Skip to content
votegrain

Privacy

Demo request privacy notice

This notice covers the demo request form on Book a Votegrain demo, and nothing else. It describes exactly what that form collects, why we hold it, how long we keep it and how to have it removed.

Who is responsible and how to use your rights

Vote Platform Limited, based in United Kingdom, is responsible for the personal information submitted through this form. Use our privacy contact route to ask a question or request access, correction, restriction of processing or deletion, or to object to our processing.

We process the request on this basis: Our legitimate interests under Article 6(1)(f) UK GDPR in responding to a person who asks for a Votegrain demonstration, arranging that demonstration and protecting the request form from abuse. We use only the business-contact details needed for those purposes, do not add the requester to unrelated marketing, and they can object by contacting us. If you remain dissatisfied after contacting us, you can complain to UK Information Commissioner's Office (ICO).

What we collect

Only what you choose or type, plus a few technical values the form needs to work safely.

  • Your answers

    Your name, your email address and your organisation's name, which you type; and your organisation's type and size, the kind of decision you have in mind, roughly how many people would take part and your preferred timeframe, which you choose from a list. Optionally, anything you add under “anything else”.

  • A request reference

    A random identifier your browser generates for the submission, so that a refresh or a second click does not create a second request. It is not your name, but it is linked to your request and we treat it as part of that record.

  • An abuse-prevention identifier

    A one-way, keyed value derived from your network address, and a second one derived from your email address. Neither the network address nor the email address is stored alongside them, and neither derived value can be turned back into what it came from without our secret key. They exist so that one source cannot flood the form.

  • Which link you arrived from, and what you were shown

    Which link on this site brought you to the form — one of a short fixed list, never a full address or a referring website — and the dated version of this notice that was on the page when you submitted, so we can say exactly what you were told.

Why we hold it, and what we will not do

To arrange your demo

We use your details to contact you, arrange a time and prepare a demo that reflects the decision you described. That is the only purpose.

No marketing enrolment

Requesting a demo does not enrol you, your colleagues or your organisation in marketing communications, newsletters or any mailing list. We do not sell or rent these details. When the form is enabled, Vercel processes the submitted form on the server and the isolated Supabase database stores it. The email path receives only a constant internal alert and an unrelated random retry token — no answer you submit, browser request identifier, database enquiry identifier or submission time. The form places no advertising or analytics cookies.

Kept away from the product

Demo requests are stored in a marketing database that is completely separate from the Votegrain product. Nothing about organisations, members, ballots, votes, results, reports or analysis is reachable from it, and nothing in the product reads it.

Please do not send us more

We never ask for files, voter identities, decision papers, budgets or passwords, and the form has nowhere to put them. Please keep your answers high level and leave personal, confidential and commercially sensitive information out.

Processors, mailbox automation and transfers

Vercel hosts the website and transiently processes the submitted form on the server. The isolated Supabase website project is the only persistent store of the submitted enquiry and is hosted in its London region. Resend sends demo@votegrain.com a constant operational alert, which Google Workspace hosts. The alert contains no submitted field, browser request identifier, database enquiry identifier or submission time; its ordinary delivery metadata includes the internal routing addresses and an unrelated random retry token. Hermes Agent may read only that generic mailbox alert to notify Luke Ellis. Luke also monitors the mailbox, remains accountable and reviews the authoritative enquiry in authenticated Supabase.

The Supabase enquiry database is hosted in London. Vercel may transiently process the submitted form outside the United Kingdom. Resend, Google Workspace, Hermes Agent and Hermes's configured OpenAI API provider may process the generic alert and ordinary delivery metadata outside the United Kingdom, including in the United States, but receive no submitted field, browser request identifier or database enquiry identifier through that alert. Where a restricted transfer applies, we rely on the relevant provider's contractual transfer safeguards, such as a UK Addendum or other mechanism recognised under UK data-protection law. Contact demo@votegrain.com to request details or a copy of the relevant safeguard.

How long we keep it

An enabled form records an expiry date 12 months from the day you submit the request. Its operationally verified schedule removes expired requests and their linked delivery records automatically. If that schedule has not been verified, the form stays unavailable and accepts nothing. The internal email is a constant alert containing no submitted field, browser request identifier or database enquiry identifier; its generic operational metadata follows the providers' and mailbox's ordinary retention controls. The abuse-prevention identifier expires far sooner, within hours, when its counter does.

The Supabase enquiry and its linked delivery record are deleted 12 months after submission, or sooner when an applicable deletion request is actioned. The email path receives no submitted field, browser request identifier or database enquiry identifier. Its constant alert, internal routing addresses, unrelated random retry token and ordinary provider message metadata follow the providers' and mailbox's operational retention controls; they cannot identify the requester from the alert alone. Luke Ellis owns access to the Supabase record and actions requests sent to demo@votegrain.com.

Asking us to delete it sooner

Use the public privacy contact route above, reply to the message we send you about your demo, or reply to the message that brought you here, and ask us to delete your demo request. We will remove it and confirm that we have. You do not need to give a reason.

If you would rather do nothing, you do not have to. For an enabled form, the verified deletion process removes your request whether or not you ask.

Back to the demo request