Privacy Notice

Effective date: June 1, 2024

INTRODUCTION

This Privacy Notice (“Notice”) describes Kobo, Inc.’s (“Kobo”, “we”, “our”, or “us”) practices for collecting, using, maintaining, protecting, and disclosing your personal information through (i) kobotoolbox.org, its subdomains, and any other website where this Notice is posted (“Website”); and (ii) Kobo’s online hosted services and any related software, application, content, functionality, documentation, and services (collectively, with the Website, the “Service(s)” or “KoboToolbox”) offered by Kobo, whether as a guest or registered user.

Kobo provides our Services to individuals and organizations to administer surveys and collect data (“Users”, “You”, “you”). Users may use KoboToolbox to collect data, including personal data, from individuals who provide their data in response to surveys, customizable by Users (“Participants”). Kobo collects Personal Information (defined below) from Users who register for and access the Services. Through KoboToolbox, Users can collect and process Personal Information of Participants (“Participant Personal Information”) for their own purposes. Therefore, unless circumstances necessitate otherwise, for the purposes of the European Union General Data Protection Regulations (“GDPR”) and/or United Kingdom’s Data Protection Act 2018 (“DPA”), Kobo is a controller in relation to the Personal Information it collects on Users and is a processor in relation to Personal Information it collects on behalf of Users from Participants. Kobo does not process Participant Personal Information for any purpose other than as directed by Users. If you are a Participant and would like to exercise your privacy rights, please contact the User in whose survey you are participating directly, and we will work with the User to address your privacy rights.

Please read this Notice carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with this Notice, your choice is not to use our Services. This Notice may change from time to time (see Changes to this Notice). Please check the “Last Modified” date at the top of this Notice to ensure that you are viewing the most current version of this Notice.

1. PERSONAL INFORMATION WE COLLECT ABOUT YOU, HOW WE COLLECT IT, AND HOW LONG WE STORE IT

When you engage with certain Services, we will collect your Personal Information which is information that identifies (whether directly or indirectly) a particular individual. Except as otherwise indicated, the Personal Information we collect is such that we need it to carry out the requested action. If you do not provide us with your Personal Information, we would not be able to do so. As used in this Privacy Notice, “Personal Information” includes “Personal Data” as defined under the EU data protection law.

We collect Personal Information when you:

