GDPR Compliance

How Insightum.ai upholds the EU General Data Protection Regulation.

Last updated: February 2026

The General Data Protection Regulation (GDPR) is the cornerstone of EU data protection law. At Insightum.ai, we don't treat GDPR as a checkbox — it's a foundational principle that shapes every aspect of our platform, from how we collect data to how we build our AI systems.

Privacy by Design and Default

Every feature we build starts with privacy in mind. We collect only the minimum data necessary for each purpose (data minimization). Respondent data is anonymous by default — no personal identifiers are shared with researchers unless explicitly consented. Our systems are designed so that privacy is the default setting, not an afterthought.

Lawful Processing

We process personal data under clearly defined legal bases: consent (Article 6(1)(a)) for respondent participation in interviews, contract performance (Article 6(1)(b)) for delivering services to our researcher users, and legitimate interest (Article 6(1)(f)) for platform improvement and security. Each processing activity is documented and justified.

Data Subject Rights

Both researchers and respondents can exercise their full GDPR rights: the right to access their data, the right to rectification, the right to erasure ('right to be forgotten'), the right to restrict processing, the right to data portability, and the right to object. Respondents can withdraw consent at any time, and we make this process simple and immediate.

Data Protection Measures

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). We maintain strict access controls — only authorized personnel can access personal data. All infrastructure is hosted exclusively in EU data centers, ensuring your data never leaves European jurisdiction. We conduct regular Data Protection Impact Assessments (DPIAs) for high-risk processing activities.

Sub-processors

We work with a limited number of GDPR-compliant sub-processors: Cint (respondent recruitment), ElevenLabs (voice technology), Google Cloud (AI processing), and Stripe (payments). Each sub-processor is bound by a Data Processing Agreement (DPA) that ensures equivalent data protection standards. We regularly review our sub-processors' compliance.

Breach Notification

In the event of a personal data breach, we will notify the relevant supervisory authority (the Slovak Data Protection Authority) within 72 hours of becoming aware of the breach. If the breach poses a high risk to individuals' rights and freedoms, we will notify affected data subjects without undue delay.

Contact Our Data Protection Team

For any GDPR-related inquiries, data access requests, or concerns, contact us at info@insightum.ai. Our data controller is CE Fidelity Slovakia, s.r.o., Špitálska 2, 811 08 Bratislava, Slovakia. You also have the right to lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR).