Data Processing
How Aletso VOF acts as your data processor for survey response data under Article 28 GDPR — and how to obtain a signed Data Processing Agreement for your institution.
- Operated by
- Aletso VOF
- Governing law
- The Netherlands
- Data stored in
- Frankfurt, Germany (European Union)
- Contact
- privacy@lensym.com
01Who is responsible for what
When you collect survey responses through Lensym, the GDPR assigns two distinct roles:
You — the data controller
- You decide what data your surveys collect and why
- You are responsible for having a valid legal basis
- You provide privacy notices to your respondents
- You handle respondent rights requests, with our assistance
Aletso VOF — the data processor
- We process survey response data only on your instructions
- We store and secure the data on your behalf
- We never use your response data for our own purposes
- We assist you in meeting your GDPR obligations
For your own account data (name, email, billing), Aletso VOF is the controller — see our Privacy Policy.
02Our processor commitments
As your processor, Aletso VOF commits to the obligations Article 28 GDPR requires:
- Instructions only: we process survey response data solely to provide the Service, never for our own purposes
- Confidentiality: access to personal data is limited to what is strictly necessary to operate and support the Service
- Security: we maintain the technical and organizational measures described in our Security Practices
- Sub-processors: we only use the providers listed in our Sub-Processor Register, and give 30 days notice before changes
- Assistance: we help you respond to data subject requests and, where relevant, data protection impact assessments
- Breach notification: we inform you without undue delay if a breach affects your survey data
- Deletion and return: you can export or delete your data at any time; after account deletion, remaining copies are removed according to our retention schedule
03Where data is processed
Survey response data is stored in Frankfurt, Germany (European Union). Where a sub-processor handles personal data outside the European Economic Area, transfers are safeguarded by EU Standard Contractual Clauses or an adequacy decision, as documented per provider in the Sub-Processor Register.
04Obtaining a signed DPA
Many institutions — universities, ethics boards, corporate procurement — require a signed Data Processing Agreement before research can start. We are happy to provide one.
Email privacy@lensym.com with the subject “DPA request” and the legal name of your organization. We respond within a few business days.