CircleLytics (a trademark of Dutch-domiciled GroupStrat B.V.) processes Personal Identifyable Information (PII) of subjects (invitees/respondents) of online Dialogues (online questionnaires).
Besides your IP address (for security auditing) we do not store any personal information on our website, other than the information that is mentioned in our Cookie Policy. Your IP address will remain a maximum of 30 days at our website hosting.
Information that is filled in on our contact form or demo request form is solely used for the response to that request.
Information is one of an organization’s most valuable assets. Our customers rely on us to ensure that their data is processed securely,handled responsibly, and only accessible to authorized users. That is why information security is not an additional feature of our platform—it is a fundamental principle underlying every aspect of our service.
Our SaaS platform operates within a hosting chain that is entirely Dutch-owned. This allows us to maintain full transparency regarding the organizations involved in delivering our services while ensuring that every party meets the highest standards for security, reliability, and operational continuity.
Your data is processed within a controlled environment whereconfidentiality, integrity, and availability are safeguardedthroughout the entire service chain.
The technology powering our platform is built on proven Open Source software. This is a deliberate strategic choice.
Open Source offers significant advantages for Information Security
Information security extends beyond our own organization. We,together with every organization in our hosting chain, are certified according to ISO/IEC 27001, the internationally recognized standard for Information Security Management Systems(ISMS).
This means that information security risks are systematically identified, managed, monitored, and continuously improved throughout the complete delivery chain.
For our customers, this provides confidence that information security is embedded at every level of our service—not just within our own organization.
Our platform has been designed to help organizations process personal data in accordance with the requirements of the General Data Protection Regulation (GDPR).
It provides the technical safeguards and functionality needed to support responsible processing of personal information while enabling organizations to fulfill their own compliance obligations.
GDPR compliance is ultimately a shared responsibility between the software provider and the organization using the software. We provide a secure technical foundation that enables organizations to work with personal data responsibly and confidently.
Privacy and information security are integrated into our platform from the very first stage of development. We apply the principles of Privacy by Design, Privacy by Default,Security by Design, and Security by Default throughout our software architecture.
This means that privacy protection and security are built into the platform itself rather than being added afterwards.
Access to the platform is protected through an enforced password policy requiring strong passwords and periodic password renewal.
For additional protection, the platform supports Two-Factor Authentication (2FA) using Time-based One-Time Passwords (TOTP), significantly reducing the risk of unauthorized access.
Organizations can also integrate the platform with their existing identity management infrastructure through Single Sign-On (SSO), providing secure and centralized authentication for users.
For employee surveys and organizational research, respondent trust is essential. Our platform therefore incorporates technical safeguards that enforce respondent anonymity whenever anonymous participation is required.
This protection is embedded within the application itself, ensuring that individual responses cannot be traced back to specific respondents while still allowing organizations to gain meaningful insights at an aggregated level.
Organizations often need multiple users to access reports and dashboards. Our platform includes built-in authorization structures that enable colleagues to collaborate and share insights while maintaining the confidentiality and anonymity of respondents.
This enables effective teamwork without compromising privacy.
Our default configuration is designed to maximize security and privacy from the moment the platform is deployed. Organizations do not need to configure complex security settings to work responsibly with personal data.
By making secure choices the default, we reduce the risk of human error and help organizations maintain a high level of data protection.
Information security is an ongoing process rather than a one-time implementation. We continuously invest in:
Our commitment to continuous improvement ensures that our platform evolves alongside new technologies, emerging threats, and changing regulatory requirements.
Selecting a SaaS platform is about more than functionality alone—it is about trust.
By combining a fully sovereign Dutch hosting chain, proven Open Source technology, ISO/IEC 27001 certification throughout our delivery chain, and software built according to Privacy and Security by Design principles, we provide our customers with a secure and reliable foundation for handling sensitive organizational information.
This allows you to focus on your organization and your people,while we ensure that your data is protected with the highest standards of information security.
For our Customer Relationship Management system (CRM) we use GDPR compliant HubSpot in an EU datacenter.
To guarantee the safety of your data, we are ISO27001 certified. This means that our organisation and technology are set up conform the norms of the ISO27001 framework and that this is frequently audited.
Certificate number K-0220060

Our Location
Dr. Lelykade 22 - Unit 4, 2583CM The Hague, The Netherlands
Phone number
0031 (0)85 401 1161