Courtesy translation. In case of any discrepancy, the Spanish version at `/legal` prevails.
Last updated: 29 July 2026
How to read this policy (summary first, detail after)
This policy is written in layers. Layer 1 is a brief summary in table form so the essentials can be understood in one minute. Layer 2 develops each point in detail (sections 1 to 13), as required by Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD) (Spain's Organic Law on the Protection of Personal Data and the Guarantee of Digital Rights).
An important nuance explained in section 2: Camaleonic Survey plays two distinct roles depending on the data at issue. Sometimes we are the controller of the processing (we decide the "why" and the "how") and sometimes we are the processor (we process data on behalf of a client and following its instructions). This policy mainly describes what we do as controller; when we act as processor, the policy that applies is that of the client who created the survey.
LAYER 1. Basic data protection information
| Controller | Camaleonic ads 2020 S.L., a Spanish company (trading brand: Camaleonic Survey). General contact and contact for data protection matters: [email protected]. |
| Dual role | We are processors of survey responses (the client that creates the survey is the controller). We are controllers of the client's account and billing data, technical data needed to operate and protect the platform and, after consent, usage data processed through Google Analytics 4. We also produce genuinely aggregated, anonymized analytics that cannot identify a person or reconstruct an individual response. |
| Purposes | Providing and maintaining the survey service; managing the client's account, subscription and billing; sending transactional emails and invitations; protecting the platform against abuse/bots; measuring website use with consent; and producing aggregated, anonymized analytics. |
| Legal basis | Performance of a contract (service, account), legitimate interest (security, technical logs and service improvement), prior consent (Google Analytics 4, non-essential cookies and optional data the client decides to request in its survey) and legal obligation (billing/accounting). |
| Recipients | Providers acting as processors/sub-processors (database, computing infrastructure, payments, anti-bot, web analytics, AI inference, machine translation). See the list of sub-processors and section 5. We do not sell personal data. |
| International transfers | The primary storage of surveys and responses takes place in the European Union. When AI or machine translation features are used, the necessary content may be processed occasionally outside the EEA. Google Analytics 4 may involve a transfer of usage data to Google LLC in the US; Stripe operates from the US and Cloudflare has a global footprint. The safeguards in sections 5, 6 and 11 apply. |
| Retention | Survey responses are retained according to the controlling client's configuration: each survey may have its own retention period, with an automatic daily purge once it expires; after the logical deletion of a response, a final purge is applied after 30 days. Other data, per section 7. |
| Rights | Access, rectification, erasure, objection, restriction and portability. Data subjects may exercise them by writing to [email protected] (see section 8). |
| Complaint | Data subjects have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es (see section 9). |
| Additional information | All detailed information is set out in Layer 2 (sections 1 to 13). |
LAYER 2. Detailed information
1. Controller and how to contact us
The controller is Camaleonic ads 2020 S.L., a Spanish company that operates the service under the trading brand Camaleonic Survey.
- General contact: [email protected]
- Contact for data protection matters: [email protected]
Data Protection Officer (DPO). Camaleonic ads 2020 S.L. has assessed whether it is appropriate to appoint a Data Protection Officer under art. 37 GDPR and art. 34 LOPDGDD, and has concluded that its processing does not meet the conditions that make such an appointment mandatory: it is not a public authority or body, its core activities do not consist of the regular and systematic monitoring of data subjects on a large scale, and they do not involve large-scale processing of special categories of data (art. 9 GDPR) or of data relating to criminal convictions and offences (art. 10 GDPR). Accordingly, no Data Protection Officer has been appointed. Instead, there is a designated privacy contact that handles all data protection requests: [email protected]. This assessment is reviewed periodically and, if the circumstances of the processing change, a DPO will be appointed and this policy will be updated.
For any question about this policy or about the processing of your data, including exercising your rights (section 8), you can write to us at [email protected].
2. Our dual role: when we are "processor" and when "controller"
GDPR distinguishes between the controller (who decides the purpose and the means) and the processor (who processes data on behalf of the controller, following its instructions). Both roles coexist within Camaleonic Survey, and who decides about your data depends on which role applies:
a) When we are PROCESSOR: survey responses. When a client (any organization that contracts Camaleonic Survey: a company, a hotel, a university, a brand, a government body, an SME…) creates a survey and distributes it, that client is the controller of the processing of the responses collected from respondents. We merely process those responses on behalf of the client and following its instructions (we host them, protect them, and display them to the client). In that scenario:
- The client decides what is asked, for what purpose, and for how long the responses are retained.
