Skip to main content

Legal

Privacy policy

What personal data passes through ATFS, why we have it, who else sees it, and what you can make us do about it. Written to be read, not to be survived.

In effect from 15 August 2026. We will post any change here and, where the change is material, tell account holders by email before it takes effect.

Who we are

Afterthought Feedback Services Pvt. Ltd. (“ATFS”, “we”, “us”) is a data research and analysis company registered in India. We build and operate the ATFS survey platform: software our customers use to design questionnaires, collect answers in the field, and analyse what comes back.

This policy explains what personal data passes through that platform, why, for how long, and what you can require us to do about it. It is written against the Digital Personal Data Protection Act, 2023 (“DPDP Act”) — the text of which is published by the Ministry of Electronics and Information Technology at meity.gov.in(opens meity.gov.in in a new tab).

The two roles we play

Almost every question people ask us about privacy has a different answer depending on which of two roles we are in at the time, so it is worth stating plainly before anything else.

Data Fiduciary
For the accounts of the people who sign in to ATFS — names, work email addresses, sign-in records, billing. We decide why and how that data is processed, so we answer for it directly.
Data Processor
For the survey answers our customers collect. The organisation running the survey decides what to ask, who to ask, and what to do with the answers. We hold and process that data on their written instructions and for no purpose of our own.

If you answered someone’s survey and want your responses removed, the organisation that ran the survey is the one who decides. Tell us at privacy@snsurveys.com and we will identify them for you and pass the request on; we cannot delete their data on our own initiative.

What we collect, as a Data Fiduciary

This section covers account holders — the people who sign in to build and read surveys.

Account data
Your name, work email address, organisation name, role, and whether your email has been verified. Provided by you at registration, or by your identity provider if you sign in with Google or Microsoft.
Consent record
The moment you agreed to this policy: a timestamp, your browser's user-agent string, and a one-way SHA-256 hash of your IP address. We store the hash, never the address itself, because the hash is enough to evidence consent and the address is not needed for anything else.
Authentication data
A salted bcrypt hash of your password — never the password. If you sign in through an identity provider we store the provider name and the account identifier it issues, and no password at all.
Usage records
Timestamps of your sign-ins, an audit log of administrative actions taken inside your organisation, and server logs that record request paths and status codes for security and diagnosis.
Billing data
Your plan and payment status. Card details are entered on Razorpay's own checkout and are never sent to, seen by, or stored on our systems.

Survey answers, as a Data Processor

What a survey asks is decided entirely by the organisation running it. Some ask nothing identifying at all; others collect a name, a phone number or a flight reference because the study needs it.

  • Respondents are shown a consent notice before the first question, and the answer to that notice is recorded alongside the response.
  • Every response is stored against the tenant that owns the survey, and isolation between tenants is enforced in the database itself with row-level security — not only in application code.
  • Responses collected offline are held encrypted on the device until the network returns, then synced and cleared.
  • We do not sell survey data, and we do not use one customer's responses to build products, models or benchmarks for anyone else.

Why we process it

Under § 4 of the DPDP Act personal data may be processed only for a lawful purpose, and only with consent or for a legitimate use the Act itself defines. Ours are:

  • To give you the service you asked for — creating your account, keeping you signed in, running your surveys, and showing you the results.
  • To keep the service safe — rate limiting sign-in attempts, detecting abuse, and keeping an audit trail your own administrators can inspect.
  • To bill you, where you are on a paid plan, and to meet the tax and accounting records the law requires us to keep.
  • To tell you things you need to know about your account: a verification link, a password reset, a security notice. These are not marketing and cannot be switched off while the account is open.

We do not run advertising, we do not profile you, and we do not make automated decisions that produce legal effects about you.

Who else touches the data

We use a small number of processors to run the platform. Each one gets the least data that lets it do its job, under contract, and none of them may use it for their own purposes.

Hosting and database
Amazon Web Services, in the Asia Pacific (Mumbai) region. Application data and backups stay in that region.
Payments
Razorpay (India). Receives the order amount and a reference to your organisation. Card details go directly to Razorpay and never through us.
Transactional email
Resend. Receives your email address and the contents of the message being sent to you.
Survey distribution
Where your organisation chooses to send invitations by WhatsApp or SMS, the recipient's phone number and the invitation text are passed to Meta's WhatsApp Cloud API or MSG91 respectively.
AI analysis
Groq (United States). Used only when an analysis feature is invoked. Identifiers are stripped from the text before it leaves our servers — email addresses, phone numbers, Aadhaar, PAN, passport numbers and UPI handles are redacted by a filter that runs on every payload.
Error monitoring and abuse controls
Sentry for application errors and Upstash for rate-limit counters. Both receive technical metadata, not survey content.

