01
Who is responsible for survey data?
For a hosted employee survey, the organization running the survey normally decides why the survey is conducted, which questions are asked, who receives it, how long results are kept, and who can see them. That organization is normally the data controller. Happily processes the data to provide the service and normally acts as a data processor under the organization’s instructions.
Happily is the controller for the account, billing, support, security, and optional website analytics data that we collect for our own business purposes. A self-hosting organization operates its own deployment and is responsible for that deployment’s privacy and security configuration.
02
Data we process
Account data includes email address, optional name and organization details, authentication records, workspace membership, product settings, support communications, and billing references. Stripe processes payment details; Happily does not store full card numbers.
Survey data includes survey questions and settings, answers, optional team selection, a random response identifier, submission time, and completion duration. The response API deliberately does not store a respondent IP address, browser user-agent, name, or email unless the survey creator explicitly asks for identifying information in a question.
Free-text answers may contain personal or sensitive information supplied by the respondent. Respondents should avoid names or sensitive details unless the question makes them necessary, and survey creators should avoid asking for information they do not need.
03
Survey participants
A random identifier is used to store a response, but pseudonymous does not always mean anonymous. Team, department, timing, distinctive written comments, or identifying questions can reveal a person, especially in a small group. Authorized survey owners and collaborators can access response records and exports.
The survey organization is responsible for giving employees an appropriate notice, choosing a lawful basis, limiting access, setting retention, handling employee rights, and using reporting thresholds. Consent is not always the appropriate basis in an employment relationship because it may not be freely given.
To access, correct, restrict, object to, or request deletion of a survey response, contact the organization named on the survey first. If you cannot reach it, email privacy@happily.ai with the survey link and enough information for us to route the request without asking you to disclose your answers by email.
04
Purposes and legal bases
We process hosted survey data to provide the service under our contract with the customer and its documented instructions. We process account, billing, security, and essential communications where necessary to perform a contract, meet legal obligations, or pursue legitimate interests such as preventing abuse and maintaining the service.
Optional product analytics runs only after the visitor grants permission. We do not sell personal data. We do not use customer survey responses for public benchmarking, model training, or unrelated research unless the customer gives separate, documented authorization and the use is permitted by law.
05
AI-assisted reports
When an authorized user asks for an AI report, selected survey scores, categories, and relevant written responses may be sent to Google’s Gemini service to draft summaries, themes, and recommendations. The draft must be reviewed by a person before it is shared. AI output can be incomplete or inaccurate and is not an employment decision.
Survey creators should not include names or unnecessary sensitive details in AI report inputs. Customers that require specific processing locations, zero-retention configurations, or additional contractual controls should confirm those requirements with us before enabling AI reports.
06
Service providers and international transfers
The hosted service uses Supabase for authentication, database, and storage; Vercel for application hosting; Google for AI features and optional analytics; Stripe for payments; and Resend for transactional email. These providers process data for the requested service under their applicable terms and data-processing commitments. The public subprocessor register lists their purposes and location notes.
Providers may process data outside the country where a user is located. Where required, we and our customers must use an appropriate transfer mechanism, such as an adequacy decision or contractual safeguards. Hosting region and vendor configuration should be confirmed in the customer’s Data Processing Agreement before rollout.
07
Retention and deletion
Account and survey data is currently retained while the account or survey remains active, unless the customer deletes a survey or asks us to delete the account. Deleting a survey removes its linked responses and reports from the primary database through cascading database rules. Backup copies may remain for a limited recovery period.
Workspace owners can set response retention from 30 days to 10 years. A daily job removes expired responses and generated reports. Vendor logs, backups, support records, and customer-created exports follow separate operational schedules. Submit a tracked request in Privacy & data settings or contact privacy@happily.ai. We verify identity and explain any lawful retention exception.
08
Security
The hosted service uses HTTPS, Supabase authentication, row-level database access rules, server-side validation for response submission, role-limited report access, expiring share links where configured, and minimum group thresholds for team and pulse reporting.
No system can promise zero risk. Customers must manage user access, revoke former team members, protect exports, avoid overly identifying survey questions, and notify us promptly of suspected incidents. We maintain an incident process so controllers can assess any required regulator and employee notifications.
09
Your privacy rights
Depending on applicable law, you may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a data-protection authority. Some rights depend on the legal basis and may be subject to legal exceptions.
For account data, contact privacy@happily.ai. For employee survey data, contact the organization that ran the survey first because it normally controls the purpose and can identify the relevant survey. We may verify identity before acting on a request and will not ask for more information than necessary.
Contact and privacy requests
Email privacy@happily.ai. Include the type of request and, for a survey, its link or organization name. Do not email survey answers or identity documents until we provide a secure verification method.
See the current subprocessor register for vendors that may handle data when specific features are enabled.
Happily.ai · Bangkok, Thailand · Data protection contact: privacy@happily.ai