Data Processing Addendum
Last updated: 30 July 2026
This Data Processing Addendum ("DPA") forms part of the terms of service and applies automatically to every organization using StaffVoice — no signature needed. It reflects Article 28 UK GDPR. If your procurement process needs a countersigned copy, email us.
Roles and scope
Your organization ("Customer") is the controller of personal data processed through the service; StaffVoice is the processor. Processing covers: respondent notes and responses, invite and roster emails, signed names where a respondent opts in, report content, and delivery metadata — for the sole purpose of providing the service described in the terms. Duration: the life of the Customer's account plus the deletion windows below.
Our commitments as processor
- Process personal data only on the Customer's documented instructions — which are: operate the service as configured by the Customer — unless UK law requires otherwise.
- Ensure everyone with access is bound by confidentiality.
- Apply the technical and organizational measures on the security page, including the structural anonymity design, TLS in transit, encryption at rest, and the raw-note deletion window (at most 30 days after a pulse closes).
- Assist the Customer with data-subject requests and with UK GDPR obligations on security, breach notification, and impact assessments — noting that responses are stored unlinked to identity, so requests concerning a specific respondent's submitted response cannot be fulfilled by design.
- Notify the Customer without undue delay after becoming aware of a personal data breach affecting their data.
- Delete the Customer's personal data on account deletion, except where law requires retention.
- Make available the information reasonably necessary to demonstrate compliance with this DPA.
Sub-processors
The Customer authorizes these sub-processors, engaged under written terms no less protective than this DPA:
- Anthropic (US) — AI rewriting and report generation
- Resend (US) — transactional email
- Stripe (US/UK) — billing
- Vercel (US) — application hosting
- Neon (US) — database hosting
- Slack / Microsoft — message delivery, only where the Customer connects them
We'll announce sub-processor changes at least 30 days before they take effect (by email or in the product); if the Customer reasonably objects on data-protection grounds and we can't offer an alternative, the Customer may terminate the affected service with a pro-rata refund.
International transfers rely on the UK International Data Transfer Agreement or Addendum, or the UK extension to the EU–US Data Privacy Framework, as applicable to each provider.
Contact
DPA questions, countersigned copies, or security documentation: [email protected].