KoboToolbox Data Privacy Policy

Version May 20, 2018, in effect from May 25, 2018 for all users

This data privacy policy applies to the KoboToolbox hosted instance available through kobotoolbox.org (kf.kobotoolbox.org and eu.kobotoolbox.org). For other instances powered by our open-source code, please contact the host. Note that KoboToolbox does not collect or store data from those other instances. KoboToolbox is licensed for use under the GNU license available here.

What type of data do we control and process?

This data privacy policy distinguishes between data that in controlled by KoboToolbox and data that is processed by KoboToolbox.

KoboToolbox is:

  • A data controller of very limited data about site visitors and account holders (i.e. we determine the purposes, conditions and means of the processing of personal data). KoboToolbox collects webpage analytics from unregistered and registered users of its webpage using Google Analytics – pages visited, clicks, browser used, language choice, country of origin and so on. For registered users, KoboToolbox collects e-mail and basic information as part of the registration process and stores users’ preference in their profile (e.g. language).

  • A data processor of data collected by account holders (i.e. processes data on behalf of a data controller). Once a registered user creates a project, KoboToolbox stores the information related to the survey (e.g. form) and data collected by the account holder (i.e. submissions). This includes data submitted by participants completing forms designed by registered users and can include personal information.

How do we use your data?

KoboToolbox takes very seriously the privacy, confidentiality and security of personal information and any data collected or stored using KoboToolbox.

  • Data that we control:
    Data under our control which includes site visitors data (website analytics) and registration data (username, password and profile) is used in aggregated ways to monitor usage and growth of KoboToolbox. This enables us to report especially on humanitarian activities. Personal information from registered users is used to provide services to registered users and communicate with registered users about our services. Registered users can view, edit, and delete their personal information stored in their profile, unregister from communication emails, or delete their account. Personal information is never shared or sold to third parties.

  • Data that we process:
    KoboToolbox processes data on behalf of registered users who created a project and collected data. Registered users fully own their application data and KoboToolbox does not use, share, or sell that information. Metadata about projects may be used in aggregated ways to analyze usage with the permission of the account holder. This metadata does not include personal information.

Registered users are the data controllers of the data they collect using KoboToolbox and are responsible for the safe management of personal information, including compliance with the General Data Protection Regulation (GDPR). KoboToolbox allows users to share application data publicly or with selected users. Information shared publicly is visible to anyone and can be indexed by search engines. KoboToolbox is not responsible for how registered users handle survey participants’ personal information. We may assist individual respondents in contacting registered users with regards to GDPR requests.

How do we protect your data?

KoboToolbox is committed to protecting the data you entrust to us. We employ industry standard best practices (both technical and administrative) to protect against unauthorized access of your data. We cannot guarantee, however, its absolute security. To protect from loss of data, we do frequent system and incremental backups which are stored encrypted in various locations. To further protect your data, we encourage you to never to share your login information and to change your passwords regularly. If you have any questions regarding our security and backup procedures, please contact us.

Changes to the Privacy Policy

We may need to modify this privacy statement from time to time, especially in response to changing norms and legislations, so please review it frequently. If we make material changes to this policy, we will notify you here or by means of a notice on our homepage so that you are aware of any changes with relation to what information we collect, how we use it, and under what circumstances, if any, we disclose it.

Contact us

If you are uncertain about our data privacy policy or have requests with regards to general compliance, including GDPR rights, please contact us. We respond to requests within 30 days.