Privacy Statement
This statement explains how Calibrum handles personal data collected during normal business activities and how data are processed through its software and services.
Privacy Statement
Last updated: August 4, 2026
This Privacy Statement explains how Calibrum Inc., a Utah corporation (“Calibrum,” “we,” “us,” or “our”), handles personal data collected during normal business activities and how personal data are processed through the Surveylet platform and related subscription and professional services (collectively, the “Services”).
1. DATA PRIVACY FRAMEWORK
Calibrum participates in the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) as administered by the U.S. Department of Commerce. Calibrum has certified to the U.S. Department of Commerce that it adheres to the applicable Data Privacy Framework Principles with respect to personal data received from the European Union, the United Kingdom (and Gibraltar), and Switzerland in reliance on those frameworks.
If there is any conflict between this Privacy Statement and the applicable Data Privacy Framework Principles, the Principles will govern. Calibrum’s participation does not cover human resources data.
To learn more about the Data Privacy Framework program, visit www.dataprivacyframework.gov. To review Calibrum’s certification, visit the Data Privacy Framework List and search for “Calibrum.”
2. CALIBRUM SOFTWARE AND SERVICES
Calibrum provides online collaborative survey software and related services for corporations, research organizations, universities, government entities, and other customers. The Services are accessed through a supported web browser and Internet connection.
Customers determine what information they collect through the Services, the purposes for which it is collected, and how it is used. Information submitted to or generated through the Services on behalf of a customer is referred to as “Customer Data.” Customer Data may include information collected from survey respondents (“Respondents”).
For Customer Data, Calibrum generally acts as a processor or service provider on behalf of the customer, and the customer generally acts as the controller or business. Calibrum processes Customer Data according to the customer’s instructions, the applicable agreement, and applicable law.
3. INFORMATION COLLECTED DURING NORMAL BUSINESS ACTIVITIES
When you visit our website, contact us, request information, purchase Services, create or administer an account, or communicate with our sales or support teams, we may collect information such as:
- name, business contact information, organization, and job title;
- account, subscription, transaction, and support information;
- communications and information you choose to provide to us; and
- technical and usage information, such as IP address, browser and device type, referring URLs, pages visited, date and time information, cookie identifiers, and interactions with our website.
We use this information to provide and administer the Services, process transactions, respond to inquiries, provide technical support, secure and improve our website and Services, communicate service-related information, and conduct lawful sales and marketing activities.
Cookies and similar technologies may be used to operate the website, remember preferences, understand website usage, and improve content. Calibrum may use analytics providers, including Google, which may collect technical and usage information when you visit our website. You may control cookies through your browser or device settings, subject to the functionality of the website.
Calibrum uses third-party payment processors for online payments. Calibrum does not directly store complete payment-card information on its website or application servers.
Calibrum does not sell personal data or Customer Data. We may disclose personal data to service providers that help us operate our business and Services, including providers of hosting, security, analytics, payment processing, communications, customer support, and professional services. We may also disclose information when required by law, legal process, or a valid governmental request; to protect rights, safety, and security; or in connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business, subject to appropriate protections.
4. CUSTOMER DATA
Customers own and control their Customer Data. Depending on how a customer uses the Services, Customer Data may include personal data, sensitive personal data, health-related information, or other regulated information. Customers are responsible for providing required notices, obtaining required consents or other lawful bases, and using the Services in compliance with applicable law.
Calibrum processes Customer Data to provide, maintain, secure, support, and improve the Services; comply with customer instructions and contractual obligations; prevent misuse; and comply with applicable law. Calibrum may create and use anonymized or aggregated information that does not identify a customer or individual for lawful business purposes.
Calibrum does not sell Customer Data. Calibrum may disclose Customer Data to authorized personnel and service providers only as reasonably necessary to provide and secure the Services, comply with customer instructions, or satisfy legal obligations. Service providers that process Customer Data on Calibrum’s behalf are required to protect the information and use it only for authorized purposes.
