Skip to content
Independently verified · Quarterly re-audit
EU VETTED

LimeSurvey

VERIFIED
Forms & surveys · Germany
Founded 2003 · limesurvey.org ↗

German GPL-licensed open-source survey platform (LimeSurvey GmbH Hamburg, project since 2003), self-host first.

Why this score?

LimeSurvey GmbH (Hamburg, Germany; founded August 2015, but the open-source LimeSurvey project itself dates to 2003 by Carsten Schmitz who remains Founder + CTO) is one of the longest-running open-source survey platforms in Europe, GPL-2.0+ licensed with source on GitHub, deployable on customer infrastructure (PHP + MySQL/PostgreSQL/SQLite/MSSQL) for full sovereignty; also offered as managed LimeSurvey Cloud — rated 4/5: a strong EU-owned open-source profile with no CLOUD Act exposure, but the DPA is not publicly accessible — it is reachable only inside a customer account; the rubric reserves 5/5 for a publicly accessible DPA.

SCORE
4.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About LimeSurvey

LimeSurvey is one of the longest-running open-source survey platforms in Europe — the project was started by **Carsten Schmitz** in 2003, and the commercial entity **LimeSurvey GmbH** (Hamburg, Germany) was founded in August 2015 to better coordinate development and provide commercial services around the open-source codebase. Schmitz remains Founder + CTO. The platform is licensed under **GPL v2 (or later)** with source on GitHub, runs on PHP with MySQL / PostgreSQL / SQLite / MSSQL backends, and is widely deployed in EU universities, public administrations, and research institutions. The LimeSurvey Cloud managed tier is the commercial alternative to self-host.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-18).
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option Yes
PRICING

Pricing & tiers

FREEMIUM
Custom pricing

Contact vendor for tier or volume pricing.

View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives in this category