Privacy notice
This document explains how MeaningfulCX GmbH ("Meaningful", "we", "us") collects, uses, and protects personal data.
1. Who we are
MeaningfulCX GmbH is a German company providing a qualitative and quantitative research platform to businesses, universities, and research organisations ("Customers").
Legal entity: MeaningfulCX GmbH
Address: Birketweg 45, 80639 Munich, Germany
Registration: HRB 291808, Amtsgericht Munich
Contact: contact@meaningful.app
2. Our role under GDPR
We process personal data in two distinct capacities:
As Data Controller (for platform users)
When you use our platform as a researcher, organisation admin, or team member, we are the data controller for your account data.
We collect:
- Account information (name, email, company)
- Usage data (features accessed, login times)
- Billing information (processed by payment provider)
- Analytics (PostHog, anonymised)
Legal basis: Contract performance (Article 6.1(b)) and legitimate interests (Article 6.1(f)).
As Data Processor (for research participants)
When you participate in a survey or interview created by one of our Customers, we are a data processor and our Customer is the data controller.
What this means:
- Our Customer determines what data to collect and why
- Our Customer is responsible for obtaining your consent
- Our Customer must respond to your GDPR rights requests
- We process your data only on behalf of and according to our Customer's instructions
We process:
- Interview and survey responses
- Optional demographic information (age, occupation, location)
- Quality-assurance data (country, region, city, ISP, timezone, and a one-way hashed IP address) retained for fraud prevention and sample quality purposes — this data cannot be used to identify an individual
- Consent timestamp (recorded when a participant accepts the research consent statement)
- Technical data (device type, timestamps)
To exercise your rights as a research participant:
Contact the organisation that invited you to participate. Their contact information should be provided in the invitation or at the start of the interview or survey.
If you cannot identify the organisation, contact us at contact@meaningful.app and we will assist in forwarding your request.
3. How we process research participant data
Data collection
Research participant data is collected through online interviews (text or voice), surveys and questionnaires, optional demographic forms, and file uploads provided by Customers (such as audio recordings, pre-collected survey data, and documents).
Data storage
All data is stored in the European Union:
- Primary storage: AWS S3 (Frankfurt, Germany)
- Databases: AWS DynamoDB (Frankfurt, Germany)
- Backups: AWS S3 (cross-region to Ireland, within EU)
AI processing
We use artificial intelligence to analyse research data:
- AWS Bedrock (Claude): Text analysis, thematic coding, insight generation — EU (Frankfurt)
- Azure OpenAI (GPT): Text analysis, real-time interview chat, summarisation — EU (Sweden)
- Azure Speech Services: Real-time voice-to-text for AI-moderated interviews (voice audio is not stored; only text transcripts are retained) — EU (Sweden)
Your data is not used to train AI models. AI providers process data in real-time and do not retain it for model improvement.
Data minimisation: All AI processing runs within our own EU cloud infrastructure. Customer Data does not leave our cloud boundary and is not shared with or retained by AI providers. Research participants are typically pseudonymised before they enter the platform, as Customers generally use external panel providers that handle consent and pseudonymisation upstream. Meaningful retains only non-identifying quality-assurance data per response (country, region, city, ISP, timezone, and a one-way hashed IP) which cannot be linked back to an individual.
Data sharing
Your data may be accessed by:
- The Customer: The organisation that invited you has full access to your responses
- Customer's team members: Researchers and analysts designated by the Customer
- Sub-processors: See our sub-processor list
Your data is never shared with other Customers or sold to third parties.
Data retention
Data is retained for as long as the Customer keeps it on the platform. Customers can delete workspaces, projects, and data sources at any time.
- During subscription: Customer controls when to delete data
- Account termination: Data deleted within 90 days after Customer account closure
4. Sub-processors
We engage the following core sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure, AI processing | EU (Frankfurt) |
| Microsoft Azure | AI processing, transcription | EU (Sweden) |
| PostHog | Platform analytics (anonymised) | EU |
| Clerk | Authentication | US (DPF) |
Additional optional sub-processors (Google Gemini, Perplexity AI, Parallel AI) are engaged only when Customers enable specific features. See the full sub-processor list for details.
All sub-processors are bound by data processing agreements with security and confidentiality obligations equivalent to ours. We notify Customers 30 days before engaging new sub-processors.
5. International data transfers
All research participant data is stored and processed exclusively within the European Union (AWS Frankfurt and Azure Sweden).
Platform user data may be processed by Clerk (authentication provider, US). These transfers are covered by the EU–US Data Privacy Framework (DPF) adequacy decision, with Standard Contractual Clauses (SCCs) as fallback.
6. Cookies and tracking technologies
We use cookies and tracking technologies from PostHog to understand how our website and platform are used, measure the effectiveness of our marketing, and improve user experience. You can manage your cookie preferences through your browser settings.
7. Your rights under GDPR
For platform users (we are the Controller)
You have the following rights:
- Right of access (Art. 15): Request a copy of your account data
- Right to rectification (Art. 16): Correct inaccurate data via account settings or by emailing us
- Right to erasure (Art. 17): Delete your account via account settings or by emailing us
- Right to data portability (Art. 20): Export your data in JSON format
- Right to object (Art. 21): Object to processing based on legitimate interests
- Right to lodge a complaint: Contact your supervisory authority
To exercise these rights, email contact@meaningful.app. We will respond within 30 days.
For research participants (Customer is the Controller)
You must contact the organisation that invited you to participate. They are responsible for providing you with a copy of your data, correcting inaccuracies, deleting your data upon request, and responding within 30 days.
If you cannot reach the organisation, email contact@meaningful.app with your email address, the approximate date you participated, the topic of the research, and your request. We will forward your request to the Customer and follow up to ensure they respond.
8. Security measures
- Encryption: TLS 1.3 in transit, AES-256 at rest
- Access control: Multi-factor authentication, role-based access, least privilege
- Monitoring: 24/7 security monitoring, automated threat detection, audit logs
- Testing: Annual penetration testing, quarterly vulnerability scanning
- Certifications: Pursuing SOC 2 Type II and ISO 27001
9. Data breaches
For platform users: We will notify you within 72 hours of becoming aware of a breach affecting your data.
For research participants: We notify the Customer (organisation) within 24 hours. The Customer is responsible for notifying you if required by GDPR.
10. Children's privacy
Our platform is not intended for children under 16. We do not knowingly collect data from children under 16 without parental consent. If you are a Customer conducting research with participants aged 16–17, you must obtain parental consent and comply with local age of consent laws.
11. Changes to this privacy notice
We may update this notice to reflect changes in our practices or legal requirements. Material changes will be communicated to Customers via email at least 30 days before they take effect.
12. Complaints
If you have concerns about our use of your personal data, contact us at contact@meaningful.app. If you remain unhappy, you may complain to your local data protection authority.
Germany (BfDI): www.bfdi.bund.de
EU supervisory authorities: edpb.europa.eu
Last updated: April 2026
For questions or requests regarding this Privacy Notice, please contact us at contact@meaningful.app