Privacy policy
Version 1.1 · Updated
This policy explains how José Alejandro Chaves Ramírez, an individual trading as Knotfix —«Knotfix»—, processes personal data in Censuma, its workplace climate survey service. It is written under Law No. 8968, the Costa Rican Personal Data Protection Act, and its implementing regulation, Executive Decree No. 37554-JP, which are the rules of our domicile.
Censuma is sold outside Costa Rica, so many people are covered by another regime as well —the European GDPR, the UK GDPR, the Swiss FADP, California's CCPA. What changes in each case is in the «Depending on where you are, the rules change» section, and what we say here is guaranteed to everyone alike, not only to those who can demand it.
Two different relationships, worth keeping apart
Censuma involves two kinds of personal data, and Knotfix does not play the same role in both. Nearly every question we get comes from mixing them up.
Account data belongs to the contracting organization and to the users who administer that account. Here Knotfix is the data controller: it decides what the data is used for and answers for it. That is what this policy covers.
Survey data is the roster and the answers of that organization's employees. Here the controller is the client organization, not Knotfix: it decides who is measured, what is asked and why. Knotfix only processes that data on its behalf and under its instructions. Those conditions are set out in the Data processing addendum.
If you work at an organization that uses Censuma and want to know what happens to your answers, the short version is in the «Survey answers» section below, and the long one is owed to you by your employer.
Who processes your data
| Controller | José Alejandro Chaves Ramírez (an individual), trading as Knotfix |
| National ID (cédula) | 5-0448-0254 |
| Address | Guanacaste province, Liberia canton, Liberia district, La Cruz. Postal code 50101, Costa Rica |
| Contact for data protection matters | knotfixservice@knotfix.com |
| Phone | +506 8791 7066 |
What data we process, and why
| Category | What it includes | Where it comes from | What for |
|---|---|---|---|
| Account identification | Name, email, role within the account, preferred language | Provided at signup or on invitation | Creating and running the account, authentication, support |
| Credentials | Email, password and two-step verification factors | Provided by the person | Authentication. We do not store them: they live with our identity provider, and Knotfix never sees the password |
| Billing | Legal name, company ID, tax address | Provided by the Client | Issuing the electronic invoice required by tax law |
| Payment method | Card details | Entered by the person in the payment processor's form | Charging the subscription. Card details never pass through our servers: they travel from the browser to the processor |
| Service usage | Access logs, IP address, device type | Generated by using the system | Security, detecting improper access, diagnosing faults |
| Result-access log | Who consulted which results, from which study and with which segment | Generated when results are consulted | Detecting attempts to re-identify respondents. It is an anonymity measure, not a productivity one, and it does not record the values consulted |
| Communications | Subject and message sent to support, plus the sender's email and organization | Provided by the sender; email and organization are added by the system | Handling the request. They live in our mailbox, not in a product database |
| Brand image | The logo the organization uploads for its reports | Provided by the Client | Branding downloadable reports |
| Survey data | Roster and answers | Uploaded and generated by the Client | Providing the service — see the Addendum |
We do not request sensitive data as defined in article 9 of Law 8968 —racial or ethnic origin, political opinions, religious or philosophical beliefs, health, sex life and sexual orientation— and the service is not designed to collect it. Client organizations can add their own questions to a questionnaire, and are contractually bound not to use that ability to collect sensitive data.
On what legal basis
Each piece of data is processed on a ground of its own, and they are not all the same:
| Ground | What it covers |
|---|---|
| Performance of the contract | Account identification, credentials and payment method. Without them there is no account and no service to provide: they are the contract, not an extra someone opts into |
| Legitimate interests | The access logs and the results-consultation log. The interest is the security of the service and detecting attempts to re-identify respondents. It was weighed against what it costs the person, and two limits came out of that balancing and are written above: the consultation log does not record the values and both have a deletion deadline |
| Legal obligation | Billing data, for the period tax rules require |
| Consent | Only what is genuinely optional. Today: nothing. There is no analytics, no profiling and no marketing email |
⚠️ The checkbox ticked at sign-up is not the legal basis for the service, and the two should not be confused. That checkbox is the express consent article 5 of Law 8968 asks for and, above all, the record that these three documents were accepted: a contract being signed. Under the GDPR the basis for providing the service is performance of that contract and not consent —among other reasons because consent that cannot be withdrawn without losing the service would not be freely given, and that would be exactly the case here.