- The information that you, as a respondent, must receive (art. 13 GDPR), and to whom you address your rights, is, in the first instance, that of the controlling client. We will help redirect your request to that controller if you write to us.
- The terms of this processing are governed by Data Processing Terms (art. 28 GDPR) entered into between the client and Camaleonic Survey, which set out the subject matter, duration, nature and purpose of the processing, the categories of data subjects and data, and the obligations and rights of the controller.
b) When we are CONTROLLER. We decide the "why" and the "how" ourselves in the following cases:
- Client account and billing data: registration, account administration, the subscription and the billing of whoever contracts Camaleonic Survey.
- Technical data and consented website use: the logs needed to operate and protect the service and, only after prior consent, usage data processed through Google Analytics 4 to measure and improve the website.
- Aggregated, anonymized analytics: statistical results produced in such a way that they never allow a natural person to be identified or an individual response to be revealed. Respondents' personal data is never sold or commercialized under any circumstances.
The full chain, from start to finish. The respondent (data subject) provides their answers to the client that created the survey (the controller of the processing); that client relies on Camaleonic Survey (the processor); and Camaleonic Survey relies, in turn, on a small number of infrastructure and artificial intelligence sub-processors (database, computing, AI inference, machine translation). Each link in the chain is contractually bound to the previous one with equivalent data protection guarantees.
The rest of this policy (sections 3 to 13) mainly describes the processing activities in which we are controller. For processing activities in which we are processor, the privacy policy of the client that created the survey prevails.
3. What data we process, by category
3.1. Data of the people who respond to surveys (respondents). Depending on how the client configures the survey, we may process (as processor, on behalf of the client):
- Responses to the survey questions.
- Response metadata: language, duration and timestamps.
- Respondent's email, only if the survey requests it (for example, to enter a prize draw or to receive a follow-up communication determined by the client).
- Demographic data, only if the survey requests it: age, gender and/or city.
- Pseudonymized technical data for security and duplicate/abuse control: IP address, user-agent and a device identifier (device-id), processed through hash-based pseudonymization (see section 10 on security). Important: pseudonymization reduces the risk but is not the same as anonymization: we treat these values as personal data.
- Anonymous surveys: when the client configures a survey as anonymous, no direct identifiers of the respondent are collected, although pseudonymized technical identifiers may be processed (hashes of IP, browser and device) for security and anti-abuse purposes. Those hashes are pseudonymized personal data and we process and protect them as such.
3.2. Client account data (we are controller). Identification and contact data necessary to create and administer the account and manage the subscription and billing. As a general rule we collect: first and last name of the contact person, email address, name and identification of the organization, access credentials, and payment data necessary for billing. We do not intentionally collect special categories of data (art. 9 GDPR) through account data.
3.3. Platform usage and technical data (we are controller). Data on the operation and security of the service and the technical logs necessary to operate, maintain and protect the platform. When measurement is enabled under the controls in this policy, we use Google Analytics 4 (provider: Google Ireland Limited, with a possible transfer to Google LLC in the USA covered by the Standard Contractual Clauses and the EU-US Data Privacy Framework) to produce aggregate web analytics (page views, traffic source, device type) that help us improve the site. Google Analytics 4 uses cookies (for example `_ga`) and device identifiers. In accordance with art. 22.2 of the LSSI-CE and the ePrivacy Directive (2002/58/EC), analytics tags do not load until you give your prior consent in the banner. Survey response, kiosk, public-result and excluded internal surfaces do not use this analytics. When measurement is enabled, you can withdraw or grant consent again using the controls at the end of this policy; withdrawal stops subsequent collection and removes Google Analytics cookies that the site can access. While measurement is disabled, those controls are not shown and Google Analytics does not load.
3.4. Invitation data. When invitations or transactional emails are sent, we process the recipients' email addresses. Part of this data may not be obtained directly from the data subject but supplied by the client; in those cases, art. 14 GDPR applies (information to be provided where personal data has not been obtained from the data subject).
We do not intentionally process special categories of data (art. 9 GDPR) or data relating to criminal convictions and offences.
