LimeSurvey - Easy online survey tool LimeSurvey - Easy online survey tool
  • الحلول
    • Solutions sub
  • قوالب
    • Templates sub
  • منتج
    • استطلاع رأي
    • استطلاع رأي
    • تصويت
    • نموذج
    • مسح
  • الدعم
    • مدونة
    • نظرة عامة
    • مركز المساعدة
    • المنتديات
    • الدعم
    • جهات الاتصال
    • الشركاء
  • التسعير
Contact salesسجّل الدخول ابدأ - مجانًا
LimeSurvey - Easy online survey tool LimeSurvey - Easy online survey tool
  • الحلول
    الحلول الشائعة
    نموذج تقييم 360 درجة

    نموذج تقييم 360 درجة

    استبيان تقييم الفعالية الأكاديمية

    استبيان تقييم الفعالية الأكاديمية

    جميع قوالب الاستبيان
    دورك
    مدير الأعمال
    أخصائي رعاية العملاء
    منسق الحدث
    مدير التسويق
    مسؤول الموارد البشرية
    طبيب/عامل صحي
    مدير المنتج
    مدير الرياضة
    طالب
    معلم/مربي
    باحث سوق
    أنواع الاستبيانات
    الأعمال
    شركات
    العميل
    التعليم
    الجامعات
    الأحداث
    الرعاية الصحية
    الموارد البشرية
    أبحاث السوق
    التسويق
    غير الربحي
    منتج
    رياضة
    أخرى
    حالات الاستخدام
    البحث الأكاديمي
    تقييم المقرر الدراسي
    تجربة العملاء
    رضا العملاء
    تجربة الموظف
    تحفيز الموظفين
    تخطيط الأحداث
    تقسيم السوق
    أبحاث السوق
    رضا المرضى
    تسعير المنتج
  • قوالب
    الاختيارات الشائعة
    نموذج تقييم 360 درجة

    نموذج تقييم 360 درجة

    استبيان تقييم الفعالية الأكاديمية

    استبيان تقييم الفعالية الأكاديمية

    جميع قوالب الاستبيان
    قوالب الاستبيان
    قوالب الأعمال
    قوالب الشركات
    قوالب العملاء
    قوالب تعليمية
    قوالب الأحداث
    قوالب الرعاية الصحية
    قوالب الموارد البشرية
    نماذج أبحاث السوق
    قوالب المنظمات غير الربحية
    قوالب المنتجات
    قوالب الرياضة
    قوالب أخرى
    قوالبنا
    • دوركدورك
      • مدير الأعمال
      • أخصائي خدمة العملاء
      • منسق الفعاليات
      • مسؤول الموارد البشرية
      • مدير تسويق
      • طبيب/عامل صحي
      • مدير المنتج
      • طالب
      • مدير رياضي
      • معلم/مربي
    • نماذج الاستطلاعنماذج الاستطلاع
      • الأعمال
        • نموذج الطلبات
        • التسوق
        • نموذج الحجز
        • شركة ناشئة
      • شركة
        • مُعَلَّم
        • محترف
      • عميل
        • تجربة العملاء
        • رضا العملاء
        • ملاحظات العملاء
        • ولاء العملاء
        • تقييم العميل
        • خدمة العملاء
      • التعليم
        • تقييم الدورة
        • طالب
        • معلم
        • أكاديمي
        • تقييم المدرب
        • مدرسة
        • رضا الطالب
        • جامعة
      • حدث
        • تجربة الحدث
        • تخطيط الفعاليات
        • تخطيط الاجتماعات
      • الرعاية الصحية
        • رضا المريض
        • لياقة بدنية
        • تقييم الكحول
        • تقييم الصحة النفسية
        • الصحة النفسية
        • موافقة المريض
        • مريض
        • اختبار الشخصية
      • الموارد البشرية
        • تجربة الموظف
        • تحفيز الموظفين
        • التقييم الشامل 360 درجة
        • تطبيق
        • تقييم المرشح
        • البحث عن وظيفة
        • استبيان الموظف
        • موظف
        • مشاركة الموظفين
        • رضا الموظفين
        • رضا الوظيفة
        • نبض
      • أبحاث السوق
        • تجزئة السوق
        • بحث
        • اختبار المفهوم
        • البحث عبر الإنترنت
      • تسويق
        • توليد العملاء المحتملين
        • وعي العلامة التجارية
        • فعالية الإعلان
        • بناء العلامة التجارية
        • تصور العلامة التجارية
        • علامة تجارية
      • غير ربحي
        • كنيسة
        • حقوق الإنسان
        • مجتمع
        • سياسي
      • منتج
        • تجربة المنتج
        • تسعير المنتجات
        • تقييم المنتج
      • رياضة
        • لياقة البدنية
        • غولف
      • أخرى
        • نماذج مجهولة الهوية
        • استطلاع رأي
        • علم الفلك
        • قائمة التحقق
        • رعاية الأطفال
        • نموذج الشكوى
        • نموذج الاتصال
        • نموذج الاستفسار
        • نموذج التقييم
        • نموذج التعليقات
        • تقييم المعلم
        • الأمومة
        • حيوان أليف
        • استطلاع
        • خصوصية
        • اختبار
        • استمارة التسجيل
        • نموذج الطلب
        • رضا
        • تقييم ذاتي
        • ورقة تسجيل
        • وسائل التواصل الاجتماعي
        • تدريب
    • حالات الاستخدامحالات الاستخدام
      • البحث الأكاديمي
      • تقييم الدورة
      • تجربة العميل
      • رضا العملاء
      • تجربة الموظف
      • تحفيز الموظفين
      • تخطيط الفعاليات
      • تقسيم السوق
      • أبحاث السوق
      • رضا المرضى
      • تسعير المنتج
  • منتج
    القوالب الشائعة
    نموذج تقييم 360 درجة

