Last updated: 20 July 2026
Courtesy translation. In case of any discrepancy, the Spanish version at `/legal` prevails.
This page explains how Camaleonic Survey governs artificial intelligence
in its service: under what principles, what controls the client has, and
what privacy guarantees apply. The AI layer is **optional and can be
disabled per organization** and is subject to the commitments detailed
below.
In brief (the essentials in 30 seconds)
- Control rests with the client. AI is optional and can be disabled per organization (a shutdown switch, or kill-switch): it comes enabled by default and each organization can disable it at any time from its settings. If disabled, the account works exactly as it would without it.
- No models are trained on client data. Neither on respondents' answers, nor on client content.
- We pseudonymize before sending. Data that needs to pass through a model is prepared beforehand to minimize what is identifiable.
- We label AI-generated content. When text, a segmentation, or a report is produced by a model, we mark it as "generated with AI."
- Inference providers. Inference is performed by Groq (USA) for most AI features and by Anthropic (USA) for multi-survey analysis and design palette extraction, both acting as data sub-processors covered by the EU's Standard Contractual Clauses.
- A serious framework. We are guided by the NIST AI Risk Management Framework (AI RMF 1.0) and by Regulation (EU) 2024/1689 (the "AI Act").
In summary: _it is optional and can be disabled per organization; no models
are trained on client data; users are notified of what the AI generates; and
inference is performed by providers established in the USA (Groq and
Anthropic) under Standard Contractual Clauses._
1. Activation and control of AI
Camaleonic Survey's AI layer is optional and can be disabled per organization (see §6): it comes enabled by default and the client can disable it at any time. Camaleonic Survey only runs AI inference on respondents' answers or on an account's data if the organization that owns them has not disabled the corresponding feature.
The features described below (survey generation, insights and segmentation, reports) are rolled out gradually and transparently: those not yet rolled out will be offered when they become available, and this document should not be read as a statement that all of them are already live on every account. Each one is activated separately and is subject to the rules in this document.
Regardless of AI, our security and privacy baseline remains in force: encryption in transit (TLS) and at rest, per-organization isolation, and pseudonymization of technical signals (IP, user-agent, device-id) via hashing, with logical deletion of responses and automatic purging after 30 days.
2. Responsibility model (who is responsible for what)
Camaleonic Survey is a survey SaaS for any type of organization (companies, consultancies, hotels, universities, brands, public administrations, SMEs…): the client registers, subscribes, and creates their own surveys. The allocation of roles does not change with AI, but it is worth restating because it determines who owns each decision:
- Respondents' answers: the client who creates the survey is the data controller. Camaleonic Survey acts as data processor: it processes that data on behalf of the client and following its instructions, for the purposes that the client (as controller) determines.
- Client account data (registration, billing) and the aggregated and anonymized / benchmark analytics that we commercialize: Camaleonic Survey is the data controller.
Consequence for AI: any AI feature that touches respondents' answers does so as a processor, within the client's instructions, and is activatable/deactivatable by the client (see §6).
Contractual documentation. The incorporation of AI features is documented as a sub-processing activity within the applicable Data Processing Terms, by means of a features and sub-processors annex. Its activation is communicated to the client with 30 calendar days' notice, during which the client, in its capacity as controller, may object to the incorporation of the new sub-processor; processing is always carried out in accordance with the controller's documented instructions.
Aggregated / benchmark analytics. The analytics that Camaleonic Survey commercializes as controller are built exclusively on aggregated and anonymized data that do not allow the identification or re-identification of natural persons; individual responses or identifiable data are never commercialized. Where pseudonymized data is processed for that purpose, the legal basis is Camaleonic Survey's legitimate interest (art. 6.1.f GDPR), duly weighed through the corresponding balancing test, as reflected in the privacy notice and in the contract with the client.
3. Reference framework
We govern the AI layer by combining two recognized references:
3.1. NIST AI Risk Management Framework (AI RMF 1.0)
A voluntary NIST framework (published in January 2023) for managing risk throughout the AI lifecycle. We adopt its four core functions:
- Govern: policies, responsibilities, and a risk-management culture for AI; who approves activating each feature and under what conditions.
- Map: identifying the context, the actors affected (clients and respondents), the boundaries of the system, and the possible harms.
- Measure: evaluating and monitoring the behavior of each feature (quality, bias, data leakage) before and during its use.
- Manage: prioritizing and treating risks, documenting residual risk, and responding to incidents.
3.2. Regulation (EU) 2024/1689 (the "AI Act")
As a company headquartered in the EU, we frame the design of the AI layer within Regulation (EU) 2024/1689. In particular, we assume the transparency obligations of Article 50 (see §4), applicable from 2 August 2026 under the Regulation's own timetable.