  • Register for an account: In the course of registering for an account, we will collect your identifiers (first and last name, organization name, username, email address), industry sector, and country of residence. We will use this information to set up the Services for your use and communicate with you about the Services. We use HubSpot as our customer relationship management (CRM) tool for processing some of this data. This helps us provide user support, document communications, and improve our Services to you. For more information, please review HubSpot’s Privacy Policy. If you register for a paid subscription, Stripe, our third-party payment processor will directly receive your identifiers (name, email address, billing address) and sensitive financial account information (payment card number, CVV, expiration date, and ZIP code) to charge your payment card based on the payment terms of your subscription. To the extent the EU or UK data protection laws apply, the legal basis for this processing is the performance of our contract with you. We retain your Personal Information for as long as your account is active and for no more than two years after it has become inactive. If you request that your account be deleted, we will remove your Personal Information within 30 days.
  • Fill out a contact form: When you fill out a contact form, we will collect your identifiers (name, email address), organization name, country, and anything you decide to include in the “Message” field of the contact form. We will use this information to process your correspondence and respond to your message and provide you with additional assistance (as applicable). To the extent the EU data protection law applies, the legal basis for collecting this information is to respond to your message the performance of our contract with you. We retain your Personal Information for two years. If you have an account, we will retain your Personal Information for as long as your account is active and for no more than two years after it becomes inactive. If you request that your account be deleted, we will remove your Personal Information within 30 days.
  • Join our newsletter: When you subscribe (opt in) to our newsletter, we will collect your email address. We will use this information to send you our periodic newsletter and information we feel may be of interest to you. To the extent EU or UK data protection laws apply, the legal basis for the processing of this information is your consent. You may revoke your consent at any time with effect going forward by clicking on the “unsubscribe” link included in the email. Please note that we will continue to send you notifications necessary to the Services or to requested products or services. Our communications contain tracking technologies, provided by and therefore shared with our third-party email marketing provider, to analyze whether a predefined action took place by a recipient, such as opening our communications, in order to better adapt and distribute our communications. You can disable tracking by disabling the display of images by default in your email program. We retain your Personal Information for two years. If you have an account, we will retain your Personal Information for as long as your account is active and for no more than two years after it becomes inactive. If you request that your account be deleted, we will remove your Personal Information within 30 days.
  • Donate: When you donate to us, Stripe, our third-party payment processor, and Fundraise Up, our donation platform, will directly receive your identifiers (name, email address, billing address), whereas Stripe will also receive sensitive financial account information (payment card number, CVV, expiration date, ZIP code; or your PayPal or Google Pay authentication token from your mobile wallet) to process the donation payment (including transaction costs, if you elect to do so) and to comply with any legal obligations related to the donation. The use and retention of your Personal Information by the third-party processors is subject to their own privacy policies. For additional information, please see Stripe’s Privacy Policy, Fundraise Up’s Privacy Policy, PayPal’s Privacy Policy and Google Pay’s Privacy Policy. We will email you a receipt of the donation for your records. To the extent the EU or UK data protection laws apply, the legal basis for this processing is that it is necessary for the performance of our contract with you. We only receive the donation from our payment processor and a record of the donation, and do not maintain your sensitive financial account information unless you choose to make a recurring donation. If you choose to make a recurring donation and agree to the storage of your payment information, our third-party payment processor will store your sensitive financial account information for future donations. To the extent the EU or UK data protection laws apply, the legal basis for this processing is your consent. You can revoke your consent to this processing and cancel recurring donations as set forth in our Terms of Service. We retain your Personal Information for two years. If you have an account, we will retain your Personal Information for as long as your account is active and for no more than two years after it becomes inactive. If you request that your account be deleted, we will remove your Personal Information within 30 days.
  • Participate in a video conference: When you participate in a video conference with us through our third-party video conference provider, we will collect your physical appearance (if your camera is turned on) and auditory information (the sound of your voice) during the video conference. We use this information to conduct the video conference. We do not record the calls or retain your contact information without explicitly obtaining your consent. To the extent EU or UK data protection laws apply, the legal basis for collecting this information is that it is necessary for the performance of our contract with you to answer your queries as presented on the call.
  • Attend an event: When you sign up to attend an event, we will collect your event registration information (name and email address). We will use this information to plan for the event, communicate with you about the event, and allow you into the event. To the extent the EU or UK data protection laws apply, the legal basis for collecting your information is to facilitate your attendance at the event. If you do not provide this information, you would not be able to participate in the event. We retain your Personal Information for two years. If you have an account, we will retain your Personal Information for as long as your account is active and for no more than two years after it becomes inactive.
  • User Contributions: When you interact with parts of our Services, such as by posting a message on our Community Forum (collectively, “User Contributions”), we will collect your identifiers (name and email address) and any information that you include in your message. Your messages may be published or displayed on public areas of the Services or transmitted to other Users of the Services or third parties. If at any time you want your User Contribution to the Community Forum deleted, you can delete your message directly on the forum. To the extent EU or UK data protection laws apply, the legal basis for this processing is your consent. You can revoke your consent at any time with effect moving forward by emailing us at info@kobotoolbox.org. We retain your Personal Information for two years. If you have an account on the Community Forum, we will retain your Personal Information for as long as your account on the Community Forum is active and for no more than two years after it becomes inactive.
  • Interact with the Services: In addition to the Personal Information you provide directly to us, we also collect information from you automatically as you use our Services via “cookies”, pixels, and similar tracking technologies. To the extent the EU or UK data protection laws apply to the placement of cookies on our Website, the legal basis for this processing is your consent. You may withdraw your consent at any time with effect moving forward by managing your Cookie Preferences on our Website. To the extent the EU or UK data protection laws apply, the legal basis for the placement and access of strictly necessary cookies is the performance of a contract. These cookies are essential for providing the functionalities of our Services.

    Particular third-party cookies used in our Services include Stripe, Google Analytics, Fundraise Up, and HubSpot. In general, you can disable cookies by setting your browser to refuse cookies or to indicate when a cookie is being sent. Please note, if you opt out of these targeted cookies, your opt out will be specific to the web browser, application, or device from which you accessed the opt out. If you use multiple devices or web browsers, you will need to opt out of each browser or device that you use. You can generally opt out of receiving personalized ads from third-party advertisers and ad networks who are members of the Network Advertising Initiative (NAI) or who follow the Digital Advertising Alliance’s Self-Regulatory Principles for Online Behavioral Advertising (DAA) by visiting the opt-out pages on the NAI website and DAA website.

