Legal

Privacy Policy

Effective date: July 9, 2026  ·  Last updated: July 9, 2026

Contents
  1. Who we are
  2. Data we collect
  3. How we use your data
  4. Legal basis (GDPR)
  5. Data sharing and processors
  6. International data transfers
  7. Data retention
  8. Your rights
  9. Cookies
  10. Children's privacy
  11. Security
  12. Changes to this policy
  13. Contact us

In plain terms: We collect only what we need to run the service. We don't sell your data. Your respondents' data belongs to you. We use EU-based infrastructure and comply with GDPR.

1. Who we are

Cletica ("Cletica", "we", "us", or "our") is a survey and research platform operated by [Legal Entity Name] ("Company"), registered at [Company Address].

We act as the data controller for the personal data of our customers (users who create accounts on Cletica). For the personal data of survey respondents collected through surveys created by our customers, we act as a data processor — our customers are the data controllers for their respondents' data.

Questions about this policy: [email protected]

2. Data we collect

2.1 Account data

When you register or sign in, we collect:

2.2 Organization data

When you create an organization on Cletica, we store the organization name, slug (subdomain identifier), plan, and branding settings (colors, logo, custom CSS).

2.3 Survey and response data

We store the surveys you create, including question text, settings, and logic rules. We also store the responses submitted by your respondents, including:

This data is created and controlled by you as our customer. We process it on your behalf.

Anonymous public surveys: When a survey is completed via a public link (not a personal link tied to a specific contact), responses are stored without any identifier linking them to a natural person. Cletica has no means to identify the respondent from the response data alone, and therefore cannot fulfill deletion or access requests for anonymous responses on behalf of a respondent who contacts us directly. If a respondent submits a data subject request, they should contact the organization that created the survey, as that organization is the data controller for the survey data.

2.4 Contact CRM data

If you use the Contacts feature, we store contact records you import or create: name, email, phone, external ID, tags, and custom attributes. You are the controller of this data.

2.5 Usage and technical data

We automatically collect:

2.6 Payment data

We do not store your payment card details. Payments are processed by Paddle (our Merchant of Record). We receive only non-sensitive transaction metadata (plan purchased, amount, transaction ID).

2.7 Waitlist

If you submit your email on our waitlist form, we store your email address, the language you used, and your IP address. This data is used solely to notify you when registration opens.

3. How we use your data

PurposeData used
Provide and operate the Cletica platformAccount data, survey data, response data
Authentication and account securityEmail, password hash, Google ID, IP address
Send transactional emails (verification, password reset, invitations)Email address
Process subscription paymentsAccount data, billing metadata from Paddle
Prevent fraud and abuseIP address, usage logs
Improve the platformAggregated, anonymized usage data
Respond to support requestsAccount data, information you provide
Send product announcementsEmail address (with opt-out available)
Waitlist notificationEmail address from waitlist form

If you are located in the European Economic Area (EEA), our legal basis for processing your data is:

5. Data sharing and processors

We do not sell your personal data. We share data only with the service providers listed below, under data processing agreements, strictly to operate the platform:

ProviderPurposeLocation
Amazon Web Services (AWS)Cloud hosting (EC2), database (RDS PostgreSQL), file storage (S3), email delivery (SES)EU (Frankfurt, eu-central-1)
CloudflareCDN, DDoS protection, bot protection (Turnstile CAPTCHA)Global (EU servers available)
GoogleOAuth sign-in (if you use "Sign in with Google")Global
PaddlePayment processing and subscription management (Merchant of Record)UK / Global

We may disclose data to law enforcement or government authorities if required by applicable law, or to protect the rights, property, or safety of Cletica, our users, or the public.

6. International data transfers

Our primary infrastructure is located in the EU (AWS Frankfurt). Some of our service providers (such as Cloudflare and Google) process data in other regions.

Where we transfer data outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission.

7. Data retention

Data typeRetention period
Account and organization dataUntil account deletion, then 30 days before permanent deletion
Survey and response dataUntil deleted by the customer or account deletion
Contact CRM dataUntil deleted by the customer or account deletion
Usage and server logs30 days rolling
Billing records7 years (legal requirement)
Waitlist emailsUntil registration opens or upon unsubscribe request

8. Your rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, email us at [email protected]. We will respond within 30 days. If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection authority.

9. Cookies and local storage

We use the following cookies and browser storage:

We do not use third-party advertising or tracking cookies. We do not share cookie data with advertisers.

10. Children's privacy

The Cletica platform is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

If you use Cletica to conduct surveys involving minors, you are solely responsible for obtaining any required parental or guardian consent in accordance with applicable law (COPPA, GDPR Article 8, etc.).

11. Security

We take appropriate technical and organizational measures to protect your data:

No system is completely secure. In the event of a data breach affecting your rights and freedoms, we will notify you and the relevant authorities as required by law.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. For material changes, we will notify you by email (if you have an account) or by posting a notice on our website. Your continued use of Cletica after the effective date of any changes constitutes acceptance of the updated policy.

13. Contact us

For privacy-related questions, data requests, or complaints:

We aim to respond to all inquiries within 30 days.