Legal
Privacy policy
In effect from 15 August 2026. We will post any change here and, where the change is material, tell account holders by email before it takes effect.
Who we are
Afterthought Feedback Services Pvt. Ltd. (“ATFS”, “we”, “us”) is a data research and analysis company registered in India. We build and operate the ATFS survey platform: software our customers use to design questionnaires, collect answers in the field, and analyse what comes back.
This policy explains what personal data passes through that platform, why, for how long, and what you can require us to do about it. It is written against the Digital Personal Data Protection Act, 2023 (“DPDP Act”) — the text of which is published by the Ministry of Electronics and Information Technology at meity.gov.in(opens meity.gov.in in a new tab).
The two roles we play
Almost every question people ask us about privacy has a different answer depending on which of two roles we are in at the time, so it is worth stating plainly before anything else.
- Data Fiduciary
- For the accounts of the people who sign in to ATFS — names, work email addresses, sign-in records, billing. We decide why and how that data is processed, so we answer for it directly.
- Data Processor
- For the survey answers our customers collect. The organisation running the survey decides what to ask, who to ask, and what to do with the answers. We hold and process that data on their written instructions and for no purpose of our own.
If you answered someone’s survey and want your responses removed, the organisation that ran the survey is the one who decides. Tell us at privacy@snsurveys.com and we will identify them for you and pass the request on; we cannot delete their data on our own initiative.
What we collect, as a Data Fiduciary
This section covers account holders — the people who sign in to build and read surveys.
- Account data
- Your name, work email address, organisation name, role, and whether your email has been verified. Provided by you at registration, or by your identity provider if you sign in with Google or Microsoft.
- Consent record
- The moment you agreed to this policy: a timestamp, your browser's user-agent string, and a one-way SHA-256 hash of your IP address. We store the hash, never the address itself, because the hash is enough to evidence consent and the address is not needed for anything else.
- Authentication data
- A salted bcrypt hash of your password — never the password. If you sign in through an identity provider we store the provider name and the account identifier it issues, and no password at all.
- Usage records
- Timestamps of your sign-ins, an audit log of administrative actions taken inside your organisation, and server logs that record request paths and status codes for security and diagnosis.
- Billing data
- Your plan and payment status. Card details are entered on Razorpay's own checkout and are never sent to, seen by, or stored on our systems.
Survey answers, as a Data Processor
What a survey asks is decided entirely by the organisation running it. Some ask nothing identifying at all; others collect a name, a phone number or a flight reference because the study needs it.
- Respondents are shown a consent notice before the first question, and the answer to that notice is recorded alongside the response.
- Every response is stored against the tenant that owns the survey, and isolation between tenants is enforced in the database itself with row-level security — not only in application code.
- Responses collected offline are held encrypted on the device until the network returns, then synced and cleared.
- We do not sell survey data, and we do not use one customer's responses to build products, models or benchmarks for anyone else.
Why we process it
Under § 4 of the DPDP Act personal data may be processed only for a lawful purpose, and only with consent or for a legitimate use the Act itself defines. Ours are:
- To give you the service you asked for — creating your account, keeping you signed in, running your surveys, and showing you the results.
- To keep the service safe — rate limiting sign-in attempts, detecting abuse, and keeping an audit trail your own administrators can inspect.
- To bill you, where you are on a paid plan, and to meet the tax and accounting records the law requires us to keep.
- To tell you things you need to know about your account: a verification link, a password reset, a security notice. These are not marketing and cannot be switched off while the account is open.
We do not run advertising, we do not profile you, and we do not make automated decisions that produce legal effects about you.
Where the data lives
Account data, survey definitions, responses and backups are stored in India, in AWS’s Mumbai region. That is a deliberate choice and it is the default for every customer.
Two categories leave India, and we would rather say so here than have you discover it later: the error-monitoring and rate-limiting services described above, which see technical metadata, and the AI analysis provider, which sees redacted survey text at the moment an analysis feature is used. If your organisation cannot accept that, the AI analysis features can be disabled for your tenant on request — write to privacy@snsurveys.com.
How long we keep it
- Survey responses
- For as long as the organisation that collected them keeps them, subject to a per-tenant retention window that defaults to 24 months. Administrators can shorten it.
- Deleted records
- Marked deleted immediately and removed permanently after a 90-day grace period, which exists so an accidental deletion can be undone.
- Account data
- For as long as the account is open. An account with no sign-in for 12 months is deactivated automatically.
- Billing records
- For the period Indian tax law requires us to retain them, which outlives the account itself.
- Security logs
- Rotated on a rolling window measured in weeks, not years.
How it is protected
- Traffic is encrypted in transit with TLS, and data at rest is encrypted by the storage layer.
- Passwords are stored as salted bcrypt hashes and are never recoverable, by us or by anyone else.
- Sessions use a signed, HttpOnly, SameSite=Strict cookie with a matching anti-forgery token on every state-changing request.
- Tenant isolation is enforced by PostgreSQL row-level security, so a query that forgets its tenant filter returns nothing rather than someone else's data.
- Administrative actions are written to an append-only audit log your own administrators can export.
- Access to production is restricted to named staff, and reviewed.
No system is perfect. If we become aware of a personal data breach we will notify the Data Protection Board of India and every affected Data Principal as § 8(6) of the DPDP Act requires, without waiting to finish our own investigation first.
Your rights, and how to use them
Chapter III of the DPDP Act gives every Data Principal a set of rights. They are real and we will act on them.
- Access (§ 11)
- A summary of the personal data we hold about you and who we have shared it with.
- Correction and erasure (§ 12)
- Have inaccurate data corrected, incomplete data completed, and data erased where we no longer need it for the purpose you gave it for or to meet a legal obligation.
- Grievance redressal (§ 13)
- Raise a complaint with us and get an answer. You may escalate to the Data Protection Board only after using this route.
- Nomination (§ 14)
- Nominate someone to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of them, write to privacy@snsurveys.com from the address the account or the response is associated with. We answer within 30 days, and we will tell you if we need to verify who you are before we act.
If your request concerns a survey run by one of our customers, we pass it to them, because the answers are theirs to decide about. Their administrators handle it through the data-request tools in Settings, which can export or erase everything held for a single respondent.
Withdrawing consent is as easy as giving it. Where withdrawal means we can no longer run part of the service for you, we will say which part before you confirm.
Children
ATFS accounts are for people aged 18 and over. We do not knowingly create accounts for children.
Where a customer designs a survey that will be answered by anyone under 18, § 9 of the DPDP Act applies to them: verifiable parental consent is required, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright. Our Terms make that the customer’s responsibility, and the platform offers no advertising or tracking features of any kind.
Changes to this policy
This version is in effect from 15 August 2026. When we change it we will update this page and move that date. If a change materially affects how we handle your personal data, we will email account holders before it takes effect rather than relying on you to notice.
Contacting us
For anything about this policy or your personal data, write to privacy@snsurveys.com.
Our Grievance Officer under § 13 of the DPDP Act can be reached at grievance@snsurveys.com. Please include enough detail to identify the account or survey involved. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
Afterthought Feedback Services Pvt. Ltd.. See also our Terms of Service and our DPDP disclosure.