Legal
Data processing agreement
Last updated 2026-08-28
This is a template. It describes the intended processor terms in plain language so your counsel can evaluate them before a call. It is not an executed agreement, and the executable version should be requested and reviewed.
1. Roles
The customer is the controller. Ballot Signal is the processor. The customer determines the purposes and means of processing; we process only on the customer’s documented instructions, which are the configuration choices made in the product plus this agreement.
2. Subject matter and duration
Consent-gated identification of the customer’s own website visitors and routing of the resulting supporter records to destinations the customer configures, for the term of the underlying agreement.
3. Categories of data subjects and personal data
Data subjects: visitors to the customer’s website who granted consent.
Personal data: name, email address, telephone number, postal address, on-site behavior after consent, attribution parameters, and the consent record (timestamp, version, source URL, categories).
Special category data: none is intentionally processed. Note that inferences about political opinion may be sensitive in some jurisdictions given the nature of the customer’s website, and the customer should account for that in its own assessment.
4. Our obligations
- Process only on documented instructions.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organizational security measures, described on security & privacy.
- Not engage a sub-processor without notice and an opportunity to object.
- Assist the controller with data subject requests, security incidents and impact assessments, taking into account the nature of processing.
- Delete or return personal data at the end of the agreement, at the controller’s election.
- Make available the information reasonably necessary to demonstrate compliance.
5. Sub-processors
A current list is maintained on security & privacy. We give advance notice of changes and a period to object.
6. Security incidents
We notify the controller without undue delay after becoming aware of a personal data breach affecting their data, with the information available at the time and updates as the investigation proceeds.
7. Consent gate
We will not process data for visitors who have not granted the required consent categories. This is a technical control in the pipeline, not a policy commitment, and it is not configurable off. See platform.
8. International transfers
Processing takes place in the jurisdictions listed on security & privacy. Where a transfer mechanism is required, the appropriate mechanism will be incorporated by reference in the executed agreement.
9. Deletion
On instruction, or at the end of the agreement, we delete the controller’s personal data from live systems on a defined schedule and from backups on the backup expiry cycle. We cannot delete data already written into the controller’s own destination systems — that is a controller-side action, and our documentation identifies the fields to filter on.
10. Not legal advice
This page is a plain-language summary written by a software company. Have counsel review the executable agreement.