Ga naar hoofdinhoud
For procurement, IT and data protection teams

Security & data protection

All data at rest — database, uploaded files, backups and cache — is stored in the United Kingdom. Application processing takes place in the EEA (Frankfurt, Germany).

Last reviewed: July 2026. Questions, our DPA, or a completed security questionnaire: [email protected]

Where your data lives

Data Provider Locatie
Primary database (accounts, discussions, votes) Neon (PostgreSQL) United Kingdom (London)
Uploaded files and media Amazon Web Services S3 United Kingdom (London)
Database backups Amazon Web Services S3 United Kingdom (London)
Cache and rate limiting (transient) Redis Cloud United Kingdom (London)
Application hosting Render EEA (Frankfurt, Germany)

No personal data is stored at rest outside the United Kingdom.

Subprocessors

The full list of service providers that may process data on our behalf, and where that processing happens. This list is kept in step with our Privacybeleid.

Provider Doel Processing location
NeonManaged PostgreSQL databaseUnited Kingdom
RenderApplication hostingGermany (EEA)
Amazon Web ServicesObject storage and backupsUnited Kingdom
Redis Cloud (Redis Ltd)Managed cache (transient data)United Kingdom
StripePayment processing — card data never touches our serversUSA
ResendTransactional and subscription emailUSA
PostHogProduct analyticsEU
Google (Tag Manager / Analytics)Site analyticsUSA
SentryError monitoring and diagnosticsEU
AnthropicTranslation and content generation — public statement text only, no account identifiersUSA
CookieYesCookie consent managementGlobal CDN
Pol.isLegacy embedded discussions only — not used for new consultationsUSA

Transfers to US providers are safeguarded by the UK International Data Transfer Agreement / UK Addendum and, where the provider is certified, the UK Extension to the EU–US Data Privacy Framework.

Security measures

Encryption
TLS 1.2+ for all traffic; AES-256 encryption at rest for the database and object storage.
Backups and recovery
Automated daily database backups to UK object storage with 30-day retention, plus provider point-in-time recovery. The restore procedure is documented and tested.
Change control
All changes flow through version control with automated deployments. No manual server access in the normal course of operation.
Access control
Least-privilege credentials per service. Secrets are held in the hosting platform’s encrypted store, never in source code.
Abuse prevention
Rate limiting, bot detection and moderation tooling are built into the platform — including protections against automated voting.
Monitoring
Independent uptime monitoring and error alerting across all services.

Data protection

  • Controller: William Roberts Coaching and Advisory Ltd (England, company no. 15629688), processing under UK GDPR and the Data Protection Act 2018.
  • Anonymous by default: participants do not need an account. Anonymous participation uses a hashed identifier, not identity.
  • Data minimisation: we collect the minimum needed to run a consultation. Individual votes are never shown to other participants or to the consultation owner.
  • Your data is yours: full export in CSV and JSON at any time; deletion on request. Consultation data is owned by the commissioning organisation.
  • DPIA support: we provide a pre-completed Data Protection Impact Assessment template for public-sector clients.

Assurance

  • Inherited provider certifications: AWS (ISO 27001, SOC 2), Render (SOC 2 Type II), Neon (SOC 2 Type II), Stripe (PCI DSS Level 1).
  • Cyber Essentials certification is in progress.
  • Open source: the platform and its consensus methodology are publicly auditable — no vendor lock-in. The software can be independently inspected or self-hosted.

Available on request

  • Data Processing Agreement (DPA)
  • Pre-completed DPIA template for public-sector consultations
  • Completed security questionnaires

E-mail [email protected] and we will respond promptly.

Reporting a vulnerability

We welcome good-faith security research. Please report suspected vulnerabilities to [email protected] and allow us reasonable time to remediate before public disclosure. See also /.well-known/security.txt.