Security Practices
The concrete technical and organizational measures protecting your data on Lensym — what we encrypt, where data lives, and how we respond when something goes wrong.
- Operated by
- Aletso VOF
- Governing law
- The Netherlands
- Data stored in
- Frankfurt, Germany (European Union)
- Contact
- privacy@lensym.com
01Our approach
Security at Lensym starts with a simple principle: we only claim what we actually do. This page describes the concrete technical and organizational measures that protect your data today — no aspirational certifications, no marketing language.
In short
- All data is encrypted in transit and at rest
- Personal data is stored in the EU (Frankfurt, Germany)
- Two-factor authentication is available on every account
- We collect only the data the Service needs to function
02Encryption
03Infrastructure
Lensym runs on established, security-audited cloud providers rather than self-managed servers:
Application — Cloudflare
- Serverless hosting on Cloudflare’s global network
- DDoS protection and web application firewall
- Bot protection on public survey endpoints
Database — Neon (PostgreSQL)
- Hosted in Frankfurt, Germany (EU)
- Encryption at rest, TLS-only connections
- Automated backups with point-in-time recovery
The full list of infrastructure providers, including what each one processes, is in our Sub-Processor Register.
04Application security
Account protection
- Two-factor authentication (TOTP)
- Email verification on signup and email changes
- Session expiry after 7 days, refreshed daily
- Active-session overview with remote sign-out
Platform safeguards
- HTTP-only, secure session cookies with CSRF protection
- Strict access controls: your surveys and responses are only accessible to your account
- Respondents answer without accounts; response links are scoped to a single response
05Data minimisation
The best protection for data is not collecting it in the first place:
- Survey respondents do not need accounts, so we hold no respondent profiles
- Sentiment and text analysis run on our own infrastructure — response data is never sent to third-party AI services
- No advertising or tracking scripts anywhere on the platform
- Technical logs are kept for at most 90 days
06Incident response
If a security incident affects personal data, we follow the GDPR breach notification requirements:
- We assess and contain the incident as soon as it is discovered
- Where required, we notify the Dutch Data Protection Authority within 72 hours
- Affected customers are informed without undue delay, with clear information about what happened and what we are doing
- We document every incident and the measures taken
07Responsible disclosure
Found a vulnerability? We genuinely want to know. Report it to privacy@lensym.com with enough detail to reproduce the issue.
- We confirm receipt and keep you informed while we investigate
- We won’t take legal action against good-faith research
- Please give us reasonable time to fix the issue before public disclosure