4. Purposes and legal basis for each processing activity
We process your data for the following purposes, each with its legal basis under art. 6 GDPR:
| Purpose | Legal basis (art. 6 GDPR) |
|---|---|
| Providing the survey service (hosting and processing responses on behalf of the client) | As processor, in accordance with the Data Processing Terms (art. 28); the legal basis vis-à-vis the respondent is determined by the controlling client. |
| Creating and administering the client's account | Performance of a contract (art. 6.1.b). |
| Managing the subscription, billing and accounting/tax compliance | Legal obligation (art. 6.1.c) and performance of contract for payment collection. |
| Sending transactional emails and invitations | Performance of contract and legitimate interest (art. 6.1.f) for transactional emails and invitations inherent to the service. Sending commercial communications by email requires consent (art. 6.1.a), in accordance with art. 21 of the LSSI-CE. |
| Collecting optional respondent data that the client decides to request (e.g. the respondent's email for a prize draw, for the client's marketing purposes, or another purpose determined by the client) | Consent of the respondent (art. 6.1.a); the specific purpose and its lawfulness are determined by the controlling client in its survey. |
| Collecting demographic data of the respondent (age/gender/city) | Consent of the respondent (art. 6.1.a); determined by the controlling client in its survey. |
| Security and abuse/bot prevention (Turnstile, IP/UA/device-id hashing, isolation) | Legitimate interest (art. 6.1.f): protecting the integrity of the service. |
| Maintenance and improvement of the service | Legitimate interest (art. 6.1.f) for technical logs needed to operate and protect the service. Consent for Google Analytics 4 and any cookie or identifier that is not strictly necessary (art. 22.2 LSSI-CE; ePrivacy Directive 2002/58/EC). |
| AI and machine translation features (when the client uses them) | As processor, in accordance with the Data Processing Terms and the instructions of the controlling client (art. 28 GDPR); the legal basis vis-à-vis the respondent is determined by the client. See section 11. |
| Aggregated, anonymized analytics | Legitimate interest (art. 6.1.f). It is produced exclusively from aggregated, anonymized results that do not allow any person to be identified or any individual response to be revealed; respondents' personal data is never sold or commercialized under any circumstances. The corresponding legitimate interest balancing test is documented. |
Where the basis is consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal. Where the basis is legitimate interest, you have the right to object (section 8) and may request information about the corresponding legitimate interest assessment (LIA) by writing to [email protected].
5. Recipients and sub-processors
We do not sell personal data. To provide the service we rely on technology providers acting as processors or sub-processors, bound by contract (art. 28 GDPR) and subject to confidentiality and security obligations. The verified providers are:
| Provider | Function | Location / operation |
|---|---|---|
| Supabase | Managed database, authentication and storage | European Union |
| Amazon Web Services (AWS) | Computing infrastructure on which the application runs | International |
| Cloudflare Turnstile | Anti-bot protection | Global |
| Google Analytics 4 | Consented web analytics on eligible pages; it does not receive survey responses | EU / possible US |
| Stripe | Payments (client accounts only) | US |
| Groq | AI inference (primary provider of the service's AI features) | US |
| Anthropic | AI inference for specific features: multi-survey analysis and brand palette extraction from an image | US |
| MyMemory / LibreTranslate | Machine translation engines (only when the client uses translation; the survey text is sent to the engine) | International |
The sub-processor Groq is additionally subject to a contractual commitment not to use client data to train models. In the case of the machine translation engines, the survey text is sent to the engine only when the client uses the translation feature.
List of sub-processors. We maintain an up-to-date list of sub-processors, available to controlling clients who request it at [email protected]. Before adding or replacing a sub-processor, we will notify controlling clients with 30 calendar days' advance notice, during which they may object on reasonable grounds, in accordance with art. 28.2 GDPR.
We may also disclose data to public authorities where there is a legal obligation to do so.
6. International data transfers
It is important to distinguish between where the data is stored and where it may occasionally be processed:
- Primary storage (EU). The database (Supabase) is hosted in the European Union. Surveys and respondents' responses are therefore stored within the EEA.
- Occasional processing outside the EU. When the client uses artificial intelligence or machine translation features, the content strictly necessary to provide the feature is transmitted, on a per-request basis, to the corresponding providers (Groq, Anthropic, translation engines), which may process it in the US or other countries. That occasional transmission does not change where the data is stored: the data continues to reside in the EU.
- Other providers. Google Ireland Limited provides Google Analytics 4 and may transfer consented usage data to Google LLC in the US; Stripe (payments, client account data only) operates from the US; Cloudflare (anti-bot) has a global footprint; AWS provides the computing infrastructure on which the application runs.