Until August 2026 this policy said that withdrawing consent meant we could no longer provide the service. That was the confusion above, written down, and it has been corrected: what exists for anyone who does not want to continue is to delete the account, which the owner does from the product itself and which erases the data immediately, with nobody in between. Consent for anything actually provided on the basis of consent can be withdrawn at any time, without retroactive effect, by writing to the address in the previous section.
Survey answers
This matters most to the person answering, so it is spelled out:
Who responded and what they responded are stored with no relationship between them. It is not a denied permission or a value hidden behind a role: the link does not exist in the database. The system can say that a person has taken part —which is needed to follow up— and cannot say what they answered, neither to the organization nor to Knotfix. The date of the answer is stored without a time, so the two ends cannot be rejoined by order of arrival either.
Results are published in aggregate and only once a group reaches a minimum number of responses, so that no result lets anyone deduce an individual's. That threshold cannot be switched off by role, by plan or by support.
There is one exception worth reading twice: free-text questions. When the organization adds an open question, whatever is written there is shown to it verbatim, along with the branch of the organization it belongs to, with no filtering of names or identifying details. There is still no link to the person, but a text can identify whoever wrote it by what it says or by how it is written. If you are answering a survey, keep that in mind before giving details that identify you.
Who we share it with
We do not sell personal data, do not disclose it for advertising, and do not use it to train models.
We share it only with providers supplying us infrastructure services —and only what they need to supply them— under contractual obligations of confidentiality and of processing it solely on our instructions:
| Provider | What for | Country |
|---|---|---|
| Hostinger | Application hosting (private server) | United States |
| PlanetScale | Database: roster, answers and results | United States |
| Clerk | Identity and authentication of account users | United States |
| Resend | Delivery of system email, including survey invitations | United States |
| Cloudflare (R2) | Storage of the organization's logo | United States |
| Polar | Card payment processing and subscription billing as merchant of record | United States |
| Allegra | Issuing and delivering the electronic invoice to the tax authority | Costa Rica |
We also disclose it when ordered by a competent authority through a reasoned decision, or when a legal rule requires it.
International transfers
Part of the infrastructure is hosted outside Costa Rica, in the countries listed above, and Knotfix is domiciled in Costa Rica. What covers that transfer depends on where the data leaves from:
- From Costa Rica: article 14 of Law 8968, with the express authorization given by accepting this policy.
- From the European Economic Area: the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, which the Data processing addendum incorporates with its annexes filled in. The Commission has not found Costa Rica adequate, so those clauses are not decoration: they are what makes the transfer lawful, and that is why they come with an assessment of the destination country and with supplementary measures, all in that Addendum.
- From the United Kingdom: the same clauses with the ICO Addendum (version B1.0).
- From Switzerland: the same clauses with the adaptations the Swiss FADP requires.
⚠️ For the MEASUREMENT data the controller is the client organization, not us, so those clauses are signed with it and not with each employee. They are in the Addendum, already accepted when the contract was accepted: no separate signature is needed.
Before engaging a new provider we verify that it offers an equivalent level of protection and that it accepts obligations equivalent to ours, and we add it to the table. We give 30 days notice before bringing one in.
How long we keep it
| Data | Period |
|---|---|
| Account data | While the account exists. The owner may delete it at any time from the product, at which point the data is erased immediately and irreversibly |
| Survey data | Set by the Client; deleted or returned at termination, per the Addendum |
| Billing | As required by Costa Rican tax rules |
| Result-access log | 12 months |
| Server access logs | Operational and short-lived: they live on the infrastructure for as long as they help diagnose a problem and are discarded on each deployment. They are not archived or used for any other purpose |
Once the period is over, data is deleted or irreversibly anonymized.
An account that expires without being closed is not deleted on its own. When the trial or the subscription ends, the account becomes read-only: what has already been measured can still be consulted, and nothing more can be written. Data is kept that way until the owner deletes the account, and that deletion is immediate and irreversible.
How we protect it
We apply the technical and organizational measures required by article 10 of Law 8968: encryption in transit and at rest, access control by role and by organization, access logs, environment separation and periodic backups. Knotfix staff with access are bound by the duty of confidentiality in article 11, which survives the end of their relationship with us.