We will also disclose data where a law, a court, or a lawfully issued government order requires it. Where we are permitted to tell you that such a request was made, we will.

Where the data lives

Account data, survey definitions, responses and backups are stored in India, in AWS’s Mumbai region. That is a deliberate choice and it is the default for every customer.

Two categories leave India, and we would rather say so here than have you discover it later: the error-monitoring and rate-limiting services described above, which see technical metadata, and the AI analysis provider, which sees redacted survey text at the moment an analysis feature is used. If your organisation cannot accept that, the AI analysis features can be disabled for your tenant on request — write to privacy@snsurveys.com.

How long we keep it

Survey responses
For as long as the organisation that collected them keeps them, subject to a per-tenant retention window that defaults to 24 months. Administrators can shorten it.
Deleted records
Marked deleted immediately and removed permanently after a 90-day grace period, which exists so an accidental deletion can be undone.
Account data
For as long as the account is open. An account with no sign-in for 12 months is deactivated automatically.
Billing records
For the period Indian tax law requires us to retain them, which outlives the account itself.
Security logs
Rotated on a rolling window measured in weeks, not years.

How it is protected

  • Traffic is encrypted in transit with TLS, and data at rest is encrypted by the storage layer.
  • Passwords are stored as salted bcrypt hashes and are never recoverable, by us or by anyone else.
  • Sessions use a signed, HttpOnly, SameSite=Strict cookie with a matching anti-forgery token on every state-changing request.
  • Tenant isolation is enforced by PostgreSQL row-level security, so a query that forgets its tenant filter returns nothing rather than someone else's data.
  • Administrative actions are written to an append-only audit log your own administrators can export.
  • Access to production is restricted to named staff, and reviewed.

No system is perfect. If we become aware of a personal data breach we will notify the Data Protection Board of India and every affected Data Principal as § 8(6) of the DPDP Act requires, without waiting to finish our own investigation first.

Your rights, and how to use them

Chapter III of the DPDP Act gives every Data Principal a set of rights. They are real and we will act on them.

Access (§ 11)
A summary of the personal data we hold about you and who we have shared it with.
Correction and erasure (§ 12)
Have inaccurate data corrected, incomplete data completed, and data erased where we no longer need it for the purpose you gave it for or to meet a legal obligation.
Grievance redressal (§ 13)
Raise a complaint with us and get an answer. You may escalate to the Data Protection Board only after using this route.
Nomination (§ 14)
Nominate someone to exercise these rights on your behalf in the event of your death or incapacity.

To exercise any of them, write to privacy@snsurveys.com from the address the account or the response is associated with. We answer within 30 days, and we will tell you if we need to verify who you are before we act.

If your request concerns a survey run by one of our customers, we pass it to them, because the answers are theirs to decide about. Their administrators handle it through the data-request tools in Settings, which can export or erase everything held for a single respondent.

Withdrawing consent is as easy as giving it. Where withdrawal means we can no longer run part of the service for you, we will say which part before you confirm.

Children

ATFS accounts are for people aged 18 and over. We do not knowingly create accounts for children.

Where a customer designs a survey that will be answered by anyone under 18, § 9 of the DPDP Act applies to them: verifiable parental consent is required, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright. Our Terms make that the customer’s responsibility, and the platform offers no advertising or tracking features of any kind.

Cookies

We set no advertising cookies, no analytics cookies and no third-party trackers. The cookies we do set exist because the product cannot work without them:

sns_session
Your signed-in session. HttpOnly, so no script can read it.
sns_csrf
The anti-forgery token your browser echoes back on state-changing requests.
sns_oauth
A ten-minute value that ties an SSO sign-in to the browser that started it. Deleted the moment the sign-in completes.
NEXT_LOCALE
The language you chose, so a survey link opens in it.
atfs.prefs
Not a cookie — your theme, density and text-size choices, kept in your browser's local storage and never sent to us.

Changes to this policy

This version is in effect from 15 August 2026. When we change it we will update this page and move that date. If a change materially affects how we handle your personal data, we will email account holders before it takes effect rather than relying on you to notice.

Contacting us

For anything about this policy or your personal data, write to privacy@snsurveys.com.

Our Grievance Officer under § 13 of the DPDP Act can be reached at grievance@snsurveys.com. Please include enough detail to identify the account or survey involved. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.

Afterthought Feedback Services Pvt. Ltd.. See also our Terms of Service and our DPDP disclosure.