AI Disclosure Statement

Edition: August 2026

What PaperSurvey.io does

PaperSurvey.io is a survey platform operated by Mygtukynas, MB. Customers design a survey once and collect responses on paper, on the web, or both. Completed paper forms are scanned or photographed, uploaded, and turned into structured data that can be reviewed, analysed and exported.

Most of that pipeline is deterministic. Tick boxes and multiple-choice answers are read by optical mark recognition (OMR) from the known position of every box on the printed page, and each page is identified and aligned using a printed QR code and alignment marks. No generative AI and no external AI service is involved in those steps, and none is involved in web survey collection, statistics, charts or exports.

AI is used for a small number of specific tasks, described below. Each task works only on the requesting customer's own data, and none of them makes decisions about people.

The provider and the models. These features run on an enterprise AI platform operated by a sub-processor, not on models PaperSurvey.io trains or hosts. That platform hosts models from several developers, and we may move between them as more capable ones appear without changing sub-processor: the provider stays the same whichever model answers a request. The sub-processor list, published in our privacy policy and forming Annex 1 to our Data Processing Agreement, names both the platform and the model developer in use, and changes to it carry the notice and objection rights in section 6 of that Agreement. Section 6(8) separately authorises alternative providers reached directly. Whichever is used must meet the same conditions: no training on customer data, processing in the European Union, and only transient retention for abuse monitoring.

Where AI is used

Handwriting transcription. Handwritten open-ended answers and handwritten numbers on paper forms are transcribed by large language models accessed through the AI provider's enterprise platform. We send cropped images of the individual answer fields rather than whole pages. A fast model reads each field first; any field below our confidence threshold is automatically re-read by a more capable model. Every transcription carries a confidence score, and fields below the acceptance threshold are flagged for a person to confirm in the Verify tab instead of being accepted automatically. Customers set that threshold per question, and may also choose a mode that accepts every reading without flagging. Model versions change over time as more capable models become available.

Handwritten digits. Number fields printed as individual digit boxes are read first by an in-house digit recognition model that runs on our own infrastructure, and only readings it is not confident about are escalated to the AI provider. Number fields written free-form are read by the AI provider in the same way as handwritten text. Uncertain results are routed to human review either way.

Sentiment and topic tags. When an open-ended answer is transcribed, the same model call can return a sentiment label (positive, neutral or negative) and up to three short topic tags. These power the sentiment and topics charts in the analysis views. They are stored only for questions where sentiment or topic analysis is switched on, and the setting can be changed per question at any time.

Survey import. Customers can upload an existing questionnaire as a Word, PDF or text file and have it converted into an editable PaperSurvey survey. The document is sent to the same AI provider, which returns a structured list of questions. Those questions are written into the survey the customer selected and opened in the editor, where they can be checked, changed or deleted before the survey is printed or published. The feature only runs when a customer starts it.

Automatic translation. Question wording and answer options can be machine-translated into other languages by the same provider's machine translation service. Translation only runs when a customer requests it, and every translation can be edited afterwards.

Data and training

No training of third-party models on customer data. Our AI providers do not use content submitted through their enterprise APIs to train or improve their models. That is excluded by the enterprise terms we operate under, for transcription, handwritten digits, sentiment and topic tags, survey import and machine translation alike. The alternative providers authorised in section 6(8) of our Data Processing Agreement give the same guarantee under their enterprise terms, and we only work with providers whose terms do.

No cross-customer data sharing. Each AI request contains only the requesting customer's data. One customer's data never contributes to output for another customer.

Retention by the AI provider. The provider may cache prompts and outputs for a limited period for abuse detection and safety review under its enterprise service terms. We have not opted out of that abuse-monitoring window. Beyond it, nothing a customer sends is retained by the provider, and no request is used to answer another. We will provide the provider's current data-handling terms, including the applicable retention period, to any customer who asks.

Data location. AI requests are processed in the European Union, in the provider's EU region. That covers handwriting transcription, handwritten digits, sentiment and topic tags, survey import and machine translation, and any alternative provider may be used only through its EU data residency option. All traffic to the provider is encrypted with TLS.

Special categories of data. A handwritten open-ended answer can contain anything the respondent chose to write, including health information or other special categories of personal data under Article 9 GDPR. We do not detect or classify that content; it is transcribed like any other handwriting, under the same terms, and it is the customer as controller who decides what a survey asks and on what lawful basis.

Restricted operating mode. The restricted mode described in our Technical and Organizational Measures deactivates the paths that carry survey content to third parties the customer has not asked for: inbound scan-by-email, Dropbox, Google Sheets, Zapier, machine translation, response content in notification emails, public analysis views and support impersonation. Handwriting transcription stays on, since it is how a scanned form is read. A customer who wants no third-party AI processing of handwriting can switch handwriting recognition off for the team, and answers are then captured by optical mark recognition and manual entry only.

