Privacy Policy
This policy explains how Aletso VOF collects, uses, and protects your personal data when you use Lensym, in accordance with the General Data Protection Regulation (GDPR) and Dutch privacy law.
- Operated by
- Aletso VOF
- Governing law
- The Netherlands
- Data stored in
- Frankfurt, Germany (European Union)
- Contact
- privacy@lensym.com
01Who we are
Aletso VOF is a company established in the Netherlands that provides the Lensym survey platform (the “Service”).
Depending on the context of the data processing:
We act as data controller
- For personal data relating to account registration, billing, website usage, and communication with users.
We act as data processor
- For survey response data processed on behalf of customers using the Service. We process such data only in accordance with the customer’s instructions.
02What data we collect
Account information
- Name and email address (required for account creation)
- Organization name (optional)
- Profile information you choose to provide
- Authentication data (encrypted passwords, two-factor authentication data)
Survey data
- Survey questions and content you create
- Response data collected through your surveys
- Survey settings and configurations
- Analytics and usage data relating to your surveys
For survey response data, Aletso VOF acts as a data processor and processes such data solely on behalf of the customer, in accordance with their instructions.
Technical data
- IP addresses (for security and fraud prevention)
- Browser and device information
- Usage patterns and feature interactions
- Error logs and diagnostic data
03How we use your data
Primary purposes
- Service delivery: providing survey tools and managing your account
- Security: protecting against fraud, abuse, and unauthorized access
- Support: responding to your questions and technical issues
- Legal compliance: meeting our legal obligations under EU law
For survey response data collected through surveys created by customers, Aletso VOF processes such data only on behalf of the customer using the Service.
What we don’t do
- We never sell your personal data to third parties
- We don’t use your data for advertising or marketing to others
- We don’t profile users for commercial purposes
- We don’t share survey responses with anyone except the customer who collected them
04Data sharing and transfers
We only share personal data in limited circumstances and always with appropriate safeguards.
Service providers
We work with carefully selected service providers that help us operate the Service. These providers process personal data only where necessary and under appropriate contractual and data protection safeguards. Our service providers may include providers for:
- Infrastructure and hosting
- Content delivery, security, and bot protection
- Payment processing
- Transactional email delivery
International transfers
We store personal data in Frankfurt, Germany. Where personal data is processed outside the European Economic Area, we rely on appropriate safeguards in accordance with applicable data protection laws.
For full transparency, our current sub-processors and related information are available in our Sub-Processor Register.
05Data security
We implement appropriate technical and organizational measures to protect your data.
Technical measures
- Encryption in transit (TLS) and at rest (AES-256)
- Multi-factor authentication
- Regular security reviews
- Secure EU data centres
Organizational measures
- Staff security training
- Access controls and monitoring
- Incident response procedures
- Regular policy reviews
Read more in our Security Practices.
06Your rights under GDPR
As an individual in the EU, you have the following rights regarding your personal data:
See Your Rights for a detailed explanation of each right and how to exercise it. To exercise any of these rights, contact us at privacy@lensym.com. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
07Data retention
We only retain personal data for as long as necessary for the purposes outlined in this policy, unless a longer retention period is required by law:
08Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:
- Email all users about the changes
- Update the “last updated” date at the top of this policy
- Provide a summary of key changes
- Give you time to review before changes take effect
Changes will not apply retroactively unless required by law.
09Contact information
Supervisory authority
If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority: Autoriteit Persoonsgegevens.