Legal

Data Processing Agreement

Last updated: September 8, 2026

This Data Processing Agreement ("DPA") is entered into by SmallCloud Technologies Incorporated ("Processor", "we", "us") and the customer organization that uses ChalkHR Polls & Surveys ("Controller", "Customer").

Version 2026-09-08. Effective 8 September 2026. This DPA forms part of the Terms of Service (the "Agreement"). If there is a conflict, this DPA controls for the Processing of Customer Personal Data, except that the Standard Contractual Clauses control for Restricted Transfers.

By installing or using the Service, or by signing a copy of this DPA, Customer agrees to these terms. To receive a countersigned copy, email privacy@chalkhr.com with Customer's legal name and registered address.

1. Definitions

Capitalized terms have the meanings in the Agreement or below:

  • Data Protection Laws means GDPR (EU) 2016/679, the UK GDPR, the UK Data Protection Act 2018, the Swiss FADP, and any similar laws that apply to the Processing.
  • Customer Personal Data means Personal Data that Customer or its users submit to the Service, or that we Process on Customer's behalf to provide the Service.
  • Personal Data Breach has the meaning in GDPR Article 4(12).
  • Restricted Transfer means a transfer of Customer Personal Data from the EEA, UK, or Switzerland to a country that does not benefit from an adequacy decision.
  • SCCs means the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor).
  • UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
  • Subprocessor means a third party engaged by us to Process Customer Personal Data.

2. Roles

For Customer Personal Data, Customer is the controller (or a processor instructing us as a subprocessor) and SmallCloud Technologies Incorporated is the processor (or subprocessor). Each party will comply with Data Protection Laws that apply to it.

Processor details: SmallCloud Technologies Incorporated, a corporation under the Canada Business Corporations Act, corporation number 10391301, CRA business number 796185288, Ontario, Canada. The registered office address is available on request. Privacy contact: privacy@chalkhr.com.

This DPA does not apply to personal data we process as an independent controller (for example, billing contacts we collect ourselves, or analytics on chalkhr.com about visitors who are not using the Service as Customer's users).

3. Customer's instructions

We will Process Customer Personal Data only: (a) to provide, secure, and support the Service as described in the Agreement and Annex I; (b) as documented in this DPA; and (c) as required by law, in which case we will notify Customer before Processing unless the law prohibits notice.

Customer is responsible for the lawfulness of its instructions, for the accuracy of Customer Personal Data, and for any special-category or sensitive data its users submit in poll questions or responses. The Service is not designed for special-category data. Customer shall not instruct us to Process such data unless Customer has a lawful basis and accepts the residual risk.

4. Confidentiality

We will ensure that persons authorised to Process Customer Personal Data are bound by confidentiality and Process it only as needed to perform their duties.

5. Security

Taking into account the state of the art, costs, nature of the Processing, and the risk to data subjects, we will implement appropriate technical and organisational measures as described in Annex II and on chalkhr.com/security.

6. Subprocessors

Customer gives general written authorisation for us to engage the Subprocessors in Annex III and to replace them, provided we: (a) impose data-protection terms on each Subprocessor that are no less protective than this DPA; (b) remain liable to Customer for the Subprocessor's performance; and (c) update chalkhr.com/security at least 30 days before a new production Subprocessor starts Processing Customer Personal Data.

Customer may object on reasonable data-protection grounds by emailing privacy@chalkhr.com within 15 days of the update. We will work in good faith to avoid the Subprocessor or otherwise address the objection. If we cannot, Customer may terminate the affected Service as its sole remedy.

7. International transfers

Processor is established in Canada. The European Commission has issued an adequacy decision for Canada. Production Customer Personal Data is stored in the United States (see Annex I). Transfers from the EEA to Processor that are Restricted Transfers are subject to the SCCs, which the parties hereby enter into. Module Two applies. The SCC annexes are completed by Annexes I–III of this DPA. For Clause 17, the parties select the laws of Ireland. For Clause 18, the parties select the courts of Ireland. The optional docking clause is not used.

For Restricted Transfers subject to UK GDPR, the UK Addendum is incorporated. Tables 1–3 of the Addendum are completed by the party details and Annexes in this DPA. Table 4: neither party may end the Addendum under that table except as the Addendum allows.

For Switzerland, the SCCs apply with the adaptations commonly used for the FADP (references to GDPR read as FADP; supervisory authority and courts are Swiss).

We will use Subprocessors only where a lawful transfer tool exists (adequacy, SCCs, or participation in the EU-US Data Privacy Framework, as applicable to that vendor).

8. Assistance with data-subject rights

Taking into account the nature of the Processing, we will assist Customer, by appropriate technical and organisational measures, to respond to requests to exercise data-subject rights. Customer is the primary contact for its users. If we receive a request that relates to Customer Personal Data, we will direct the requester to Customer unless legally required to respond ourselves.

We will also assist Customer with its obligations under GDPR Articles 32 to 36 (security, breach notification to authorities and data subjects, DPIAs, and prior consultation), considering the information available to us. Self-serve export is not yet a product feature; we will provide a machine-readable export of tenant poll data on written request.

9. Personal Data Breach

We will notify Customer without undue delay, and no later than 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, at the email Customer uses for the Service or any address Customer designates. The notice will describe, to the extent known: the nature of the breach, likely consequences, measures taken or proposed, and a contact point. We will cooperate with Customer's investigation and mitigation.

