QUESTIONSTAR

Security & data protection at QUESTIONSTAR

We treat the questions of our customers (administrators) and of survey respondents separately — because their concerns are different.

Hosting & infrastructure

  • Our own hardware in German IONOS data centers — under our own management
  • TLS encryption in transit (HTTPS)
  • Encryption at rest (database level)
  • Geo-separated backup locations (production and backup servers in different data centers — protection against local disasters)

Availability & backups

  • 99.97% availability (measured over the last 12 months)
  • Daily backups (24-hour cycle, full)
  • Restoration typically within a few hours on request
  • Backup locations geographically separated from production servers

Note: outages of external internet backbones or internet service providers are outside our control.

Real-time data capture

Every answer is saved the moment it’s entered — not only when moving to the next page.

The benefit: protection against data loss from dropped connections, closed browsers or interrupted sessions.

Audit trail

The following events are logged internally:

  • Login / logout
  • Account creation / plan changes
  • Survey creation, editing and deletion
  • Response arrival and deletion
  • User management (invitations, removals)

Reported transparently:

  • Data exports by users are currently not logged (on the roadmap)
  • Anonymity-setting changes are enforced at system level (one-way enforcement — once anonymous, stays anonymous), but not logged separately
  • Admin actions are partially captured (around 10% of actions — being expanded)

Audit entries are visible internally to our developers; a customer-facing audit-log export is on the roadmap.

GDPR compliance

  • DPA (data processing agreement) available — as a PDF download
  • Compliance with Art. 28 (processing), Art. 32 (security measures) and Art. 33 (incident notification) GDPR
  • Granular anonymity settings for surveys:
    • IP storage: full / partially masked (first two octets removed) / none
    • Private questions with separate data storage
    • Optional key for joining private and general data
    • Once configured anonymous — stays anonymous (one-way enforcement)
  • Access (Art. 15) and erasure rights (Art. 17) — researcher-mediated: we implement requests for our customers
  • Incident notification within 72 hours per GDPR Art. 33

Access protection

Server access

  • Only via IP-restricted remote desktop (whitelist) for QS developers
  • Console access exclusively through the IONOS backend
  • Physical protection through IONOS data-center security
  • Access by QS staff only — no external contractors

User authentication

  • Standard password requirements: at least 8 characters, 1 digit, 1 uppercase letter
  • License administrators can set their own password policies for their teams

Reported transparently:

  • Two-factor authentication (2FA) is currently not available — on the roadmap

Sub-processors

Full list of third parties that process personal data:

  • IONOS Cloud GmbH (Germany) — hosting of the server infrastructure
  • Twilio SendGrid (certified SCC compliance) — email delivery for survey invitations and reminders

Other services used without personal-data processing:

  • Microsoft Azure (Frankfurt) — CDN for static assets (images, scripts)

We use no external analytics tools and no external error-tracking services.

Full list with contract and data-location details on request via support@questionstar.com.

Security testing & certifications

Internal testing

  • Regular internal security testing with Nikto (web-server scanner)
  • OWASP recommendations applied for web-application security

Hosting certification

  • The IONOS data centers are ISO 27001 certified (this covers the physical infrastructure — not the QUESTIONSTAR application itself)

Reported transparently:

  • External penetration tests by third parties are currently not performed
  • QUESTIONSTAR itself is not ISO 27001 certified

When you have questions or incidents

Security or GDPR questions: support@questionstar.com

Incident reports: We report notifiable incidents within 72 hours per GDPR Art. 33.

Further information