This article outlines the privacy policy disclosures you should consider when using Novella to survey your customers and website visitors. It's written for teams running NPS, CSAT, or CES surveys through hosted survey pages, the embeddable widget, or email surveys.
This is general guidance, not legal advice. Your specific obligations depend on your business, your markets, and how you configure Novella. Talk to your legal counsel or DPO before finalizing your policy.
Under GDPR, you (the business collecting feedback) are the data controller. Novella acts as your data processor. Your privacy policy should name Novella (or describe it as a customer feedback platform provider) in the section listing the processors or service providers who handle personal data on your behalf.
If you maintain a subprocessor list or a "who we share data with" section, include:
Depending on how you've configured your surveys, Novella may collect:
Your policy should describe these categories in plain language so visitors and customers understand what's collected when they respond to a survey or interact with the widget on your site.
Common legal bases for customer feedback surveys include:
If you rely on legitimate interest, be prepared to explain the balancing test you've done (this doesn't need to be in the public policy, but you should have it documented internally).
If you're using Novella's embeddable widget on your website, it may use cookies or browser storage to avoid showing the same survey repeatedly to the same visitor and to track response state. This needs a mention in your cookie policy or cookie banner, not just your privacy policy, including:
Novella's infrastructure runs in the EU (Hetzner, Frankfurt), and its analytics layer (Tinybird) is also EU-hosted (Frankfurt). If all your processing stays within Novella's EU infrastructure, your transfer disclosures are simpler. If you use integrations that send survey data to non-EU tools (certain CRMs, BI platforms, or your own downstream systems), disclose those transfers and the safeguard used (e.g. Standard Contractual Clauses).
Decide how long you keep survey responses and respondent data, and state it. Common approaches:
Your policy should reflect whatever retention setting you actually use, not a generic placeholder.
Include the standard GDPR rights section if you don't already have one: access, rectification, erasure, restriction, portability, and objection. Make clear how a respondent can ask you to delete their feedback data, since these requests come to you as the controller, not to Novella directly. You're responsible for relaying deletion or access requests to Novella if needed.
If you've signed a Data Processing Agreement (DPA) with Novella, you can reference that your processor relationships are governed by DPAs consistent with Article 28 GDPR. You don't need to publish the DPA itself, just note that one is in place.
If you need documentation to support your privacy policy update, our sales or support team can provide our subprocessor list, DPA, and security overview on request.