On-demand campaigns — the protection regime is chosen first, then enforced.
Sumvadis runs survey campaigns on its own EU infrastructure. Every campaign declares its protection regime up front — anonymous, pseudonymous or identified — and that choice determines what may be collected, what is stored, and what leaves the platform when the campaign closes.
No account, no e-mail, no IP kept — nothing stored can identify a respondent. At campaign close, any combination of characteristics shared by fewer than five respondents is suppressed (k-anonymity) before any export.
Participants are known by a code only they hold — codes are derived cryptographically, never stored. Designed for repeated measures (retest) without ever naming anyone.
Consent comes first: every collected field is declared when the campaign is created, and data stays on the EU data plane. The survey owner acts as data controller (see Terms).
The data plane lives in the European Union (Frankfurt) — per campaign, by default.
No login, no e-mail, no IP kept. Raw data lives in the EU and is k-anonymised (rule of five) when the campaign closes.
Each participant’s profile is computed by our native engine on their own device — the result never has to leave it.
No cookies, no trackers, no analytics — on this site or in the app. Only your device’s local storage, for strictly functional needs.
Join-QR, live counter, and the room’s aggregate profile — refreshed as answers arrive, without exposing anyone.
English, French and German across the whole journey — instruments, screens and restitutions.
Load-tested: 2000 simultaneous submissions absorbed in 12.7 s — zero loss, zero identifiers.
The campaign declares its protection regime, its instrument and its languages — this frame is set before anything is collected.
Questionnaire, additional fields and consent are frozen in the campaign definition when it is created.
A link or a QR code; everyone answers on their own device, and each profile is computed on that device.
The campaign closes; the dataset — k-anonymised in the anonymous regime — is exported for aggregate analysis.
AI-generated media served by the platform carry C2PA-signed provenance and a visible AI mark.
A public security contact (RFC 9116 security.txt), acknowledgement within 72 hours.
Analyses are produced by scripted, versioned tools — reproducible, with no manual case-by-case inspection.