Security

A practical guide to how we handle security, privacy and data protection. Whether you're evaluating SmartCX or already a customer, this page gives you straight answers to the security, privacy and compliance questions we're asked most often.

Last updated: July 2026

The short version

  • All customer personal data is stored and processed in secure UK data centres, under UK jurisdiction and data protection law
  • We're a fully UK-owned and operated business, so your personal data is not subject to US surveillance laws like the CLOUD Act or FISA
  • All data is encrypted both in transmission using TLS 1.2 and at rest using SQL Transparent Data Encryption (TDE)
  • All collected response data is solely controlled by you. SmartSurvey does not access it for any purpose, except in the circumstances of account support with the permission of the account holder or for security purposes
  • All SmartSurvey employees, including support and engineering staff, are UK based and security vetted to the BS7858 standard, the UK benchmark for personnel screening in sensitive industries
  • Once deleted, survey data will only exist on backups, which can persist for up to 30 days before it is fully erased

Certifications: ISO 27001, Cyber Essentials Plus, NHS DSPT (code 8K376), FSQS accredited, HIPAA compliant, UK GDPR, SecurityScorecard A (98/100).

Frequently asked questions

Where is our data stored?

Our servers are based in the UK. No one will access your data unless they have the credentials to access your account, you publish that data, or our staff for the purposes of providing you support or fixing a technical issue. Our staff are all UK based.

Is our data encrypted?

Yes, all data is encrypted both in transmission using TLS 1.2 and at rest using SQL Transparent Data Encryption (TDE). We use Microsoft SQL Server TDE to encrypt data at rest using the AES encryption algorithm.

Who is the data controller and who is the processor?

We are the Data Controller for data specifically about our customers. This refers to your contact information, payment information and other data that is held by us, so that we can provide you with the service we do. We then act as a Data Processor for the data that our customers collect from their respondents. Our customers are Data Controllers for the data they collect from and about their respondents. Respondents are Data Subjects.

Who can access our data?

Only employees with certain privileges can access your data with your permission in order to provide you with support, for fixing technical issues or other services that you have expressly requested. All our employees have signed confidentiality provisions and are trained regularly on data protection and GDPR.

What is your data retention policy?

As you are the data controllers for your surveys, you are responsible for setting the retention policies for your surveys. Once deleted, the survey will only exist on backups, which can persist for up to 30 days before it is fully erased.

Can surveys be made anonymous?

Yes, surveys can be set to be anonymised. This will mean that the IP address (and email address for surveys distributed via email) of the respondent will not be recorded.

What about IP address data?

By default, we record the IP address of every respondent. This can be changed in the Survey Settings or in the Tracking Link Settings by activating anonymous surveys. The IP address is always transmitted to us as part of the process of making a connection across the internet, but with anonymous surveys activated, it is discarded before it can be observed.

How do we comply with deletion, rectification, access and portability requests?

The platform allows you to find, edit, export and delete specific responses for a survey. These features mean that all the rights conferred under GDPR can be complied with.

How do you handle data breaches?

We have robust systems which alert us when a data breach occurs. As soon as we discover a data breach has occurred or even suspect a data breach, we will communicate this to you as soon as possible and will provide you all the details to help you comply with your GDPR breach notification responsibilities.

Do you have a DPO?

Yes. We have appointed a DPO and possess a data protection team handling all aspects of data protection and privacy, ranging from cyber security to legal compliance.

Can AI features be switched off?

Yes. AI tools process personal data in UK-based Microsoft data centres, with no training of LLMs and no data transferred outside the UK. In rare cases, Microsoft might reroute personal data (for example, due to a legal request or major failure). AI tools are optional and can be turned off at any time.

Infrastructure and data centres

All customer data is hosted on dedicated servers in UK data centres with robust physical security, provided by our UK infrastructure hosting sub-processors, ANS Group and Iomart. We store backups in a separate physical location.

