At a glance
efiner is designed to help you collect user feedback in a privacy-conscious and compliant way. This page outlines how Refiner handles data and what you need to consider when using the product.
When using Refiner, you may send and process user data such as identifiers, attributes (traits), and survey responses. Depending on your use case and location, this data may be subject to data protection regulations.
Here is a quick overview of what Refiner provides to help you stay compliant:
- Data hosting: AWS (eu-west-1, Ireland)
- Data residency: All user data is stored and processed within the European Union
- Data protection frameworks: GDPR, CCPA & HIPAA compliant
- Data processing role: Refiner acts as a data processor for your user data; you remain the data controller
- Data control: You have control over data retention, deletion, and export
- Sub-processors: By default, no user data is processed by third-party sub-processors other than our hosting provider
- SOC 2 Type II: Certified infrastructure and controls (request report here)
- Penetration Testing: Regular PenTests are conducted by independent third parties (request latest report here)
- Encryption: All data is transmitted and stored encrypted (In-Transit & At-Rest)
- Authentication: SAML 2.0 Single Sign-On (SSO) supported
- Integrations: Data sharing with third-party tools is fully controlled by you
If you require additional documentation, security questionnaires, or compliance attestations, please contact our team.