Courtesy translation. In case of any discrepancy, the Spanish version at `/legal` prevails.
Last updated: 20 July 2026
At Camaleonic Survey, data security is a design requirement, not an add-on. Below are the technical and organizational measures applied to protect the information of clients and of the individuals who respond to their surveys, in compliance with Article 32 of Regulation (EU) 2016/679 (GDPR).
An honest warning before going into detail: despite all efforts, no method of transmission over the Internet or of electronic storage is completely secure, and we therefore cannot guarantee absolute security. What we do commit to is applying, reviewing and continuously improving the measures described on this page.
1. Encryption
- In transit: all communication with the platform takes place over TLS (HTTPS). Unencrypted connections are not permitted.
- At rest: the database and file storage are kept encrypted at rest by the underlying infrastructure.
2. Isolation between organizations
Each client (organization) operates in a logically isolated space. Access to data is restricted at the database level through row-level security policies (Row-Level Security), such that one organization cannot, by design, access another organization's data.
3. Minimization and pseudonymization
- Participants' technical identifiers (IP address, browser, and device identifier) are stored pseudonymized using a hash function with a server-side secret, not in plain text.
- Surveys can be configured in anonymous mode, in which case no direct identifiers of participants are collected, although pseudonymized technical identifiers (hashed IP, browser and device) may be processed for security and anti-abuse purposes.
- Response retention is configurable per survey, with automatic deletion of responses once the configured period expires. Responses deleted by the client are permanently purged after a 30-day trash period.
4. Access control
- Authentication of each organization's users with passwords subject to strength policies.
- Least-privilege role model: administrator, member (with editing permissions), and reader.
- Access by Camaleonic Survey's internal staff to client data is restricted: it is limited to what is strictly necessary to provide and support the service and takes place under strict controls.
5. Application protection
- Strict security headers: Content Security Policy (CSP) with a per-request nonce, HSTS, a restrictive referrer policy, and browser permissions control.
- Anti-abuse protection: anti-bot verification (Cloudflare Turnstile) and persistent rate limits on public-facing surfaces.
- Server-side validation: all inputs are validated on the server using strict schemas, and HTML content is sanitized to prevent injection attacks.
6. Continuity and recovery
The database is provided as a managed service: the infrastructure provider operates periodic backups in accordance with its own timeframes and procedures, and incident recovery relies on those backups.
7. Incident and breach management
Camaleonic Survey maintains an internal incident response procedure, with a designated lead and an incident log. In the event of a breach of security affecting personal data processed on behalf of a client, the client will be notified without undue delay and, at the latest, within 48 hours of becoming aware of it. The statutory 72-hour deadline for notifying the supervisory authority (AEPD), provided for in Article 33 of the GDPR, falls on the client in its capacity as controller; the very purpose of this early notification is to enable the client to fulfill its own notification obligations (Articles 33 and 34 of the GDPR).
8. Data residency and infrastructure
The application runs on AWS infrastructure and the database is a managed service hosted in the European Union, where survey responses are stored. Ancillary services and their locations are detailed in the list of subprocessors; transfers outside the European Economic Area are safeguarded by Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).
9. Subprocessors
The providers involved in delivering the service are published, together with their purpose and location, in the list of subprocessors, which is kept up to date.
10. Certifications and continuous improvement
Camaleonic Survey does not currently hold SOC 2 or ISO/IEC 27001 certifications. Our approach is to apply and document the practices described on this page and to review them periodically. Obtaining recognized industry certifications is part of our roadmap; until a certification has been obtained and expressly announced, nothing on this page should be read as a certification currently in force.
11. Security contact
To report a security incident or ask a question, please write to [email protected].