PrimeSurvey
Survey software for non-interventional research

What PrimeSurvey actually does.

PrimeSurvey is a survey and research data-collection platform for non-interventional research, public consultation and participant or staff surveys. It is EU owned, hosted, developed and operated by Nuwa Limited. It suits this work, and it is not the tool for regulated interventional clinical trials or customer experience programmes, so discount anything here that sounds like it is.

This page is long and specific, and the last section lists what the product cannot do. That section is there because you would find out anyway, and finding out from a sales call is worse for both of us.

The wrong fit
  • Regulated interventional clinical trials.
  • Customer experience or employee engagement programmes.
  • Panel-based market research, because quota management, panel integration and sample weighting are all absent and all table stakes in that market.
Read the full scope, stated plainly
Building the instrument

Thirteen element types, on a file format that carries no code.

13 element types. 10 take an answer: rating, numeric, comment, radio, checkbox, dropdown, boolean, date, ranking and matrix. Three carry structure rather than answers: panel, callout and disclosure. The toolbox adds ready-made presets for net promoter, opinion and Likert scales.

Conditional visibility runs on 10 operators, equals and answered among them, and they nest with all, any and not. That is show and hide. There is no branching engine. Piping and calculated fields are absent too.

The interchange format carries no code to run. It holds no expression strings and no regular expressions, so there is nothing to evaluate. A questionnaire file from an untrusted source cannot execute anything when you import it. A format that is safe to exchange is worth more than one that can do arithmetic.

Illustration. Thirteen element kinds across five palettes
Getting it approved

Publication waits for a complete lawful basis. HTTP 409 when it is missing.

The lawful basis wizard runs inside the builder. A survey whose basis is unsettled cannot be published.

The impact assessment wizard walks the 9 WP248 criteria and records whether the data protection officer was consulted under Article 36. A study that needs an assessment and has none is refused at publication inside a serialisable transaction. The refusal is written to the audit log as survey.launch_blocked and returned as HTTP 409.

Elements that usually carry special-category data arrive flagged. Turning the flag off takes an audited attestation.

Article 30 records are authored in the product, frozen, and exported as PDF and JSON-LD. A database trigger holds the frozen snapshot, so it cannot be amended later.

Illustration. The launch-readiness surface and its HTTP 409 refusal
Asking people

Four access modes, and a salted hash in place of any raw IP.

Public. A link, no account. The session token is stored as a SHA-256 hash, never in the clear. Password. A shared passphrase hashed with argon2id, with no per-participant identifier.

Invite. Per-participant grants with a one-time code hashed with argon2id. The invitation address is discarded once the invitation is sent. Pseudonymised. The same gate as Invite, with addresses suppressed on import and on export.

Consent is captured before the questionnaire opens and written to append-only tables. Withdrawal under Article 7(3) is participant-facing, recorded as a lifecycle event rather than a deletion. Answers drop out of analysis while the record of the withdrawal is kept, so the withdrawal is itself the evidence it happened.

Raw IP addresses are never stored. What is stored is a salted SHA-256 hash.

Pseudonymised

Pseudonymised data stays personal data, and the platform enforces that.

Pseudonymised data is still personal data. The European Data Protection Board stated this in Guidelines 01/2025.

In Invite and Pseudonymised modes a participant reference exists, generated by a cryptographic random number generator and stored in the clear. It joins to the response through two foreign keys, which is how a withdrawal can be honoured.

One caveat, stated plainly. In Public mode with the consent-signature flow, the signature stores a typed name, a hashed IP and the user agent, joined to the answers. A signed Public survey is not anonymous. Do not put that word in front of your ethics committee.

The platform holds customers to this too. Write anonymous into your own impact assessment or Article 30 record and the save pauses until you attest.

Accessibility

WCAG 2.2 AA is our tested target.

WCAG 2.2 AA is the tested target. 20 Playwright specifications run axe on every change, against WCAG 2.0, 2.1 and 2.2 at levels A and AA. 6 of them drive participant-facing pages, the half most vendors leave untested.

Automated tooling catches about a third of the success criteria. There is no manual keyboard suite and no screen-reader suite yet, so the claim stops at tested target.

Ranking uses move buttons and an ARIA live region rather than a drag handle, because drag and drop is a known barrier under SC 2.1.1 and SC 2.5.7. Reports render to PDF/UA-1, so the document is tagged.

On the law. A public body is bound by the Web Accessibility Directive 2016/2102 through EN 301 549 v3.2.1, which maps to WCAG 2.1 A and AA. Version 4.1.0 is at final draft and on 08-08-2026 it is not cited in the Official Journal. The European Accessibility Act does not list survey software among its service categories.

Languages

Twenty-four languages in the interface. Your questionnaire is authored by file.