    • Stripe: We use Stripe to process payments for paid subscriptions and for processing donations. When you initiate a payment, Stripe may install cookies on your browser or read cookies that are already present to help authenticate your identity and provide you with a seamless payment process. To learn more about how Stripe uses and shares information, visit Stripe's Privacy Policy. For further details on how you can manage your privacy choices, please see YOUR INFORMATION CHOICES below.
    • Google Analytics: We use Google Analytics to collect information on your use of the Services for the purpose of improving the Services. To collect this information, Google Analytics installs cookies on your browser or reads cookies that are already on your browser. Google Analytics also receives information about you from applications that you have downloaded that partner with Google. We do not combine the information collected through the use of Google Analytics with Personal Information. To learn more about Google’s ability to use and share information collected by Google Analytics about your visits to our Website or to another application which partners with Google, visit their Privacy & Terms page. To prevent your data from being used by Google Analytics, you can download the Google Analytics opt-out browser add-on, which can be accessed here. To revoke your consent to our use of Google Analytics cookies, please manage your Cookie Preferences on our Website. To learn more about your privacy choices, please see YOUR INFORMATION CHOICES below.
    • Fundraise Up: We use Fundraise Up as a third-party online donation platform on our Website to collect donations and to analyze your behavior while using our Website as it relates to donations. For more information, please see Fundraise Up’s Privacy Policy. To revoke your consent to our use of Fundraise Up cookies and trackers, please manage your Cookie Preferences on our Website. To learn more about your privacy choices, please see YOUR INFORMATION CHOICES below.
    • HubSpot: We use HubSpot to analyze the data traffic on our Website and your behavior while using our Website. We use this information to gain valuable insights into user behavior on our Website for the purpose of improving our Website. We also use HubSpot’s conversion tracking to analyze whether a predefined action took place by an email recipient, such as opening our email, in order to better adapt and distribute our emails. For more information, please review HubSpot's Privacy Policy. To revoke your consent to our use of HubSpot cookies, please manage your Cookie Preferences on our Website. To learn more about your privacy choices, please see YOUR INFORMATION CHOICES below.

2. HOW WE SHARE YOUR PERSONAL INFORMATION

Kobo shares Personal Information in the following instances:

  • Within Kobo: Where necessary, Kobo will share your Personal Information within Kobo to efficiently carry out and improve our business and to the extent permitted by law. To the extent the EU or UK data protection laws apply, the legal basis for this sharing is our legitimate interest in carrying out our business operations efficiently.
  • With other Users: Other Users may have access to information that you publish or post on public areas of the Services — see User Contributions. This may also include any Personal Information you choose to include when making a survey project or form library content (such as Public Collections) public in your account.
  • With service providers: We use third parties (for example, web hosting services) to provide, protect, or improve our Services on our behalf and as necessary to fulfill our contract with you. These third parties may only access your Personal Information when absolutely necessary in order to perform these tasks on our behalf. We share the following information with third-party service providers: (i) identifiers (name, payment card number, CVV, expiration date, ZIP code) with our payment processor to process payments; (ii) identifiers (name, email address, telephone number) with our CRM to assist with customer relationships; (iii) identifiers (name, email address) with our email marketing provider to facilitate promotional email messages; (iv) identifiers (name, address, email address, telephone number) and sensitive financial account information (bank account details, credit card number, expiration date, CVV, and ZIP code) with our third-party donation platform and payment processor to process your donation; and (v) your physical appearance and auditory information (the sound of your voice) with our video conference provider to facilitate the video conference meeting with you. Please contact us if you require detailed information about our third-party processors.
  • In the event of a corporate reorganization: In the event that we enter into or intend to enter into a transaction that alters the structure of our business, such as a reorganization, merger, acquisition, sale, joint venture, assignment, consolidation, transfer, change of control, or other disposition of all or any portion of our business, assets, or stock, we would share Personal Information with third parties, including the buyer or target (and their agents and advisors) for the purpose of facilitating and completing the transaction. We will also share Personal Information with third parties if we undergo bankruptcy or liquidation, in the course of such proceedings. To the extent the EU or UK data protection laws apply, the legal basis for sharing this information is our legitimate interest in carrying out our business operations or your consent in cases where consent is required for sharing the information.
  • For legal purposes: We share your Personal Information where we are legally required to do so, such as in response to court orders, subpoenas, governmental/regulatory bodies, law enforcement, or legal process, including for national security purposes. We may share your information with our legal advisors or auditors to: (i) establish, protect, or exercise our legal rights; (ii) as required to enforce our Terms of Service or other contracts; or (iii) defend against legal claims or demands. We also share this information with third parties as necessary to: (i) detect, investigate, prevent, or take action against illegal activities, fraud, or situations involving potential threats to the rights, property, or personal safety of any person; (ii) comply with the requirements of any applicable law; or (iii) comply with our legal obligations. To the extent EU or UK data protection laws apply, the legal basis is compliance with EU law or our legitimate interest to comply with other laws that apply to us.
  • With your consent: Apart from the reasons identified above, we may request your permission to share your Personal Information for a specific purpose. We will notify you and request consent before you provide the Personal Information or before the Personal Information you have already provided is shared for such purpose. You can revoke your consent at any time with effect moving forward by emailing us at info@kobotoolbox.org.