    نموذج تقييم 360 درجة

    استبيان تقييم الفعالية الأكاديمية

    استبيان تقييم الفعالية الأكاديمية

    جميع قوالب الاستبيان
    منتجات
    استطلاع رأي
    استطلاع رأي
    تصويت
    نموذج
    مسح
    الأدوات
    حاسبة هامش الخطأ
    حاسبة حجم العينة
    حاسبة معدل جهد العميل (CES)
    حاسبة معدل رضا العملاء (CSAT)
    حاسبة معدل الترويج الصافي (NPS)
    حاسبة معدل الترويج الصافي للموظفين (eNPS)
    حاسبة الدلالة الإحصائية
    حاسبة اختبار A/B
    حاسبة حجم عينة MaxDiff
    حاسبة تحسين الأسعار
  • الدعم
    • مدونة
    • نظرة عامة
    • مركز المساعدة
    • المنتديات
    • الدعم
    • جهات الاتصال
    • الشركاء
  • التسعير
اَلْعَرَبِيَّةُ AR
  • Bokmål
  • Čeština
  • Dansk
  • Deutsch
  • Deutsch (Schweiz)
  • English
  • Español
  • Español (Mexico)
  • Français
  • हिन्दी
  • Hrvatski
  • Bahasa Indonesia
  • Italiano
  • 日本語
  • 한국어
  • Magyar
  • Bahasa Melayu
  • Монгол
  • Nederlands
  • Polski
  • Português
  • Português (Brasil)
  • Română
  • Русский
  • Slovenčina
  • Suomi
  • Svenska
  • Tagalog
  • ไทย
  • Türkçe
  • Українська
  • Tiếng việt
  • 简体中文(中国大陆)
  • 繁體中文 (台灣)
Contact sales سجّل الدخول ابدأ - مجانًا
ابدأ - مجانًا

