Privacy Policy

How we collect, use, and protect your personal data — in line with the EU GDPR and the privacy controls built into our platform.

Last updated: September 2026

Introduction

elects.online ("we," "our," or "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard personal data when you use our online voting platform, in line with the EU General Data Protection Regulation (GDPR) and other applicable data-protection laws. It reflects the privacy controls built into the platform, including the in-app Privacy Center where you can manage consent, export your data, and request deletion.

Our Role: Controller & Processor

Voting data (your institution's election)

For voter registers, ballots, and vote records, your institution is the data controller and elects.online acts as a data processor on their behalf, under a GDPR-compliant Data Processing Addendum.

Your platform account

For the personal data in your own account (name, email, login credentials), elects.online is the data controller.

Information We Collect

Personal Information

  • Name, email address, and contact information
  • Account credentials (encrypted passwords)
  • Organization and election-related information
  • Voter register details provided by your institution

Usage Information

  • Device information (browser type, operating system)
  • IP address and general location data
  • Pages visited and actions taken on the platform
  • Voting participation timestamps (not vote content)
  • Consent and cookie-preference records

Legal Bases for Processing

Under the GDPR we rely on the following legal bases (Art. 6):

  • Consent (Art. 6(1)(a)) — for processing voting data and for marketing communications; you can withdraw consent at any time.
  • Contract (Art. 6(1)(b)) — to provide the platform and the services you sign up for.
  • Legitimate interests (Art. 6(1)(f)) — to secure the platform, prevent fraud, and improve our services.
  • Legal obligation (Art. 6(1)(c)) — where we must keep records to comply with the law.

Your Vote is Private

We take vote privacy extremely seriously. Your actual vote choices are encrypted and cannot be viewed by elects.online staff, election administrators, or any third party.

  • Votes are encrypted end-to-end using industry-standard cryptography
  • Vote content is separated from voter identity in our systems
  • Election results are aggregated without exposing individual votes
  • Audit logs track participation, not vote choices

Your GDPR Rights

  • 1 Access (Art. 15) the personal data we hold about you
  • 2 Rectify (Art. 16) inaccurate or incomplete data
  • 3 Erase (Art. 17) your data — the “right to be forgotten”
  • 4 Restrict (Art. 18) processing in certain circumstances
  • 5 Data portability (Art. 20) — export your data in a machine-readable format
  • 6 Object (Art. 21) to certain processing
  • 7 Withdraw consent at any time
  • 8 Lodge a complaint with your data-protection supervisory authority

You can exercise many of these rights directly from the in-app Privacy Center — export your data (Art. 20) or submit a deletion request (Art. 17). We respond within 30 days. Votes tied to an active or contested election may be retained until the audit period lapses, to protect election integrity.

Cookies

We use cookies in the following categories. When you first visit, our cookie banner lets you accept or customize; you can change your choices anytime in the Privacy Center.

Essential

Required for session and security. Always on.

Analytics

Usage statistics to improve the platform. Optional (consent-based).

Marketing

Optional and off by default.

Data Retention

We keep personal data only as long as needed for the purposes above. Typical retention periods:

  • Voter register data — retained for the duration of the institution’s active contract, plus 1 year.
  • Ballots & vote records — retained per the election audit policy (default 5 years, institution-configurable).
  • Referral records — retained 2 years from validation, then anonymized.
  • Session & login logs — retained 90 days for security auditing.
  • Account data after a deletion request — purged within 30 days, except where legal or audit holds apply.

Data Processing Addendum & Sub-processors

Data Processing Addendum (DPA)

Institutions accept our GDPR-compliant Data Processing Addendum when they sign up. It governs how we process personal data on their behalf as their processor.

Sub-processors

We use a limited set of vetted sub-processors, including our payment providers Monnify and Paystack (to process plan payments) and our cloud hosting/infrastructure providers. Card details are handled by these PCI-compliant providers and are never stored on our servers.

Data Security

We implement robust measures to protect your information:

Encryption

256-bit SSL/TLS for all data in transit

Secure Infrastructure

Data stored in secure, monitored data centers

Access Controls

Strict access controls & multi-factor authentication

International Data Transfers

Where personal data is transferred outside your region, we apply appropriate safeguards (such as standard contractual clauses) to ensure an equivalent level of protection under the GDPR.

Contact Us

For any question about this Privacy Policy, to exercise your rights, or to reach our privacy team, contact us: [email protected] (general), [email protected] (privacy), [email protected] (support)

© 2025 elects.online. All rights reserved.