Fivesay

Privacy Policy

Effective 22 July 2026

Fivesay is designed so that respondent anonymity is technically enforced — not just promised. This policy describes what information we process, why, where it is stored, and your rights under the GDPR and the Icelandic Data Protection Act No. 90/2018.

The core: no names, email addresses, IP addresses or device data are ever stored with survey answers. We cannot trace an answer to a person — which is precisely why nobody else can either.

1. Controller and roles

The service is operated by Nómi ehf., Reykjavík, Iceland. Privacy inquiries: privacy@fivesay.com.

Our role is twofold:

  • For the website, accounts and operation of the service, Nómi ehf. is the data controller.
  • When a registered user uploads a staff mailing list and sends surveys, their company is the controller of that processing — Nómi ehf. acts as a processor, handling the addresses solely to deliver the survey. Our data processing agreement is published at fivesay.com/dpa and forms part of the terms of service.

2. Anonymity of survey answers

When someone answers a pulse, we store the scores, the eNPS answer (where applicable) and the written comment — and nothing else. No names, email addresses, IP addresses, browser or device information accompany the answer into the database.

  • Results only unlock once at least 5 answers have arrived, and then update only in steps of 5 — a single new answer can never be isolated.
  • Comments are displayed in random order, without scores and without timestamps.
  • Because answers cannot be linked to individuals, we cannot fulfil requests for access to or erasure of a specific answer (Art. 11 GDPR) — that is a feature of the design, not a loophole.

3. What we process

DataPurpose and legal basisRetention
Account: work email and nameSign-in and account operation — contract (Art. 6(1)(b) GDPR)Until the account is deleted
Sign-in links by emailSecure passwordless sign-in — contractEach link is valid for 10 minutes
Mailing lists (staff emails on your own domain)Survey delivery on your company's behalf — processed as a processorUntil the owner deletes the list or the account
Ballots (single-use answer keys)One answer per person without recording who answered — only a SHA-256 hash is stored, never linked to the answer itself — legitimate interest (result integrity)Unused keys are invalidated when a survey is re-sent
Survey answersAggregate results for the group — no personal identifiers, see section 2For the lifetime of the pulse
Hosting provider logs (incl. short-lived IP addresses)Security, debugging and abuse prevention — legitimate interestShort-term retention at Vercel
Web analytics (Vercel Analytics)Aggregate, cookieless usage statistics that do not identify individuals — legitimate interestAggregate only

4. Cookies

We use strictly necessary cookies only — no advertising or tracking cookies, and no third-party tracking pixels.

CookiePurposeLifetime
Session cookieKeeps a registered user signed inFor the session
Language cookie (NEXT_LOCALE)Remembers your language choice1 year
“Already answered” cookie (one per pulse)Prevents duplicate answers — lives only in your browser and is never stored on our side30 days
Results admin cookieGives the person who created a pulse access to their results page30 days

5. Hosting, subprocessors and transfers outside the EEA

We use the following subprocessors to operate the service:

ProviderRoleData location
Neon Inc.Database (Postgres)European Union (AWS data centers in the EU)
Vercel Inc.Web hosting and runtimeCompute in the EU; global CDN for static assets
Resend Inc.Email deliveryUnited States

The database — where answers, lists and accounts are stored — is hosted within the EU. Email delivery and parts of web hosting involve processing in the United States; those transfers rely on the European Commission's adequacy decision under the EU-US Data Privacy Framework and, where applicable, Standard Contractual Clauses (SCCs). Remember: the survey answers themselves contain no personal identifiers.

6. Your rights

Under data-protection law you have the right to access your data, and to rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest. Send requests to privacy@fivesay.com; we respond within one month.

Note: rights concerning your email address on your employer's mailing list should be raised with your employer, who is the controller of that processing — we assist them in fulfilling such requests. Rights do not extend to anonymous survey answers, see section 2.

You may lodge a complaint with the Icelandic Data Protection Authority, Persónuvernd (personuvernd.is), or your local supervisory authority.

7. Security

  • All traffic is encrypted with TLS, as are database connections. Data is encrypted at rest in an EU-hosted database.
  • Answer keys are stored as SHA-256 hashes — never in readable form.
  • Sign-in is passwordless; no passwords are stored.
  • Access cookies are HttpOnly and protected against cross-site requests.
  • The 5-answer minimum is built into the code and is not configurable.

8. Children

The service is a workplace tool and is neither intended for nor directed at children.

9. Changes to this policy

We update this policy when the service changes — for example if a subprocessor is added. Material changes will be announced to registered users. The effective date at the top always reflects the current version.

Terms of serviceBack to the front page