OpiScopeSurvey — Product Privacy Notice
OpiScopeSurvey — Product Privacy Notice
Status: DRAFT Effective: [DATE] Version: 0.2 Last updated: 2026-08-311. Introduction
This Product Privacy Notice explains how OpiScopeSurvey handles personal data. It supplements the OpiScope Platform Privacy Policy — read both together.
OpiScopeSurvey is the survey creation and management product of the OpiScope platform. This notice covers:- Survey content you create
- Responses you collect from participants
- How data flows through the survey lifecycle
2. Definitions
These terms are used throughout this Product Privacy Notice and all OpiScope legal documents:
| Term | Definition |
|---|---|
| Controller (or "Data Controller") | The legal entity that determines the purposes and means of processing personal data, as defined in Art. 2 of Organic Law 2004-63. In our product interface, this is called "Organization." In our marketing materials, this is called "Publisher." |
| Organization | The product-interface term for the entity that owns surveys and acts as data controller. |
| Publisher | The marketing/commercial term for the Organization. |
| Org Owner | The natural person authorized to bind the Organization and accept legal documents on its behalf. |
| Team Member | An employee or agent of the Organization acting under its authority. |
| Survey Creator | A Team Member or the Org Owner with permission to create surveys on behalf of the Controller. |
| Processor | An entity that processes personal data on behalf of the Controller. OpiScope acts as Processor for product data. |
| Respondent | A natural person who participates in a survey by providing responses. |
| Personal Data | Any information relating to an identified or identifiable natural person (Art. 2, Organic Law 2004-63). |
| Sensitive Data | Data relating to health, religion, politics, race, union affiliation, genetic or biometric data (Arts. 47-49, Organic Law 2004-63). |
| Anonymized Data | Data that cannot identify any natural person by any means reasonably likely to be used. Anonymized data is NOT personal data and falls outside the scope of Organic Law 2004-63. |
| INPDP | Instance Nationale de Protection des Données Personnelles — Tunisia's national data protection authority. |
| Flag | A report submitted by any person alleging that a survey violates OpiScope's Terms, Privacy Policy, or applicable law. |
| Verified Badge | A badge OpiScope assigns to a Publisher who has uploaded valid INPDP documentation (prior declaration and, where applicable, authorizations) and had it verified by OpiScope. |
| Anonymous Survey | A survey that uses OpiScope's Anonymous Survey service, which strips ALL identifiers before storage so that no personal data is collected from respondents. |
3. Controller & Processor Roles
3.1 For Organizations (Publishers/Survey Creators)
You are the data controller for:- Your survey questions and content
- All responses collected from your respondents
- Any personal data of your participants
3.2 For Survey Respondents
The survey creator (Organization/Publisher) is your data controller. OpiScope processes your response data on their behalf.For questions about how your data is used, contact the survey creator directly. For OpiScope's platform-level data practices, see the Platform Privacy Policy.
3.3 For Org Owners
The Org Owner acts as the legal representative of the Organization and:
- Files prior declarations with INPDP on behalf of the Organization
- Obtains INPDP authorizations (sensitive data, cross-border) on behalf of the Organization
- Ensures Team Members comply with data protection obligations
4. What Data We Collect
4.1 Survey Content (Provided by You)
| Data | Purpose |
|---|---|
| Survey title, description | Display and identification |
| Questions, options, logic | Survey functionality |
| Survey settings (anonymous, single response, etc.) | Survey behavior configuration |
| Branding (logo, colors) | Survey appearance |
4.2 Response Data (Provided by Respondents)
| Data | Purpose |
|---|---|
| Survey responses | Core survey functionality |
| IP address (if enabled by creator) | Security, fraud prevention, deduplication |
| User agent (if enabled) | Compatibility, security |
| Timestamps | Response tracking, analytics |
| Metadata (device, browser, source) | Analytics, quality control |
4.3 Aggregated & Analytics Data
| Data | Purpose |
|---|---|
| Response counts | Survey progress tracking |
| Completion rates | Survey quality metrics |
| Drop-off points | Survey improvement |
| Aggregate statistics | Results display |
4.4 Platform Data (Collected by OpiScope)
Even for anonymous surveys, OpiScope's infrastructure temporarily processes:
- IP address — logged for security, then deleted within [X] seconds/minutes
- Security logs — retained for [Y] days for security purposes
- Access logs — retained for [Z] days for troubleshooting
5. How We Use Survey Data
5.1 Providing the Service
- Display surveys to respondents
- Record and store responses
- Calculate aggregate statistics
- Enable survey creators to view and export results
5.2 Security & Integrity
- Detect and prevent fraud (e.g., bot responses, duplicate submissions)
- Enforce survey settings (single response, closed surveys)
- Monitor for abuse
5.3 Product Improvement
- Analyze aggregate usage patterns to improve OpiScopeSurvey
- Train AI models (only with explicit consent, for AskOpiScope features)
- Fix bugs and improve performance
5.4 AI Interpretation (AskOpiScope)
- If enabled, survey data is processed by AI to generate interpretations
- AI outputs are clearly labeled as AI-generated
- AI does not use respondent PII for model training without explicit consent
5.5 Insights Production from PublicSurveys
For PublicSurveys (surveys listed in OpiScopeDirectory), OpiScope co-owns the rights to anonymized/aggregated response data and may process it to produce insights, analytics, and research products.
