Come to visit
Strandveien 55,
1366 Lysaker – Oslo Norway
Org: 997 906 314
Last update: 27 July 2026
This policy applies to people invited to or participating in surveys conducted by InFact or through the InFact survey platform. It also applies when you contact us about a survey or provide contact details for a prize draw or other survey incentive. Survey-specific information shown in the invitation or at the start of a survey supplements this policy.
InFact AS (“InFact”, “we”, “us”, “our”) conducts market research, opinion research and other surveys for our own purposes and on behalf of customers. This policy explains how personal data relating to survey respondents is collected, used, shared, protected and retained.
You do not create a platform account to answer a survey. Respondents normally receive a survey link by email or SMS, are invited by telephone, or take part through an automated voice survey (IVR). You can review this policy on our website and through links provided with survey invitations where available.
The survey invitation, introduction or project-specific privacy notice may provide additional details, including the identity of the customer responsible for the survey, the purpose, the source of your contact details, whether the survey is anonymous, and any project-specific retention period. If project-specific information differs from this general policy, the project-specific information applies to that survey.
When InFact is the data controller. InFact is the controller when we determine why and how personal data is processed, for example for InFact’s own surveys, survey-related inquiries, security logs, or administration of an incentive that we organise.
When a customer is the data controller. For many customer surveys, the customer commissioning the survey determines the purpose, questions, respondent group and use of the results. InFact then normally acts as a data processor and processes personal data only on the customer’s documented instructions and under a data processing agreement. The customer’s identity will normally be stated in the survey invitation, introduction or project-specific privacy notice.
When roles are shared or separate. In limited cases, InFact and another organisation may each be controllers for separate parts of the processing or may act as joint controllers. Where relevant, this will be explained in the survey-specific information.
InFact AS
Organisation number: 983 067 999
Strandveien 55
1366 Lysaker – Oslo
Norway
Email: post@infact.no
Website: infact.no
Data Protection Officer: Iryna Lazorenko
Email: iryna@infact.no
Participation in surveys is normally voluntary unless the survey invitation clearly states otherwise. You may choose not to participate, stop before submitting your response, or leave optional questions unanswered. Some questions may be marked as required because an answer is necessary for the survey flow or analysis; you can still choose not to complete the survey.
You are not required to create an account. If you do not provide information requested in a survey, the consequence is normally only that your response may be incomplete or cannot be submitted. Any other consequence will be explained before the information is collected.
After a response has been submitted, it may not always be possible to remove it, especially if the response was collected anonymously or has already been anonymised and can no longer be linked to you.
Depending on the survey, we may obtain personal data:
Current or project-specific respondent source providers may include:
The source may vary by customer, country, sample method and survey type. The survey invitation or project-specific notice may identify the source. You may also contact us for information about the source used in a particular case.
Depending on the survey and how it is conducted, we may process the following categories:
Some surveys may ask about sensitive subjects or special categories of personal data under GDPR Article 9. This can include information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data used for identification, health information, or information concerning sex life or sexual orientation.
Such information is processed only when it is necessary for the defined survey or research purpose, there is a valid legal basis and an applicable Article 9 condition, and appropriate safeguards are in place. These safeguards may include data minimisation, confidentiality obligations, restricted access, separation of contact details from responses, pseudonymisation, anonymisation and defined deletion periods.
Where InFact acts as processor, the customer is responsible for determining the lawful basis and Article 9 condition. Where InFact acts as controller, the applicable condition will be identified before or at the time of collection where required. You should avoid including unnecessary personal or sensitive information in open-text answers.
Anonymous surveys. Where a survey is described as anonymous, survey results are not intended to be linked to direct identifiers such as your name, email address or telephone number. Limited technical logs may still be processed for security and troubleshooting, but they are not used to identify your survey answers unless necessary to investigate misuse or a security incident.
Pseudonymous surveys. A code or other identifier may be used instead of your direct identity. The information needed to reconnect the code to a person is kept separately and access is restricted.
Identified surveys. Some surveys require responses to be linked to a person, customer, employee, member or case, for example for follow-up or service delivery. This will be stated in the invitation or survey introduction.
Prize draws. Where technically and operationally possible, contact details provided for a prize draw are stored separately from survey answers. Prize-draw contact details are not used for marketing unless you have separately agreed to that use.
The specific purpose and legal basis depend on the survey and on whether InFact or a customer is the controller. Where a customer is the controller, the customer determines the legal basis and InFact processes the data on documented instructions. The relevant basis may be explained in the survey invitation, introduction or the customer’s privacy notice.