3. YOUR INFORMATION CHOICES

You have the following choices with respect to your Personal Information:

  • Correct or view your information. You may email us at info@kobotoolbox.org to correct or view any Personal Information of yours in our possession.
  • Opt out of Google Analytics. To prevent your data from being used by Google Analytics, you can download the Google Analytics opt-out browser add-on, which can be accessed here.
  • Opt out of other cookies. All session cookies are temporary and expire after you close your web browser. Persistent cookies can be removed by following your web browser’s directions. In general, you can disable cookies and limit the collection and use of information through them by setting your browser to refuse cookies or to indicate when a cookie is being sent. For information about how to see the cookies that have been placed on your computer or device and how to reject and delete the cookies, please visit: https://www.aboutcookies.org/. Please note that each web browser is different. To find information relating to your browser, visit the browser developer’s website and mobile application. If you configure your web browser to block all cookies or to alert you when a cookie is being sent, some features of our Services may not function properly. If you choose to opt out, we will place an opt-out cookie on your device. The opt-out cookie is browser specific and device specific and only lasts until cookies are cleared from your browser or device. The opt-out cookie will not work for essential cookies. If the opt-out cookie is removed or deleted, if you upgrade your browser, or if you visit us from a different device, you will need to return and update your preferences. By clicking on the opt-out links below, you will be directed to the respective third-party website where your device will be scanned to determine who maintains cookies on your device. At that time, you can choose to opt out of all targeted advertising, or you can choose to opt out of specific targeted advertising by selecting individual companies who maintain a cookie on your device.


  • Opt out of email tracking. You can disable email tracking by disabling the display of images by default in your email program.
  • Opt out of marketing communications. You may opt out of receiving marketing emails from us by clicking the “Unsubscribe” link provided at the bottom of each email we send. Please note that we will continue to send you notifications necessary to the Services, your account, purchases, or any assistance you request.

4. YOUR RIGHTS REGARDING YOUR INFORMATION

Below are the rights of Users with respect to the Personal Information we collect. Users can exercise these rights by making updates in their Account settings or contacting us at info@kobotoolbox.org. To exercise their rights, Participants should contact the User in whose survey they are participating, and we will work with the User to address these rights.

  • Right to access: You have the right to ask us for access to the Personal Information we have collected from you. You can request a copy of your data by emailing us at info@kobotoolbox.org or by signing into your user account and visiting your user profile setting.
  • Right to rectification: You have the right to ask us to rectify Personal Information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. As a user, you can also correct information we have about you by signing into your account and visiting your user profile setting.
  • Right to erasure: You have the right to request the erasure of any Personal Information that we are not obligated to retain or continue processing (also known as the right to be forgotten). For example, you can request that we delete your Personal Information if: (i) we no longer need the data for the purpose it was collected for, (ii) we process the data based on your consent and you revoke your consent, (iii) you object to our processing based on legitimate interest (and we do not have an overriding legitimate interest), or (iv) you object to our processing for direct marketing purposes. We may not be able to immediately erase your Personal Information if we have a lawful reason or a legal or contractual obligation to retain the Personal Information or continue the processing. We will use reasonable efforts to honor your requests for deletion; however, certain residual information may actively persist on the Services even if you close your account. Your Personal Information may remain in our archives, and information you update or delete, or information within a closed account, may persist internally for our administrative purposes, to the extent permitted by law.