Data ownership

All data collected through PaperSurvey.io belongs to the customer. We do not sell or license it, and the only third parties that receive it are the sub-processors listed in our Data Processing Agreement, which process it on our documented instructions. When a survey is deleted it is held in the trash for 90 days and then permanently removed from production systems; encrypted offsite backups are purged within three months. Closing an account stops web survey collection and ends billing; the surveys, responses, uploaded files and team data held under it are erased on request to gdpr@papersurvey.io.

Human oversight (GDPR Art. 22)

AI output in PaperSurvey.io is a transcription or an analytical aid, never a decision. The original scan of every answer is kept and shown next to the recognised value, every value can be edited, and low-confidence fields are held for human confirmation before they count as verified. Sentiment labels and topic tags describe text; they do not trigger any action.

The platform does not carry out automated decision-making with legal or similarly significant effects on individuals under GDPR Article 22. Quiz and points scoring is calculated deterministically from the recorded answers. If a score depends on a handwritten field, we recommend confirming any flagged fields before relying on it.

Bias and discrimination

The models are used to read handwriting and to describe the tone and subject of written text. They do not profile individuals, assess people or produce any output about a respondent beyond what that respondent wrote. Transcription accuracy can vary with legibility, language and script, which is why every field carries a confidence score and uncertain fields go to a person. Sentiment and topic tags are approximate, language-dependent and intended for aggregate analysis; they should not be treated as assessments of individual respondents.

Accuracy

Automated recognition is never assumed to be perfect. The authoritative record is always the scanned image, which is stored alongside the recognised data and can be opened from any response. Confidence thresholds, the Verify tab and the recognition summary on each survey exist so that customers can see how much of a dataset was verified by a person. Recognised values can occasionally be wrong or incomplete; that is a known property of current models, and the review workflow is designed around it.

Controls available to customers

  • Sentiment and topic analysis can be switched off per question.
  • Survey import and automatic translation only run when a customer starts them.
  • Confidence thresholds route uncertain fields to human review; customers decide when a survey is verified.
  • Customers who need handwriting recognition disabled for a survey or team can contact support and we will configure it.

Credential security

Access to AI providers uses dedicated service credentials that are stored on our servers and are not accessible to customers. Customers never supply their own AI provider keys. All traffic to AI providers goes over HTTPS.

EU AI Act

Under Regulation (EU) 2024/1689 (the AI Act), as amended by Regulation (EU) 2026/1744, PaperSurvey.io is the provider of the AI systems described above, which are built on general-purpose AI models obtained from the AI provider. Where we use those systems in the course of our own activity we are also their deployer. The provider of the underlying general-purpose AI models is that AI provider, named in the sub-processor list, and not PaperSurvey.io: we neither train nor fine-tune those models.

Classification. The intended purpose of these features is to read what a respondent has written on a form and to make it available to the organisation that ran the survey. They do not evaluate, rank, profile or make decisions about people. On that intended purpose none of the high-risk categories in Annex III applies. None of the practices prohibited by Article 5 is carried out either: the platform performs no biometric categorisation, no social scoring and no emotion recognition, and it generates no image, audio or video content of any kind.

Not an emotion recognition system. Sentiment labels are inferred from the words a respondent wrote, after transcription, and never from biometric data such as facial expression, voice or handwriting style. An emotion recognition system under Article 3(39) is one that infers emotions from biometric data, so this feature falls outside that definition. It can also be switched off per question.

No biometric processing. Handwriting is read for its content only, never analysed to identify or authenticate the writer. Where a form contains a signature field, the signature is captured and stored as an image and is deliberately excluded from recognition; it is not compared, matched or used to identify anyone.

Transparency. The transparency duties in Article 50 have applied since 2 August 2026. They are not triggered here: the AI features do not interact with respondents, and generate no synthetic audio, image, video or text within the meaning of Article 50(2), because transcription reproduces what a respondent actually wrote rather than generating new content, so there is nothing that must be marked or declared under that article. This statement, together with the description of human oversight above, is how we meet our transparency commitments to customers.

Customer obligations. How a customer uses the platform can change its own position. An organisation that uses PaperSurvey.io to evaluate learning outcomes, to assess candidates or employees, or to decide access to a service may itself become the provider of a high-risk AI system under Article 25(1)(c), by putting the system to a purpose that makes it high-risk, and take on the corresponding obligations rather than the lighter deployer ones, which apply from 2 December 2027 for the systems listed in Annex III. Customers planning such a use should assess it before starting, and we will support that assessment on request.

Staff competence. We take measures to support the development of AI literacy among the personnel who work with these features and, so far as we are able, to ensure they understand the capabilities, limits and risks of the recognition pipeline, in line with Article 4.

Contact

Questions about this document or our use of AI:

hello@papersurvey.io · gdpr@papersurvey.io · https://www.papersurvey.io