Your data, handled carefully.
Who we are
DataImpel builds a survey analysis and reporting platform for market research agencies and in-house insights teams. This policy covers our marketing website and the DataImpel platform.
For any question about this policy, or to exercise any of the rights described below, write to privacy@dataimpel.ai.
Which data we are responsible for
DataImpel acts in two different roles, and it matters which one applies to you.
For this website and any enquiry you send us, we are the data controller, so we decide what is collected and why.
For the survey data your team loads into the platform, you remain the controller and DataImpel acts as your processor. We handle it on your documented instructions, under a data processing agreement, and for no other purpose.
What we collect
From the website, when you choose to give it to us:
- Demo enquiries: name, work email, company, role, typical project size, and anything you write in the message field
- Server logs: IP address, browser type and pages requested, kept briefly for security and troubleshooting
What the platform holds
If your organisation is a DataImpel customer, the platform also holds:
- Account details needed to sign you in and scope your access
- The survey data your team uploads, which may contain respondent personal data, depending on what you collected
- The analyses, reports, portals and exports produced from that data
Why we use it, and on what legal basis
- To answer your enquiry and tell you about DataImpel: our legitimate interest in responding to a business approach you initiated
- To provide the platform to your organisation: performance of our contract with your organisation
- To process survey data into analyses and reports: on your instructions as our customer, under Article 28 of the GDPR as your processor
- To keep the service secure and prevent abuse: our legitimate interest in protecting the platform and its users
- To meet accounting, tax and other legal duties: compliance with a legal obligation
What we never do with it
We do not sell personal data, and we do not share it for advertising.
Your data is never used to train or fine-tune a model, ours or anyone else's. Training opt-out is set by contract with every AI service involved in processing.
Who else processes it
We use a small number of subprocessors, each bound by a written contract that limits them to our instructions and excludes any use of your data for training:
- Infrastructure and database hosting
- The AI services behind analysis and narrative drafting
- Email delivery for transactional messages
- Plausible Analytics, for website measurement: EU-hosted, sets no cookies and stores no personal data
Where it is stored
EU (Frankfurt) or North America (US or Canada), chosen per workspace. If you choose EU hosting, your platform data is stored in the EU.
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with tenant isolation enforced at the database level.
Our team works from the Netherlands. Some of our subprocessors are established outside the EEA; where providing the service involves transferring personal data to them, that transfer is covered by the European Commission's Standard Contractual Clauses.
How long we keep it
- Survey data, analyses and reports: held in your workspace until you delete them or ask us to
- Account details: for as long as your organisation uses DataImpel, then deleted on request
- Demo enquiries: while we are in contact, and for a reasonable period afterwards
- Server logs: a short rolling window for security and troubleshooting
Cookies and similar technologies
The site sets no analytics, advertising or tracking cookies, and no third party sets cookies through it. There is nothing to consent to and no banner to dismiss.
We measure website traffic with Plausible Analytics, an EU-hosted service that sets no cookies, assigns no identifier and does not follow you across sites. It collects no personal data. We see aggregate counts only: pages viewed, referring site, country, and broad device and browser type.
One strictly necessary cookie is set so the site works: the brochure sets a single cookie so you need not re-enter the password on each visit, which expires after seven days.
If we ever need a cookie that is not strictly necessary, we will ask for your consent before setting it and update this policy first.
You can clear or block cookies in your browser settings at any time. Blocking the brochure cookie means re-entering the password on each visit; nothing else on the site depends on one.
Your rights
Where we are the controller, you can ask us to do any of the following, free of charge:
- Give you a copy of the personal data we hold about you
- Correct it if it is wrong, or complete it if it is partial
- Delete it, where we have no overriding reason to keep it
- Restrict or object to how we use it, including any direct marketing
- Send it to you, or to someone else, in a portable format
If your data reached us inside a customer's dataset
If you took part in a survey and your details reached us that way, the organisation that ran the survey is the controller, not DataImpel. Contact them first. If you contact us instead, we will pass your request to them promptly and support them in answering it.
How to complain
Write to privacy@dataimpel.ai and we will respond within one month, as GDPR requires. If you are not satisfied with our answer, you have the right to complain to your local data protection supervisory authority. In the Netherlands, that is the Autoriteit Persoonsgegevens.
Changes to this policy
We update this policy when our practices change. The date it was last revised is shown at the foot of this page, and material changes will be flagged to customers directly rather than only posted here.
Contact
Privacy questions, data subject requests and DPA enquiries: privacy@dataimpel.ai
Security and vulnerability reports: security@dataimpel.ai
Last updated 25 August 2026
For platform controls, hosting, auditability and compliance posture, see the security page. Security & governance
