Skip to content
votegrain

Legal

Data Processing Addendum

The controller–processor terms and processing schedule for Customer Data.

Audience
Customers, privacy teams and authorised signatories
Version
DPA-2026-08-29-V1
Effective date
2026-08-29

1. Scope, definitions and precedence

This DPA forms part of the Customer Agreement and applies when Votegrain processes personal data in Customer Data for the Customer. Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings given by the applicable Data Protection Law.

Mandatory transfer terms prevail for a restricted transfer; this DPA prevails over the Customer Agreement for personal-data processing; and the Order supplies the Customer-specific processing and commercial choices.

2. Roles and documented instructions

For Customer Data, the customer is normally the controller (or a processor acting on another controller's instructions) and VOTE PLATFORM LIMITED is the processor. Votegrain processes Customer Data only on documented instructions, including the executed agreement, Orders and configured service use, unless law requires otherwise.

Votegrain remains an independent controller for its own account administration, security, fraud prevention, commercial and legal-compliance processing described in the Privacy Notice.

If Votegrain believes an instruction infringes applicable Data Protection Law, it will tell the Customer unless law prohibits notice and may pause the affected processing while the parties resolve it. Where law requires processing outside the Customer's instructions, Votegrain will notify the Customer before processing unless that law prohibits notice.

3. Customer obligations and rights

The Customer controls the purpose and essential instructions for Customer Data. It must have the necessary lawful basis, authority, notices, permissions and controller/processor contracts; use proportionate data; keep instructions lawful; configure authorised access; and respond to participant questions or rights requests as controller.

The Customer may give additional documented instructions that are consistent with the service and agreement. A change requiring material engineering, risk or provider work may require a new Order, fees and implementation period.

4. Processing Schedule — subject matter and duration

  • Subject matter: provision, security, support and administration of the Votegrain service selected in the Order.
  • Nature and purpose: collecting, recording, organising, storing, retrieving, structuring, displaying, analysing, exporting, sharing when instructed, restricting, deleting and otherwise processing Customer Data to run the Customer's governed decision processes.
  • Duration: the Order term plus its export/return window, deletion processing, backup expiry and any limited legal hold stated in the Retention, Return and Deletion Schedule.
  • Frequency: continuous or event-driven while authorised users configure and use the service, plus scheduled security, backup and deletion operations.

5. Processing Schedule — people and data

  • Data subjects: authorised customer personnel, members, invitees, voters, reviewers, administrators, viewers and support contacts included lawfully by the customer.
  • Identity, account and access data: names, business contact details, user identifiers, roles, memberships, invitations, eligibility, authentication state and security events.
  • Decision-process data: organisation and initiative details, options, descriptions, links, custom fields, schedules, rules, participation status and Customer notices.
  • Ballot and result data: write-once ballot records, limited eligibility/duplicate-prevention linkage, aggregate results, suppression state, reports, forecasts and approved shares/exports.
  • Optional attributes: Customer-defined participant attributes and ballot-time snapshots, subject to purpose, minimisation and small-cell controls.
  • Support, audit and operational data: user requests, audit events, export/share evidence, diagnostic context and incident correspondence.
  • AI data only where enabled: the inputs and outputs identified in the AI Use Schedule; authoring checks may include proposed title, description, options, links, custom fields and organisation standards, not only post-vote aggregates.
  • Special-category, criminal-offence, health, government-identifier, payment-card, children's and other highly sensitive data are prohibited by default. This contractual restriction does not mean the product detects every data type.

6. Confidentiality and personnel

Votegrain will ensure that each person authorised to process Customer Data is subject to a statutory or contractual duty of confidentiality, receives access only for an authorised purpose and is trained proportionately to their role. Support access must be least-privilege, time-bounded where supported and auditable.

7. Security measures

Votegrain maintains technical and organisational measures taking account of the nature, scope, context and purpose of processing and the risk to people. The Security Overview describes the connected production controls for tenant isolation, access, authentication, write-once ballots, suppression, encryption, logging, monitoring, vulnerability management, continuity, backups and incident response.