Technical and organisational measures (TOM) To ensure that the Data Processor engages in contract processing of personal data in accordance with the law, the following technical and organisational measures shall be observed pursuant to Art. 32 GDPR: Confidentiality Physical access control This involves minimum measures to prevent unauthorised persons from accessing data processing systems that process personal data: Data centre Electronic access control system with logging Guidelines for escorting and identifying guests in the building 24/7 staffing of the data centres Video surveillance at the entrances and exits Office spaces (LimeSurvey GmbH) Visitors may not enter offices unattended Entrance doors to office spaces are particularly resistant and made of metal All doors are equipped with security locks Secure locking system with transponder cards Individually lockable cabinets System access control This involves minimum measures to prevent the use of data processing systems by unauthorised persons: Data centre The passwords for the dedicated servers provided will be changed by the Client LimeSurvey GmbH after initial commissioning and will not be known to the Data Processor (data centre). Software (LimeSurvey) Passwords in LimeSurvey shall be determined exclusively by the Client. Passwords shall not be stored directly, but only via a salted SHA-256 hash. The Client can select within the application which data (participants and/or survey data) is stored in the database in encrypted form (at-rest encryption). Encryption shall be performed symmetrically with the encryption XSalsa20-Poly1305 – the key is stored outside the database. System administration of the servers (LimeSurvey GmbH) Exclusive authentication with asymmetric cryptosystem (encryption by public and private keys) Office spaces/employees (LimeSurvey GmbH) Authentication to the operating system and applications is performed via individual user ID and password Automatic lock by screen saver with password entry after 5 minutes of inactivity. Employees shall also be instructed to lock the workstation computer when leaving the room. Employees shall be instructed to keep passwords secret and to change them if they suspect they are compromised The following minimum requirements shall apply to the passwords: The password must have at least 10 characters for the additional use of 2-factor authentication (2FA), and without the use of 2FA must have at least 14 characters. The password must contain characters from at least three of the following four groups: a-z, A-Z, 0-9, other printable ASCII characters. To reduce the risk of passwords being guessed, no trivial passwords may be used (trivial would be a word from a dictionary, surname or first name, the user ID, date of birth, car licence plate number, telephone number or other details from the user's personal environment that may also be known to other people). Computer hard drives shall always be encrypted. This applies to both desktop PCs and mobile devices (notebooks, laptops, etc.). Employees shall be prohibited from using mobile data carriers or installing third-party software without prior consultation. Data access control This involves minimum measures to ensure that people authorised to use a data processing system can only access the data subject to their access authorisation and that personal data cannot be read, copied, modified or removed without authorisation during processing: System administration (LimeSurvey GmbH) Number of administrators reduced to a "minimum" Complete and proper deletion/destruction of data carriers before any other use or handover Management of system and user rights by defined system administrators Office spaces/employees (LimeSurvey GmbH) Number of administrators reduced to a "minimum" The data processing systems (Internet, e-mail, server systems, etc.) shall be used exclusively for professional purposes. Content/data may only be stored on a server or your own PC if this is necessary for professional purposes. Content/data that is no longer required must be deleted. Regular checking and updating of authorisations, including blocking of, e.g., departed employees Access logging and evaluation shall be performed at least annually Verification and documentation of where personal data has been transferred to (transfer control) Drive-specific access Complete and proper GDPR-compliant deletion including deletion protocol before any other use or handover. GDPR-compliant disposal of data carriers including log. Prohibition of bring-your-own device Separation control This involves minimum measures to ensure that personal data collected for different purposes and for different clients is processed separately: Logical client separation (in software) Setting of individual database rights Separate database and database