Classification. The AI features described are classified as limited or minimal risk systems under the AI Act, subject where applicable to the transparency obligations of art. 50. Camaleonic Survey acts as deployer of integrated AI systems from an external provider, without developing or placing on the market its own general-purpose models; accordingly, it does not assume the specific obligations of a general-purpose AI model provider.
4. Transparency (Article 50 of the AI Act)
Core commitment: we will never present what a machine has done as if it were human.
- Labeling of AI-generated content. Any text, segmentation, or report produced or assisted by a model is clearly and visibly marked as "generated with AI" (or "AI-assisted" where applicable) across the Service's surfaces, a criterion applied progressively to all AI features as they are rolled out.
- Notice of interaction with AI. If any feature comes to involve direct conversational interaction (e.g., an assistant that converses with a user), the user is informed that they are interacting with an AI system.
- Traceability. We record which feature generated each artifact, so that it can be explained and, if the client requests it, reverted or regenerated without AI.
- Machine-readable marking. AI-generated text content is marked visibly for the user and, where technically appropriate, in machine-readable format, in accordance with art. 50.2 of the AI Act and the applicable code of practice. We do not generally invoke the exceptions under art. 50; when content has been reviewed and editorially adopted by the client, that human review is recorded.
5. Data principles for AI
5.1. No models are trained on Client data
- We do not use respondents' answers to train, retrain, or fine-tune any model.
- We do not use client content (questions, configurations, results) to train models.
- With the external inference providers we rely on contractual terms that exclude training on our data and on our clients' data, and that limit their retention to what is strictly necessary to return the response.
5.2. Pseudonymization before sending to the model
Before any data passes through a model, we pseudonymize it: minimizing and separating what could identify a person from the content the model needs to do its job.
Honest note on terminology: we speak of pseudonymization, not
anonymization. Pseudonymization reduces risk, but does not turn the
data into anonymous or irreversible data; it remains personal data and
remains protected.
As a minimum standard, before data is sent to an external model, direct identifiers are removed or tokenized (first name, surname, email, phone number, device identifiers, and IP address) and geolocation is generalized below the level that would allow re-identification; only the substantive content necessary for the feature travels onward. The inference providers are added as sub-processors in the record of processing activities and in the client's Data Processing Terms.
5.3. Minimization per feature
Each feature receives only the data it needs to produce its result, and nothing more. See the per-feature privacy notes in §7.
5.4. Ownership of results and guarantees
- Ownership. The results generated by AI from the client's content and answers (texts, segmentations, reports), as well as the client's own content, belong to the client. Camaleonic Survey does not claim intellectual property rights over such results, without prejudice to third-party rights and to the provisions of Real Decreto Legislativo 1/1996 (Ley de Propiedad Intelectual, Spain's consolidated text of the Intellectual Property Law).
- Assistive nature and guarantees. AI results are assistive in nature: they may contain errors or inaccuracies and do not constitute professional advice (legal, financial, medical, or of any other kind). The client is responsible for maintaining effective human oversight over them and for reviewing them before disseminating them or making decisions that produce effects on individuals. The service is provided without any guarantee of uninterrupted availability or of the accuracy of results. Camaleonic's liability is limited to the extent valid under Spanish law, without excluding any liability that cannot legally be limited.
6. Client control: kill-switch and opt-in
- The AI layer is optional per organization. Each client can activate or deactivate it from their account settings.
- AI comes enabled by default and can be disabled per organization at any time. Deactivation takes immediate effect and requires no justification; no AI feature is necessary for the use of the Service.
- Off means off. If an organization deactivates AI, its data is not sent to any inference provider for those features, and the account continues operating normally without them.
- Camaleonic Survey retains each organization's current AI configuration and is working to log the status changes (on/off) of each feature in an auditable manner.
- In addition to the switch, the platform applies a cost and consumption guardrail that automatically interrupts the execution of AI features when the plan's credit thresholds are reached, preventing runaway consumption.
7. The service's AI features (with their privacy note)
Below is what each feature does and what data it touches. All of them share the rules in §4, §5, and §6. Some features may be rolled out gradually by plan or organization; those not yet active on an account will be added when they become available, with these same guarantees.
7.1. Survey generation
- What it does: helps the client draft questions and structure the survey based on their input.
- Privacy note: it works on the content the client writes (the survey's objective, question drafts). Under normal conditions it does not process respondents' answers (at the time of generating the survey, no answers yet exist). The result is labeled as "generated with AI" and the client can edit or discard it freely.
7.2. Insights and segmentation
- What it does: detects patterns and proposes segments based on the answers collected.