The Customer is responsible for its endpoints, credentials, administrators, role configuration, exported copies and timely removal of access. A security measure may be updated where the overall protection is not materially reduced.

8. Personal data breaches

Votegrain will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data and will provide available information reasonably needed for the Customer's assessment, notification and communication duties. Information may be supplied in phases as the investigation progresses.

No separate contractual clock extends the without-undue-delay duty or promises that an initial notice contains facts not yet known. The Customer controls notifications to its data subjects or regulator unless law requires Votegrain to act directly.

9. Rights requests and regulatory assistance

Taking account of the nature of processing and available functionality, Votegrain will reasonably assist the Customer with data-subject requests and with security, breach, data-protection impact assessment and prior-consultation duties applicable to the service. Votegrain will not answer a Customer Data rights request as controller unless the Customer authorises it or law requires it.

If Votegrain receives a request about Customer Data, it will direct the requester to the Customer where practicable. Additional assistance beyond standard service functionality may be chargeable where law permits and the need was not caused by Votegrain's breach.

10. Subprocessors

The Customer gives general written authorisation for Votegrain to use the subprocessors in the approved Subprocessor and International Transfer Schedule. Votegrain must impose written data-protection obligations that provide materially equivalent protection for the relevant processing and remains responsible for each subprocessor's performance to the extent required by applicable law.

Votegrain will give at least 30 days' advance notice of a new or replacement subprocessor to the Customer's legal or privacy contact recorded in the Order. An emergency replacement needed for security, legal compliance or provider failure may occur sooner, with notice as soon as reasonably practicable.

The Customer may object during the notice period on reasonable, documented data-protection grounds. The parties will try for 15 days to resolve the concern through a configuration change or reasonable alternative. If they cannot, the Customer may stop the affected optional feature or terminate the affected Order before the new subprocessor begins; Votegrain will refund prepaid fees for the unused terminated period, and export and deletion follow this DPA. An objection does not create access to another tenant's confidential provider evidence.

11. International transfers

Votegrain will not make or authorise a restricted transfer of Customer Data unless a lawful transfer route applies. The approved schedule must record the parties, roles, data, destination, onward transfers, safeguards and any required transfer risk assessment or data-protection test.

For UK-restricted transfers, the parties incorporate the applicable UK International Data Transfer Addendum to the EU standard contractual clauses or another lawful UK safeguard identified in the Subprocessor Schedule. For an EEA restricted transfer, the applicable 2021 EU standard contractual clause module applies where required. Access from Australia is subject to the UK transfer safeguard and assessment recorded for the service. Mandatory transfer clauses prevail over conflicting commercial terms.

12. Audit and compliance evidence

Votegrain will make available information reasonably necessary to demonstrate compliance with this DPA. Current independent reports, policies, test summaries and responses to a reasonable questionnaire are the default evidence route.

Where that evidence is insufficient and applicable law requires more, the Customer may conduct one audit in a 12-month period on at least 30 days' written notice, plus an additional audit after a material personal data breach or credible material non-compliance. Audits must protect other tenants, security and confidentiality, avoid production disruption and use an independent qualified auditor. The Customer bears the reasonable audit cost unless the audit identifies a material Votegrain breach.

13. Retention, Return and Deletion Schedule — rules

The Customer determines the live retention of Customer Data within applicable law and service capability. The 24-month decision-record period applies while an Order remains active. When the last Order ends, the end-of-service schedule takes precedence for live Customer Data, while the stated accepted-ballot and bounded-evidence exception continues. A Customer instruction cannot require indefinite retention without a stated purpose.

Deletion is operator-mediated. The end of a pilot, disabling a user or deleting an account does not itself delete every organisation record, accepted ballot, audit event, provider log or backup. Votegrain follows the return, deletion and retained-record process below.