users with password for each Client Data collected with the contractual software will only be used by the Client or for the purpose defined in the Contract. Pseudonymisation The processing shall be carried out, as far as possible, in such a way that the data can no longer be attributed to a natural person without the use of additional information. LimeSurvey website The recording of IP addresses shall be avoided in the system administration and recorded IP addresses shall be anonymised by shortening them. LimeSurvey cloud The option of anonymisation/pseudonymisation by the Client through appropriate configuration within the software. Integrity Handover control This involves minimum measures to ensure that personal data cannot be read, copied, altered or removed without authorisation during electronic transmission or during transport or storage on data carriers: Data centre All employees are to be regularly trained/instructed in data protection. Data protection-compliant deletion of data after completion of the order. Software (LimeSurvey cloud) The connection between the browser and the cloud application shall always be always encrypted with SSL (https://). Office spaces/employees (LimeSurvey GmbH) The use of mobile data carriers is strictly prohibited. All employees are obliged to maintain confidentiality pursuant to Art. 5 (2) GDPR. Email communication and access to documents by LimeSurvey GmbH employees shall be protected by encryption and firewalls. Mobile access to the company network is only possible by using VPN. Input control (traceability, documentation) This involves minimum measures to ensure that it is possible to subsequently check whether and by whom personal data can be entered, modified or removed in data processing systems: Software (LimeSurvey cloud) Assignment of rights for the input, modification and deletion of data by the Client The option of activation of an audit log by the Client to log data changes Office spaces/employees (LimeSurvey GmbH) All employees shall sign a confidentiality clause that also protects the Client after their employment. All employees of the Data Processor shall only be able to access such data if it is necessary for their work. Employees may only access data of a customer within the framework of firmly defined rules Availability This involves minimum measures to ensure that personal data is protected against accidental destruction or loss, against technical malfunctions due to the failure of the operating/application software, against negligent/intentional actions, and against harmful software: Data centre Implementation of uninterruptible power supply (UPS) Equipment for monitoring temperature and humidity in server rooms Fire and smoke detection systems The early fire detection system shall be connected to the fire alarm centre of the local fire brigade Air conditioning in server rooms System administration (LimeSurvey cloud) Use of intrusion detection systems Use of anti-virus software Use of a software firewall Automatic DDOS protection of the server Regular updating of all software components, at least every 7 days. Backup & recovery concept: General data backup for all user files (images, design templates, etc.) shall be backed up incrementally every 24 hours (i.e., only changes). A main backup is to be performed every 7 days. A maximum of 2 main fuses are to be provided. The data in the user database shall be completely backed up every 24 hours. The last 7 days are to be stored daily; weekly backups are to be stored for 4 weeks. All data shall be encrypted during backup and stored on a special external data system (in the same data centre). All servers are generally to be equipped with raid hard drive systems. In the event of a hard drive failure, the software shall continue to run on a hard drive after a brief interruption in operation (restart of the server). In principle, a defective hard drive is to be replaced within 24 hours, so that full security is then provided again. Monitoring (other, review, evaluation and evaluation) This involves minimum measures to ensure that the measures are suitable to guarantee safety and withstand the loads, if possible with fixed minimum time intervals. General An external data protection officer shall be employed in accordance with legal requirements Employees are to be regularly trained in data protection Data centre Data shall be stored physically or logically separately from other data. The data is also to be backed up to logically and/or physically separate systems. LimeSurvey cloud Logical client separation (in software) Setting of individual database rights Separate database and database users with password for each Client Data collected with the contractual software will only be used by the Client for the purpose defined in the Contract.

