← Back to Home

Data Processing Agreement

Last updated: October 5, 2026

About This Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between TinyPoll and our customers for the provision of the TinyPoll polling service. It addresses the requirements of data protection laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Australian Privacy Act 1988.

By using TinyPoll, you agree to this DPA in addition to our Terms of Service and Privacy Policy.

1. Definitions

2. Roles and Responsibilities

For the purposes of data protection law:

Where the Customer is itself a processor acting for another controller, the Customer is a Processor and TinyPoll is its sub-processor (Module Three). This DPA then applies in the same way, with the Customer passing that controller's instructions on to TinyPoll.

For TinyPoll's own purposes (billing, account management, website analytics, and answering email sent to TinyPoll, apart from any Personal Data an email contains — see Section 3), TinyPoll acts as an independent Controller as described in our Privacy Policy.

3. Scope of Processing

Data CategoryExamplesPurpose
Workspace identifiersSlack Team IDMulti-workspace support, billing
User identifiersSlack User IDsVote tracking, poll ownership
Slack profile and account dataFrom Slack: user IDs, display and real names, admin and owner flags, and whether an account is a guest, a bot or deactivated. Voter names are read when a poll is shown and held briefly in an in-memory cache, never written to storage. The web app reads the signed-in user's own name and avatar from Slack each time it loads and does not store themCounting seats, identifying admins, showing voter names on non-anonymous polls, and showing who is signed in to the web app
Channel identifiersSlack Channel IDs; for a poll created in the web app, the channel's name and whether it is privateDisplay polls in correct channel; label polls and decide who may see them in the web app
Poll contentQuestions, answer optionsProviding the polling service
Voting dataVote recordsRecording and displaying results
Authentication tokensSlack bot tokens (encrypted)Interacting with your Slack workspace
Web app sessionsHashed session identifier, Slack User ID and Team ID, workspace admin flag, sign-in method, created and last-used timestampsSigning users in to app.tinypoll.io and deciding what they may see and manage
Web app sign-in recordsSingle-use nonces; Sign in with Slack state and nonce valuesPreventing reuse or tampering of a sign-in
Access logsIP address, user agent, request path, timestampSecurity, abuse investigation, and service operation
Audit recordsActor's Slack User ID, admin flag, surface (Slack or web), poll ID, action, timestampAccountability: who created, changed, or deleted a poll. Never poll content or vote choices
Archived poll metadataCreator's Slack User ID, Channel ID, question length, option count, vote total, anonymity flag, timestampsService analytics after a poll is deleted. Never poll content
Customer data in support emailPersonal Data from the Customer's workspace that a sender includes in email to TinyPoll, such as poll content or user details quoted in a requestActing on the request, for example a deletion or a fix

The web app rows — sessions and sign-in records — apply to app.tinypoll.io. Every other row applies to the Slack app and the web app alike, except that the channel name and privacy flag in the Channel identifiers row are stored only for polls created in the web app, and except Customer data in support email. The rest of an email to TinyPoll — the sender's own name, address and message — is TinyPoll's own correspondence, which it handles as an independent Controller (Section 2).

4. TinyPoll's Obligations

TinyPoll shall:

  1. Process Personal Data only for the purpose of providing the Service, and only in accordance with the Customer's documented instructions (i.e., the Terms of Service).
  2. Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
  3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
    • Encryption of data at rest and in transit
    • AWS infrastructure with enterprise-grade security controls
    • Cryptographic verification of all Slack API requests
    • Least-privilege access controls and IAM policies
    • Automated data deletion per retention schedules
    • Web app sessions stored as hashed identifiers behind a host-only, HttpOnly, Secure, SameSite=Lax session cookie, with a strict origin check and a separate, deliberately JavaScript-readable double-submit CSRF token on every state-changing request
    • Content Security Policy, HSTS, and no third-party scripts on app.tinypoll.io
  4. Not engage a Subprocessor without providing the Customer with prior notice (see Section 5).
  5. Assist the Customer, where reasonably possible, in responding to data subject rights requests.
  6. Delete or return Personal Data upon termination of the Service (for Customer data in support email, on the Customer's request), subject to legal retention requirements.
  7. Make available to the Customer information necessary to demonstrate compliance with this DPA.

5. Subprocessors

TinyPoll uses the following subprocessors to deliver the Service:

SubprocessorPurposeLocation
Amazon Web Services (AWS)Cloud hosting, data storage, computeSydney, Australia (ap-southeast-2)
Slack Technologies (Salesforce)Slack platform integrationUnited States
Google LLC (Google Workspace)Email hosting: holds the Customer data a sender includes in email to a @tinypoll.io addressUnited States and other countries where Google has data centres

TinyPoll also uses the providers below for its own purposes: billing, and its website. They process data for TinyPoll, which acts as an independent Controller for those purposes (Section 2); they receive no Personal Data under this DPA and are not Subprocessors. Stripe receives the workspace ID and the purchaser's email address, not workspace members' data. They are listed for completeness.

