Trust Center
Security·Last updated July 2026

Security Practices

The concrete technical and organizational measures protecting your data on Lensym — what we encrypt, where data lives, and how we respond when something goes wrong.

Operated by
Aletso VOF
Governing law
The Netherlands
Data stored in
Frankfurt, Germany (European Union)

01Our approach

Security at Lensym starts with a simple principle: we only claim what we actually do. This page describes the concrete technical and organizational measures that protect your data today — no aspirational certifications, no marketing language.

In short

  • All data is encrypted in transit and at rest
  • Personal data is stored in the EU (Frankfurt, Germany)
  • Two-factor authentication is available on every account
  • We collect only the data the Service needs to function

02Encryption

In transitTLS 1.2+ on every connection
At restAES-256 (managed by our database provider)
PasswordsNever stored in plain text — salted and hashed
Payment detailsTokenized by Stripe; card numbers never touch our servers

03Infrastructure

Lensym runs on established, security-audited cloud providers rather than self-managed servers:

Application — Cloudflare

  • Serverless hosting on Cloudflare’s global network
  • DDoS protection and web application firewall
  • Bot protection on public survey endpoints

Database — Neon (PostgreSQL)

  • Hosted in Frankfurt, Germany (EU)
  • Encryption at rest, TLS-only connections
  • Automated backups with point-in-time recovery

The full list of infrastructure providers, including what each one processes, is in our Sub-Processor Register.

04Application security

Account protection

  • Two-factor authentication (TOTP)
  • Email verification on signup and email changes
  • Session expiry after 7 days, refreshed daily
  • Active-session overview with remote sign-out

Platform safeguards

  • HTTP-only, secure session cookies with CSRF protection
  • Strict access controls: your surveys and responses are only accessible to your account
  • Respondents answer without accounts; response links are scoped to a single response

05Data minimisation

The best protection for data is not collecting it in the first place:

  • Survey respondents do not need accounts, so we hold no respondent profiles
  • Sentiment and text analysis run on our own infrastructure — response data is never sent to third-party AI services
  • No advertising or tracking scripts anywhere on the platform
  • Technical logs are kept for at most 90 days

06Incident response

If a security incident affects personal data, we follow the GDPR breach notification requirements:

  • We assess and contain the incident as soon as it is discovered
  • Where required, we notify the Dutch Data Protection Authority within 72 hours
  • Affected customers are informed without undue delay, with clear information about what happened and what we are doing
  • We document every incident and the measures taken

07Responsible disclosure

Found a vulnerability? We genuinely want to know. Report it to privacy@lensym.com with enough detail to reproduce the issue.

  • We confirm receipt and keep you informed while we investigate
  • We won’t take legal action against good-faith research
  • Please give us reasonable time to fix the issue before public disclosure