Version 2.1 · last updated 2026-08-27
This describes what Downright actually does with personal data. Where something depends on a supplier we name the supplier rather than make a promise on their behalf, and where we do not yet know something we say so.
Downright is operated by Flat Rock UG (haftungsbeschränkt), Germany. For anything in this policy, write to hello@usedownright.com.
We have not appointed a Data Protection Officer. We are a small company whose core activity is not large-scale monitoring or special-category data, so Art. 37 GDPR does not require one. We say this because buyers ask.
You have a Downright account. We are the controller of your account data, and this policy is our agreement with you.
You received a survey from a business. That business decides who is asked and what is asked; they are the controller. We only act on their instructions, as their processor. To have your data corrected or erased, ask them — but you can unsubscribe from us directly, at any time, using the link in the email.
What we hold, and why:
Legal bases: Art. 6(1)(b) for everything needed to run the service you asked for; Art. 6(1)(f) for keeping the service secure and preventing abuse; Art. 6(1)(a) for analytics and the chat widget, which run only if you accept them and can be withdrawn at any time on the cookie page.
We process this on behalf of the business that surveyed you. What exists:
We do not record the IP address of anyone answering a survey. Survey pages load no analytics, no chat widget, no external fonts and no CDN, so no third party is told you were there either. That is also why you are never shown a cookie banner on one.
If you answered through a public link rather than an emailed invitation, there is no contact record at all: the answer is anonymous unless you chose to leave an email address afterwards.
A word about the comment box: it is free text, so it can contain anything you type into it. Please do not put health details, financial details or anything else sensitive in there. The business that surveyed you will read it.
These are our processors. We add nobody to this list quietly.
| Who | What for | What they see | Where |
|---|---|---|---|
| Mailgun (Sinch) | Delivering survey invitations and transactional email | Recipient email address and name, delivery status | European Union |
| Stripe | Taking payment for paid plans, and issuing invoices and receipts | Billing name, email address, billing address, VAT number, card details | Ireland, with transfers to the United States |
| DigitalOcean | Running the application, database and uploaded logos | All service data | European Union |
|
Google Analytics
only if you accept cookies |
Marketing website statistics | Usage and device data of website visitors | United States |
|
Tawk.to
only if you accept cookies |
Live chat on the marketing website | Chat messages and usage data of website visitors | United States |
|
Google (Sign in with Google)
only if you choose it |
Optional sign-in for account holders | Email address and account identifier | United States |
Survey email is delivered through Mailgun's European infrastructure. Uploaded logos are stored on our own server rather than with an object-storage provider, so that is one supplier fewer than most tools of this kind.
Where a supplier is outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses together with that supplier's own safeguards. That covers the suppliers marked above as consent-only, which is another reason they do not run until you say yes, and it covers Stripe, which contracts with us through its Irish company but is a United States business.
Card details are entered on Stripe's own pages and never reach our servers. What we hold of a payment is the fact that an account has a Stripe customer and which plan it is on.
We do not delete things on a timer, and we would rather say so than invent a retention schedule we do not run:
Under the GDPR you can ask for access, correction, erasure, restriction, portability, and object to processing. What matters more than the list is whether there is a mechanism, so:
If you answered somebody's survey and want your answer removed, ask the business that sent it. If you cannot reach them, write to us and we will pass it on and help them act on it.
You can complain to a data protection supervisory authority. The competent authority depends on the German state in which we are established; the list of German authorities is published by the federal commissioner. You may also complain to the authority where you live or work.
This page carries a version and a date. If the suppliers or the purposes change materially, we reset cookie consent so the question is put to you again rather than assumed.
Cookies · Security · Terms · Company details