• Privacy

General

CircleLytics (a trademark of Dutch-domiciled GroupStrat B.V.) processes Personal Identifyable Information (PII) of subjects (invitees/respondents) of online Dialogues (online questionnaires).

Our website

Besides your IP address (for security auditing) we do not store any personal information on our website, other than the information that is mentioned in our Cookie Policy. Your IP address will remain a maximum of 30 days at our website hosting. Information that is filled in on our contact form or demo request form is solely used for the response to that request.

Our tool

Information Security as the Foundation of Our Service

Information is one of an organization’s most valuable assets. Our customers rely on us to ensure that their data is processed securely,handled responsibly, and only accessible to authorized users. That is why information security is not an additional feature of our platform—it is a fundamental principle underlying every aspect of our service.

A Fully Sovereign Dutch Hosting Chain

Our SaaS platform operates within a hosting chain that is entirely Dutch-owned. This allows us to maintain full transparency regarding the organizations involved in delivering our services while ensuring that every party meets the highest standards for security, reliability, and operational continuity.

Your data is processed within a controlled environment whereconfidentiality, integrity, and availability are safeguardedthroughout the entire service chain.

Open Source by Design

The technology powering our platform is built on proven Open Source software. This is a deliberate strategic choice.

Open Source offers significant advantages for Information Security

  • Source code can be independently reviewed.
  • Security vulnerabilities are continuously identified and addressed by a global community of experts.
  • There is no dependency on a single software vendor.
  • Security updates are released quickly and transparently.Rather than reducing security, Open Source increases transparency,auditability, and long-term sustainability. The European Union emphasizes the importance of this in their Tech Sovereignty Package.

ISO 27001 Throughout the Entire Chain

Information security extends beyond our own organization. We,together with every organization in our hosting chain, are certified according to ISO/IEC 27001, the internationally recognized standard for Information Security Management Systems(ISMS).

This means that information security risks are systematically identified, managed, monitored, and continuously improved throughout the complete delivery chain.

For our customers, this provides confidence that information security is embedded at every level of our service—not just within our own organization.

Supporting GDPR-Compliant Operations

Our platform has been designed to help organizations process personal data in accordance with the requirements of the General Data Protection Regulation (GDPR).

It provides the technical safeguards and functionality needed to support responsible processing of personal information while enabling organizations to fulfill their own compliance obligations.

GDPR compliance is ultimately a shared responsibility between the software provider and the organization using the software. We provide a secure technical foundation that enables organizations to work with personal data responsibly and confidently.

Privacy and Security by Design & by Default

Privacy and information security are integrated into our platform from the very first stage of development. We apply the principles of Privacy by Design, Privacy by Default,Security by Design, and Security by Default throughout our software architecture.

This means that privacy protection and security are built into the platform itself rather than being added afterwards.

Strong Authentication

Access to the platform is protected through an enforced password policy requiring strong passwords and periodic password renewal.

For additional protection, the platform supports Two-Factor Authentication (2FA) using Time-based One-Time Passwords (TOTP), significantly reducing the risk of unauthorized access.

Organizations can also integrate the platform with their existing identity management infrastructure through Single Sign-On (SSO), providing secure and centralized authentication for users.

Anonymity by Design

For employee surveys and organizational research, respondent trust is essential. Our platform therefore incorporates technical safeguards that enforce respondent anonymity whenever anonymous participation is required.

This protection is embedded within the application itself, ensuring that individual responses cannot be traced back to specific respondents while still allowing organizations to gain meaningful insights at an aggregated level.

Secure Collaboration

Organizations often need multiple users to access reports and dashboards. Our platform includes built-in authorization structures that enable colleagues to collaborate and share insights while maintaining the confidentiality and anonymity of respondents.

This enables effective teamwork without compromising privacy.

Secure Defaults

Our default configuration is designed to maximize security and privacy from the moment the platform is deployed. Organizations do not need to configure complex security settings to work responsibly with personal data.

By making secure choices the default, we reduce the risk of human error and help organizations maintain a high level of data protection.

Continuous Security

Information security is an ongoing process rather than a one-time implementation. We continuously invest in:

  • Timely deployment of security updates.
  • Continuous monitoring of our infrastructure.
  • Risk management and mitigation.
  • Continuous improvement of security processes.
  • Maintaining the availability and resilience of our services.

Our commitment to continuous improvement ensures that our platform evolves alongside new technologies, emerging threats, and changing regulatory requirements.

Security You Can Trust

Selecting a SaaS platform is about more than functionality alone—it is about trust.

By combining a fully sovereign Dutch hosting chain, proven Open Source technology, ISO/IEC 27001 certification throughout our delivery chain, and software built according to Privacy and Security by Design principles, we provide our customers with a secure and reliable foundation for handling sensitive organizational information.

This allows you to focus on your organization and your people,while we ensure that your data is protected with the highest standards of information security.

Our CRM

For our Customer Relationship Management system (CRM) we use GDPR compliant HubSpot in an EU datacenter.

ISO27001

To guarantee the safety of your data, we are ISO27001 certified. This means that our organisation and technology are set up conform the norms of the ISO27001 framework and that this is frequently audited.

Certificate number K-0220060

Get in touch with us

The first step is done—you’re considering CircleLytics to lead your team with greater impact. Next step, contact us or book a consultation or demo instantly. We’re excited to meet you, learn about your challenges and vision, and explore how we can advance your impact.

Our Location

Dr. Lelykade 22 - Unit 4, 2583CM The Hague, The Netherlands

Phone number

0031 (0)85 401 1161

Please confirm that you are not a robot by completing the reCAPTCHA challenge.