It is important to ensure personal information is protected when designing a Suzy Connect survey. Below are answers to frequently-asked questions.
Who is the data controller? Who is the processor? Generally speaking, your company is the data controller in Suzy Connect scenarios, and Suzy is the processor.
Will personal information be transferred to me when I launch a Suzy Connect? It depends on what questions you ask in your survey and what information the respondent chooses to provide in response. For more details, contact your Suzy representative.
Will my company be sharing our customers’ personal information with Suzy when using a Suzy Connect? Whether or not personal information is shared from you to Suzy when designing the Suzy Connect survey is entirely up to you. For example, a client could append email=janedoe@email.com in the URL, but Suzy strongly discourages that practice as a very poor UX and edge case.
Can I ask for respondent personal information when using a Suzy Connect? Are there specific types of personal information that are prohibited? Yes, if you utilize “Legal Questions” when setting up your Suzy Connect survey and follow our general Respondent Privacy Guidelines. In the Legal Questions step, you are able to ask for respondent consent to collect their personal information. Consult with your legal team for your company’s guidelines on the collection of personal information.
There are certain types of personal information that you cannot request via Suzy Connect and Suzy’s platform. Examples include protected health information and protected financial information. For details, review our Guidelines.
Does Suzy ask Suzy Connect respondents for consent? No. Unlike our other products, where we handle capturing consent from our member-respondents for you, our Suzy Connect offering is specifically designed to let you send surveys to your audiences. We recommend that you take advantage of the “Legal Questions” step when setting up your Suzy Connect survey. In that step, you are able to ask for respondent consent, ask respondents to review your company’s privacy policy or terms and conditions, verify respondent age, etc. In another step, you can customize the survey footer, so that respondents see a link to your company’s privacy policy or other terms throughout the survey-taking experience.
Separately, a link to Suzy’s privacy policy is always visible to respondents during the survey-taking experience.
What results can I share internally? If the insights contain personal information, you can share insights with your internal teams, assuming your company’s internal policies and applicable data laws permit it; however, it is critical that such content refrains from containing Prohibited Personal Information. For details, review our Respondent Privacy Guidelines.
What results can I share externally? What can’t I share? You cannot share results containing Prohibited Personal Information. For all other results, consult with your legal team to determine what can and cannot be shared externally based on your company’s policies. For example, if your company needs a specific/additional likeness release, Suzy can help facilitate that. Please reach out to your Suzy contact to begin that process.
Are Suzy Connect surveys HIPAA Compliant? No, not at this time.
What are your data retention policies for Suzy Connect data? Our standard operating procedures for data retention are set forth in Suzy’s DPA in the section titled “Data Destruction.”
What about data subject rights? Can Suzy Connect respondents ask for their information to be deleted? Yes. Respondents have certain rights related to their personal information under data protection laws, including the right to ask to have their personal information deleted. Respondents can directly submit a request with Suzy using the form linked from our Trust Center. Suzy processes such privacy requests in compliance with applicable laws and will communicate requests to the client under the terms of the client’s agreement with Suzy and/or applicable law.
If a respondent instead submits a data subject request directly to your company and your company forwards that request to Suzy, Suzy will process such request in compliance with applicable laws and the terms of our agreement with you.
What happens if a respondent shares personal information that I didn’t ask for? If a respondent shares personal information that you didn’t ask for (for example, the respondent accidentally exposes their credit card number, provides their name, or someone else besides the respondent appears on camera), reach out to your Suzy representative or Support.
Why do I have to review a disclaimer box before launching my Suzy Connect survey? We’ve included the prompt as a reminder to treat Suzy Connect results with special care, especially if the results contain personal information.