Security & data protection
All data at rest — database, uploaded files, backups and cache — is stored in the United Kingdom. Application processing takes place in the EEA (Frankfurt, Germany).
Last reviewed: July 2026. Questions, our DPA, or a completed security questionnaire: [email protected]
Where your data lives
| Data | Provider | Location |
|---|---|---|
| Primary database (accounts, discussions, votes) | Neon (PostgreSQL) | United Kingdom (London) |
| Uploaded files and media | Amazon Web Services S3 | United Kingdom (London) |
| Database backups | Amazon Web Services S3 | United Kingdom (London) |
| Cache and rate limiting (transient) | Redis Cloud | United Kingdom (London) |
| Application hosting | Render | EEA (Frankfurt, Germany) |
No personal data is stored at rest outside the United Kingdom.
Subprocessors
The full list of service providers that may process data on our behalf, and where that processing happens. This list is kept in step with our Privacy Policy.
| Provider | Purpose | Processing location |
|---|---|---|
| Neon | Managed PostgreSQL database | United Kingdom |
| Render | Application hosting | Germany (EEA) |
| Amazon Web Services | Object storage and backups | United Kingdom |
| Redis Cloud (Redis Ltd) | Managed cache (transient data) | United Kingdom |
| Stripe | Payment processing — card data never touches our servers | USA |
| Resend | Transactional and subscription email | USA |
| PostHog | Product analytics | EU |
| Google (Tag Manager / Analytics) | Site analytics | USA |
| Sentry | Error monitoring and diagnostics | EU |
| Anthropic | Translation and content generation — public statement text only, no account identifiers | USA |
| CookieYes | Cookie consent management | Global CDN |
| Pol.is | Legacy embedded discussions only — not used for new consultations | USA |
Transfers to US providers are safeguarded by the UK International Data Transfer Agreement / UK Addendum and, where the provider is certified, the UK Extension to the EU–US Data Privacy Framework.
Security measures
- Encryption
- TLS 1.2+ for all traffic; AES-256 encryption at rest for the database and object storage.
- Backups and recovery
- Automated daily database backups to UK object storage with 30-day retention, plus provider point-in-time recovery. The restore procedure is documented and tested.
- Change control
- All changes flow through version control with automated deployments. No manual server access in the normal course of operation.
- Access control
- Least-privilege credentials per service. Secrets are held in the hosting platform’s encrypted store, never in source code.
- Abuse prevention
- Rate limiting, bot detection and moderation tooling are built into the platform — including protections against automated voting.
- Monitoring
- Independent uptime monitoring and error alerting across all services.
Data protection
- Controller: William Roberts Coaching and Advisory Ltd (England, company no. 15629688), processing under UK GDPR and the Data Protection Act 2018.
- Anonymous by default: participants do not need an account. Anonymous participation uses a hashed identifier, not identity.
- Data minimisation: we collect the minimum needed to run a consultation. Individual votes are never shown to other participants or to the consultation owner.
- Your data is yours: full export in CSV and JSON at any time; deletion on request. Consultation data is owned by the commissioning organisation.
- DPIA support: we provide a pre-completed Data Protection Impact Assessment template for public-sector clients.
Assurance
- Inherited provider certifications: AWS (ISO 27001, SOC 2), Render (SOC 2 Type II), Neon (SOC 2 Type II), Stripe (PCI DSS Level 1).
- Cyber Essentials certification is in progress.
- Open source: the platform and its consensus methodology are publicly auditable — no vendor lock-in. The software can be independently inspected or self-hosted.
Available on request
- Data Processing Agreement (DPA)
- Pre-completed DPIA template for public-sector consultations
- Completed security questionnaires
Email [email protected] and we will respond promptly.
Reporting a vulnerability
We welcome good-faith security research. Please report suspected vulnerabilities to [email protected] and allow us reasonable time to remediate before public disclosure. See also /.well-known/security.txt.