5. RIGHTS OF INDIVIDUALS IN THE EUROPEAN UNION AND UNITED KINGDOM

Individuals in the EU and UK are entitled certain rights to their Personal Information under applicable law. To the extent these laws apply to our processing of your Personal Information, you are entitled to the following rights:

  • Right to restrict processing: If you believe that your Personal Information is inaccurate, that our processing is unlawful, or that we do not need your Personal Information for a specific purpose, you have the right to request that we restrict the processing of this Personal Information. You also have the option to request that we stop processing your Personal Information while we assess your request. If you object to our processing (per your right to object as described below), you may also request that we restrict processing of your Personal Information while we make our assessment.
  • Right to object to processing: You have the right to object to processing of your Personal Information which is based on our legitimate interest (Article 6(1)(f) GDPR), by referencing your personal circumstances that makes you want to object to the processing on this ground.
  • Right to data portability: You have the right to ask that we transfer your Personal Information to another organization or that we transfer it to you. However, this right only applies when: (i) you have provided your Personal Information to us, (ii) the legal basis for the processing is your consent or for the performance of a contract, and (iii) the processing is carried out by automated means.

To exercise your rights, or for more information on how to exercise your rights, please contact us at info@kobotoolbox.org.

6. CHILDREN’S PRIVACY

The Services are general audience and intended for Users eighteen (18) years old and older. We do not knowingly collect Personal Information from anyone under the age of 18.

7. INTERNATIONAL JURISDICTIONS

Our Services are hosted and offered in the United States of America (US) and are subject to US federal, state, and local laws which allow government agencies to access Personal Information under certain circumstances. To conduct the collection and transfer of Personal Information (both from our Users to us and from us to our service providers), we have executed standard contractual clauses (“SCCs”) which have been approved by the European Commission. Please see the Controller to Processor and Processor to Processor SCCs for more information.

8. DO NOT TRACK

We do not respond to Do Not Track requests. Do Not Track is a preference you can set in your web browser to inform websites and mobile applications that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.

9. INFORMATION SECURITY

Kobo implements and maintains robust security measures to protect the Personal Information that we collect and retain, as described on this page . These include, but are not limited to, access controls and encryption designed to guard against unauthorized access and ensure data confidentiality. We have stringent contractual relationships with anyone with whom we share information, requiring them to adhere strictly to the same standards set by EU and UK data protection laws, as well as other relevant regulations. We are committed to both the letter and the spirit of these laws, ensuring that your Personal Information is treated with the highest level of care and security.

10. DATA RETENTION

In addition to the data retention periods outlined in PERSONAL INFORMATION WE COLLECT ABOUT YOU, HOW WE COLLECT IT, AND HOW LONG WE STORE IT, Kobo will retain your Personal Information until: (i) it is no longer needed for the purpose it was collected for, or (ii) we delete your information pursuant to your request, or (iii) for longer periods for the specific purposes identified below:

  • To exercise or defend legal claims: When your Personal Information is relevant to a legal claim or dispute involving Kobo, we retain that information during the pendency of that claim or dispute and for up to one (1) year after.
  • Compliance with our regulatory or legal obligations: We may need to retain certain information for longer periods to comply with legal requirements. For example, we need to retain information related to your purchase of our Services for specific periods for tax and accounting purposes. We also need to keep a record of your Participants’ rights requests pursuant to regulatory requirements.

11. CHANGES TO THIS NOTICE

We may amend this Privacy Notice in our sole discretion at any time. If we do, we will post the changes to this page and will indicate the date the changes take effect. We encourage you to review our Privacy Notice to stay informed. If we make changes that materially affect your privacy rights, we will notify you by prominent posting on the Website and/or via email, and we will obtain your consent, if required.

12. HOW TO CONTACT KOBO

Kobo welcomes your questions or comments regarding this Privacy Notice. Please contact us at:

Kobo, Inc.
37 Highland Ave
Cambridge MA, 02139
United States
Email Address: info@kobotoolbox.org