  • Firewall: our firewall is set up as a separate machine that acts as a gateway for access to all other servers in our system. The firewall acts as a barrier so that we only have a single point of entry to our system, which is through the web browser. All of our internal databases and applications are shielded from any access outside the firewall
  • Vulnerability scanning: we run extensive network and infrastructure security scans using Tenable Nessus software, trusted worldwide as the gold standard for vulnerability assessment
  • Penetration testing: annual penetration testing or sooner if there is a significant change to the infrastructure
  • Monitoring: we have monitoring tools in place to measure server and application performance, ensuring the performance of all our devices (CPU, memory, disk storage) and access to our website from different locations
  • Encryption: all survey web pages are SSL encrypted by default. During transit from client to server, data is encrypted with TLS. We use Microsoft SQL Server Transparent Data Encryption (TDE) to encrypt data at rest using the AES encryption algorithm

Sub-processors

Effective from 1 August 2025. The current list is always maintained on our Sub-Processors page.

Infrastructure sub-processors

Sub-processorPurposeData residencyNotes
ANS Group LtdInfrastructure hostingUnited Kingdom
Iomart GroupInfrastructure hostingUnited KingdomIncludes Redstation
Civo LtdCloud infrastructure for processing customer survey data for AI Insights featuresUnited KingdomNo data transferred outside UK
Amazon Web Services EMEA SarlFile uploads/downloads to customer accountsUK and IrelandAWS sub-processors
Cloudflare, Inc.Content delivery and performance/security enhancementUK servers within Cloudflare's Anycast networkCloudflare sub-processors

Other sub-processors

Sub-processorPurposeData residencyNotes
MessageBird B.V.SMS feature processingNetherlands and Belgium (EU)No processing outside the EU
VultrEmail tool (sending/scheduling/export)United KingdomNo access to customer data
FireText Communications LtdSMS feature processingUnited Kingdom
Microsoft AzureSentiment analysis (microservices)United KingdomNo training of LLMs; no data transferred outside UK
Membrane IncEnables third-party integrationsMay vary depending on third-party serviceData may be transferred outside the UK by third parties

Optional features such as integrations, custom APIs and webhooks can involve data leaving the UK depending on how you configure them. Trigger-only setups keep all data within our UK infrastructure. See the Customer Data Guide for a feature-by-feature residency breakdown.

Technical and organisational measures (TOMs)

Account security

  • Two-factor authentication: users with paid accounts can enable two-factor authentication on their account using a third-party app, such as Google Authenticator. On our Enterprise plans users can also activate two-factor authentication via SMS
  • Single sign on: Single Sign On (SSO) links the platform to your organisation's internal user directory, so your users only require their organisation's user credentials to log in. Available as an add-on on our Enterprise Plus accounts
  • Password policies: master users of Enterprise Plus accounts can create password policies that all sub-user accounts must comply to, defining the level of complexity, mandatory elements and expiry windows for passwords
  • IP restriction: Enterprise Team and Enterprise Plus accounts benefit from the option to restrict access to specific IP addresses only
  • User permissions: master users and sub-users on team accounts can assign different permissions to other users: Design, Settings, Collect, Results, Clear and Copy
  • Shared account notification: our notification system will notify the user if a second user has logged in using their user credentials at the same time as them
  • Session timeouts: an active session has a duration of 2 hours after non-activity. After this point, your users will need to log in again. This helps to protect your account from access via an unattended workstation

Survey security

  • All survey web pages are SSL encrypted by default
  • Users on paid accounts can require a password to access a survey
  • For an additional level of security, a username and password can be required for survey respondents to access the survey
  • Shared survey results summary can require a password to access
  • Users on Enterprise and above can restrict a survey to only be accessible from specific IP addresses

People

  • All SmartSurvey employees, including support and engineering staff, are security vetted to the BS7858 standard, the UK benchmark for personnel screening in sensitive industries
  • All our employees have signed confidentiality provisions and are trained regularly on data protection and GDPR
  • Our customer support team follow a strict process to verify they are speaking to the registered account holder

Documents and DPA/NDA

Taken together, our Terms of Use and Privacy Policy make clear how we will treat your data and that of your respondents.

  • Information security white paper: for more technical information, our information security white paper explains the infrastructure, encryption and other measures that are in place to protect data. Available on request
  • HIPAA: we offer our Enterprise customers HIPAA compliant surveys and the opportunity to enter into a Business Associate contract with us for the purposes of HIPAA compliance
  • Compliance audits: we take a strong stance on helping our customers carry out compliance audits
  • Risk Ledger: if you're an Enterprise Plus customer and a Risk Ledger account holder, you can request to connect with us as part of your infosec questionnaire completion process

Do you need more information?

For security related concerns: security@smartsurvey.co.uk

For legal and data protection questions: legal@smartsurvey.co.uk