Starting in 2010, the number of inquiries concerning privacy keeps growing, usually because Sosci Survey is being used to conduct employee-surveys. More often than not, surveys fail because privacy concerns cannot be eliminated completely.
This is why Sosci Survey takes data protection very seriously. We enable social science research that reliably complies with data protection legacy.
SoSci Survey enables you to collect data in a way that doesn't allow to identify the specific participant of the questionnaire. Using these features rewards you with non-personal data that doesn't violate anyone's privacy.
Recording Minimal User Data
Upon opening a webpage, a browser usually submits other data along with the IP-address. Information like browser-ID, operating system or language settings is saved into a logfile, along with the type of request (usually the url) and a timestamp.
The Server www.soscisurvey.de is configured not to store IP addresses in the access logfiles. Therefore, even a combination of timestamps and server logfiles does not allow a reconstruction if IP addresses.
A survey project usually stores the questionnaire access time and the time for completing a questionnaire, into the dataset. Other information is not stored unless activated in the project settings.
Unencrypted data transfer theoretically allows for thrid parties to gain access to the transmitted information.
The server www.soscisurvey.de therefore uses SSL encryption with a signed certificate, noticeable at the "HTTPS" preceding the URL. All data is being encrypted by the browser and decoded by the server. This process is considered very secure.
Secure Server Environment
The SoSciSurvey.de-server is located in Europe, since 2013 in Munich in a certified datacenter operated by the M-net Telekommunikations GmbH. The datacenter is certified with 4 stars by eco Datacenter Star Audit, warranting organizational, constructional, technical, and supply security. The server is secured against unauthorized access according to common standards. Technical operation of the server is provided by the InterNetWire Communications GmbH.
The server runs Linux along with the webserver-software Apache and NGINX (since october 2013), which are considered secure. Regular security updates ensure the safe operation and in-time fixes of eventual security holes. Access to the server is SSH-encrypted.
Data backups of the projects and the datasets are created daily to ensure the safety of the data.
SoSci Survey will not pass on any data to third parties. Other parties do not have access to the data. We have concluded agreements with the server host corresponding to §11 Bundesdatenschutzgesetz (German data protection law).
By default, the questionnaires do not use any cookies. Instead, to identify a user on filling out a questionnaire, the user ID is not being stored permanently on a user's computer but transferred from one questionnaire page to the next.
Cookies do not serve as reliable means to prevent multiple questionnaire submissions. The only way to avoid those is by using personalized questionnaire links using the serial mail or serial number function in Sosci Survey.
Contract about Processing of Personal Data
If your study works with personal data, it may be necessary to make a contract about the processing of personal data (ADV) with us. If such a contract becomes relevant for you, please contact us via email.
SoSci Survey Privacy Features
No Recording of IP Address
Particularly companies need little work to extrapolate from an IP address to the corresponding person.
The storage of the IP address is therefore optional and can be switched on or off in the project settings. By default, no IP addresses are recorded.
Because its information value is mostly negligible, you can usually relinquish it.
Anonymous Panel Studies
If you are conducting studies with a known set of participants or panel studies where participants are to be repeatedly interviewed, SoSci Survey provides a project-internal partcipants administration function. All datasets by the same User will get a unique ID (Serial number). This ID does not allow consolitation with an Email-Adress or the identity of the user.
However, on conducting panel studies that requires participants to be interviewed repeatedly, SoSci Survey will store an email/user-ID-assignment in a different database so that users can get an individual link. Upon deleting the email adresses, this assignment will be deleted as well.
Separate Email Address Collection
You might want to collect email or postal addresses to provide incentives like a raffle or study outcomes. SoSci Survey offers the functionality to store email addresses in a different database with no possibility to consolidate the address with the original questionnaire dataset. In this case, the participant's questionnaire details will remain anonymous.
If collecting very sensitive data, recording of timestamps may be disabled in the project settings. In this case, neither the interview's starting time, nor dwell times will be stored.
This measure further decreases the probability that collected data is de-anonymized by merging with external data (e.g., an Internet provider's connection data).
Please note, that timestamps may still be reconstructed from the server logfiles. If it is necessary to disable the logfiles for a specific survey due to privacy issues, please contact us.
Deletion of Collected Data
Project managers have the ability to delete collected data as well as the entire survey at any time. Even manual filing and archiving of the survey within the user account is possible. By default, any project will be filed if the project manager doesn't log in within 3 months. If this happens, all data of the survey project will be deleted and the questionnaire will be archived as XML-file– in case the user wants go back to it at a later point.
Unrelated to these deletions are backups - we save them on our server on a daily basis to guarantee a stable operation of the server. This way data loss or accidental deletions caused by technical malfunctions can be repaired. These backups are saved for a time period of 1 year and are deleted afterwards. We don't use any of this data, except for the purpose of recovery. Please note that the recovery of lost data caused by the project manager, such as accidental deletion, is tied to a surcharge of 60 euros.
Data Protection while Using www.soscisurvey.de
Reading our website www.soscisurvey.de is usually possible without stating any personal data about yourself. However to use our services, such as creating online questionnaires using the software SoSci Survey, a registration is required. This is also stated in our General Terms and Conditions. Insofar as possible, the collection of personal data on our side takes place on a voluntarily basis. This data won't be shared with third parties unless you explicitly agree to it.
Please note that we can't guarantee the protection of data transfer within the internet (i.e. communication via email).
If you haven't found an answer to your question within this document, please don't hesitate to contact SoSci Survey.
© 2006-2015 SoSci Survey GmbH Contact Details