Technical and organisational measures (TOM)

To ensure that the Data Processor engages in contract processing of personal data in accordance with the law, the following technical and organisational measures shall be observed pursuant to Art. 32 GDPR:

Confidentiality

Physical access control

This involves minimum measures to prevent unauthorised persons from accessing data processing systems that process personal data:

Data centre

  • Electronic access control system with logging
  • Guidelines for escorting and identifying guests in the building
  • 24/7 staffing of the data centres
  • Video surveillance at the entrances and exits

Office spaces (LimeSurvey GmbH)

  • Visitors may not enter offices unattended
  • Entrance doors to office spaces are particularly resistant and made of metal
  • All doors are equipped with security locks
  • Secure locking system with transponder cards
  • Individually lockable cabinets

System access control

This involves minimum measures to prevent the use of data processing systems by unauthorised persons:

Data centre

  • The passwords for the dedicated servers provided will be changed by the Client LimeSurvey GmbH after initial commissioning and will not be known to the Data Processor (data centre).

Software (LimeSurvey)

  • Passwords in LimeSurvey shall be determined exclusively by the Client.
  • Passwords shall not be stored directly, but only via a salted SHA-256 hash.
  • The Client can select within the application which data (participants and/or survey data) is stored in the database in encrypted form (at-rest encryption). Encryption shall be performed symmetrically with the encryption XSalsa20-Poly1305 – the key is stored outside the database.

System administration of the servers (LimeSurvey GmbH)

  • Exclusive authentication with asymmetric cryptosystem (encryption by public and private keys)

Office spaces/employees (LimeSurvey GmbH)

  • Authentication to the operating system and applications is performed via individual user ID and password
  • Automatic lock by screen saver with password entry after 5 minutes of inactivity. Employees shall also be instructed to lock the workstation computer when leaving the room.
  • Employees shall be instructed to keep passwords secret and to change them if they suspect they are compromised
  • The following minimum requirements shall apply to the passwords:
    • The password must have at least 10 characters for the additional use of 2-factor authentication (2FA), and without the use of 2FA must have at least 14 characters.
    • The password must contain characters from at least three of the following four groups: a-z, A-Z, 0-9, other printable ASCII characters.
    • To reduce the risk of passwords being guessed, no trivial passwords may be used (trivial would be a word from a dictionary, surname or first name, the user ID, date of birth, car licence plate number, telephone number or other details from the user's personal environment that may also be known to other people).
  • Computer hard drives shall always be encrypted. This applies to both desktop PCs and mobile devices (notebooks, laptops, etc.).
  • Employees shall be prohibited from using mobile data carriers or installing third-party software without prior consultation.

Data access control

This involves minimum measures to ensure that people authorised to use a data processing system can only access the data subject to their access authorisation and that personal data cannot be read, copied, modified or removed without authorisation during processing:

System administration (LimeSurvey GmbH)

  • Number of administrators reduced to a "minimum"
  • Complete and proper deletion/destruction of data carriers before any other use or handover
  • Management of system and user rights by defined system administrators

Office spaces/employees (LimeSurvey GmbH)

  • Number of administrators reduced to a "minimum"
  • The data processing systems (Internet, e-mail, server systems, etc.) shall be used exclusively for professional purposes.
  • Content/data may only be stored on a server or your own PC if this is necessary for professional purposes. Content/data that is no longer required must be deleted.
  • Regular checking and updating of authorisations, including blocking of, e.g., departed employees
  • Access logging and evaluation shall be performed at least annually
  • Verification and documentation of where personal data has been transferred to (transfer control)
  • Drive-specific access
  • Complete and proper GDPR-compliant deletion including deletion protocol before any other use or handover.
  • GDPR-compliant disposal of data carriers including log.
  • Prohibition of bring-your-own device

Separation control

This involves minimum measures to ensure that personal data collected for different purposes and for different clients is processed separately:

  • Logical client separation (in software)
  • Setting of individual database rights
  • Separate database and database users with password for each Client
  • Data collected with the contractual software will only be used by the Client or for the purpose defined in the Contract.

Pseudonymisation

The processing shall be carried out, as far as possible, in such a way that the data can no longer be attributed to a natural person without the use of additional information.

LimeSurvey website

  • The recording of IP addresses shall be avoided in the system administration and recorded IP addresses shall be anonymised by shortening them.

LimeSurvey cloud

  • The option of anonymisation/pseudonymisation by the Client through appropriate configuration within the software.

Integrity

Handover control

This involves minimum measures to ensure that personal data cannot be read, copied, altered or removed without authorisation during electronic transmission or during transport or storage on data carriers:

Data centre

  • All employees are to be regularly trained/instructed in data protection.
  • Data protection-compliant deletion of data after completion of the order.

Software (LimeSurvey cloud)

  • The connection between the browser and the cloud application shall always be always encrypted with SSL (https://).

Office spaces/employees (LimeSurvey GmbH)

  • The use of mobile data carriers is strictly prohibited.
  • All employees are obliged to maintain confidentiality pursuant to Art. 5 (2) GDPR.
  • Email communication and access to documents by LimeSurvey GmbH employees shall be protected by encryption and firewalls.
  • Mobile access to the company network is only possible by using VPN.

