Security and privacy

Anonymity that does not depend on anyone keeping a promise

Orgpuls promises that nobody can see who answered what. That promise is built into how the data is stored, not into a routine someone has to follow. Here is what that means in practice.

From NOK 265/month excl. VAT · 15 days free · No card · Answers stored in the EUNo department is shown until at least five have answered.

What we store, and what we do not

For each employee, the register holds name, e-mail and group, and a mobile number if you use SMS. The answer itself is stored in a table that has no column that could hold a link to a person. The row holds which round the answer belongs to, which group the person is in, and the hour it was submitted, rounded to the hour.

The invitation link is looked up by a cryptographic checksum when it is used. The invitation records that it has been used, so the reminder does not go to you – but never which answer it gave. There is no view, export or query that can say what a named person answered – not even for administrators – because the information does not exist.

Five answers, or a dash

No group is shown until at least five have answered. The limit is enforced by the database and cannot be lowered, only raised. When the figures for the other groups would reveal a hidden group, one more group is held back, so nobody can calculate their way there.

Comments and conversations

A comment is shown only when the group it comes from has enough answers, and the group never travels with the comment. The writer gets a private key to the conversation; the database stores only a checksum of it. If a manager wants to talk directly, they can ask – but only the employee can make themselves known, by writing from their own e-mail.

Legal basis

The legal basis is legal obligation, GDPR article 6(1)(c), with sections 3-1 and 4-3 of the Working Environment Act – not consent, because an employee cannot consent freely to their employer. The questions are designed to avoid health information, which an employer shall not collect. The screening for offensive behaviour and for violence and threats is reported only as a count.

Storage

  • The data is stored on servers in the EU (Frankfurt), under the GDPR
  • Answers are not shared with third parties, and no answers are used to train models
  • A single answer cannot be retrieved or deleted on its own, because it cannot be linked to a person (GDPR article 11)

Data processing agreement

The organisation is the controller, and Orgpuls AS is the processor. The data processing agreement under GDPR Article 28 is in Orgpuls under Settings, where the managing director reads and signs it, and can print or save it as PDF. The sub-processors are Supabase (database and sign-in, Frankfurt), Vercel (hosting, Frankfurt) and Brevo (e-mail and SMS).

Try it on your own undertaking

Enter the organisation number and we fetch the rest from the Norwegian company register. You are up and running in three minutes, and do not need to give card details before you have decided.

Get started freeFrom NOK 265/month excl. VAT · 15 days free · No card · Answers stored in the EU
Security, privacy and anonymity | Orgpuls