Selecting respondents and sending survey invitations or reminders. To draw a relevant or representative sample, contact potential respondents, manage opt-outs and avoid unnecessary repeat contact. Common legal bases include legitimate interests under GDPR Article 6(1)(f), public task under Article 6(1)(e), legal obligation under Article 6(1)(c), or consent under Article 6(1)(a), depending on the controller and project.
Conducting surveys and collecting responses. To carry out market, opinion, customer, employee, public-service or other research. Common legal bases include legitimate interests, public task, legal obligation, contract-related processing or consent, depending on the project.
Analysis, quality control and reporting. To validate data quality, analyse responses, prepare statistics and provide results to the customer. Results are normally aggregated or anonymised where this meets the purpose.
Administering prize draws and incentives. To register participants, select and contact winners, deliver prizes, prevent misuse and document fulfilment. The legal basis may be contract-related processing, legitimate interests, consent or legal obligation, depending on the draw and its terms.
Security, diagnostics and prevention of misuse. To protect respondents, customers, systems and data, identify technical errors, investigate suspected misuse and maintain service availability. InFact generally relies on legitimate interests under Article 6(1)(f) for this processing.
Compliance and legal claims. To comply with legal duties and to establish, exercise or defend legal claims. The legal basis may be Article 6(1)(c) or Article 6(1)(f).
We do not normally use survey responses to make decisions based solely on automated processing that produce legal effects or similarly significant effects for you. Survey tools may use automatic routing, validation, randomisation, scoring or quality checks to operate the questionnaire, but these functions do not normally make such significant decisions about respondents. If a specific project uses significant automated decision-making or profiling, this will be explained before you participate.
We do not sell personal data. Depending on the project, personal data may be disclosed or made available to:
Customers normally receive aggregated or anonymised results. Identifiable or pseudonymous survey data is provided only where this is necessary for the stated purpose and consistent with the project-specific information provided to respondents.
Main provider categories used in survey delivery may include:
Providers and locations may change where necessary. When a provider processes personal data on behalf of InFact, we require an appropriate agreement and limit processing to the relevant service.
Personal data is stored and processed primarily within the European Economic Area (EEA). If personal data is transferred to, or otherwise processed in, a country outside the EEA, the controller will ensure that a lawful transfer mechanism and appropriate safeguards are in place. These may include an adequacy decision by the European Commission, the EU Standard Contractual Clauses and supplementary technical or organisational measures where required.
You may contact the Data Protection Officer for more information about safeguards relevant to a specific transfer.
We retain personal data only for as long as necessary for the purpose for which it was collected, unless a longer period is required or permitted by law. Project-specific agreements or notices may set shorter or longer periods where justified.
Survey pages and our website may use cookies or similar technologies that are necessary for functions such as session handling, language settings, security, accessibility and reliable submission of responses. Non-essential cookies, such as analytics or marketing cookies, are used only where a valid consent or other lawful basis is available and where required by applicable law.
You can manage non-essential cookies through the cookie banner or cookie settings where these are offered. More detailed information is provided in our Cookie Policy, which is available on our website.
InFact applies appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, confidentiality obligations, encryption, logging, monitoring, backups, vulnerability management, secure development practices, incident handling, pseudonymisation and data minimisation, depending on the risks and the project.
No system can be guaranteed to be completely secure. If you believe that a survey link, invitation or response may have been misused or exposed, please contact us promptly.
Where applicable, you may have the right to:
Withdrawal of consent does not affect processing that was lawful before withdrawal. Rights may be limited in certain circumstances, including where data has been anonymised, where InFact cannot identify which response belongs to you, or where continued processing is required by law.
Where InFact acts as processor, the customer is normally responsible for responding to your request. You may contact the customer directly or contact InFact, and we will refer or assist with the request as appropriate.
We normally respond without undue delay and within one month. We may request additional information where reasonably necessary to verify your identity.
Please describe what your request concerns and provide enough information for us to identify the relevant survey or processing activity. Do not send unnecessary sensitive information.
General privacy and survey inquiries: post@infact.no
Data Protection Officer: Iryna Lazorenko – iryna@infact.no
If you believe that personal data has been processed in breach of applicable data-protection law, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or another competent supervisory authority.
Datatilsynet: Datatilsynet website
Some research projects may lawfully include children or young people. Where this is the case, the survey will be designed for the relevant age group, project-specific information will be provided, and consent from a parent or guardian will be obtained where required by law. Additional safeguards may include age-appropriate language, limited collection, restricted access and shorter retention periods.
We may update this policy when our services, legal requirements or processing practices change. The current version and review date will be made available on our website. Material project-specific changes will be communicated through the relevant survey or other appropriate channel where required.