- Privacy note: this is the most sensitive feature, because it processes respondents' answers. Here Camaleonic Survey acts as the client's processor. Data is pseudonymized before being sent to the model (§5.2): the analysis works on patterns, not on identities. Email addresses or other contact data, where they exist (e.g., if the client collects them for an optional purpose that the client determines, such as a giveaway, a marketing send, or a later follow-up), and direct demographic data are handled with special caution.
- Special categories (art. 9 GDPR). Where a segmentation could infer special categories under art. 9 GDPR from the cross-referencing of demographic data (age, gender, city, or others), such inferences are excluded by default: the feature does not generate or store such categories without a documented instruction and a valid legal basis from the client as controller.
- Sensitive contexts. In particularly sensitive contexts (health data, minors in educational or university settings, employment data), the AI feature must be kept disabled by the client unless the client, as controller, enables it with specific instructions, reinforced safeguards, and, where applicable, a prior assessment.
7.3. Reports
- What it does: drafts readable reports and summaries based on aggregated results.
- Privacy note: it works preferentially on aggregated data and already-calculated results, not on individual records. Every AI-generated report is marked as "generated with AI." The client is responsible for reviewing the report before disseminating it.
8. Inference providers (international transfers)
Part of the AI processing is carried out through external inference providers located outside the EU, which entails an international data transfer duly safeguarded.
Providers. The inference providers are:
- Groq, Inc. (USA): inference for the credit-consuming AI features (survey generation, insights, quality and sentiment analysis, reports, and assisted translation).
- Anthropic, PBC (USA): multi-survey analysis and design palette extraction.
- Machine translation engines (MyMemory or LibreTranslate), only when the client uses the translation feature and solely to return the requested translation.
All of them act as data sub-processors. Processing in the USA is safeguarded under the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), together with any supplementary measures as applicable. The AI model providers process data solely to return the requested response, under contractual terms that exclude training on that data and limit its retention to what is strictly necessary.
To be transparent about where the data is located: the database is hosted in the EU (a managed Supabase database) and the application runs on AWS infrastructure, but not all sub-processors are in the EU: client account payments (Stripe) operate from the USA and anti-bot protection (Cloudflare Turnstile) is global. The AI layer adds the inference sub-processors listed above, also outside the EU.
Onboarding of sub-processors. The onboarding of an AI provider as a sub-processor is notified to clients with 30 calendar days' notice, during which the client may object in accordance with the sub-processing clauses of the applicable Data Processing Terms.
9. Internal governance and responsibilities
- Per-feature approval: no AI feature is activated in production without passing through the Govern–Map–Measure–Manage cycle (§3.1) and without a documented decision on who approves it.
- Impact assessment (DPIA): the insights and segmentation feature, because it involves profiling and large-scale processing of respondents' answers, undergoes a Data Protection Impact Assessment (DPIA) under art. 35 GDPR before activation. Camaleonic Survey, as processor, provides the client-controller with reasonable assistance in carrying it out, with approval remaining the controller's responsibility.
- Incidents and breaches: in the event of a personal data security breach affecting AI processing, Camaleonic Survey notifies the client-controller without undue delay and, at the latest, within 48 hours of becoming aware of it. The statutory 72-hour deadline before the supervisory authority (the AEPD), provided for in art. 33 GDPR, rests with the client in its capacity as controller; the purpose of this early notification is to enable the client to comply with its obligations under arts. 33 and 34 GDPR.
- Logging and audit: we keep records of which feature generated each artifact and of the on/off status per organization, so that we can be held accountable.
- Review: this page is reviewed and updated before each new AI feature is activated.
10. What we will NOT do
To put it in writing so we can be held to it:
- We will not train models on respondents' answers or on client content.
- We will not activate AI on the data of an organization that has it disabled.
- We will not present AI-generated content as if it were human.
- We will not claim that data is "anonymous" or that a hash is "irreversible": we speak of pseudonymization, which reduces risk but does not remove the personal nature of the data.
- We will not activate a new AI feature without completing the governance cycle and, where applicable, its DPIA.
Identification and contact
- Service provider: Camaleonic ads 2020 S.L., a Spanish company (trading name: Camaleonic Survey). Depending on the feature concerned, it acts as data processor on behalf of its clients or as data controller with respect to account data, billing, and aggregated and anonymized analytics.
- Contact for privacy and Responsible AI matters: [email protected].
Governing law and jurisdiction. This page and the AI governance it describes are governed by Spanish law. For any dispute, the courts of the registered office of Camaleonic ads 2020 S.L. shall have jurisdiction, except where mandatory consumer-protection rules provide otherwise.
This page describes Camaleonic Survey's AI governance and is kept updated
with each new feature. It forms part of our privacy documentation and is
complemented by the applicable privacy notice and Data Processing Terms.