Data Processing Agreement
Last updated: October 5, 2026
About This Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between TinyPoll and our customers for the provision of the TinyPoll polling service. It addresses the requirements of data protection laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Australian Privacy Act 1988.
By using TinyPoll, you agree to this DPA in addition to our Terms of Service and Privacy Policy.
1. Definitions
- "Customer" means the Slack workspace administrator or organisation that has installed TinyPoll.
- "TinyPoll" means TinyPoll (ABN 33 214 294 124), the provider of the Service.
- "Personal Data" means any information relating to an identified or identifiable person that TinyPoll processes on the Customer's behalf, whether through the Service or because a sender includes it in email to TinyPoll (see Section 3).
- "Processing" means any operation performed on Personal Data.
- "Subprocessor" means a third party engaged by TinyPoll to process Personal Data on behalf of the Customer.
2. Roles and Responsibilities
For the purposes of data protection law:
- Customer is the Controller (unless the paragraph below applies) — you determine why and how Personal Data from your Slack workspace is processed through TinyPoll.
- TinyPoll is the Processor — we process Personal Data only as necessary to provide the polling service, and only on your instructions (as set out in the Terms of Service).
Where the Customer is itself a processor acting for another controller, the Customer is a Processor and TinyPoll is its sub-processor (Module Three). This DPA then applies in the same way, with the Customer passing that controller's instructions on to TinyPoll.
For TinyPoll's own purposes (billing, account management, website analytics, and answering email sent to TinyPoll, apart from any Personal Data an email contains — see Section 3), TinyPoll acts as an independent Controller as described in our Privacy Policy.
3. Scope of Processing
| Data Category | Examples | Purpose |
|---|---|---|
| Workspace identifiers | Slack Team ID | Multi-workspace support, billing |
| User identifiers | Slack User IDs | Vote tracking, poll ownership |
| Slack profile and account data | From Slack: user IDs, display and real names, admin and owner flags, and whether an account is a guest, a bot or deactivated. Voter names are read when a poll is shown and held briefly in an in-memory cache, never written to storage. The web app reads the signed-in user's own name and avatar from Slack each time it loads and does not store them | Counting seats, identifying admins, showing voter names on non-anonymous polls, and showing who is signed in to the web app |
| Channel identifiers | Slack Channel IDs; for a poll created in the web app, the channel's name and whether it is private | Display polls in correct channel; label polls and decide who may see them in the web app |
| Poll content | Questions, answer options | Providing the polling service |
| Voting data | Vote records | Recording and displaying results |
| Authentication tokens | Slack bot tokens (encrypted) | Interacting with your Slack workspace |
| Web app sessions | Hashed session identifier, Slack User ID and Team ID, workspace admin flag, sign-in method, created and last-used timestamps | Signing users in to app.tinypoll.io and deciding what they may see and manage |
| Web app sign-in records | Single-use nonces; Sign in with Slack state and nonce values | Preventing reuse or tampering of a sign-in |
| Access logs | IP address, user agent, request path, timestamp | Security, abuse investigation, and service operation |
| Audit records | Actor's Slack User ID, admin flag, surface (Slack or web), poll ID, action, timestamp | Accountability: who created, changed, or deleted a poll. Never poll content or vote choices |
| Archived poll metadata | Creator's Slack User ID, Channel ID, question length, option count, vote total, anonymity flag, timestamps | Service analytics after a poll is deleted. Never poll content |
| Customer data in support email | Personal Data from the Customer's workspace that a sender includes in email to TinyPoll, such as poll content or user details quoted in a request | Acting on the request, for example a deletion or a fix |
The web app rows — sessions and sign-in records — apply to app.tinypoll.io. Every other row applies to the Slack app and the web app alike, except that the channel name and privacy flag in the Channel identifiers row are stored only for polls created in the web app, and except Customer data in support email. The rest of an email to TinyPoll — the sender's own name, address and message — is TinyPoll's own correspondence, which it handles as an independent Controller (Section 2).
4. TinyPoll's Obligations
TinyPoll shall:
- Process Personal Data only for the purpose of providing the Service, and only in accordance with the Customer's documented instructions (i.e., the Terms of Service).
- Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data at rest and in transit
- AWS infrastructure with enterprise-grade security controls
- Cryptographic verification of all Slack API requests
- Least-privilege access controls and IAM policies
- Automated data deletion per retention schedules
- Web app sessions stored as hashed identifiers behind a host-only,
HttpOnly,Secure,SameSite=Laxsession cookie, with a strict origin check and a separate, deliberately JavaScript-readable double-submit CSRF token on every state-changing request - Content Security Policy, HSTS, and no third-party scripts on app.tinypoll.io
- Not engage a Subprocessor without providing the Customer with prior notice (see Section 5).
- Assist the Customer, where reasonably possible, in responding to data subject rights requests.
- Delete or return Personal Data upon termination of the Service (for Customer data in support email, on the Customer's request), subject to legal retention requirements.
- Make available to the Customer information necessary to demonstrate compliance with this DPA.
5. Subprocessors
TinyPoll uses the following subprocessors to deliver the Service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, data storage, compute | Sydney, Australia (ap-southeast-2) |
| Slack Technologies (Salesforce) | Slack platform integration | United States |
| Google LLC (Google Workspace) | Email hosting: holds the Customer data a sender includes in email to a @tinypoll.io address | United States and other countries where Google has data centres |
TinyPoll also uses the providers below for its own purposes: billing, and its website. They process data for TinyPoll, which acts as an independent Controller for those purposes (Section 2); they receive no Personal Data under this DPA and are not Subprocessors. Stripe receives the workspace ID and the purchaser's email address, not workspace members' data. They are listed for completeness.
| Provider | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing (paid plans only) | United States |
| Google LLC | Website analytics (website only, not Slack app) | United States |
| Zoho Corporation | Customer support chat (website only) | United States / India |
Last reviewed September 8, 2026: no subprocessors were added for the TinyPoll web app. It runs on the same AWS infrastructure in Sydney as the Slack app, and sign-in is handled by Slack, which is already listed above.
Updated October 1, 2026: Google LLC, which appears in the providers table above for website analytics, now also hosts TinyPoll's email through Google Workspace, and is listed as a Subprocessor for that purpose. Email sent to any @tinypoll.io address is delivered to and stored there. It is a subprocessor for the Customer data a sender includes in an email, such as a bug report that quotes a poll. For the rest of TinyPoll's correspondence, which TinyPoll handles as an independent Controller (Section 2), Google is TinyPoll's own provider rather than a subprocessor. This page is our notice of that change; if you object, you may terminate the Service as described below.
We will give notice of any new subprocessor by updating this page at least 14 days before it starts processing Personal Data. Customers who want that notice by email can subscribe by writing to legal@tinypoll.io, and we email subscribers at the same time. If you object to a new subprocessor, you may terminate the Service.
6. International Data Transfers
TinyPoll's primary data processing occurs in Australia (AWS ap-southeast-2). Australia has no adequacy decision under the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection (FADP), so transfers of Personal Data to TinyPoll from the EEA, the UK and Switzerland are covered as follows.
6.1 Standard Contractual Clauses
Where the Customer's use of the Service involves a transfer to TinyPoll of Personal Data that is subject to the GDPR, the UK GDPR or the FADP, the following are incorporated into this DPA by reference, with the Customer as data exporter and TinyPoll as data importer:
- EEA: the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (the "SCCs"): Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is a processor.
- United Kingdom: the SCCs as amended by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force 21 March 2022) (the "UK Addendum").
- Switzerland: the SCCs, with the adaptations in Section 6.4.
6.2 How the SCCs are completed
- Clause 7 (docking clause): does not apply.
- Clause 9(a): Option 2, general written authorisation. TinyPoll informs the Customer of an intended change at least 14 days in advance by the means in Section 5: updating this page, and emailing customers who subscribe. The Customer agrees that these means satisfy Clause 9(a).
- Clause 11(a): the optional language does not apply.
- Clause 13 and Annex I.C: where the Customer is established in an EU Member State, the supervisory authority of that Member State; where it is not established in the EU but has appointed a representative under Article 27 GDPR, the supervisory authority of the Member State where the representative is established; otherwise, the Irish Data Protection Commission.
- Clause 17: Option 1. The SCCs are governed by the law of Ireland.
- Clause 18(b): disputes are resolved by the courts of Ireland.
- Annex I.A (list of parties): Data exporter: the Customer, identified by its Slack workspace. Its address and contact person are those in its billing details for a paid plan, or as it gives them to TinyPoll at legal@tinypoll.io. Its activities are its use of the Service. Data importer: TinyPoll (ABN 33 214 294 124), Melbourne, VIC, Australia. Contact: Privacy contact, privacy@tinypoll.io. Its activities are providing the Service as this DPA describes. The parties' roles are set out in Section 2. Each party is treated as having signed and dated Annex I on the day the Customer agrees to this DPA.