The interface ships in all 24 official EU languages. Every one of the 1,515 interface strings exists in all 24 catalogues, checked by a continuous integration guard on every change. Between 95.3 and 99.2 per cent of values differ from the English source.

What is measured is that they are translated, not that a native speaker has reviewed them.

Survey content is a separate matter. The file format carries every author string across all 24 locales, and the participant runtime honours a language switch. There is no authoring screen. The only route to a multilingual questionnaire today is to author the file outside the product and import it.

Reading the results

Descriptive tabulation, with small-cell suppression built in.

Counts, means, ranges and distributions for ratings and numerics. Choice and boolean distributions, date buckets, mean rank per ranked item, per-row distributions for matrices.

Two protections are on by default. Free text never leaves the reducer, so only a count reaches an aggregate. Small-cell suppression enforces k-anonymity at k=5 with complementary suppression. A row with one suppressed cell loses a second, because one suppressed cell is recoverable by subtraction. That second rule is the one usually missing.

Charts are built in. Statistical testing is not. For significance tests, weighting or cross-tabulation, export the responses to your own tools.

Illustration. Aggregate reporting with small-cell suppression
Identity and access

OIDC and SAML, with the gaps named.

Single sign-on over OIDC and SAML 2.0. SAML is service-provider-initiated only, and identity-provider-initiated flows are off by design. The key pair is RSA-2048, generated server-side, the private key encrypted at rest. SHA-1 signatures are rejected, InResponseTo is validated, clock skew is capped at 120 seconds and responses at 256 kibibytes.

Domain ownership is proved with a DNS TXT record. Just-in-time provisioning is supported.

Permissions are 84 slugs across 19 resource families. 6 built-in roles, plus custom roles an organisation builds itself. A custom role cannot grant more than the tier allows or more than its creator holds. A denial carries a machine-readable reason.

Row level security is forced on 20 of 47 tables, covering surveys, responses and the compliance records. Even the table owner is subject to policy. SCIM, automated deprovisioning and directory role mapping are absent, so a user provisioned through single sign-on lands as a member and is promoted by hand.

Leaving

The questionnaire and the data both come back out.

The questionnaire exports as a file and imports back from the same file, with locales and logic preserved. A SurveyJS definition imports too, though the import is not demonstrated lossless and is not claimed to be.

Responses export as CSV, JSON-LD, SQL or PDF, with row-level and aggregate variants and a redaction flag. Reports render to PDF/A-2a and PDF/UA-1.

Self-hosting is a Dockerfile, a two-service compose file with one named volume, 18 documented environment variables and a health endpoint. No seat cap and no response cap. It needs Postgres and a Typst binary on an absolute path, and transactional email runs through Scaleway. There is no published container image and no production deployment manifests today.

The honest inventory

Where the platform stops.

Read this section. It is the part of this page we would want if we were you.

Illustration, not live dataEnforced by database trigger
In the builder
Show and hide is the only logic, with no branching or skip logic on top. There is no piping, and no calculated or derived fields. The builder has no expression language, no regular-expression validation and no custom error messages. Rating, numeric and comment elements are always required. Question order is fixed, and only answer options within a question can shuffle. Matrices have two cell types and author-fixed rows, and ranking uses buttons rather than a drag handle. Page breaks are not author-controlled. Once responses arrive, the structure locks. There is no file-upload or image-choice element, no quotas, no CAPTCHA, no webhooks and no scheduled reminders.
In compliance
No automated retention and no scheduled deletion. Retention is recorded as prose in your Article 30 record and enforced by you. Subject access, portability and erasure requests are not handled in the product. Withdrawal is. Article 9(2)(j) national provisions are seeded for a single member state today, not for all twenty-seven. The audit log refuses UPDATE at the database layer, so an entry cannot be altered once written. It does not refuse DELETE, which is why we will not call it append-only. Six other tables refuse both.
In exports
No SPSS, Stata, R or XLSX. No codebook or data-dictionary export.
In analysis
Significance testing, weighting and cross-tabulation are absent, as are drop-off and completion-funnel analytics. Export the responses and run those in your own tools.
In identity
SCIM and automated deprovisioning are absent, and so is directory role sync. Single sign-on is service-provider-initiated only, and domain ownership is proved by DNS TXT rather than by email.
In distribution
No published container image. No production deployment assets.
In scope
PrimeSurvey suits non-interventional research and consultation. It is the wrong tool for regulated interventional clinical trials, for customer experience or employee engagement programmes, and for panel-based market research, where quota management, panel integration and sample weighting are all table stakes and all absent here.

Start with an account, or read the mechanism first.

What exists today: an account you can create, four published prices, a self-hosted edition with no caps and an inbox a person reads. There is no trial or demo yet, and saying otherwise would be the first false thing on this page.

If you are a data protection officer or a research IT lead, say so in the first line and describe what you have to satisfy. It makes the first reply useful instead of a request for a meeting.