This Data Processing Agreement ("DPA") forms part of the agreement between the customer identified in an Order or accepted online terms ("Controller") and SIMPLEVOTE LTD (Company No. 17251484), registered in England and Wales ("Processor"). It applies where SimpleVote processes personal data for the Controller and is intended to satisfy Article 28 UK GDPR and, where applicable, Article 28 EU GDPR.
Effective version: 2026-07-17. If this DPA conflicts with the service terms on processing personal data, this DPA prevails.
1. Definitions and interpretation
"Data Protection Law" means the UK GDPR, Data Protection Act 2018 and PECR, and EU GDPR where it applies. "Personal Data Breach", "processing", "controller", "processor" and "data subject" have their statutory meanings. References to written instructions include configuration and actions submitted through the service.
2. Processing instructions and compliance
- Processor shall process personal data only on documented Controller instructions, including transfers, unless required by law.
- If legally required to process otherwise, Processor shall inform Controller before processing unless prohibited by law.
- Processor shall immediately inform Controller in writing if, in its opinion, an instruction infringes Data Protection Law, shall explain the concern, and may suspend only the affected instruction while the parties resolve it.
- Controller is responsible for the lawfulness, accuracy, transparency and minimisation of personal data and for its Article 6 basis and any Article 9 condition.
3. Confidentiality and security
Processor shall ensure persons authorised to process personal data are subject to confidentiality obligations and shall maintain appropriate technical and organisational measures having regard to risk, cost, state of the art and the nature of processing. The current measures are in Schedule 2 / TOMs. Provider certifications cover those providers, not SIMPLEVOTE LTD. SimpleVote separately holds Cyber Essentials and Cyber Essentials Plus.
4. Personal data breaches
A Personal Data Breach for this clause includes unauthorised access and accidental or unintended permanent destruction of Controller personal data. Processor shall give the Controller and its nominated DPO or privacy contact written notice without undue delay and, in any event, within 24 hours after becoming aware of a Personal Data Breach affecting Controller personal data. Notice will be sent to the Controller's account contact and will include, as information becomes available: nature and scope; categories and approximate numbers of data subjects and records; likely consequences; containment and remediation; and a contact point. Incomplete information may be supplied in phases. Processor shall preserve relevant evidence, cooperate with Controller, and not notify data subjects or authorities for Controller unless instructed or legally required.
5. Data subject requests and DPIAs
Taking account of the processing, Processor shall provide all assistance reasonably required for data-subject rights and the Controller's obligations under Articles 32-36, including security, breach assessment and notifications, DPIAs and prior ICO consultation. This assistance is a core processor obligation and shall not be withheld or reduced because of subscription tier, feature plan or purchase of professional services. Processor shall forward requests received directly where it can identify the Controller and shall not respond substantively unless authorised. See DPIA support.
6. Subprocessors
Controller gives general written authorisation for the subprocessors in Schedule 3. Processor shall impose the same data-protection obligations by written contract and remain fully liable to Controller for each subprocessor's performance of those obligations. Processor shall give at least 30 days' prior notice of a new or replacement subprocessor by email to the Controller's nominated legal/privacy contact and through an auditable Trust Centre subscription mechanism. Controller may object in writing on reasonable data-protection grounds during that period. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate the affected service.
7. International transfers
Processor shall not transfer Controller personal data outside the UK or EEA without a lawful transfer mechanism. Depending on destination and provider this may include adequacy regulations, the UK-US Data Bridge, the UK International Data Transfer Addendum or Agreement, or EU Standard Contractual Clauses. Edge delivery, support and provider systems may process data outside the primary database region under those mechanisms.
8. Return, deletion and termination
At Controller's choice and subject to product capability, Processor shall return or delete personal data after services end and delete copies, unless law requires retention. Backup and provider copies may age out through normal cycles and remain protected until deletion. Anonymised records outside Data Protection Law may remain. Current operational periods are in Schedule 4.
9. Information and audit
Processor shall make available information reasonably necessary to demonstrate Article 28 compliance. Controller should first use current certifications, policies and questionnaire responses. No more than once annually, or after a material breach, Controller may request a proportionate remote audit on reasonable notice. Audits must protect other customers, security and confidential information and be at Controller's cost unless they identify a material breach by Processor. On-site access is not automatic and requires written scope.
Schedule 1 - processing details
| Subject matter | Hosting and operating online elections, nominations, voter communications, counting and results. |
|---|---|
| Duration | Customer term plus deletion/return period. |
| Nature and purpose | Collection, storage, organisation, transmission, authentication, support, deletion and counting with voter identity stored separately from ballot rankings, on Controller instructions. |
| Data subjects | Voters, candidates, nominators, scrutineers, election managers and people named in election content. |
| Personal data | Names, email addresses, roles, candidate content, eligibility and turnout status, authentication metadata, audit events, support content and configuration. |
| Special categories | Not required by the service, but political opinions, trade-union membership or other Article 9 data may be inferred from membership, candidacy or customer content. |
| Frequency | Continuous or as initiated by Controller during the customer term. |
| Controller instructions | Agreement, configured settings, authorised service actions and written support instructions. |
Schedule 2 - technical and organisational measures
The public TOMs statement at /trust/toms is incorporated into this DPA. Measures are subject to continuous improvement and may be replaced by controls that do not materially reduce overall protection.