Input control (traceability, documentation)

This involves minimum measures to ensure that it is possible to subsequently check whether and by whom personal data can be entered, modified or removed in data processing systems:

Software (LimeSurvey cloud)

  • Assignment of rights for the input, modification and deletion of data by the Client
  • The option of activation of an audit log by the Client to log data changes

Office spaces/employees (LimeSurvey GmbH)

  • All employees shall sign a confidentiality clause that also protects the Client after their employment.
  • All employees of the Data Processor shall only be able to access such data if it is necessary for their work.
  • Employees may only access data of a customer within the framework of firmly defined rules

Availability

This involves minimum measures to ensure that personal data is protected against accidental destruction or loss, against technical malfunctions due to the failure of the operating/application software, against negligent/intentional actions, and against harmful software:

Data centre

  • Implementation of uninterruptible power supply (UPS)
  • Equipment for monitoring temperature and humidity in server rooms
  • Fire and smoke detection systems
  • The early fire detection system shall be connected to the fire alarm centre of the local fire brigade
  • Air conditioning in server rooms

System administration (LimeSurvey cloud)

  • Use of intrusion detection systems
  • Use of anti-virus software
  • Use of a software firewall
  • Automatic DDOS protection of the server
  • Regular updating of all software components, at least every 7 days.
  • Backup & recovery concept:
    • General data backup for all user files (images, design templates, etc.) shall be backed up incrementally every 24 hours (i.e., only changes).
    • A main backup is to be performed every 7 days. A maximum of 2 main fuses are to be provided.
    • The data in the user database shall be completely backed up every 24 hours. The last 7 days are to be stored daily; weekly backups are to be stored for 4 weeks.
    • All data shall be encrypted during backup and stored on a special external data system (in the same data centre).
    • All servers are generally to be equipped with raid hard drive systems. In the event of a hard drive failure, the software shall continue to run on a hard drive after a brief interruption in operation (restart of the server). In principle, a defective hard drive is to be replaced within 24 hours, so that full security is then provided again.

Monitoring (other, review, evaluation and evaluation)

This involves minimum measures to ensure that the measures are suitable to guarantee safety and withstand the loads, if possible with fixed minimum time intervals.

General

  • An external data protection officer shall be employed in accordance with legal requirements
  • Employees are to be regularly trained in data protection

Data centre

  • Data shall be stored physically or logically separately from other data.
  • The data is also to be backed up to logically and/or physically separate systems.

LimeSurvey cloud

  • Logical client separation (in software)
  • Setting of individual database rights
  • Separate database and database users with password for each Client
  • Data collected with the contractual software will only be used by the Client for the purpose defined in the Contract.

قانوني

  • الشروط والأحكام
  • إشعار قانوني
  • سياسة الخصوصية
  • الإلغاء
  • الانسحاب

معلومات عنا

  • مدونة
  • النشرة الإخبارية
  • الوظائف

Open Source

  • المجتمع
  • المنتديات
  • المطورون
  • الترجمة
  • أنواع الاستبيانات
  • قوالب الاستبيان
  • أدوات الاستطلاع
  • حالات الاستخدام
GDPR CCPA ISO 27001 is in progress
اَلْعَرَبِيَّةُ AR
  • Bokmål
  • Čeština
  • Dansk
  • Deutsch
  • Deutsch (Schweiz)
  • English
  • Español
  • Español (Mexico)
  • Français
  • हिन्दी
  • Hrvatski
  • Bahasa Indonesia
  • Italiano
  • 日本語
  • 한국어
  • Magyar
  • Bahasa Melayu
  • Монгол
  • Nederlands
  • Polski
  • Português
  • Português (Brasil)
  • Română
  • Русский
  • Slovenčina
  • Suomi
  • Svenska
  • Tagalog
  • ไทย
  • Türkçe
  • Українська
  • Tiếng việt
  • 简体中文(中国大陆)
  • 繁體中文 (台灣)
Copyright © 2006-2026 LimeSurvey GmbH ⚓ Hamburg, Germany