Key distinction:- If data is truly anonymized (irreversible, no re-identification possible), this processing falls outside Organic Law 2004-63.
- If data is pseudonymized (can be re-identified with a key), it remains personal data and OpiScope acts as controller for that processing.
6. Legal Bases for Processing
| Purpose | Legal Basis | Controller |
|---|---|---|
| Survey creation & management | Contract performance (you with OpiScope) | You |
| Response collection | Your legal basis (consent, legitimate interest, etc.) | You |
| Response storage | Contract performance (you with OpiScope) | You |
| Security monitoring | Legitimate interest | OpiScope |
| Aggregate analytics | Legitimate interest (anonymized) | OpiScope |
| AI interpretation | Consent (opt-in) | OpiScope |
| Insights production (PublicSurveys) | Not personal data (if anonymized) | OpiScope (if controller) |
7. INPDP Compliance for Publishers
7.1 Prior Declaration
Before using OpiScopeSurvey to collect personal data, you must file a prior declaration with the INPDP (Art. 7, Organic Law 2004-63).
7.2 Sensitive Data Authorization
If your survey collects Sensitive Data, you must obtain INPDP authorization BEFORE collecting (Arts. 47-49).
7.3 Cross-Border Transfer Authorization
If you transfer respondent data outside Tunisia, you must obtain INPDP authorization (Art. 52).
7.4 Exception: Anonymous Surveys
If you use OpiScope's Anonymous Survey service and NO personal data is collected from respondents, the above INPDP obligations do not apply to your survey content.
However, OpiScope still processes platform data (IP, security logs) as a controller, and this is covered by OpiScope's own prior declaration.
8. Data Sharing
8.1 With the Survey Creator
- Responses are accessible to the survey creator and authorized Team Members
- Survey creators can export response data
- Team Members with appropriate permissions can view responses
8.2 With Respondents
- Respondents can view their own responses (if the survey allows it)
- Respondents can request a copy of their data from the survey creator
8.3 With Third Parties
- OpiScope subprocessors — for hosting, storage, and processing (under DPA)
- Integrations — if the survey creator enables integrations (e.g., webhooks, Zapier, Google Sheets), response data may flow to those services
- Directory — if the survey is listed in OpiScopeDirectory, only aggregated results are shown (never individual responses)
- Legal requirements — if required by law or court order
8.4 We Do NOT
- Sell respondent data
- Share individual-level data with third parties without consent
- Use respondent data for our own marketing
9. Cross-Border Data Transfers
9.1 Data Residency
Survey data is stored in [specify region]. The specific data residency depends on deployment configuration.
9.2 Transfer Mechanisms
When respondent data is transferred outside Tunisia, INPDP authorization is ALWAYS required (Art. 52, Organic Law 2004-63).
If you enable integrations with services outside Tunisia (e.g., Google Sheets, Zapier), this constitutes a cross-border transfer and you must obtain INPDP authorization.
9.3 Self-Hosted Deployments
If you deploy OpiScopeSurvey on your own infrastructure, you are responsible for your own data residency and transfer compliance.
