Privacy & GDPR
EZSurvey is designed to help research teams collect useful answers while limiting unnecessary exposure of personal data.
Last updated: 11 August 2026
What data we process
Depending on the study, a customer may upload contact details such as telephone numbers, names, email addresses, language, region, consent or do-not-contact status. The platform may also store questionnaire answers, operator and agent activity, timestamps, device information, GPS or media evidence when the customer deliberately enables those features.
EZSurvey does not decide the purpose of a customer’s research. The customer normally acts as the data controller and EZSurvey acts as a technology provider/processor under the applicable agreement.
How data is protected
- Role-based workspace access and authenticated operator accounts.
- Masked contact information in CATI operator views wherever the full value is not necessary.
- Workspace-scoped queries and audit records for important actions.
- Purpose, consent, retention, suppression-list, and export controls as configurable research metadata.
- Privacy-aware CAPI design for offline storage, synchronization, GPS, photos, audio, video, and signatures.
- AI analysis is limited to approved datasets and should exclude direct identifiers unless a documented purpose requires them.
Opt out and stop contact
A respondent can tell the interviewer to stop, refuse a question, or request no further contact. The customer must record that instruction in the project’s disposition or suppression workflow. For a public CAWI survey, use the study’s contact address or the respondent-support link shown in the invitation. We do not use research contact lists for EZSurvey marketing.
Workspace administrators can also mark a contact as do-not-call and remove it from future assignments. This is a platform control; customers remain responsible for honoring applicable legal and client-specific suppression obligations.
Access, correction, deletion, and portability
Respondents should contact the organisation that commissioned the study, because that organisation controls the research purpose and legal basis. The organisation can ask EZSurvey to locate, correct, export, restrict, anonymise, or erase records subject to legal exceptions and documented retention duties.
A workspace administrator can permanently erase the entire workspace and its research data from the authenticated administration area. The action requires re-authentication and the exact confirmation phrase DELETE WORKSPACE. It is irreversible and is recorded before the workspace cascade is removed.
Retention and deletion
Research data should be kept only for the documented project, legal, audit, and contractual period. Customers configure the retention decision; EZSurvey’s production roadmap includes scheduled retention review, deletion, anonymisation, export, and backup-expiry jobs. Backups may have a separate expiry window and must not be treated as instantly erased primary data.
Important limitation
“GDPR-aligned privacy by design” is a product design statement, not a certification or guarantee that every customer project is compliant. Compliance depends on lawful basis, notices, participant rights, retention, processor agreements, international transfers, sector rules, and customer configuration. Obtain qualified privacy advice for your project.
Contact
For platform privacy questions, contact the EZSurvey privacy team through the support address supplied with your workspace agreement. For a specific study, contact the organisation named in that study’s participant notice.
Submit a privacy request
Use this form to request no further contact or exercise a data right. Include the study or organisation name if you know it.