Legal Framework

Terms of Service

When you create an account with Refiner, you agree to our Terms of Service and Privacy Policy. Both documents are designed with a strong emphasis on data protection, regulatory compliance, and information security.

For Enterprise customers, we offer the option to execute custom agreements, including tailored Data Processing Agreements (DPAs) and additional contractual safeguards as required.

Roles & Responsibilities

Refiner provides the tools and infrastructure to support compliance, but you are responsible for configuring your implementation in accordance with applicable laws.

Generally speaking

  • You (the customer) act as the data controller, deciding what data is collected and how it is used.
  • Refiner acts as the data processor, processing data on your behalf.

This means you are responsible for:

  • Defining the legal basis for data collection
  • Informing users about how their data is used
  • Handling user rights requests (access, deletion, etc.)

Data Protection (GDPR, CCPA, …)

Refiner supports compliance with major international data protection regulations and healthcare standards. Our platform is designed to help you meet your regulatory obligations while maintaining full administrative control over your data.

If you operate in the European Union or process data of EU residents, the General Data Protection Regulation (GDPR) applies.

To stay compliant, you should:

  • Establish a valid legal basis for processing (e.g. legitimate interest or consent)
  • Inform users about data collection in your privacy policy
  • Provide mechanisms for users to access or delete their data

Refiner supports:

  • Data access requests
  • Data deletion requests

We provide multiple technical and organizational mechanisms to support lawful data processing, subject access requests, deletion workflows, and controlled data retention.

For detailed information, please refer to:

Data Security (SOC 2)

Refiner applies industry-standard security measures to protect your data, including:

  • Encrypted data transmission (HTTPS)
  • Secure infrastructure and access controls
  • Ongoing monitoring and best practices for data protection

We work with Scytale to manage our security certification requirements. Audits are performed by an independent third party, Decrypt Compliance.

Refiner has successfully completed a SOC 2 Type II audit every year since 2024, validating the operational effectiveness of our security controls over each respective audit period.

For additional details on our security posture and to request a copy of our SOC 2 report, please refer to:

Consent & Tracking

Depending on how you use Refiner, you may need to obtain user consent before collecting data.

This is especially relevant when:

  • Using the JavaScript SDK in combination with cookies or tracking technologies
  • Operating in jurisdictions with strict consent requirements (e.g. EU ePrivacy Directive)

Refiner’s JavaScript SDK stores an anonymous user token in the browser’s Local Storage to ensure consistent user recognition and correct survey delivery.

No sensitive personal data is stored in Local Storage or cookies by default – only the minimal technical identifiers necessary to operate the SDK.

For more details, please refer to the dedicated documentation page.

You are responsible for:

  • Integrating Refiner with your consent management solution (if applicable)
  • Respecting user preferences regarding tracking and data collection

Accessibility

We are committed to making our surveys accessible to all users by following established accessibility best practices. This includes using semantic HTML, ensuring proper keyboard navigation, and maintaining compatibility with assistive technologies. Accessibility is an ongoing effort, and we continuously work to identify and address potential barriers. We welcome feedback from our users to help us improve and provide a more inclusive experience for everyone.

Was this helpful? Let us know with a quick a vote