10. Data Retention
10.1 Survey Data
| Data | Retention |
|---|---|
| Survey content (questions, settings) | Duration of account + 1 year |
| Individual responses | Per the survey creator's settings (default: [specify — e.g., 2 years]) |
| Aggregated statistics | Indefinitely (anonymized) |
| Export files | 30 days after generation |
10.2 After Account Deletion
- Survey content and responses are deleted within 30 days of account closure
- Anonymized aggregate statistics are retained (cannot be deleted as they are not personal data)
- Backup data is deleted within [specify — e.g., 30 days]
10.3 Survey Creator Responsibilities
As data controller, you must:
- Set appropriate retention periods for your respondent data
- Delete data when no longer necessary
- Honor respondent deletion requests
11. Respondent Rights
11.1 Rights of Survey Respondents
Survey respondents have the right to:
- Information — know who is conducting the survey and its purpose
- Access — request a copy of their responses
- Rectification — correct inaccurate responses
- Erasure — request deletion of their responses
- Withdraw consent — withdraw at any time
- Object — object to processing
- Data portability — receive their data in a structured format (where applicable)
11.2 How Respondents Exercise Rights
- Contact the survey creator — the creator is the data controller and must respond
- Contact OpiScope — if the creator is unresponsive, respondents may contact us at [privacy@opiscope.com]
- File a complaint — with INPDP (Tunisia) or their local DPA (EU/EEA)
11.3 OpiScope's Assistance
We will assist survey creators in responding to respondent requests, including:
- Providing tools to export respondent data
- Enabling deletion of individual responses
- Providing information about our security measures
12. Security
12.1 Technical Measures
- Encryption in transit — TLS 1.3
- Encryption at rest — AES-256
- Access controls — role-based access for Team Members
- Anonymization — IP addresses not stored for anonymous surveys
- Audit logs — tracking of access to response data
12.2 Survey Creator Controls
Survey creators can configure:
- Anonymous surveys (no IP/UA collection)
- Single-response-per-email (deduplication)
- Response encryption at rest
- Access permissions for Team Members
13. Cookies & Tracking in Surveys
13.1 Essential Cookies
| Cookie | Purpose | Duration |
|---|---|---|
| `survey_session` | Prevent duplicate responses | Session |
| `response_id` | Allow respondents to resume | [Specify — e.g., 7 days] |
13.2 Analytics (with consent)
Survey creators may enable analytics that use additional cookies. This is disclosed in the survey's welcome card.
14. Children's Privacy
14.1 Surveys Targeting Children
If you create a survey targeting children (under 16):
- You must obtain verifiable parental consent
- You must provide a child-appropriate privacy notice
- You must not collect unnecessary data
- You must comply with all applicable child protection laws
14.2 OpiScope's Role
OpiScope provides tools to collect parental consent but does not verify its validity. You are responsible for ensuring valid parental consent.
15. AI Interpretation (AskOpiScope)
15.1 How AI Uses Data
If you enable AskOpiScope:
- Survey responses are processed by AI to generate interpretations
- AI does not store or retain response data beyond what is necessary for processing
- AI outputs are generated in real-time and not stored unless you save them
15.2 AI Limitations
- AI interpretations are not a substitute for professional research analysis
- AI may produce errors or biased outputs
- AI outputs should be reviewed and validated by a human before publication
- AI outputs must be clearly labeled as AI-generated when shared
15.3 Opt-Out
You may disable AI interpretation at any time in your survey settings.
16. Flagging
16.1 Right to Flag
Any person may flag a survey for violation of:
- OpiScope's Terms of Service
- This Product Privacy Notice
- Applicable Tunisian law (including INPDP rules)
16.2 Flag Categories
| Category | Examples |
|---|---|
| INPDP violation | No prior declaration, sensitive data without authorization |
| Privacy violation | Data collected beyond what's disclosed |
| ToS violation | Spam, fraud, illegal purpose |
| Sensitive data | Collecting health/religion/politics without authorization |
| Misleading content | Fake academic/commercial |
| Harassment | Questions target protected group |
| Minor protection | Collecting from children without consent |
| Fabrication | Fake survey |
16.3 How Flags Are Handled
See the OpiScopeSurvey Product Terms of Service, Section 15.
17. Changes to This Notice
We may update this Product Privacy Notice from time to time. Material changes will be notified at least 30 days in advance via email and in-platform notification. Continued use after changes constitutes acceptance.
18. Contact
| Purpose | Contact |
|---|---|
| Product support | [survey-support@opiscope.com] |
| Privacy inquiries | [privacy@opiscope.com] |
| Data subject requests | [privacy@opiscope.com] |
| Legal | [legal@opiscope.com] |
19. Governing Law
This Product Privacy Notice is governed by:
- Tunisian law — Organic Law No. 2004-63 and applicable regulations
- GDPR — for respondents in the EU/EEA, to the extent applicable
- Other local laws — where required by jurisdiction
This document is a draft. It must be reviewed by qualified Tunisian legal counsel before publication. It does not constitute legal advice.