Security & privacy

Elly asks your people what is really going on, and they only speak freely when their words are safe. Here is what we do to keep them safe, in plain words.

Beveiliging & privacy

Elly vraagt je mensen wat er echt speelt, en ze praten alleen vrijuit als hun woorden veilig zijn. Hier lees je wat we doen om ze veilig te houden, in gewone taal.

Keeping your data safe

For participants

Everyone Elly talks to

Say what you think. Your words are handled with care, from the conversation to the report.

  • Reports show what your team or a larger group said, never your name
  • Your invitation link is personal and expires
  • Every connection is encrypted, from your phone to our database
  • Your organisation never sees your own answers without your consent
Read our privacy policy

For organisations

HR and change management

You stay in charge of your people's data. We process it for you.

  • You are the controller, we are the processor
  • Our agreement sets out how we handle your data, under the GDPR
  • Hosted on Microsoft Azure, in the EU
  • Your team logs in with a password, participants with a personal link
  • We fill in your IT team's security questionnaire
Read our terms

Je gegevens veilig

Voor deelnemers

Iedereen met wie Elly praat

Zeg wat je denkt. We gaan zorgvuldig om met je woorden, van het gesprek tot het rapport.

  • Rapporten tonen wat je team of een grotere groep zei, nooit je naam
  • Je uitnodigingslink is persoonlijk en verloopt
  • Elke verbinding is versleuteld, van je telefoon tot onze database
  • Je organisatie ziet je eigen antwoorden nooit zonder jouw toestemming
Lees onze privacyverklaring

Voor organisaties

HR en verandermanagement

Jij houdt de regie over de gegevens van je mensen. Wij verwerken ze voor jou.

  • Jij bent verwerkingsverantwoordelijke, wij zijn verwerker
  • Onze overeenkomst legt vast hoe we met je gegevens omgaan, onder de AVG
  • Gehost bij Microsoft Azure, in de EU
  • Je team logt in met een wachtwoord, deelnemers met een persoonlijke link
  • We vullen de securityvragenlijst van je IT-team in
Lees onze voorwaarden

Compliance & certificates

Every conversation falls under the GDPR. You decide what happens with the data; we only process it for you, as our agreement sets out.

  • GDPR

    Controller and processor

    A full data processing agreement can be drafted immediately on request

    In place
  • Hosting

    Microsoft Azure

    Our host holds ISO 27001 and SOC 2

    In place
  • Your IT team

    Security questionnaire

    On request

    Upon request
  • Our own certificate

    ISO 27001 or SOC 2

    In process

    In process

Compliance & certificaten

Elk gesprek valt onder de AVG. Jij bepaalt wat er met de gegevens gebeurt; wij verwerken ze alleen voor jou, zoals onze overeenkomst vastlegt.

  • AVG

    Verantwoordelijke en verwerker

    Een volledige verwerkersovereenkomst kan direct op verzoek worden opgesteld

    Geregeld
  • Hosting

    Microsoft Azure

    Onze host heeft ISO 27001 en SOC 2

    Geregeld
  • Je IT-team

    Securityvragenlijst

    Op verzoek

    Op verzoek
  • Eigen certificaat

    ISO 27001 of SOC 2

    In uitvoering

    In uitvoering

Security at every step

  • Encrypted connections

    Every connection is encrypted, including the one to our database. The database uses Azure's standard encryption.

  • Personal links

    Participants need no account: each gets a personal link that expires. Your team logs in with a password.

  • Access by role

    Only a few authorised staff at Elephants in the Room can open the answers. Your organisation sees anonymised results.

  • Report a security issue

    Found a weakness? Tell us through our contact page and we follow it up with you.

Beveiliging bij elke stap

  • Versleutelde verbindingen

    Elke verbinding is versleuteld, ook die met onze database. De database gebruikt de standaardversleuteling van Azure.

  • Persoonlijke links

    Deelnemers hebben geen account nodig: ieder krijgt een persoonlijke link die verloopt. Je team logt in met een wachtwoord.

  • Toegang per rol

    Alleen een paar bevoegde medewerkers bij Elephants in the Room kunnen de antwoorden openen. Je organisatie ziet geanonimiseerde resultaten.

  • Meld een beveiligingsprobleem

    Een zwakke plek gevonden? Meld het via onze contactpagina en we pakken het met je op.

Before you start

What your compliance officer, works council and IT team will ask.

Every question, answered in one line. Open one to read the answer.

Your compliance officer

Is it GDPR proof?

As our terms set out under the GDPR:

  • Your role: you stay responsible for the data, as the controller
  • Our role: we only process it for you
  • Processing agreement: a full one is ready on request
Will you help us document the processing?

Yes.

  • We document with you: the personal data, the people it concerns and how it is processed, as the law requires or you ask
Where is our data stored?

In the EU.

  • Location: all our data is stored in the EU
  • Database: runs on Microsoft Azure
  • Outside the EEA: if personal data ever leaves it, the EU standard contractual clauses apply
Who else handles it?

A few suppliers help us run Elly.

  • Agreements: they are bound to our instructions
  • Your data: handled only as our agreement with you sets out, as you allow in writing, or as the law requires
  • The list: ask us for it: who, what for and where
How long do you keep it?

You stay in control.

  • Your role: your organisation is the controller; we only process on your behalf
  • During the agreement: we keep the data while it runs
  • After it ends: can be destroyed no later than 30 days after a request, as our privacy policy sets out

Your people

Can my people be recognised?

Not by name.

  • Reports: only per team or larger group, never who said what
  • Small groups: combined automatically, so each stays anonymous
  • Individual answers: nobody in your organisation sees them without their consent

Your works council

What do we tell our works council?

What Elly asks, who sees what, and how long we keep it. Send us their questions and we answer each one in writing.

