Privacy Policy
Effective: September 2026
1. Overview
FieldData is a research data collection platform built with privacy by design. For self-hosted deployments, you are the data controller and your data never touches our servers. For hosted deployments, the operator processes data on your behalf to provide the Service, in accordance with this Privacy Policy and the arrangements you accept with that operator.
2. Data We Collect
Account data: your name, email address, and assigned role. We do NOT access the contents of the forms or records you collect — those are accessible only to authorized users within your organization. Usage data: aggregated, anonymized metrics used to improve the Service (e.g., number of forms created, records collected). We never sell or rent your data, and we do not share it with third parties for their own marketing or commercial purposes. Limited processing by configured service providers (for example, when you choose to use an optional AI-assisted feature such as audio transcription) is described in Section 8 — that processing happens only when you use such a feature and only for the content needed to deliver it.
3. How We Use Your Data
To provide and maintain the Service, administer any plan you subscribe to, send security and account notifications, improve platform performance and features, comply with legal obligations that apply to the operator, and respond to your support requests via WhatsApp. We follow data minimization principles — only what is necessary to operate the Service is collected.
4. Data Storage & Security
FieldData provides role-based access control, audit logging, consent tracking, and optional application-level encryption for designated sensitive fields. The overall security of a deployment — including transport encryption (HTTPS), database and backup encryption, operational access controls, and security assessments — depends on how and where the Service is deployed and is the responsibility of the deployment operator. Contact the operator for the specifics of their arrangements.
5. Data Retention & Deletion
Retention is primarily under your control: self-hosted deployments store data in your own infrastructure, and within any deployment the operator can configure per-project retention and purge rules that archive or delete approved records automatically. You may also export or delete data through the in-product tooling, or request account deletion via the support channel. Any account-level retention commitments for a hosted arrangement are stated in its service agreement.
6. Your Rights
Depending on the law that applies to your deployment, research participants and account holders may have rights to access, rectify, export, or erase personal data, restrict or object to processing, or withdraw consent. FieldData provides tooling (exports, deletion, consent records) that helps honor these rights. To exercise rights, contact the operator of the deployment that holds the data, or the support channel below. Response commitments are defined by the operator or your service agreement.
7. Cookies & Tracking
We use only essential cookies required for authentication, user preference (e.g., theme selection), and short-lived submission confirmations. We do NOT use analytics, advertising, or tracking cookies. We do not share cookie data with third parties. See our Cookie Policy for details.
8. Third-Party Services
Where enabled, optional features rely on third parties: infrastructure hosting, AI model inference (for optional AI-assisted features such as audio transcription and the research assistant), and academic literature search providers. When you use such a feature, the content needed to deliver it — for transcription, the audio recording submitted with a record field — is sent to the configured provider for processing; the disclosure inside each feature explains what is sent before you use it. These providers process content only to deliver the feature you invoked; we do not sell or rent your data, and providers are not given your data for their own commercial purposes. Provider arrangements and safeguards are selected and maintained by the deployment operator.
9. International Data Transfers
Where data is transferred across borders depends on the hosting provider, regions, and contracts chosen by the deployment operator. Self-hosted deployments transfer data only where you choose to host or access it. Transfer safeguards for a hosted arrangement are described in its service agreement.
10. Contact & Privacy Inquiries
For privacy questions or data subject requests, contact the operator of your deployment. For the Community edition, contact us via WhatsApp at +233 507 363 199. We are committed to handling privacy inquiries promptly and transparently.
