see or store card details |
Email and the US. SendLayer's parent company is US-based and its delivery infrastructure runs in US data centres. It passes each message through without storing its content, and keeps delivery metadata (the recipient's address, timestamps, and whether a message was delivered, opened, clicked or bounced) for between 3 and 30 days before deleting it. Transfers from the UK and EU rely on Standard Contractual Clauses and the UK International Data Transfer Addendum. Only organisers are ever emailed; respondents never give an address.
These four are our only sub-processors. There is no analytics vendor, no advertising pixel, no session-recording tool, no third-party chat widget and no data broker. Nothing about your teams is sold, shared or used to train anything.
No cookies. We count page views and which site people arrived from, as daily totals with no identifiers. Your browser's own storage keeps you signed in, and holds a survey you're part-way through building until you close the tab; nothing else.
Who can see what
| Who | Can see | Cannot see |
|---|---|---|
| A respondent | Their own answers as they give them; the team report once released | Anyone else's answers |
| The organiser | The aggregate report for their own team, once it has closed with at least four responses | Who answered, who said what, or individual responses |
| A licence administrator | Who holds a seat and how active they are; findings pooled across teams, once at least two have finished; change over time, once at least three have measured again | Any individual team's report or figures, or which team said what — at any price |
| Us | The database, as any vendor's engineers can | Any way to attribute a response to a person, because that link was never recorded |
Nobody can buy their way into a team's report, including the people paying for it. An organisation licence pays for the pooled view; a team's own report belongs to that team.
Pooled figures change as each team finishes, so an administrator comparing the organisation view before and after could estimate one team's contribution. Our terms prohibit it; if that matters for your organisation, ask us.
Someone at Psych Safety may read a finished report, to check it describes teams fairly and to improve the tool. Respondents are told this before they start, it is the same aggregate report the team sees, comments are left out unless deliberately asked for, and every such read is logged.
How it's protected
- In transit: TLS everywhere. The site is HTTPS-only.
- At rest: encrypted by the database provider.
- Sign-in: no passwords exist. An organiser receives a six-digit code by email, valid for ten minutes and once; five wrong tries locks it, and codes are rate-limited per address. There is no password to reuse, phish or breach. Signed-in sessions are stored only as hashes and expire after 30 days.
- Survey links: long random keys, stored only as hashes. We hold no copy that could be leaked and used.
- Access control: every read and write goes through a database function with its own permission check. There is no general-purpose API that returns rows, and an hourly check alerts us if any function becomes reachable from the web without our approval.
- Exports: on the Practitioner and Organisation plans, results can be downloaded as data: the same counts and averages the report shows. Individual responses and comments are never included.
- Audit trail: for every organisation licence we record who did what and when — seats given and removed, surveys created, closed and released (with response counts, never answers), the organisers' panel edited, exports taken, the dashboard opened, and any quality-check read of a report by us. The administrator can see it on request; it is kept from the licence's start either way.
- Backups: managed by the database provider, point-in-time.
- Payments: handled entirely by Stripe. Card details never reach our systems.
Retention
| What | Kept for |
|---|---|
| Surveys and their responses | Three years after the survey closes |
| Organiser accounts | Two years after last use, once no surveys remain and no licence is live |
| Organisation licence audit trail | The life of the licence, and 12 months after it ends; addresses of deleted accounts are removed |
| Licence and payment records | Six years, as UK accounting rules require |
| Sign-in codes | A week after they expire (automatic) |
| Error reports | 30 days (automatic) |
| Research contributions and page counts | Kept; they carry no link to anyone |
When a survey, an account or an audit trail reaches the end of its period, a person reviews it before anything is deleted. We keep something longer only for a reason — you're still an active client, say — and we note the reason, and it comes back for review when that time is up. Infrastructure logs follow provider defaults, set as short as their tooling allows.
An organiser can delete a survey nobody has answered yet from their own dashboard.
If you want a team's data removed, email us and we'll do it — and because responses aren't linked to people, removal is of the survey rather than of a person.
Availability, and what happens if something breaks
We are a small company and we won't pretend otherwise. What we do have:
- An automated check every hour for states that shouldn't be possible, which emails us when one occurs.
- An alert when anyone hits an error while signing up, building a survey or paying, so we can often fix it before they write in.
- A daily report of errors, usage and anything outstanding.
- A release gate that refuses to deploy if any check fails, including automated walk-throughs of the main journeys against a separate staging environment.
- Named people rather than a queue: Nick on the web application, Tom on infrastructure, systems and design, Jade on practice and interpretation. You'll get one of them, not a ticket. For anything about security, including reporting a vulnerability or an incident, the contact is Tom, at support@psychsafety.com.
If something goes wrong that affects your data, we'll tell you what happened, when, and what we did — without waiting to be asked.
Questions this page doesn't answer
If you need a signed data processing agreement, a completed security questionnaire on your own template, penetration test results, or a specific contractual commitment, email support@psychsafety.com. Some of those we can do immediately, some need a conversation, and we'd rather tell you which is which than go quiet.
Last reviewed 27 September 2026.