We advise on trust - so we have to be able to document it ourselves. Here is how we protect your data and what your IT and compliance teams can request.
SurveyGauge is certified to ISO 27001, the international standard for information security management. That means documented processes for risk management, access control and incident handling.
The ISO 27017 certification covers security controls specific to cloud services - from the division of responsibility between us and you to the protection of your data in the cloud environment.
We comply with the GDPR with a data processing agreement (DPA), documented deletion policies, a sub-processor list and data minimisation by default. All data is hosted in the EU.
DPA, deletion policies, sub-processor list and certification documentation are available on request.
Request documentationDo you need to document customer satisfaction for your own ISO 9001 or ISO 14001 certification? See the requirements and how we cover them.
Your customer data does not leave the EU. As a Danish company with European customers, data protection is not a compliance checkbox for us - it is a precondition. Details on sub-processors, retention periods and your rights are set out in our privacy policy.
Less than most expect. Data minimisation is the default - we only ask for what the surveys require.
Name, work email, company and role for the contacts who should receive surveys. That is all we need to get started.
E.g. customer type, market or account owner, so results can be segmented meaningfully. Delivered as fields in the same export.
You do not need to give us access to your CRM. A simple export (e.g. CSV) is enough - an integration can always be added later if you want it.
High response rates require emails that land in the inbox - without your own domain paying the price. That is why sending is built for deliverability and reputation from the start.
All surveys are sent from dedicated, prewarmed IP addresses with established sender reputation. Survey traffic is isolated from your regular email, so the reputation of your own domain is never affected.
We insert neither open-tracking pixels nor tracked links in survey emails. That keeps emails out of spam filters, builds trust with the recipient and delivers measurably higher response rates.
The sender domain is configured with SPF and DKIM as part of onboarding, so emails are authenticated and land in the inbox. Customers see your name and domain - we make sure the technology behind it is set up correctly.
Your feedback data should be usable where you work - in CRM, BI and AI assistants. Integrations are built on open standards, and access is controlled by you.
Push contacts, trigger surveys and pull results programmatically. Documented REST API with real-time webhooks, so feedback lands in your own systems the moment it arrives.
Our MCP server (Model Context Protocol) lets AI assistants and agents work directly with your feedback data. Ask questions, pull segments and create follow-ups in natural language - with the same permissions as the user.
API keys and MCP access are issued with scoped permissions and can be revoked instantly. All activity appears in the audit log, and your data can always be exported in standard formats - no lock-in.
Yes. The DPA, deletion policies, sub-processor list and other documentation are available on request - write to hello@surveygauge.com and we will send it the same day.
All data is hosted in the EU. Details on sub-processors and transfer mechanisms are set out in our privacy policy and DPA.
No. A simple export with contacts and segment fields is enough to run the program. If you later choose an integration, scope and access are agreed precisely in the DPA.
Your data is deleted according to the retention periods agreed in the DPA, and you can have your data exported in a standard format before deletion. No lock-in.
No. Emails are sent from dedicated, prewarmed IP addresses without tracking pixels or tracked links, and the sender domain is configured with SPF and DKIM. Your own email domain is isolated from survey traffic.
Yes. We offer a documented REST API with webhooks and an MCP server so AI assistants can work directly with your feedback data. Access is issued with scoped permissions, can be revoked instantly and is logged in the audit log.
We are happy to answer directly - or bring them to a meeting where you can also see the platform.