  • Purpose: your organisation sets it, as the controller; we only process for you
  • Anonymity: we report only per team or larger group, and combine smaller groups automatically into groups of 10 to 20 people where reasonably possible
  • Who sees what: nobody in your organisation sees individual answers without consent; at Elephants in the Room, only a few authorised staff
  • Retention: while our agreement runs, destroyed no later than 30 days after it ends
Who sees the answers?

Everything is anonymised.

  • Your organisation: nobody sees individual answers, unless your colleagues gave their consent
  • Elephants in the Room: only a few authorised staff can access them
  • Reports: only per team or larger group
  • Small groups: combined automatically into one large enough to stay anonymous, 10 to 20 people where reasonably possible

Your IT team

Our IT team has a security compliance questionnaire.

Please send it. We fill it in.

  • Data location: in the EU
  • Encryption: every connection, and the database at rest
  • Access: only a few authorised staff can open the answers; your team logs in with a password, each participant gets a personal link
  • Sub-processors: only as agreed with you, list on request
  • Incidents: we tell you promptly, so you can report within your 72 hours
  • Certification: ISO 27001 or SOC 2 of our own is in process; our host, Microsoft Azure, holds both
  • Compliance checks: on reasonable request, we give you the information you need to check that we comply

Questions from your compliance officer or IT team?

Send us your questions

Voordat je begint

Wat je compliance officer, OR en IT-team gaan vragen.

Elke vraag, in één regel beantwoord. Open er een om het antwoord te lezen.

Je compliance officer

Is het AVG-proof?

Zoals onze voorwaarden onder de AVG vastleggen:

  • Jouw rol: jij blijft verantwoordelijk voor de gegevens, als verwerkingsverantwoordelijke
  • Onze rol: wij verwerken ze alleen voor jou
  • Verwerkersovereenkomst: een volledige ligt op verzoek klaar
Helpen jullie ons de verwerking vast te leggen?

Ja.

  • We leggen samen met je vast: om welke persoonsgegevens het gaat, om wie ze gaan en hoe ze verwerkt worden, zoals de wet vereist of jij vraagt
Waar staan onze gegevens?

In de EU.

  • Locatie: al onze gegevens staan in de EU
  • Database: draait op Microsoft Azure
  • Buiten de EER: gaan persoonsgegevens er ooit buiten, dan gelden de standaardcontractbepalingen van de EU
Wie werkt er nog meer mee?

Een paar leveranciers helpen ons Elly te laten draaien.

  • Overeenkomsten: ze zijn gebonden aan onze instructies
  • Je gegevens: alleen verwerkt zoals onze overeenkomst met jou vastlegt, zoals jij schriftelijk toestaat, of zoals de wet vereist
  • De lijst: vraag ons erom: wie, waarvoor en waar
Hoe lang bewaren jullie het?

Jullie houden de regie.

  • Jullie rol: je organisatie is verwerkingsverantwoordelijke; wij verwerken alleen namens jullie
  • Tijdens de overeenkomst: we bewaren de gegevens zolang die loopt
  • Na afloop: kunnen uiterlijk 30 dagen na een verzoek vernietigd worden, zoals onze privacyverklaring vastlegt

Je mensen

Zijn mijn mensen herkenbaar?

Niet bij naam.

  • Rapporten: alleen per team of grotere groep, nooit wie wat zei
  • Kleine groepen: automatisch samengevoegd, zodat elke groep anoniem blijft
  • Losse antwoorden: niemand in je organisatie ziet ze zonder hun toestemming

Je OR

Wat vertellen we onze OR?

Wat Elly vraagt, wie wat ziet en hoe lang we het bewaren. Stuur ons hun vragen en we beantwoorden ze allemaal op papier.

  • Doel: je organisatie bepaalt het, als verwerkingsverantwoordelijke; wij verwerken alleen voor jou
  • Anonimiteit: we rapporteren alleen per team of grotere groep, en voegen kleinere groepen automatisch samen tot groepen van 10 tot 20 mensen, waar redelijkerwijs mogelijk
  • Wie ziet wat: niemand in je organisatie ziet losse antwoorden zonder toestemming; bij Elephants in the Room alleen een paar bevoegde medewerkers
  • Bewaartermijn: zolang onze overeenkomst loopt, uiterlijk 30 dagen na afloop vernietigd
Wie ziet de antwoorden?

Alles is geanonimiseerd.

  • Je organisatie: niemand ziet losse antwoorden, tenzij je collega's daar toestemming voor gaven
  • Elephants in the Room: alleen een paar bevoegde medewerkers kunnen erbij
  • Rapporten: alleen per team of grotere groep
  • Kleine groepen: automatisch samengevoegd tot een groep die groot genoeg is om anoniem te blijven, waar redelijkerwijs mogelijk 10 tot 20 mensen

Je IT-team

Ons IT-team heeft een vragenlijst over security en compliance.

Stuur hem gerust op. We vullen hem in.

  • Opslag: in de EU
  • Versleuteling: elke verbinding, en de database zelf
  • Toegang: alleen een paar bevoegde medewerkers kunnen de antwoorden openen; je team logt in met een wachtwoord, elke deelnemer krijgt een persoonlijke link
  • Subverwerkers: alleen zoals met jou afgesproken, lijst op verzoek
  • Incidenten: we laten het je onverwijld weten, zodat jij binnen je eigen 72 uur kunt melden
  • Certificering: eigen ISO 27001 of SOC 2 is in uitvoering; onze host, Microsoft Azure, heeft ze allebei
  • Controle: op redelijk verzoek geven we je de informatie die je nodig hebt om te controleren dat we ons aan onze afspraken houden

Vragen van je compliance officer of IT-team?

Stuur je vragen