Legal
Privacy Policy
How we collect, store, and protect your data, and what rights you have.
1. Who we are
Domanda is a trading name operated by Lorenzo Darsie, a sole proprietorship (eenmanszaak) registered in the Netherlands.
- Registered address: Hoogstraat 110, 3111 HL Schiedam, The Netherlands
- KVK number: 74562568
- VAT number: NL002499550B72
For privacy-related enquiries, use our contact form and select the GDPR category.
2. Who this policy applies to
This policy covers two distinct groups of people:
- Account holders — people who register on Domanda to create and manage interview configurations. For this data, Domanda is the data controller.
- Respondents — people who participate in an interview created by an account holder. For respondent data, the account holder (the researcher who created the interview) is the data controller, and Domanda acts as a data processor on their behalf. Respondents should read the privacy notice shown at the start of each interview and direct any questions to the researcher who sent them the interview link.
3. Data we collect and why
Account holders
| Data | Purpose | Legal basis |
|---|---|---|
| Username and email address | Account creation, login, and communication about your account | Contract (Art. 6(1)(b)) |
| Password (stored as a one-way hash) | Account authentication | Contract (Art. 6(1)(b)) |
| Interview configurations and prompts | Delivering the interview creation and management service | Contract (Art. 6(1)(b)) |
| Billing information (name, email, payment method via Mollie) | Processing subscription payments and issuing invoices | Contract (Art. 6(1)(b)) |
| Credit balance and transaction history | Tracking usage and applying the correct plan limits | Contract (Art. 6(1)(b)) |
| Contact messages and support threads | Responding to support requests and GDPR enquiries | Contract (Art. 6(1)(b)) |
| Session identifiers and application logs | Security monitoring, fraud prevention, and abuse detection | Legitimate interest (Art. 6(1)(f)) |
Respondents
When someone participates in an interview hosted on Domanda, the following data may be collected on behalf of the account holder (the controller):
- Conversation content — the messages exchanged during the interview.
- Session identifier — a temporary identifier used to associate messages within the same session. This is not linked to a name, email address, or any other personal identifier unless the respondent has a Domanda account.
- Source parameter — how the respondent arrived (e.g. via a shared link or QR code), stored as a non-identifying label.
The account holder determines the purpose and retention of respondent data through the privacy settings they configure for each interview. Domanda processes this data solely on their instructions.
4. Third parties who receive your data
Google Cloud (Vertex AI) — sub-processor
Conversation content is sent to Google Cloud Vertex AI to power the AI interview engine. Google processes this data on our behalf under the Google Cloud Data Processing Addendum. Google is contractually prohibited from using this data to train its models. Data transfers are covered by Standard Contractual Clauses (SCCs). For details, see Google's Data Processing Addendum.
Mollie — independent controller
Payments are processed by Mollie B.V., a licensed payment institution regulated by De Nederlandsche Bank. Mollie acts as an independent data controller for payment data, subject to its own legal obligations under PSD2 and anti-money laundering regulations. We share your billing information with Mollie solely to execute payment transactions. For details of how Mollie handles your data, see Mollie's privacy policy.
Hosting provider
Our servers and database are hosted by Hosting.com on infrastructure located within the European Union. Your data does not leave the EU as part of our hosting arrangement.
Email delivery
Transactional emails (such as invoices and support replies) are sent via our hosting provider's SMTP service. Email content may include your name and email address.
We do not use any other third-party services that receive personal data, and we do not sell personal data to any third party.
5. International data transfers
Conversation content is processed by Google Cloud Vertex AI. While Google operates globally, transfers of personal data outside the European Economic Area are governed by Standard Contractual Clauses approved by the European Commission, providing an equivalent level of protection to that required under GDPR. All other data processing takes place within the EU.
6. Data retention
Account holder data
We retain your account data for as long as your account is active. You may delete your account at any time from the account settings page. On deletion, your configurations and all associated conversation data are permanently wiped. Some billing records (invoices, transaction logs) may be retained for up to 7 years to comply with Dutch financial record-keeping obligations.
Respondent data
Retention of respondent conversation data is determined by the account holder through the privacy settings of each interview configuration. Options range from indefinite retention (until the account holder deletes the data) to automatic deletion after a fixed period. A scheduled process runs daily to delete conversation data that has passed its configured retention window.
7. Cookies
We use only strictly necessary cookies. No analytics, advertising, or tracking cookies are set.
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie (sessionid) | Keeps you logged in and maintains your session state between pages | 14 days |
| CSRF token (csrftoken) | Protects form submissions against cross-site request forgery attacks | 1 year |
Because these cookies are strictly necessary for the service to function, no consent banner is required under the Dutch Telecomwet.
8. Your rights
As a Domanda account holder, you have the following rights under GDPR:
- Access (Art. 15) — you can request a copy of the personal data we hold about you.
- Rectification (Art. 16) — you can ask us to correct inaccurate data.
- Erasure (Art. 17) — you can delete your account and all associated data at any time from the account settings page. For specific erasure requests, use our contact form.
- Portability (Art. 20) — account holders can export interview response data in CSV or JSON format from the dashboard (available for configurations with the appropriate privacy settings). For a copy of your own account data, contact us via the contact form.
- Restriction (Art. 18) — you can ask us to restrict processing of your data in certain circumstances.
- Objection (Art. 21) — you can object to processing based on legitimate interest.
To exercise any of these rights, use our contact form and select the GDPR category. We will respond within 30 days. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
9. Rights for interview respondents
If you participated in an interview hosted on Domanda, the account holder (the researcher who created and shared the interview) is the data controller for your responses. Your GDPR rights in relation to that data should be directed to them, not to Domanda.
Domanda does not hold your name, email address, or any other direct identifier in connection with your responses. Because we cannot identify you from the data we hold, we are not in a position to fulfill rights requests directly (GDPR Art. 11 and Recital 57). The account holder may be able to identify and delete your data if you contact them with sufficient information for them to locate your responses.
If you later created a Domanda account, you can exercise your rights by logging in and using the account deletion feature, which will wipe any conversations linked to your account.
10. Data security
We implement the following technical and organisational measures to protect your data:
- All traffic is encrypted in transit via HTTPS (TLS). HTTP requests are automatically redirected to HTTPS in production.
- Session and CSRF cookies are set with the
Secureflag so they are never transmitted over unencrypted connections. - Passwords are stored as one-way cryptographic hashes and are never stored or logged in plain text.
- Cross-site request forgery (CSRF) protection is enforced on all state-changing requests.
- Clickjacking protection is enforced via
X-Frame-Optionsheaders. - A Content Security Policy is applied to all pages to limit the sources from which scripts and styles can be loaded.
- Transactional emails are sent over TLS-encrypted SMTP connections.
- Access to personal data is restricted to authorised personnel only.
11. Data breaches
In the event of a personal data breach we will notify the Autoriteit Persoonsgegevens within 72 hours as required by GDPR Art. 33, and will inform affected users where required by Art. 34.
12. Changes to this policy
We may update this policy from time to time. We will notify registered account holders of significant changes by email before they take effect. The version history below records all published versions.
| Version | Date | Summary |
|---|---|---|
| 1.0 | June 2026 | Initial full policy replacing the placeholder document. |
| 1.1 | July 2026 | Added a notice that versions in languages other than English and Dutch are courtesy translations. |
13. Contact us
For any questions about this privacy policy or to exercise your rights, use our contact form and select the GDPR category. We aim to respond within 5 business days.