Data Processing Addendum
Last updated:
1.Scope & Roles
This Data Processing Addendum ("DPA") forms part of the agreement between PolitiMind, Inc. ("Processor") and the customer organization ("Controller") for the provision of PolitiMind services. It applies where PolitiMind processes personal data on the Controller's behalf.
For participant data that PolitiMind collects and determines the purposes of, PolitiMind acts as an independent Controller, governed by our Privacy Policy rather than this DPA.
2.Subject Matter & Details of Processing
- Subject matter: provision of verified polling, sentiment analytics, and civic intelligence services.
- Duration: the term of the agreement plus the retention period in Section 8.
- Nature and purpose: collection, aggregation, statistical analysis, storage, and delivery of poll results and analytics.
- Categories of data subjects: Controller personnel, and where applicable, Controller-supplied audience lists.
- Categories of personal data: business contact data, account identifiers, usage logs. Controller must not upload special-category data without a written amendment.
3.Processor Obligations (GDPR Art. 28)
- Process personal data only on documented instructions from the Controller, including for international transfers, unless required by law.
- Ensure persons authorized to process data are bound by confidentiality.
- Implement the technical and organizational measures in Annex II.
- Respect the sub-processor conditions in Section 4.
- Assist the Controller with data-subject requests, DPIAs, and prior consultations, taking into account the nature of processing.
- Notify the Controller without undue delay, and in any case within 48 hours, of becoming aware of a personal-data breach.
- Delete or return personal data at the Controller's election at the end of the term.
- Make available information necessary to demonstrate compliance and allow for audits per Section 7.
4.Sub-Processors
The Controller grants general written authorization for the sub-processors listed below. PolitiMind will give at least 30 days' notice of any intended addition or replacement, during which the Controller may object on reasonable data-protection grounds.
- Supabase — database, authentication, storage, edge compute (US).
- Persona Identities — identity and biometric verification (US).
- Cloudflare — CDN, WAF, bot mitigation (global).
- HubSpot — CRM and customer communications (US/EU).
- Contentful — content delivery for published resources (EU/US).
- Sentry — error and performance monitoring (US).
- Coinbase / Base — on-chain anchoring and token distribution (public network).
Each sub-processor is bound by data-protection terms no less protective than this DPA.
5.International Transfers
- EEA: the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), are incorporated by reference and completed with the details in this DPA. Clause 17 governing law: Ireland. Clause 18 forum: Ireland.
- UK: the UK International Data Transfer Addendum (IDTA) to the EU SCCs is incorporated by reference.
- Switzerland: the SCCs apply with references to the GDPR read as references to the FADP, and the Swiss FDPIC as the supervisory authority.
- A transfer impact assessment is available to the Controller on request.
6.Annex I — Parties & Transfer Details
Data importer / Processor: PolitiMind, Inc., 1209 Orange Street, Wilmington, DE 19801, USA. Contact: chris@politimind.com.
Data exporter / Controller: as identified in the executed order form.
Frequency of transfer: continuous, for the term of the agreement.
Competent supervisory authority: determined under SCC Clause 13 by the exporter's establishment.
7.Annex II — Technical & Organizational Measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Row-level security and security-definer access functions on all tenant-scoped data.
- Least-privilege role-based access with a four-tier permission ladder and audit logging of privileged actions.
- Strict Content-Security-Policy and security headers on all public surfaces.
- Automated dependency and static security scanning; documented remediation SLAs.
- Responsible-disclosure program with safe harbor (see Security Policy).
- Backup, point-in-time recovery, and documented restoration testing.
- Pseudonymization of participant identifiers in all analytics outputs; no deanonymization of individual responses.
8.Audit Rights
PolitiMind will respond to reasonable written security questionnaires no more than once per twelve months, and will make available available third-party assessments and this DPA's annexes. On-site audits require 30 days' notice, must be conducted during business hours, must not unreasonably disrupt operations, and are subject to confidentiality.
9.Retention, Return & Deletion
On termination, PolitiMind will delete or return Controller personal data within 30 days at the Controller's election, except where retention is required by law. Backups age out on the standard backup cycle and are not restored for production use after deletion.
10.Requesting an Executed Copy
To request a countersigned DPA including SCC annexes, email chris@politimind.com with your legal entity name, address, and signatory.
