All customer data is stored on servers within the European Union. No exceptions.
Hosting region, encryption posture, and US-transfer stance stated plainly below, the sentence your DPO can copy into the assessment.
Data is processed and stored in [EU region, verify]. Transfers outside the EU/EEA are contractually and technically restricted. Our stance on US cloud legislation is documented and available to procurement.
Minimum group sizes are enforced on every aggregate view, so no staff member can single out an individual answer from ordinary reporting. Identifying students is optional: institutions can run StudentPulse fully anonymous, or connect student identities so support and follow-up can be personal. Whichever you choose, access is role-based and governed by your configuration.
Built for European institutions from day one: standard DPA, current subprocessor list, records of processing, and data-deletion guarantees. No retrofitted compliance.
The document room
Everything procurement asks for, in one place. All documents are public and download directly, no NDA, no request form, no waiting on sales.
A question the page didn't answer?
Your DPO can talk directly to ours: privacy@studentpulse.io