Last update: 4 October 2026

Privacy Policy

1) Introduction

Polzy helps organisations listen to the people around them. Because most of what we process is feedback people give in confidence, privacy is a product requirement, not a legal afterthought. This policy explains what we collect, why, how long we keep it and the choices you have. Polzy is run by Polzy B.V., Amsterdam; our registration details are on the legal notice.

2) Our two roles

When an organisation runs a survey on Polzy, that organisation decides what happens to the answers. It is the controller of everything it puts into its workspaces — the people it invites, their answers, the messages it sends — and Polzy processes that data only on its instructions, under our Data Processing Agreement. If you answered a survey, the organisation named in the survey’s privacy notice is the one to ask about your data; this page describes how Polzy handles it on their behalf, and is the page every survey links to.

We are the controller ourselves for the data of the people who use Polzy as customers and visitors: administrators’ accounts, billing and the declaration made at sign-up of who the account is for, support conversations, demo requests, the lists you subscribe to, and the security records that keep the service safe.

3) What we collect

  • Account data from administrators and members: name, work email, password (stored only as a hash), the secret behind two-step verification if it is turned on, and the sign-in method — including Google or Microsoft if you choose them.
  • Account and billing data: for a business, its name, country and VAT or registration number; for personal use, your name and the country where you live; the billing contact, invoices and payment records. Card and bank details are held by our payment provider, not by us.
  • People data a workspace adds or syncs from its HR or CRM system: name, email and the fields the workspace defines, such as department or site.
  • Survey responses, as described under Anonymity and the privacy floor.
  • Messages and support: the invitations and reminders a workspace sends, and what you write to our support team.
  • Technical data: IP address, browser and device, used for security, sign-in protection and delivery — and, for respondents, only where the survey is not anonymous.

4) Anonymity and the privacy floor

Whether a survey is anonymous is chosen by the organisation that runs it, survey by survey, and every survey says which it is in its privacy notice before the first question. In an anonymous survey, an answer is stored without the respondent’s name, email, IP address or browser, and without the invitation that delivered it, so it cannot be linked back to them. In an identified survey, the organisation can see answers with the respondent’s name. Either way, grouped results are only shown for groups of at least five people by default (an organisation can set between 3 and 50), and the floor applies to every filter, heatmap cell and export. Text a respondent writes in a comment is shown as written, so a detail that names someone can still identify them.

5) Why we use data, and on what basis

PurposeLegal basis (GDPR)
Providing the service: accounts, workspaces, surveys, reminders, scores, themes and summariesOur contract with the customer (Art. 6(1)(b)); for respondent data, the customer’s instructions (Art. 28)
Billing, invoices, VAT and the declaration of who the account is forLegal obligations under tax law (Art. 6(1)(c)) and the contract
Security: sign-in protection, abuse prevention, the audit log, error trackingOur legitimate interest, and our customers’, in a secure service (Art. 6(1)(f))
Support conversations and demo requestsThe contract, or steps you asked us to take before one (Art. 6(1)(b))
Status, blog and product-update emailsYour consent, confirmed by email and withdrawn with the link in every message (Art. 6(1)(a))

6) AI and automated processing

Polzy’s AI features analyse response text to tag themes and sentiment, write summaries and suggest actions. They run through the AI provider in our sub-processor register, only for the workspaces that use them. Neither Polzy nor that provider uses the text to train models. Polzy makes no decision about a person by automated means alone: the AI groups and summarises what was said, and people decide what to do with it.

7) Cookies

Polzy uses only the cookies and browser storage the service needs to work: keeping you signed in, protecting a sign-in through Google or Microsoft, and remembering choices such as language. We use no advertising or analytics cookies and no third-party trackers, so there is nothing to consent to.

8) Where data lives

Customer data is hosted in the European Union, on Fly.io in Amsterdam. Some sub-processors — email and SMS delivery, AI features and payments — are based in the United States; those transfers are covered by the European Commission’s Standard Contractual Clauses or the EU–US Data Privacy Framework. Every sub-processor is listed in our sub-processor register and bound by a data processing agreement.

9) Retention

  • Responses are kept for the period the workspace administrator sets (6, 12, 24 or 36 months, or for as long as the workspace exists), and deleted every night once they pass it.
  • Sent messages lose their text, personal link and recipient address after 90 days by default (an administrator can choose between 30 and 365 days); the delivery record without them is kept for the campaign’s figures.
  • Integration activity is kept for 180 days, and workflow run history for 90 days.
  • Records of AI usage and usage counters are kept for 400 days, and the audit log of administrative actions for 400 days.
  • Workspaces and organisations: a workspace an administrator deletes is read-only for 14 days, during which the deletion can be cancelled, and is then removed with everything in it; an organisation that closes is removed the same way once its last workspace is gone.
  • Invoices are kept for the period tax law requires (seven years in the Netherlands).
  • Backups are encrypted and kept for 35 days, so a deleted record leaves the last backup within 35 days (to be confirmed: the backup job is built and tested but not yet running in production).

10) Your rights

A respondent can delete their own answers to an identified survey at any time through the Privacy link in every survey — from the survey itself, its thank-you screen, or their invitation link — after confirming on screen. The answers are deleted, and the survey’s results no longer include them. An anonymous answer is not linked to the person in any way, so it cannot be singled out and deleted on request (Article 11 GDPR). For anything else — access, correction, a copy of their data, restriction or objection — respondents contact the organisation that runs the survey, whose privacy contact is named in the survey’s notice; we help that organisation answer. Administrators can export a person’s data or erase them, delete a workspace, or close their organisation from Settings.

For the data we control, you can ask us for access, correction, deletion, a portable copy, restriction, or object to processing based on our legitimate interest, and withdraw a consent at any time. Requests we cannot fulfil automatically are answered within 30 days.

11) Changes to this policy

When we change this policy, the date at the top changes. A change that affects how we use your data is announced to administrators by email and in Polzy before it applies.

12) Contact

Questions about privacy go to privacy@polzy.ai. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the authority where you live or work. Who we are, and where we are registered, is on our legal notice.

Ready to hear from your people instead of guessing?

Free for your first 100 responses a month. Paid plans start with a free trial.