Privacy Policy for formr Maynooth University instance
Last Updated: June 13th, 2025
This Privacy Policy describes how the formr Maynooth University instance ("formr," "we," "us," or "our") collects, uses, and protects your personal information when you use our survey platform and services (the "Service"). Your privacy is of utmost importance to us.
This policy distinguishes between the data of "Creators" (users who build surveys) and "Respondents" (users who take surveys).
1. The Roles: Data Controller vs. Data Processor
It is important to understand the roles under data protection law (like the GDPR):
- When you create an account with formr: For your account information (like your email address), we are the "Data Controller."
- When you create a survey and collect responses: For the data you collect from Respondents ("Response Data"), you, the Creator, are the "Data Controller." In this relationship, formr acts as the "Data Processor" on your behalf, processing the data according to your instructions.
This means Creators are responsible for the legal and ethical handling of the Response Data they collect.
2. Information We Collect
A. Information We Collect from Survey Creators
- Account Information: When you register for a formr account, we require your email address. We also securely store your password in a hashed format. You may voluntarily provide other information, such as your name or institutional affiliation. We use this information to create and manage your account, provide customer support, and communicate important service updates.
- Survey Content: We store the surveys you create, including questions, logic, and design elements ("User Content"). We process this content to provide the Service to you.
B. Information We Process on Behalf of Creators (from Respondents)
- Response Data: When a Respondent takes a survey, we collect and store their answers on behalf of the Creator. The Creator determines what data is collected. This may include opinions, demographic information, and potentially personally identifiable information (PII). formr does not use this Response Data for its own purposes.
- IP Addresses: By default, we may log the IP addresses of Respondents for security and abuse prevention purposes. The Creator may have the option to enable or disable this collection for their surveys.
C. Information We Collect Automatically
- Log Data: Like most websites, our servers automatically record information when you access our Service, including your IP address, browser type, operating system, referring web page, pages visited, and timestamps. We use this data to monitor, secure, and improve our Service.
3. Use of Cookies
A cookie is a small text file stored on your device. We believe in transparent and minimal use of cookies.
- Essential Session Cookies: We use session cookies that are strictly necessary for the Service to function. For example, they keep you logged in as you navigate the platform. These cookies are temporary and are automatically deleted from your device when you close your browser session.
- Persistent Cookies (with Consent): We may offer features that require a persistent cookie (one that remains on your device for a longer period), such as a "Remember Me" option for logging in. We will only place these cookies on your device after you have given us your explicit consent to do so. You can withdraw this consent at any time through your browser or account settings.
- No Third-Party Cookies: We are committed to your privacy. formr does not use any third-party cookies for tracking, advertising, or analytics. All cookies used are first-party cookies, essential for providing the Service.
4. How We Use Your Information
We use the information we collect (primarily Creator data) for the following purposes:
- To provide, operate, and maintain our Service.
- To manage your account, including processing payments and providing customer support.
- To send you important technical notices, updates, security alerts, and administrative messages.
- To monitor for and prevent fraudulent, unauthorized, or illegal activity.
- To improve the Service and develop new features, based on aggregated and anonymized usage data.
We will never sell your personal information to third parties.
5. How We Share Information
We only share information under the following limited circumstances:
- With Service Providers: We may use third-party companies for technical infrastructure, such as hosting servers (e.g., cloud providers) or email delivery services. These providers are carefully vetted and have access to information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
- For Legal Reasons: We may disclose your information if we believe it is reasonably necessary to comply with a law, regulation, legal process, or governmental request.
6. Data Security
We implement robust technical and organizational measures to protect the information we store. This includes using encryption for data in transit (SSL/TLS), hashing passwords, and restricting access to personal data to authorized personnel. However, no electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Data Retention
- Creator Account Data: We retain your account information for as long as your account is active and for a reasonable period thereafter in case you decide to re-activate the Service.
- Response Data: We retain Response Data on behalf of the Creator as long as their account is active. The Creator can delete Response Data at any time. When a Creator's account is terminated, we will delete associated Response Data in accordance with our data deletion schedules.
8. Your Data Protection Rights
Depending on your location, you may have the following rights regarding your personal information:
- The right to access, update, or delete the information we have on you (you can do most of this via your account settings).
- The right of rectification if that information is inaccurate or incomplete.
- The right to object to our processing of your personal data.
- The right to data portability for the information you provide to us.
- The right to withdraw consent at any time where we relied on your consent to process your information.
To exercise these rights, please contact us. If you are a Respondent, you should direct your requests to the Survey Creator (the Data Controller).
9. Children's Privacy
Our Service is not directed to individuals under the age of 16 (or the relevant age in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have, we will take steps to delete such information.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically for any changes.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at: jason@linloss.ie.