Transfer safeguards. These transfers are covered by the Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914), together with any applicable supplementary measures following the corresponding transfer assessment, in accordance with Chapter V of the GDPR. Where the provider adheres to an adequacy framework recognized by the European Commission, the transfer may additionally rely on that framework.
You may request information about the applicable safeguards by writing to [email protected].
7. Retention periods
We retain data only for as long as necessary for each purpose:
- Survey responses (we are processor): retained according to the controlling client's configuration. Each survey may have its own retention period, after which the responses are automatically purged through a daily process. When a response is deleted, we first apply a logical deletion and then a final automatic purge after 30 days. Upon termination of the contract with the client, the data is deleted or returned in accordance with the Data Processing Terms.
- Client account data: for the duration of the contract and, after its termination, blocked for the period legally required to address potential liabilities, until the applicable statute of limitations expires.
- Subscription, billing/accounting data: for the periods required by commercial and tax regulations (specifically, six years under art. 30 of the Código de Comercio (Spain's Commercial Code) and four years under Ley 58/2003, de 17 de diciembre, General Tributaria (Spain's General Tax Act)).
- Technical security data (pseudonymized IP/UA/device-id) and logs: for the time strictly necessary for security/anti-abuse purposes and, in any case, for the period legally required to address liabilities.
- Google Analytics 4 usage data: the retention period for event- and user-level data must be configured and documented in the GA4 property before measurement is enabled. Until the owner records evidence of the effective setting, Google Analytics 4 will remain disabled. Once enabled, that data will be retained only for the documented period, and the setting will be reviewed periodically against the measurement purpose. Withdrawing consent stops future collection, and Google's deletion mechanisms are used where applicable. Genuinely aggregated reports that no longer identify a person may be retained.
Once these periods have elapsed, the data is effectively deleted or anonymized.
8. Your rights and how to exercise them
As a data subject, GDPR grants you the following rights:
- Access (art. 15): to know what data of yours we process.
- Rectification (art. 16): to correct inaccurate or incomplete data.
- Erasure / "right to be forgotten" (art. 17): to request that we delete your data.
- Restriction of processing (art. 18): to request that we "freeze" the use of your data in certain cases.
- Portability (art. 20): to receive your data in a structured, commonly used format, or to have it transmitted to another controller where technically feasible.
- Objection (art. 21): to object to processing based on legitimate interest.
- Withdrawal of consent: where the basis is consent, to withdraw it at any time (without retroactive effect).
How to exercise them. You can write to us at [email protected], indicating which right you wish to exercise. We may ask you to verify your identity. We will respond within one month (extendable to two months in complex cases, art. 12 GDPR). Exercising these rights is free of charge.
Important (dual role). If your request concerns responses to a survey, the controller is the client that created that survey; in that case, as processor, we will redirect your request or help you direct it to the corresponding controller.
9. Right to lodge a complaint with the supervisory authority
If you believe that the processing of your data does not comply with applicable regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) (art. 77 GDPR), located at C/ Jorge Juan, 6, 28001 Madrid, with electronic headquarters at www.aepd.es. Before doing so, if you prefer, you can contact us at [email protected] to try to resolve the matter.
10. Data security
We apply appropriate technical and organizational measures (art. 32 GDPR). Among those already implemented:
- Encryption in transit (TLS) and encryption at rest of the data.
- Per-organization isolation through row-level security (RLS), so that one organization's data is not accessible from another.
- Pseudonymization of technical identifiers: IP, user-agent and device-id are processed via hashing. To be precise: this is pseudonymization, not irreversible anonymization; we continue to treat them as personal data and protect them as such.
- Per-survey configurable retention with automatic daily purge, logical deletion of responses and a final automatic purge after 30 days.
Data breach notification. In the event of a personal data breach, we will act in accordance with arts. 33 and 34 GDPR. When we are controller, we will notify the breach to the AEPD without undue delay and, in any case, within no more than 72 hours of becoming aware of it, unless it is unlikely that the breach poses a risk to the rights and freedoms of data subjects, and we will communicate the breach to data subjects when it entails a high risk. When we act as processor, we will notify the breach to the controlling client without undue delay and, at the latest, within 48 hours of becoming aware of the incident, providing the information reasonably available so that the client can comply with its own notification obligations (in particular, the maximum 72-hour deadline before the AEPD that art. 33 GDPR imposes on those acting as controller).
