← Measuring Psychological Safety

Security and data

Where the data lives, and who can reach it

Written for the person whose job it is to ask. If something here isn't enough, or you need it on your own paper, email support@psychsafety.com and you'll get a person who built this, not a form.

The short version. Respondents give us no name, no email address, no employee ID and no IP address. There is nothing in a team's answers that identifies who gave them — which means, for the survey itself, there is very little personal data for anyone to process, protect or leak.

That is architecture, not policy. It is also the reason most of the questions below have short answers.

Who is the controller, and who is the processor?

This is usually the first question, and the answer is unusual enough to be worth stating carefully.

Your team's answers

A response carries a rating per question; the reasons someone gives for holding back or for speaking up, picked from a fixed list; any comments they choose to write; the date it was submitted; how long it took; and whether every answer was the same, so the report can flag it. Nothing else. No name, no email, no IP address, no device identifier, no time of day. A team's report only exists once the survey has closed and at least four people have answered. Because we never receive identifying information about your employees, we are not processing your employees' personal data on your behalf — there is no identifiable person attached to a response for anyone to act on.

Two honest qualifications, because absolute claims in this area are usually wrong:

Organisers

The person who builds a survey gives us an email address, so we can send them a sign-in code, remind them about an open survey and tell them when their report is ready. We also keep their time zone, so reminders arrive in their morning, and whether they asked for our newsletter. For that, Iterum Ltd is the controller — it's our own relationship with them, not something we do on an employer's instruction.

Organisation licences

For an organisation licence we also hold the email addresses of the people given seats, and whatever the administrator chooses to put in the panel their organisers see: a short introduction, contacts and links.

The self-check

The self-check stores nothing but a count of how many were completed. If someone chooses to contribute their answers to research, those answers are stored with whatever broad context they chose to give (sector, team size, time in the team, seniority, whether they manage others, country), with no link to them.

What this means in practice

Most organisations conclude a data processing agreement isn't needed for the survey data, because there is no personal data to process. If your legal team reaches a different conclusion, say so and we'll work through it rather than argue — we'd rather understand your reasoning than win the point.

An organisation licence is different: the seat holders' email addresses and the panel your administrator writes are personal data we hold on your behalf. We'll sign a data processing agreement for an organisation licence as a matter of course — just ask.

Where it is

WhatWhereRegion
Database and application logicSupabase (managed PostgreSQL)EU — Ireland
The website itselfRenderServed via CDN
Email deliverySendLayerUnited States — organiser emails only (see below)
PaymentsStripeWe never see or store card details

Email and the US. SendLayer's parent company is US-based and its delivery infrastructure runs in US data centres. It passes each message through without storing its content, and keeps delivery metadata (the recipient's address, timestamps, and whether a message was delivered, opened, clicked or bounced) for between 3 and 30 days before deleting it. Transfers from the UK and EU rely on Standard Contractual Clauses and the UK International Data Transfer Addendum. Only organisers are ever emailed; respondents never give an address.

These four are our only sub-processors. There is no analytics vendor, no advertising pixel, no session-recording tool, no third-party chat widget and no data broker. Nothing about your teams is sold, shared or used to train anything.

No cookies. We count page views and which site people arrived from, as daily totals with no identifiers. Your browser's own storage keeps you signed in, and holds a survey you're part-way through building until you close the tab; nothing else.

Who can see what

WhoCan seeCannot see
A respondentTheir own answers as they give them; the team report once releasedAnyone else's answers
The organiserThe aggregate report for their own team, once it has closed with at least four responsesWho answered, who said what, or individual responses
A licence administratorWho holds a seat and how active they are; findings pooled across teams, once at least two have finished; change over time, once at least three have measured againAny individual team's report or figures, or which team said what — at any price
UsThe database, as any vendor's engineers canAny way to attribute a response to a person, because that link was never recorded

Nobody can buy their way into a team's report, including the people paying for it. An organisation licence pays for the pooled view; a team's own report belongs to that team.

Pooled figures change as each team finishes, so an administrator comparing the organisation view before and after could estimate one team's contribution. Our terms prohibit it; if that matters for your organisation, ask us.

Someone at Psych Safety may read a finished report, to check it describes teams fairly and to improve the tool. Respondents are told this before they start, it is the same aggregate report the team sees, comments are left out unless deliberately asked for, and every such read is logged.

How it's protected

Retention

WhatKept for
Surveys and their responsesThree years after the survey closes
Organiser accountsTwo years after last use, once no surveys remain and no licence is live
Organisation licence audit trailThe life of the licence, and 12 months after it ends; addresses of deleted accounts are removed
Licence and payment recordsSix years, as UK accounting rules require
Sign-in codesA week after they expire (automatic)
Error reports30 days (automatic)
Research contributions and page countsKept; they carry no link to anyone

When a survey, an account or an audit trail reaches the end of its period, a person reviews it before anything is deleted. We keep something longer only for a reason — you're still an active client, say — and we note the reason, and it comes back for review when that time is up. Infrastructure logs follow provider defaults, set as short as their tooling allows.

An organiser can delete a survey nobody has answered yet from their own dashboard.

If you want a team's data removed, email us and we'll do it — and because responses aren't linked to people, removal is of the survey rather than of a person.

Availability, and what happens if something breaks

We are a small company and we won't pretend otherwise. What we do have:

If something goes wrong that affects your data, we'll tell you what happened, when, and what we did — without waiting to be asked.

Questions this page doesn't answer

If you need a signed data processing agreement, a completed security questionnaire on your own template, penetration test results, or a specific contractual commitment, email support@psychsafety.com. Some of those we can do immediately, some need a conversation, and we'd rather tell you which is which than go quiet.

Last reviewed 27 September 2026.