# GetWhy A/S

GetWhy is a global provider of consumer research technology, empowering businesses with AI-driven insights to understand their customers at scale. We uphold the highest standards of data privacy and security — integrating robust encryption, access control, and compliance with industry-leading frameworks.

Proud holders of ISO/IEC 27001:2022 certification, we are continuously raising the bar on protecting our customers' data. Because being more human means being more secure.

Be More Human.

## Compliance

ISO 27001:2022

SOC 2  
GDPR

## Resources

### Compliance Certifications

ISO/IEC 27001:2022

### ISMS

[02-ISMS Information Security Management System (ISMS) Policy (EN)](https://trust.getwhy.io/?requestAccessOpen=true&requestedResources=6a326a5d24b9707919a04751)

[03-ISMS Roles, Responsibilities, and Authorities (EN)](https://trust.getwhy.io/?requestAccessOpen=true&requestedResources=6a326abce76fa8bd12a189c2)

[04-ISMS Risk Assessment and Risk Treatment Process (EN)](https://trust.getwhy.io/?requestAccessOpen=true&requestedResources=6a326af3f996481dcdaf3059)

[05-ISMS Procedure for the Control of Documented Information (EN)](https://trust.getwhy.io/?requestAccessOpen=true&requestedResources=6a326b16dcbc582e079c3008)

### Policies

[Human Resource Security Policy (EN)](https://trust.getwhy.io/?requestAccessOpen=true&requestedResources=6a326db381856e679023b8f1)

[Third-Party Management Policy (EN)](https://trust.getwhy.io/?requestAccessOpen=true&requestedResources=6a326dd72c350ee9c0a3ddbe)

[Risk Management Policy (EN)](https://trust.getwhy.io/?requestAccessOpen=true&requestedResources=6a326df275256bd4c395d1ea)

[Asset Management Policy (EN)](https://trust.getwhy.io/?requestAccessOpen=true&requestedResources=6a326e0e09d612eff4d03d4e)

### Security Testing

[ReTest Security - Web pentest (EN)](https://trust.getwhy.io/?requestAccessOpen=true&requestedResources=6a34f1983a72334da2e35bae)

## Controls

Updated 2 minutes ago

### Infrastructure security

- Encryption key access restricted
- Access control procedures established
- Production database access restricted

### Organizational security

- Employee background checks performed
- Confidentiality Agreement acknowledged by contractors
- Confidentiality Agreement acknowledged by employees

### Product security

- Data encryption utilized
- Control self-assessments conducted
- Penetration testing performed

### Internal security procedures

- Cybersecurity insurance maintained
- Configuration management system established
- SOC 2 - System Description

### Data and privacy

- Data retention procedures established
- Data classification policy established

## Data collected

- Customer personally identifiable information
- Employee personally identifiable information
- Credit card information
- Personal health information

## Subprocessors

Amazon Web Services  
• Cloud provider  
410 Terry Avenue North, WA 98109-510, USA  
Data storage, backups, CDN, DNS, SSL, domain management, emails

Google LLC  
• Audio transcription, natural language processing (English language studies)  
1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Microsoft Corporation  
• Audio transcription, natural language processing (Non-English language studies)  
One Microsoft Way, Redmond, WE 98052-6399, USA

Typeform SL  
• Participant qualification  
C/Bac de Roda, 163 (Local), 08018, Barcelona, Spain

Vanta connects to a company's core systems to continuously monitor these controls.