10. Deletion and return

When the Agreement ends, or on Customer's written request, we will delete Customer Personal Data from production systems within 60 days, unless law requires storage. At Customer's option before deletion, we will return a machine-readable copy. Backup copies may persist for up to 90 days and are then overwritten in the ordinary backup cycle. We will confirm deletion on request.

11. Information and audits

We will make available information reasonably necessary to demonstrate compliance with this DPA, including this document, the Security page, and completed security questionnaires. We do not currently hold SOC 2 or ISO 27001 reports.

If Data Protection Laws require an on-site or independent audit, Customer may conduct one on 30 days' written notice, no more than once per 12 months unless a Personal Data Breach or competent authority requires otherwise, during business hours, without disrupting operations, and at Customer's expense. Customer may use a mutually acceptable independent auditor bound by confidentiality. We may object to an auditor who is a competitor.

12. Liability

Each party's liability under this DPA is subject to the limitations in the Agreement, except that those limitations do not apply to the extent they would restrict a party's liability under the SCCs or liability that cannot be limited under Data Protection Laws.

13. Term

This DPA lasts for as long as we Process Customer Personal Data. Sections that by their nature should survive (confidentiality, deletion, liability, SCCs) survive termination.

14. General

We may update this DPA by posting a new version at chalkhr.com/dpa and changing the version date. Material reductions of Customer's rights under Data Protection Laws will not take effect for an existing Customer until 30 days after notice, except where a change is required by law. If Customer objects, Customer's sole remedy is to stop using the Service and request deletion.

Governing law and courts follow the Agreement, except as the SCCs provide for Restricted Transfers.

Annex I — Description of Processing

A. List of parties

Controller: the Customer organization using the Service (name and address as in Customer's Microsoft tenant / order / countersignature).
Processor: SmallCloud Technologies Incorporated (Ontario, Canada). The registered office address is available on request. Email privacy@chalkhr.com.

B. Description of transfer / Processing

  • Subject matter: hosting and operation of ChalkHR Polls & Surveys.
  • Duration: the term of the Agreement plus the deletion period in section 10.
  • Nature and purpose: authenticate users; store and display polls, questions, votes, and responses; send Teams bot messages and reminders; enforce plan limits; operate, secure, and debug the Service.
  • Categories of data subjects: Customer's Microsoft 365 users; optional external voters on public links.
  • Types of Personal Data: name, email, Entra object ID, tenant ID, avatar URL; team and channel identifiers and names; Bot Framework conversation references; poll titles, questions, options, votes, open-text responses; optional external voter name and email; usage events and error/log identifiers as needed to operate the Service.
  • Special categories: not collected by design. Users may type such data into free-text fields. See section 3.
  • Frequency: continuous, for as long as Customer uses the Service.
  • Storage location: production database in AWS us-east-1 (United States); API Worker placed in AWS us-east-2 (United States); Cloudflare global edge for application delivery.

C. Competent supervisory authority

For the SCCs, the supervisory authority is the authority of the EEA member state where Controller is established, or as Clause 13 of the SCCs otherwise provides.

Annex II — Technical and organisational measures

  • TLS encryption in transit for public endpoints and database connections.
  • Encryption at rest of the production database by the hosting provider.
  • Logical tenant isolation by Microsoft tenant ID on every data query.
  • Authentication via Microsoft Entra ID / Teams SSO. No passwords stored. No Microsoft Graph admin consent required for the current Polls app permission footprint.
  • Production secrets stored in the hosting platform, not in application source control.
  • Operator access limited to people who need it to run the Service.
  • Application logs and error monitoring (Axiom, Sentry) used to operate and debug the Service.
  • Anonymous-poll mode hides voter identity in the product UI; a user ID is still stored for one-vote-per-user enforcement.

See also chalkhr.com/security.

Annex III — Authorised subprocessors

Production Subprocessors as of the version date. The current list is chalkhr.com/security.

Vendor Purpose Location
Cloudflare
Cloudflare, Inc.
Cloudflare privacy policy
Application hosting (Workers, static assets), CDN, Hyperdrive database pooling, KV, Queues, Workflows, Analytics Engine, and Email Sending Global edge network; Polls API Worker placed in AWS us-east-2 (Ohio, United States)
PlanetScale
PlanetScale, Inc.
PlanetScale privacy policy
Production PostgreSQL database (system of record) AWS us-east-1 (Northern Virginia, United States)
Microsoft
Microsoft Corporation
Microsoft privacy policy
Microsoft Entra ID authentication and Teams Bot Framework message delivery Customer's Microsoft 365 geography and Microsoft global cloud
PostHog
PostHog, Inc.
PostHog privacy policy
Product analytics inside the Polls app and on chalkhr.com United States (PostHog Cloud US)
Sentry
Functional Software, Inc. d/b/a Sentry
Sentry privacy policy
Application error tracking and performance monitoring United States (Sentry US ingest)
Axiom
Axiom, Inc.
Axiom privacy policy
Application request logs used to operate and debug the Service United States
Google Analytics
Google LLC
Google Analytics privacy policy
Page-view analytics on chalkhr.com and polls.chalkhr.com United States

The following are used only for staging and pull-request previews, not production Customer tenants:

Vendor Purpose Location
Neon
Neon, Inc.
Neon privacy policy
Staging and pull-request preview databases United States