Calibrum personnel do not routinely review Customer Data. Access is limited to authorized personnel when reasonably necessary for support, security, maintenance, legal compliance, or other authorized service purposes. Customers may have the ability to limit support access, although doing so may affect Calibrum’s ability to provide timely support.
Calibrum retains Customer Data according to the applicable agreement, customer instructions, operational requirements, and legal obligations. Customers may use available product features to access, correct, export, anonymize, or delete Customer Data. Following termination or expiration, deletion and return of Customer Data are governed by the applicable agreement and Calibrum’s then-current operational procedures.
5. INTERNATIONAL TRANSFERS AND ONWARD TRANSFERS
Calibrum is based in the United States. Personal data may therefore be processed in the United States and in other locations where Calibrum or its service providers operate. Where required, Calibrum uses recognized transfer mechanisms and contractual protections for international transfers.
With respect to personal data received under the Data Privacy Framework and transferred to a third-party agent acting on Calibrum’s behalf, Calibrum remains responsible under the applicable Principles if the agent processes the information in a manner inconsistent with those Principles, unless Calibrum proves that it is not responsible for the event giving rise to the damage.
Calibrum may be required to disclose personal data in response to lawful requests by public authorities, including requests made to meet national security or law-enforcement requirements.
6. INDIVIDUAL RIGHTS AND CHOICES
If your personal data were collected through a survey or other project administered by a Calibrum customer, please contact that customer first. The customer controls the data and is generally responsible for responding to requests to access, correct, amend, restrict, or delete it. If the customer does not respond, you may contact Calibrum using the information below, and we will assist as appropriate.
Depending on applicable law, individuals may have rights to request access to, correction of, deletion of, or restriction of certain personal data, or to object to or limit certain uses and disclosures. Calibrum may need to verify a requester’s identity and may refer a request concerning Customer Data to the relevant customer.
Under the Data Privacy Framework Principles, eligible individuals may have the right to access personal data held about them and to request correction, amendment, deletion, or limitation of use and disclosure where the information is inaccurate or processed in violation of the Principles.
7. COMPLAINTS, ENFORCEMENT, AND DISPUTE RESOLUTION
Calibrum is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission with respect to its Data Privacy Framework commitments.
Calibrum commits to respond to Data Privacy Framework inquiries and complaints within 45 days. Individuals in the European Economic Area, the United Kingdom, or Switzerland should first contact Calibrum at privacy@calibrum.com.
Calibrum has committed to refer unresolved complaints concerning non-human-resources personal data covered by the Data Privacy Framework to the ICDR-AAA Data Privacy Framework Services, an independent dispute-resolution provider in the United States. This service is provided at no cost to the individual. Additional information and complaint submission instructions are available at go.adr.org/dpf_irm.html.
Under certain conditions described in the Data Privacy Framework, an individual may invoke binding arbitration after completing the required pre-arbitration steps. Additional information is available through the Data Privacy Framework arbitration materials.
8. SECURITY
Calibrum uses reasonable administrative, technical, and organizational safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. No method of transmission or storage is completely secure. Additional information is available in our Security Statement.
9. SUBPROCESSORS
Calibrum may use service providers and subprocessors to operate and support the Services. These providers may process Customer Data only for authorized purposes and subject to appropriate contractual obligations.
The following optional customer-controlled service is currently identified:
Google LLC
Function: Optional translation service initiated and controlled by the customer or user.
Additional information about service providers that may process Customer Data is available upon request or may be included in an applicable data processing agreement.
10. CHANGES TO THIS STATEMENT
Calibrum may update this Privacy Statement to reflect changes in law, technology, business practices, or the Services. The “Last updated” date at the top identifies the current published version. Where required by law or contract, Calibrum will provide additional notice of material changes.
11. CONTACT US
Questions, requests, or complaints regarding this Privacy Statement may be sent to privacy@calibrum.com or submitted through the Calibrum contact page. There is no charge for submitting a privacy inquiry or Data Privacy Framework complaint.