Schedule 3 - subprocessors and data flow
The current authorised list and data-flow explanation are at /trust/subprocessors.
Schedule 4 - retention
| Data | Period | Trigger / disposal |
|---|---|---|
| Voter names, email addresses, eligibility, invite tokens and turnout links | 30 days after close; inactive drafts: 180 days from creation | Canonical close (terminal status / closed_at); in_progress elections are never purged until closed; Automated deletion of invitees, voter/token links and recipient metadata. Open elections past their scheduled end are closed before the retention clock starts. Anonymous cast ballots and result totals are kept after identity links are removed. |
| Saved voter registers and sync/import rows | 30 days | Creation, upload, or successful sync; Expiry; renewed by upload or sync. Active imports are allowed to finish before deletion; restrictions and suppressions remain effective. |
| Recipient-level delivery, bounce, complaint and send-failure events | 90 days maximum, or the election identity purge if earlier | Event creation or election retention deadline; Automated row deletion. Open and click events are excluded from recipient-level storage. |
| De-identified hourly open/click aggregate counters | 90 days | Hourly bucket start; Automated aggregate-bucket deletion. No recipient email, token, provider message identifier or unique-person count is stored. |
| Organisation-scoped unsubscribe, objection and restriction records | Organisation service term plus 30 days | Organisation deletion or documented lifting by the Controller; Deletion after contact data and active sending capability are removed. Kept while needed to prevent unlawful re-contact; not used for marketing. |
| Nominations, proposer names/emails, nomination tokens, biographies and rejection reasons | 30 days after election close/scheduled end; inactive drafts: 180 days | Election retention deadline; Proposer rows and unaccepted nominations deleted; accepted candidate record minimised. Approved candidate name and result may remain as the election record; proposer email is never exposed publicly. |
| Candidate photos and other nomination media | Immediate queueing on replacement, rejection or deletion; otherwise 30 days after election close/scheduled end | Object replacement, candidate/election deletion, rejection, abandoned upload expiry, or election retention deadline; Files removed from storage when candidates or elections are deleted, or after the retention period. Abandoned uploads are removed after 24 hours. |
| De-identified post-vote star rating, optional text, and optional coarse platform class (iOS / Android / desktop) | 12 months | Date-only submission date; Automated deletion. Stored without voter id, token hash, email, IP address, full user-agent, device model, browser fingerprint or precise submission time. Platform class is a coarse bucket only (iOS / Android / desktop) and must not be joinable to a voter record. |
| Login-attempt security records | 90 days | Record creation; Scheduled deletion. Longer preservation requires a documented legal hold or incident record. |
| Security audit events | 24 months | Event creation; Controlled append-only retention cleanup. The cleanup route cannot alter newer records. |
| Account and organisation membership data | Account term plus 30 days | Account closure or verified deletion request; Primary-system deletion and audit-record redaction. Billing and security records follow their separate periods; legal holds are documented and access-restricted. |
| Orders, invoices, payment status and accounting records | 7 years from the transaction | Transaction or invoice date; Deletion/anonymisation in SimpleVote systems; Stripe follows its controller/processor obligations. SimpleVote does not store full payment-card numbers. |
| Support requests, correspondence and diagnostic attachments | 24 months | Ticket or request closure; Deletion from active support systems. A documented dispute or legal hold may suspend deletion only for the material required. |
| Cast ballots and published count records | Customer term, then 30 days, unless earlier deletion is instructed | Election completion or service termination; Deletion, return, or retention in anonymised form. Ballot rows are not stored with voter name or email; retention may be necessary for result integrity. |
| Lawful-basis attestation version, actor and timestamp | 24 months after the related election closes | Election close/scheduled end; Deletion or actor de-identification. The attestation wording/version is retained separately from the uploaded list. |
| Encrypted database backups and point-in-time recovery copies | Provider-configured recovery window, targeted maximum 30 days after primary deletion | Primary-system deletion and backup rotation; Automatic expiry; no restoration to ordinary processing. A deleted record may remain in an inaccessible backup until rotation and must be re-deleted if a backup is restored. |
| Hosting, database, and email provider logs | 30 days maximum (production approval gate) | Log creation; Provider expiry or deletion. Production approval is blocked until live provider configuration/terms evidence this ceiling or this matrix is corrected to the actual lawful maximum. |
10. Execution and contact
This DPA may be accepted through authorised online acceptance, an Order, or counterpart signature. Procurement and incident contact: info@simplevote.org.
