Happydemics is committed to building trustful relationships with its users. We work on different levels to make sure all your data are kept safe.
Incident response plan
We have established a formal procedure for security events and have made our staff aware of our policies in the event of a breach. When security events are detected, they are transferred to our emergency email at privacy@happydemics.com and our teams are notified and assembled in order to handle the event quickly.
Investigations are performed in person and shared across the company's departments. Measures are implemented to enable the detection and prevention of similar events in the future.
Automated correction processes
We have set up functional and frequently used automation that allows us to implement the changes made to our platforms within minutes. We usually implement code several times a week. We are therefore certain that we can quickly resolve security problems when necessary.
Data
All customer data is stored in the EU. Customer data is stored in multi-tenant databases. We do not have individual databases for each customer. However, all of our customers' data is partitioned and our application code is subject to strict confidentiality checks to ensure data confidentiality and to prevent access to customer data.
We use a mySQL database to store all data from surveys. Data is stored on secure servers with advanced encryption, after pseudonymization.
Authentication
Happydemics is served entirely over HTTPS (TLS encryption). Happydemics operates a secured business network that grants no additional resources or elevated privileges beyond what is required for our services.
GDPR Compliance at Happydemics
At Happydemics, protecting your information is an ongoing priority. Our Privacy Policy is reviewed and updated on a regular basis to clarify how we protect your personal data in accordance with the General Data Protection Regulation (GDPR).
We continuously monitor the guidelines and recommendations issued by the European Data Protection Board (EDPB), which succeeded the Article 29 Working Party in 2018, as well as guidance from relevant national data protection authorities. Our data protection processes, contractual documentation and roadmap are reviewed on an ongoing basis, and our technology partners are assessed accordingly to ensure continued compliance.
As a company operating internationally, Happydemics also complies, beyond the GDPR, with all applicable local data protection regulations in the countries where we operate and where our users and clients are located.