11. Artificial intelligence, automated decisions and profiling (art. 22 GDPR)
We do not carry out automated individual decisions that produce legal effects or similarly significantly affect you, nor do we carry out profiling with such effects, within the meaning of art. 22 GDPR.
AI features of the service. The service incorporates active artificial intelligence features: assistance in creating and analyzing surveys, generation of summaries, quality and sentiment analysis of responses, multi-survey analysis, brand palette extraction from an image, and machine translation. New capabilities will be activated gradually, as they become available. These features rely on external inference providers acting as sub-processors:
- Groq (US): primary inference provider for the AI features. The transfer is covered by the Standard Contractual Clauses (Decision (EU) 2021/914) and Groq is subject to a commitment not to use client data to train models.
- Anthropic (US): involved in specific features, namely multi-survey analysis and brand palette extraction from an image. The transfer is likewise covered by the Standard Contractual Clauses.
- Machine translation engines (MyMemory and/or LibreTranslate): when the client uses translation, the survey text is sent to the engine for translation. This processing only takes place if the client activates the feature.
In all cases:
- We process only the data strictly necessary to provide the requested function, on the basis of legitimate interest or performance of contract (art. 6.1.f and 6.1.b) with respect to account data, and as processor in accordance with the instructions of the controlling client with respect to respondent data; we do not use responses to train third-party models without an adequate legal basis.
- The data remains stored in the EU; the transmission to the provider is occasional, on a per-request basis, and limited to the content necessary to provide the feature (section 6).
- Where an AI processing activity may entail a high risk to the rights and freedoms of data subjects, we will carry out, in advance, a Data Protection Impact Assessment (DPIA, art. 35 GDPR) and apply the transparency obligations and other applicable requirements under Regulation (EU) 2024/1689 (Artificial Intelligence Act).
- Ownership of content and outputs. Content provided by the client and the outputs generated by the AI from that content belong to the client, in accordance with the Texto Refundido de la Ley de Propiedad Intelectual (Real Decreto Legislativo 1/1996, Spain's consolidated Intellectual Property Act) and the terms of the contract. We do not claim intellectual property rights over that content or those outputs.
We will inform you prominently before any new AI feature with a material impact on your data goes into operation.
12. Minors
The service is not directed at minors and, as a general rule, should not be used by them without the involvement of whoever holds parental authority or guardianship.
In Spain, under art. 8 GDPR and art. 7 of the LOPDGDD, the processing of a minor's data based on their consent is lawful only from the age of 14; below that age, the consent of the holder of parental authority or guardianship is required. (Art. 8 GDPR sets the default age at 16 but allows each Member State to lower that threshold to a minimum of 13; Spain set it at 14.)
Where a specific survey may collect data from minors (a decision that rests with the controlling client), the client must enable, through the survey's configuration, appropriate age verification mechanisms and mechanisms for collecting the consent of the holder of parental authority or guardianship, on the terms set out in the Data Processing Terms. Camaleonic Survey will endeavor to provide the client with survey configuration options that help it do so.
13. Changes to this policy
We may update this policy to reflect legal, technical or service changes (for example, the expansion of the AI features). We will publish the version in force with its update date and, where the changes are substantial, we will notify you through an appropriate channel, in particular by email to clients and/or a prominent notice within the application.
Regulatory sources cited: GDPR (Regulation (EU) 2016/679), arts. 6, 8, 9, 10, 12, 13, 14, 15-18, 20-22, 28, 32, 33-34, 35, 37, 77 and Chapter V; LOPDGDD (Ley Orgánica 3/2018, Spain's Organic Law on the Protection of Personal Data and the Guarantee of Digital Rights), arts. 7 and 34; LSSI-CE (Ley 34/2002, Spain's Information Society Services and Electronic Commerce Act), arts. 21 and 22.2; ePrivacy Directive (Directive 2002/58/EC); Commission Implementing Decision (EU) 2021/914 (Standard Contractual Clauses); Regulation (EU) 2024/1689 (Artificial Intelligence Act); Texto Refundido de la Ley de Propiedad Intelectual (Real Decreto Legislativo 1/1996, Spain's consolidated Intellectual Property Act); Código de Comercio (Spain's Commercial Code), art. 30; Ley 58/2003 (Spain's General Tax Act).