- Annex I.B (description of transfer): the data subjects are the members and guests of the Customer's Slack workspace (TinyPoll reads the member list to count seats and identify admins, and stores the IDs of those who create or vote in polls), and anyone whose Personal Data the Customer's users include in poll content or in email to TinyPoll. The categories of Personal Data and the purposes are set out in Section 3. No special category data is intended to be transferred; the Service is not designed for it, and any that the Customer's users put in poll content is the Customer's responsibility (Terms of Service, Section 5). Transfers are continuous for as long as the Customer uses the Service. Retention is set out in Section 7, and transfers to subprocessors in Section 5.
- Annex II (technical and organisational measures): the measures in Section 4.
- Annex III (list of sub-processors): not required, because Clause 9(a) Option 2 applies. The current Subprocessors are listed in Section 5.
6.3 UK Addendum
Table 1 of the UK Addendum is completed with the parties' details and key contacts in Annex I.A, TinyPoll's ABN as its registration number, and a start date of the day the Customer agrees to this DPA; Table 2 with the SCCs and the modules and options in Sections 6.1 and 6.2; and Table 3 with Annexes I to III as described in Section 6.2. For Table 4, neither party may end the UK Addendum under its Section 19.
6.4 Switzerland
For transfers subject to the FADP, references to the GDPR in the SCCs are read as references to the FADP, the Federal Data Protection and Information Commissioner is the competent supervisory authority, and the term "Member State" in Clause 18(c) does not prevent data subjects in Switzerland from bringing claims in their place of habitual residence.
6.5 Onward transfers and precedence
- Some subprocessors are located in the United States. For onward transfers to them, TinyPoll relies on the subprocessors' own transfer mechanisms (e.g., EU-US Data Privacy Framework, Standard Contractual Clauses) as applicable. AWS and Google each maintain their own data transfer frameworks compliant with GDPR requirements.
- Email sent to TinyPoll is stored by Google Workspace, which may hold it in the United States or other countries where Google operates data centres.
- If this DPA conflicts with the SCCs or the UK Addendum, the SCCs or the UK Addendum prevail.
7. Data Retention and Deletion
Personal Data processed through the Service is automatically deleted based on the Customer's plan:
- Free plan: Poll data deleted after 7 days
- Pro plan and Pro trial: Poll data deleted after 30 days
Pro retention applies while the subscription is active or the workspace is on its trial. When a trial or subscription ends, or while a subscription payment is outstanding, the Free plan period applies from the next scheduled cleanup.
Active service data (including polls, votes, and settings) is retained and deleted in accordance with the Customer's applicable plan-based retention period described above. Certain data may be retained where required by law (e.g., billing records for tax compliance) or for legitimate security purposes. Deleted data can also remain in TinyPoll's continuous point-in-time database backups, kept only to recover from a fault, for up to 35 days.
Web app data and access logs have their own schedules, independent of the plan:
- Sessions: deleted 30 days after last use, sooner if the user signs out; expiry is enforced automatically
- Sign-in records: 10 minutes or less
- Access logs: kept as operational and security logs for 90 days, for investigation and abuse prevention, as described in our Privacy Policy
- Audit records: 400 days, enforced automatically
- Archived poll metadata: 400 days, enforced automatically, or until the Customer requests deletion
Customer data in support email is kept while the request is open and afterwards as part of the record of what was asked and agreed, and is deleted on request, subject to the legal-retention exceptions set out in our Privacy Policy.
8. Data Breach Notification
In the event of a Personal Data breach, TinyPoll will:
- Notify the Customer without undue delay (and in any event within 72 hours of becoming aware of the breach).
- Provide sufficient detail to allow the Customer to meet its own breach notification obligations.
- Take reasonable steps to mitigate the effects of the breach.
9. Term and Termination
This DPA remains in effect for as long as TinyPoll processes Personal Data on behalf of the Customer. Upon termination of the Service, TinyPoll will delete Personal Data in accordance with Section 7, including Customer data in support email on request.
10. Governing Law
This DPA is governed by the laws of Australia, consistent with the governing law of the Terms of Service, except that the SCCs and the UK Addendum are governed by the law they specify (Section 6).
Need a Signed Copy?
If your organisation requires a countersigned DPA, please contact us:
Email: legal@tinypoll.io
We'll provide a signed copy within 5 business days.