Privacy Policy
Last updated: August 2026
1. Data Controller
The data controller for suPlay Poll is suPlay B.V., Ruwerstraat 9, 7545 SM Enschede, The Netherlands. You can reach us at info@suplay.nl.
2. What Data We Collect
When you use suPlay Poll, we may collect the following data:
- Votes and responses: Your answers to polls. In anonymous mode, votes are not linked to your identity. In authenticated mode, your name and/or email address may be linked to your participation, but individual votes remain anonymous by default.
- Optional participant info: If provided, your name and/or email address when joining an event.
- Session tokens: Technical identifiers to maintain your session.
- Presenter accounts: Name, email address, and hashed password for event presenters.
- Single sign-on (SSO): If your organization uses SSO, when you sign in your identity provider shares your name and email address with us to create or identify your account. We do not receive your SSO password.
- Sign in with Google:If you choose “Continue with Google”, Google shares your name and verified email address with us to create or identify your account. We never receive your Google password. You can later add a suPlay Poll password to the same account from your settings.
3. How Data Is Stored
All data is stored in a PostgreSQL database hosted by TransIP / team.blue on servers located in the Netherlands. Data is transmitted over encrypted connections (HTTPS/TLS).
4. Cookies
We use only essential cookies:
- Session token (essential, httpOnly) — maintains your participant session.
- Authentication JWT (essential, httpOnly) — keeps presenters logged in.
We do not use any tracking, analytics, or advertising cookies.
5. Who Has Access
- Event presenters can view aggregate poll results for their events. In authenticated mode, they can see which participants joined but cannot link individual votes to participants in anonymous mode.
- System administrators at suPlay B.V. have access to the database for operational purposes. Any administrative impersonation of a presenter account is logged and retained for 90 days.
- Organization owners and admins — if you belong to a team or organization account, the owners and administrators of that organization can see your name and account email and can access, manage, and reassign the events, question banks, and templates you create within that organization (for oversight, collaboration, and offboarding). They cannot see your personal workspace or other organizations you belong to.
- Subprocessors named on our Subprocessors page process data on our behalf under signed Data Processing Agreements.
6. Lawful basis (GDPR Art. 6)
| Purpose | Data | Lawful basis |
|---|---|---|
| Operate a presenter account | Name, email, hashed password | Contract (Art. 6(1)(b)) |
| Run a poll / collect votes | Votes, optional participant name/email, session token | Legitimate interests (Art. 6(1)(f)) or consent when identifying data is voluntarily provided |
| Send transactional email (verification, reset, invitation) | Email, name | Contract + legitimate interests |
| Billing and subscription management | PayPal payer identifiers, plan, billing events | Contract + legal obligation (tax retention) |
| Security, fraud prevention, rate limiting | IP address — processed transiently as a Redis counter key (typically for seconds up to one hour), not written to the application database or server logs | Legitimate interests |
| Error monitoring and service stability | Stack traces with personally-identifying fields scrubbed | Legitimate interests |
7. Retention
| Data category | Retention | Reason |
|---|---|---|
| Presenter account | Until deletion request, plus 30 days grace | Allow account recovery |
| Events, polls, votes | Retained until the presenter deletes the event. CLOSED events that have been idle for 90 days are automatically archived. Archived events follow tier-based retention: 1 year on the Free plan, 5 years on Academic, Professional, and Enterprise. The presenter is emailed before deletion (1 month ahead on Free, 6 months ahead on paid plans); opening or editing the event resets the clock. | Typical reuse window; data minimisation thereafter |
| Participant responses & names | Same retention as the parent event (cascaded on deletion). | Minimisation |
| Unverified user accounts | Purged 30 days after signup if email is never verified | No legitimate purpose once unverified |
| Pending event invitations | Purged 90 days after sending if never redeemed | Minimisation; recipient can be re-invited |
| GDPR erasure requests | Auto-fulfilled 7 days after submission (per Art. 12(3)) | Statutory deadline with a short verification window |
| Email-verification and password-reset tokens | Deleted on use or after 24-hour expiry | No purpose once consumed |
| Billing events, invoices | 7 years | Dutch tax law |
| Admin impersonation log | 90 days | Forensics + access-review |
| Sentry error events | Sentry default (30–90 days) | Operated by subprocessor; see their retention schedule |
| Database backups | 30 rolling daily, 12 rolling monthly; then overwritten | Recovery window + long-tail integrity |
8. International transfers
suPlay B.V. is established in the Netherlands and operates the application from servers in the Netherlands. All processing subprocessors used today are located in the EU: transactional email (Resend, EU), application error monitoring (Sentry, EU region —ingest.de.sentry.io), encrypted backup storage (Scaleway, NL/FR). Subscription billing is handled by PayPal (Europe) S.à r.l. et Cie, S.C.A. in Luxembourg; onward transfers to the US parent for fraud-prevention purposes are governed by Standard Contractual Clauses (SCCs) 2021/914. See our Subprocessors page for the complete list and legal basis of each transfer.
9. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access your personal data (Art. 15). Presenters can self-export via
/settings→ “Download my data”. - Rectify inaccurate data (Art. 16). Presenters can edit name/email in
/settings. - Deleteyour data (Art. 17, “right to be forgotten”). Presenters can self-delete their account via
/settings. Participants can ask the presenter or email privacy@suplay.nl. - Port your data to another service (Art. 20). Machine-readable JSON via the account-export endpoint (CSV export of votes and participants is available per-event from the presenter dashboard).
- Restrict or object to processing (Art. 18, 21). Email privacy@suplay.nl.
- Lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
We respond to data-subject requests within 30 days. If a request is complex we may extend by a further 60 days with notice.
10. Security measures
See our Security Summary for the public-facing list of technical and organisational measures, including TLS, password and token hashing, rate limiting, runtime privilege isolation, mandatory access controls, backup encryption, and incident response. Detailed measures (versions, internal topology, audit-log retention) are available on request to customers with a signed DPA.
11. Google user data (Slides add-on)
suPlay Poll offers an add-on for Google Slides. When you install and sign in to it, it accesses a limited set of Google data using the following scopes, each only for the feature it powers:
- See your primary Google Account email address (
userinfo.email) — used to sign you in. When you open the add-on, it presents the credential Google has already issued to it topoll.suplay.nl. We verify that credential with Google and read your verified email address and your Google account identifier, in order to find your existing suPlay Poll account — or to create one for you if you do not yet have one. This is what lets you use the add-on without typing a separate password. We never receive your Google password, and this permission gives us no access to anything else in your Google Account. - View and manage the presentation the add-on is installed in (
presentations.currentonly) — to read the current slide and insert a poll slide into that presentation only. The add-on cannot see or modify your other presentations. - Connect to an external service (
script.external_request) — so the add-on can talk topoll.suplay.nlto look up the poll bound to a slide and validate your sign-in. - Display the add-on sidebar (
script.container.ui) — to show the add-on interface inside Google Slides.
Only slide identifiers and the poll you bind to them are sent to suPlay Poll — never the content of your slides.
11.1 What Google user data we store, and how it is used
Google user data is used solely to operate the add-on’s user-facing features. Concretely, we store only:
- Slide bindings — the Google presentation ID and slide ID of a slide you attach a poll to, stored alongside the identifier of that poll. Google Slides offers no in-document storage, so this mapping must live on our server for the add-on and the companion browser extension to know which poll belongs to which slide. No slide content, title, thumbnail, or other presentation data is read or stored.
- Your Google account identifier and email address— stored on your suPlay Poll account so that opening the add-on signs you into the same account every time. The identifier is Google’s stable account ID; we key your account on it rather than on your email address, so that changing your email does not detach your account.
- A sidebar session token — created when you connect the add-on to your suPlay Poll account. We store only an irreversible hash of the token, never the token itself, together with the browser user-agent string that created it.
We do not use Google user data to build profiles, to train or improve machine-learning models, for advertising or lending decisions, or for any purpose beyond the features described above.
11.2 Transfer of Google user data
We do not sell Google user data, and we do not transfer it to data brokers, advertisers, or any party for advertising purposes. Slide bindings and session tokens are stored on suPlay B.V.’s own server infrastructure in the Netherlands and are not shared with any third party for their own purposes. The only parties that can process this data are the infrastructure and operational subprocessors listed on our Subprocessors page, acting on our instructions under written data-processing terms, plus disclosure where required by law. See also sections 5 (Who Has Access) and 8 (International transfers).
11.3 How Google user data is protected
Google user data is protected by the same controls as the rest of the service, described in section 10 and in our Security Summary: encryption in transit via TLS, session tokens stored only as irreversible hashes, encrypted database backups, rate limiting, runtime privilege isolation and mandatory access controls on the application server, and a documented incident-response process. Access by our personnel is restricted to named administrators and only for maintenance, security, or legal reasons.
11.4 Retention and deletion of Google user data
We retain Google user data only for as long as it serves the feature you enabled, and you can delete it at any time:
- Slide bindings are deleted immediately and automatically when you delete the bound poll or its event, and they follow the event retention schedule in section 7 otherwise. You can also detach a poll from a slide directly in the add-on sidebar.
- Session tokens expire automatically after 30 days without use, and in all cases no more than 90 days after they are created. Choosing Sign out in the sidebar revokes the token on our server straight away.
- Deleting your suPlay Poll account erases all associated session tokens, events, polls, and slide bindings. You can do this yourself from Settings, or by writing to privacy@suplay.nl.
- Revoking access at myaccount.google.com/permissions immediately ends the add-on’s ability to access any Google data. Uninstalling the add-on has the same effect.
Limited Use.suPlay Poll’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the add-on’s user-facing features; we do not sell it, do not transfer it to third parties except as needed to provide the service or where required by law, do not use it for advertising, and do not allow humans to read it except with your consent, for security or legal reasons, or where the data has been aggregated and anonymised.
12. Contact
suPlay B.V.
Ruwerstraat 9, 7545 SM Enschede, The Netherlands
General: info@suplay.nl
Privacy / data-subject requests: privacy@suplay.nl
Managing Director: Holger Schiele.
Data Protection contact: Frederik Vos, Co-founder and Head of Development.