Legal
Votegrain Privacy Notice
How Votegrain handles personal information for the website, accounts and service.
- Audience
- Website visitors, account holders and service participants
- Version
- PRIVACY-2026-08-29-V1
- Effective date
- 2026-08-29
Who is responsible
VOTE PLATFORM LIMITED is the controller for its own website, account administration, security, commercial, support and legal-compliance processing. Contact demo@votegrain.com.
When an organisation uses Votegrain to run a decision process, that organisation normally decides the purpose, electorate, notices, recipients and retention for its Customer Data. It is normally the controller and Votegrain processes that data on its documented instructions under the Customer Agreement and DPA.
Where information comes from
Information may come directly from you, from the customer that invites or administers you, from your use of the website or service, from configured providers, or from another person lawfully acting for the customer. The customer is responsible for the accuracy and legality of Customer Data it supplies or directs Votegrain to process.
Information we handle and why
- Website and demo enquiries: submitted business-contact details, fixed source, delivery state and proportionate anti-abuse records used to answer the request, arrange a demonstration and protect the form. The separately published demo-request notice gives the exact provider and 12-month enquiry-retention facts for that form.
- Accounts and access: name, email, authentication/session state, roles, memberships, invitations, security events and support records used to create, operate, secure and recover an account.
- Customer Data: membership and eligibility data, initiative content, options, custom fields, optional attributes, participation and ballot records, results, reports, exports, shares, comments and audit history processed for the customer's configured decision process.
- Commercial and contract records: customer contacts, Orders, authority declarations, accepted document versions, invoice and payment references, subscription status and related correspondence used to administer the commercial relationship and meet accounting or legal obligations.
- Security and operations: request, device, diagnostic, audit and incident information used to prevent abuse, investigate failures, protect tenants and demonstrate service operation. The first-pilot monitoring profile uses redacted Sentry diagnostics in Germany for up to 30 days, with session replay and attachments disabled.
- AI data is not processed for the first-pilot service because AI is disabled. A later Order may enable a named feature only with a revised AI Use Schedule that states its exact inputs, provider, retention and transfer position.
Controller purposes and lawful bases
- Responding to a requested demo or sales conversation: steps requested before a business contract and Votegrain's legitimate interest in responding to genuine business enquiries.
- Creating and administering an account or commercial relationship: performing the applicable agreement, taking requested pre-contract steps and Votegrain's legitimate interest in administering an organisation-facing service.
- Security, fraud prevention, service integrity and legal claims: Votegrain's legitimate interests in protecting people, tenants and the service, plus legal obligations where they apply.
- Billing, tax, accounting and compliance: performance of the commercial agreement and compliance with legal obligations.
- Optional direct marketing or non-essential device technology: consent where required. Votegrain keeps it separate from service access and contract acceptance. The first-pilot website and product profile does not use analytics, advertising, behavioural, replay, social-media or marketing cookies.
- Customer Data: Votegrain normally acts as processor and relies on the customer's documented instructions rather than choosing an independent purpose or lawful basis for the customer's decision process.
- Showing or acknowledging this notice is not itself a lawful basis, contract signature or marketing consent.
Who receives information
Information is available only to authorised Votegrain personnel, the customer and its authorised recipients, and providers that need it for the stated service. A customer's exports or external shares leave Votegrain's normal access boundary and remain the customer's responsibility.
- Infrastructure, database, authentication, transactional-email and monitoring providers identified in the current Subprocessor and International Transfer Schedule. Stripe and OpenAI do not receive Customer Data in the first-pilot profile.
- Professional advisers, auditors, insurers, potential transaction counterparties and public authorities where access is necessary, confidential and legally permitted or required.
- Customer-selected recipients, including administrators, reviewers, report viewers and authorised export/share recipients, according to the customer's configured access and notices.
International transfers and residency
The first-pilot primary database and authentication service is Supabase in London. Application requests pass through Vercel's United States infrastructure; transactional-email account data and logs are stored by Resend in the United States even when email is sent from Ireland; redacted Sentry diagnostic events are stored in Germany. Authorised Votegrain support may access Customer Data from the United Kingdom or Australia when necessary and subject to least-privilege controls.
Where UK personal data is made available outside the UK, Votegrain uses the relevant provider DPA and its incorporated UK Addendum or other lawful safeguard and completes the applicable transfer assessment. The Subprocessor and International Transfer Schedule gives the provider-level detail. A London database location does not mean that every request, email, diagnostic or support action remains in the UK.
How long information is kept
The DPA's Retention, Return and Deletion Schedule is the controlling customer-data schedule. While an Order remains active, initiative and decision records are kept for 24 months after result release or initiative closure unless the Order lawfully chooses another period. Expired invitations are removed or anonymised within 90 days; service audit and acceptance evidence is kept for six years; support and incident records for 24 months after closure; and Sentry diagnostics for 30 days.
When the last Order ends, the Customer has 30 days to request the supported export and the exit schedule overrides any unexpired live-record period. Votegrain then completes operator-mediated deletion of live Customer Data within 30 days, except for accepted ballots and bounded eligibility/audit evidence kept until 24 months after release or closure, plus accounting, legal-hold and dispute records. Supabase backups age out of the accessible backup set on a rolling seven-day cycle. Contracts, Orders, invoices and tax records are kept for six years after the relevant financial year, or longer where law or a live claim requires it.
AI and automated decisions
AI is disabled for the first-pilot service, so Customer Data is not sent to OpenAI. If a later signed Order enables a named AI feature, its current AI Use Schedule must identify the purpose, inputs, provider, retention, transfer position and human-review responsibility. AI never determines the authoritative result or chooses an option for a voter.
Votegrain does not use its own controller data to make a solely automated decision that produces legal or similarly significant effects for an individual. Customers must not use the service for a prohibited high-impact individual decision.
Your rights and complaints
Depending on applicable law, a person may have rights to access, correct, delete, restrict, object, receive a portable copy, withdraw consent where consent is used, and complain to the appropriate regulator.
For Customer Data, contact the organisation running the initiative first. Votegrain will assist that organisation under the DPA and applicable law. You may also contact demo@votegrain.com. In the UK, you can complain to the Information Commissioner's Office at ico.org.uk or by using the contact routes published there.
Children, sensitive information and changes
Votegrain is a business service and is not directed to children. Special-category, criminal-offence, government-identifier, payment-card, health and other highly sensitive data are prohibited by default unless a separately signed exception, lawful basis and verified controls approve the exact use.
Votegrain identifies each version and effective date on this page. It will give the Customer reasonable advance notice of a material change through the Customer's legal contact, except where an urgent security or legal change requires faster action. A new customer purpose, material provider or transfer change, or reduced protection follows the contract and DPA change process before that processing begins.