14. Retention, Return and Deletion Schedule — categories

  • Accounts and memberships: removed or anonymised within 30 days after a valid Customer deletion instruction where they are Customer Data and are not needed for another active Customer account or Votegrain's own legal record. Expired or revoked invitations are removed or anonymised within 90 days.
  • Initiatives, options, custom fields, participant attributes, results, reports, comments and shares while an Order is active: 24 months after result release, or after closure for an initiative with no released result, unless the Order states a lawful shorter period or justified longer governance period. When the last Order ends, these live records follow the export-and-deletion deadline below even if 24 months has not elapsed.
  • Accepted ballots and limited eligibility, duplicate-prevention and audit linkage: until 24 months after result release or initiative closure, unless the Customer lawfully instructs a shorter period. These bounded records may survive account and live initiative deletion to preserve result integrity; access is restricted and linkage is minimised or pseudonymised where possible.
  • Service audit, export/share and legal-acceptance evidence: six years after the recorded event or end of the relevant agreement, whichever is later. Opaque actor references may replace direct identifiers where identification is no longer necessary.
  • Security and diagnostic records: Votegrain service security events for up to 12 months; redacted Sentry diagnostic events for 30 days; transient Vercel operational logs for no more than 30 days. These records are not used as a durable copy of Customer content.
  • Support and incident records: 24 months after closure, except where a longer period is needed for a live legal claim or mandatory record.
  • AI request and output records: none for the first pilot because AI is disabled. A later AI-enabled Order replaces this entry with an application and provider retention period before processing begins.
  • Contracts, Orders, invoices and payment or tax records: six years after the end of the financial year to which the record relates, or longer for a live legal obligation or dispute.
  • Backups: Supabase daily backups are isolated from ordinary use and age out of the accessible backup set on a rolling seven-day cycle after live deletion, unless a legal hold applies to a separately retained record. This is not selective editing of a backup or a guaranteed restore time.

15. End of service and legal holds

During the term and for 30 days after the last Order ends, Votegrain will make the tested export stated in the Order available to an authorised Customer contact. Within 30 days after that window or a valid earlier instruction, Votegrain will delete or return live accounts, memberships, invitations, initiatives, options, custom fields, attributes, results, reports, comments, shares and other live Customer Data, including ongoing, cancelled and never-released initiatives. The accepted-ballot and bounded-evidence period above, legal obligations, live disputes and backup copies are the limited exceptions.

Retained data must remain protected and blocked from unrelated processing. Votegrain will delete it when the exception ends and will give completion evidence in the form stated in the Order. Provider backups expire on their verified cycle rather than being selectively restored only to delete one record.

16. Residency Schedule

  • Primary product database and authentication: Supabase West EU (London), project region eu-west-2. Customer Data cannot enter the pilot until the customer-production binding is verified at activation.
  • Application hosting and request processing: Vercel Inc.; the connected serverless function region is iad1 in the United States, with global content-delivery and provider support operations described in Vercel's DPA.
  • Database backups: Supabase-managed daily physical backups associated with the London customer-production project, available on a rolling seven-day basis. No contractual recovery-point or recovery-time objective applies.
  • Transactional email: Plus Five Five, Inc. trading as Resend; email is sent from Ireland, while account data, logs and API records are stored in the United States for up to 30 days.
  • Monitoring and error data: Functional Software, Inc. trading as Sentry; redacted diagnostic events are stored in Germany for 30 days. Session replay and attachments are disabled and Customer content must not be intentionally logged.
  • Payment processing: disabled for the first pilot. Stripe receives no Customer Data under this Order; billing is by manual invoice and bank transfer.
  • AI processing: disabled for the first pilot. OpenAI receives no Customer Data under this Order.
  • Support access: authorised Votegrain personnel may access from the United Kingdom or Australia only when necessary, using encrypted connections, individual authentication, least privilege and confidentiality obligations.
  • An Order-specific residency promise applies only to the categories and provider operations it expressly names; a primary database region does not imply that every provider or support action is local.

17. Liability, term and execution

This DPA remains in effect while Votegrain processes Customer Data. Its liabilities follow the Customer Agreement except where mandatory Data Protection Law or transfer terms require otherwise.

This DPA becomes binding when the Customer and Votegrain execute an Order that incorporates this exact version and its content hash. Service activation remains conditional on the signed Order, London production binding, provider-term checks and an operator-confirmed export and deletion route. Merely viewing this page is not acceptance.