ProviderPurposeLocation
Stripe, Inc.Payment processing (paid plans only)United States
Google LLCWebsite analytics (website only, not Slack app)United States
Zoho CorporationCustomer support chat (website only)United States / India

Last reviewed September 8, 2026: no subprocessors were added for the TinyPoll web app. It runs on the same AWS infrastructure in Sydney as the Slack app, and sign-in is handled by Slack, which is already listed above.

Updated October 1, 2026: Google LLC, which appears in the providers table above for website analytics, now also hosts TinyPoll's email through Google Workspace, and is listed as a Subprocessor for that purpose. Email sent to any @tinypoll.io address is delivered to and stored there. It is a subprocessor for the Customer data a sender includes in an email, such as a bug report that quotes a poll. For the rest of TinyPoll's correspondence, which TinyPoll handles as an independent Controller (Section 2), Google is TinyPoll's own provider rather than a subprocessor. This page is our notice of that change; if you object, you may terminate the Service as described below.

We will give notice of any new subprocessor by updating this page at least 14 days before it starts processing Personal Data. Customers who want that notice by email can subscribe by writing to legal@tinypoll.io, and we email subscribers at the same time. If you object to a new subprocessor, you may terminate the Service.

6. International Data Transfers

TinyPoll's primary data processing occurs in Australia (AWS ap-southeast-2). Australia has no adequacy decision under the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection (FADP), so transfers of Personal Data to TinyPoll from the EEA, the UK and Switzerland are covered as follows.

6.1 Standard Contractual Clauses

Where the Customer's use of the Service involves a transfer to TinyPoll of Personal Data that is subject to the GDPR, the UK GDPR or the FADP, the following are incorporated into this DPA by reference, with the Customer as data exporter and TinyPoll as data importer:

6.2 How the SCCs are completed

6.3 UK Addendum

Table 1 of the UK Addendum is completed with the parties' details and key contacts in Annex I.A, TinyPoll's ABN as its registration number, and a start date of the day the Customer agrees to this DPA; Table 2 with the SCCs and the modules and options in Sections 6.1 and 6.2; and Table 3 with Annexes I to III as described in Section 6.2. For Table 4, neither party may end the UK Addendum under its Section 19.

6.4 Switzerland

For transfers subject to the FADP, references to the GDPR in the SCCs are read as references to the FADP, the Federal Data Protection and Information Commissioner is the competent supervisory authority, and the term "Member State" in Clause 18(c) does not prevent data subjects in Switzerland from bringing claims in their place of habitual residence.

6.5 Onward transfers and precedence

7. Data Retention and Deletion

Personal Data processed through the Service is automatically deleted based on the Customer's plan:

Pro retention applies while the subscription is active or the workspace is on its trial. When a trial or subscription ends, or while a subscription payment is outstanding, the Free plan period applies from the next scheduled cleanup.

Active service data (including polls, votes, and settings) is retained and deleted in accordance with the Customer's applicable plan-based retention period described above. Certain data may be retained where required by law (e.g., billing records for tax compliance) or for legitimate security purposes. Deleted data can also remain in TinyPoll's continuous point-in-time database backups, kept only to recover from a fault, for up to 35 days.

Web app data and access logs have their own schedules, independent of the plan:

Customer data in support email is kept while the request is open and afterwards as part of the record of what was asked and agreed, and is deleted on request, subject to the legal-retention exceptions set out in our Privacy Policy.

8. Data Breach Notification

In the event of a Personal Data breach, TinyPoll will:

  1. Notify the Customer without undue delay (and in any event within 72 hours of becoming aware of the breach).
  2. Provide sufficient detail to allow the Customer to meet its own breach notification obligations.
  3. Take reasonable steps to mitigate the effects of the breach.

9. Term and Termination

This DPA remains in effect for as long as TinyPoll processes Personal Data on behalf of the Customer. Upon termination of the Service, TinyPoll will delete Personal Data in accordance with Section 7, including Customer data in support email on request.

10. Governing Law

This DPA is governed by the laws of Australia, consistent with the governing law of the Terms of Service, except that the SCCs and the UK Addendum are governed by the law they specify (Section 6).

Need a Signed Copy?

If your organisation requires a countersigned DPA, please contact us:

Email: legal@tinypoll.io

We'll provide a signed copy within 5 business days.