No measure makes a system invulnerable. If an incident affecting personal data occurs, we report it to whoever it concerns without delay and no later than 72 hours from detecting it, with what we know at the time.
Your rights
- Access — what data of yours we process, and a copy of it.
- Rectification — correcting anything wrong or incomplete.
- Erasure — deleting it when it was collected without authorization, is no longer necessary, or you withdraw the consent it rested on.
- Portability — receiving the data you gave us in a commonly used format, and having us pass it to another provider where technically feasible.
- Restriction — keeping it without using it while a dispute about its accuracy or about our legitimate interest is resolved.
- Objection — objecting to processing based on legitimate interests, on grounds relating to your particular situation.
- Withdrawing consent at any time, where consent is the basis, without retroactive effect.
- Not being subject to automated decisions producing legal or similarly significant effects. We do not take any: Censuma produces aggregates and decides nothing about any individual.
The first four are the right to informational self-determination of articles 7 and 11 of Law 8968; the full list is that of articles 15 to 22 of the GDPR.
To exercise them, write to knotfixservice@knotfix.com saying what you want. We may ask for reasonable proof of identity —not to put obstacles in the way, but so as not to hand your data to someone else— and we discard it as soon as the request is resolved. We answer within five business days at most, at no cost. That deadline is the one in article 7 of Law 8968; it is shorter than the GDPR's one month and it applies to everyone, not only to people in Costa Rica.
If the request concerns survey answers, bear in mind what is said above: we cannot locate one person's answers because the link does not exist. In that case we explain it, which is different from refusing.
If you are not satisfied with our answer you can complain to the supervisory authority that covers you: the Agencia de Protección de Datos de los Habitantes (PRODHAB) in Costa Rica —a simple, free procedure—, the authority of your country or place of work in the European Economic Area, the Information Commissioner's Office in the United Kingdom, or the FDPIC in Switzerland.
Where the request concerns measurement data, we route it to the client organization —which is the controller— and assist it in answering.
Depending on where you are, the rules change
This policy is written on Law 8968 because that is the law of our domicile. Here is how it reads when another one applies to you as well.
European Economic Area, United Kingdom and Switzerland. For ACCOUNT data Knotfix is the controller; for MEASUREMENT data it is a processor for the client organization, which is the controller. The legal bases are the ones in the table above; the rights are the ones in the list above; and the transfer to Costa Rica and the United States rests on the Standard Contractual Clauses, with the ICO Addendum for the United Kingdom and the Swiss adaptations — all developed in the Addendum.
California. With respect to measurement data we act as a service provider within the meaning of the CCPA/CPRA: we process it only to provide the service to the client organization and on its instructions. We do not sell or share personal information in the sense that law gives to «sell» and «share» —which includes handing it over for non-monetary consideration, as cross-context behavioural advertising would be—, we did not do so in the past twelve months and we will not. Nor do we retain, use or disclose it for any purpose other than that, or combine it with another client's data. Exercising CCPA rights means writing to the same address, and we do not discriminate against anyone who does.
Other countries. If your country's law recognizes a right this policy does not name, write to us: the list above is what we guarantee to everyone, not a ceiling.
Cookies and site measurement
This site uses the cookies strictly needed to work —session, language and theme— which do not require consent because the service cannot be provided without them.
We use no analytics and no tracking tools, neither on this site nor inside the application: there are no advertising, profiling or cross-site tracking cookies. Inside the application the session cookie is managed by our identity provider, and language and theme are stored in your own browser. If we ever add a measurement tool that identifies people, we will say so here and ask for consent before switching it on.
Minors
The service is aimed at organizations and at working adults. We do not knowingly collect data from minors. If we detect any, we delete it.
Changes
We may update this policy. The version and date above indicate which one is in force. If a change materially affects how we process data, we give notice by email 30 days in advance, and we keep a record of which version each person accepted and when.
Contact
For any question about this policy or about your personal data: knotfixservice@knotfix.com · +506 8791 7066.
Access, rectification and deletion requests are handled in writing, at the email address above: we need to verify who is asking and to keep a record of what was answered, and the phone serves neither purpose.