---
url: "https://questionstar.com/security/"
title: "Security — GDPR taken seriously, not just a checkbox"
description: "Servers exclusively in Germany (IONOS Frankfurt). DPA available. Encryption, anonymization, audit trail. GDPR as the default, not an add-on module."
lastmod: "2026-07-08"
type: "marketing"
---

# Security & data protection at QUESTIONSTAR

We treat the questions of our customers (administrators) and of survey respondents separately — because their concerns are different.

## For administrators

### Hosting & infrastructure

- Our own hardware in German IONOS data centers — under our own management
- TLS encryption in transit (HTTPS)
- Encryption at rest (database level)
- Geo-separated backup locations (production and backup servers in different data centers — protection against local disasters)

### Availability & backups

- 99.97% availability (measured over the last 12 months)
- Daily backups (24-hour cycle, full)
- Restoration typically within a few hours on request
- Backup locations geographically separated from production servers

*Note: outages of external internet backbones or internet service providers are outside our control.*

### Real-time data capture

Every answer is saved the moment it’s entered — not only when moving to the next page. The benefit: protection against data loss from dropped connections, closed browsers or interrupted sessions.

### Audit trail

Logged internally: login/logout, account creation/plan changes, survey creation/editing/deletion, response arrival and deletion, user management.

*Reported transparently:* data exports by users are currently not logged (on the roadmap); anonymity-setting changes are enforced at system level (one-way enforcement) but not logged separately; admin actions are partially captured (around 10%, being expanded). A customer-facing audit-log export is on the roadmap.

### GDPR compliance

- DPA (data processing agreement) available — as a PDF download
- Compliance with Art. 28 (processing), Art. 32 (security measures) and Art. 33 (incident notification) GDPR
- Granular anonymity settings: IP storage full / partially masked (first two octets removed) / none; private questions with separate data storage; optional key for joining private and general data; once configured anonymous — stays anonymous (one-way enforcement)
- Access (Art. 15) and erasure rights (Art. 17) — researcher-mediated: we implement requests for our customers
- Incident notification within 72 hours per GDPR Art. 33

### Access protection

**Server access:** only via IP-restricted remote desktop (whitelist) for QS developers; console access exclusively through the IONOS backend; physical protection through IONOS data-center security; access by QS staff only — no external contractors.

**User authentication:** standard password requirements — at least 8 characters, 1 digit, 1 uppercase letter; license administrators can set their own password policies for their teams.

*Reported transparently:* two-factor authentication (2FA) is currently not available — on the roadmap.

### Sub-processors

- IONOS Cloud GmbH (Germany) — hosting of the server infrastructure
- Twilio SendGrid (certified SCC compliance) — email delivery for survey invitations and reminders

Other services without personal-data processing: Microsoft Azure (Frankfurt) — CDN for static assets. We use no external analytics tools and no external error-tracking services. Full list with contract and data-location details on request via support@questionstar.com.

### Security testing & certifications

Regular internal security testing with Nikto (web-server scanner); OWASP recommendations applied. The IONOS data centers are ISO 27001 certified (this covers the physical infrastructure — not the QUESTIONSTAR application itself).

*Reported transparently:* external penetration tests by third parties are currently not performed; QUESTIONSTAR itself is not ISO 27001 certified.

## For survey respondents

### What data is collected?

- The answers you give
- Technically necessary cookies (e.g. to resume an interrupted survey) — not optional
- Optional analytics cookies — only if the survey owner enables them, can be turned off
- Optionally your IP address — full (default), shortened (first two octets) or not at all; the owner makes that choice
- Browser local storage: not used

### Who sees your answers?

The survey owner who created the survey. QUESTIONSTAR staff only if the owner requests our technical support. We don’t use your answers ourselves and don’t pass them to third parties — explicitly regulated in our terms of service.

### Anonymity — when is it real?

No personal data is collected before the survey starts — a survey is anonymous by default. If the owner configures it as anonymous: once anonymous, stays anonymous (one-way enforcement — even the owner can’t undo it later without creating a new copy). Answers to private questions are stored separately; if skipped, they remain pure noise. About the IP address: in practice, a person can’t easily be reconstructed from it — on request, the owner can disable IP storage entirely.

### Real-time saving

Your answers are saved as soon as you enter them — not only when changing pages. So answers aren’t lost if the connection drops or the browser closes.

### Your rights — how to exercise them

Access (GDPR Art. 15) and erasure (Art. 17) are implemented through the survey owner — they are the data controller; contact them first. The response should come within one month (Art. 12(3)); for extensive requests, +two months with justification. If you get stuck: support@questionstar.com — we’ll support the controller.

### Hosting & security

Your data is hosted in German data centers · TLS encryption in transit, encryption at rest · GDPR-compliant per Art. 28, 32, 33.

## Further information

- [Download the DPA as PDF](/legal/DPA-QUESTIONSTAR-EN.pdf)
- [Full privacy policy](/privacy-policy/)
- [Legal notice](/imprint/)

For security or GDPR questions and incident reports: support@questionstar.com — we report notifiable incidents within 72 hours per GDPR Art. 33.
