how privacy works

Anonymous to your employer. Protected through every report.

Candora responses are completely anonymous to HR. Private participant and reporting-group data supports survey delivery, then a separate privacy-safe result layer supplies every employer report. HR cannot switch anonymity off, access raw responses, or recut results to identify how someone answered.

from invitation to insight

One survey. Two deliberately separate data layers.

Identifiable survey source data and employer-visible results have different jobs, permissions, and database roles. The report boundary is enforced by the product, not left to an HR privacy setting.

  1. 1

    Private invitation

    Your organisation provides a participant email and reporting group. Candora sends a private one-time link so it can accept one response, manage delivery, and preserve the right group attribution.

  2. 2

    Restricted source response

    Candora validates the link and holds the submitted response in a restricted source layer. This layer is not available to employer accounts, report pages, or employer exports.

  3. 3

    Privacy-safe result

    After the survey closes, restricted processing creates versioned organisation and eligible reporting-group aggregates. Any group or question result supported by fewer than three responses is suppressed.

  4. 4

    Employer report

    Every employer-facing report and CSV reads the privacy-safe result layer. It contains aggregate metrics and protected findings, not response IDs, timestamps, individual answers, or written comments.

the employer boundary

Useful operating information in. Individual answers out.

Candora does not ask employees to trust an administrator's configuration. There is no HR-controlled anonymity switch, raw-response view, or arbitrary filtering path that can reconstruct a participant's answers.

The employer can see

The participant roster it supplied
Invitation delivery and completion status
Aggregate participation
Privacy-safe question results
Eligible reporting-group results
Grouped free-text findings

The employer cannot access

Which participant gave which answer
Raw response or answer records
Individual written comments
Results below the three-response threshold
Arbitrary recuts that isolate participants
Response IDs or timestamps in exports

written feedback

Shared patterns become findings. Individual comments do not become report content.

Candora generates a finding only when at least three distinct answers support it. Evidence is represented by local anonymous labels during analysis, direct identifiers are rejected, and the employer receives the resulting theme rather than source comments.

Does Candora know who received a survey link?

Yes. Candora uses a private link to manage delivery, accept one response, and preserve reporting-group attribution. That source linkage is restricted from employer accounts and reports. The employer can see whether an invitation was completed, but not the answers attached to it.

Can HR identify someone by combining filters?

No. Candora reports against defined reporting groups rather than arbitrary combinations of filters. HR cannot recut the source responses, and a group or question result is suppressed when fewer than three people support it.

What happens to written answers?

Written answers are held in the restricted source layer and converted into recurring findings. A finding needs support from at least three distinct answers, is checked for direct identifiers, and is never presented as an individual employee quote.

When do employer-visible results become available?

Privacy-safe result generation begins after the survey closes. Employer-facing reports are generated from that completed safe layer, not directly from live or raw responses.

membership

See what protected reporting looks like.

Inspect the synthetic sample report, then create a business account when the privacy boundary and reporting model fit your organisation.

Start membership