Draft — not in effect
This page is a working draft awaiting decisions, legal review, and the setup of its contact address. It is not a policy or an agreement, and it makes no promise. Marked gaps show what is still to be decided.
Privacy
Who we are
RoundTable Control is an online service that organizations use to manage their members, officers, communications, and records. It is operated by [Legal review needed: how the individual operator is named; no mailing address is published (F1)].
Each organization decides what information about its members and operations it enters into the service and how that information is used. We operate the service for that organization and do not use identifiable member information for purposes of our own. The legal description of this relationship is [Legal review needed: processor, service-provider, or controller position — not decided until counsel reviews it (F3)].
To run the service safely for everyone, we also manage information across the whole service: sign-in accounts, authentication, security, fraud prevention, the audit history, and the information needed to keep the service reliable. [Legal review needed: how this platform-wide information is described and on what basis it is handled (F3)]
Information the service holds
An organization that uses the service, and the people it invites, can keep the following in it:
- Names, and email, phone, and postal address contacts.
- Organization memberships, roles, and positions, and the dates they apply.
- Sign-in account details, handled by our sign-in provider. Passwords are never stored by the application itself.
- Messages, announcements, acknowledgements, tasks, requests, and activity attendance.
- Forms submitted through the service, and logos and images an organization uploads.
- Election check-ins and ballots. Anonymous ballots are stored without the voter's identity.
- A history of administrative actions, kept to show who changed what and when.
How it is used
Information is used to run the service for the organizations you belong to: to let you sign in, to show you what your roles allow, and to deliver the invitations, setup links, and sign-in links you ask for. We do not send marketing email.
We do not use identifiable member information for analytics, research, marketing, sale, sharing, or any other purpose of our own.
Who can see it
Who can see or change your information is decided by the roles your organization assigns, which can include officers of the wider organization it belongs to. [Founder input needed: confirm the visibility description (F4)]
Our own staff access information only to operate and support the service. [Legal review needed: access and confidentiality commitments]
Service providers
The service runs on these providers, which process information on our behalf:
- Supabase — database and sign-in (United States).
- Vercel — application hosting.
- Resend — delivery of invitation, setup, and sign-in emails.
Cookies
The service uses only cookies it needs to work: to keep you signed in, to carry an account-setup link while you finish setting up, to confirm your identity again before sensitive actions, and to recognize an election check-in device. It uses no advertising or analytics cookies. [Legal review needed: cookie notice sufficiency]
Keeping and deleting information
How long information is kept after you leave an organization, or after an organization stops using the service, and how deletion requests are handled, is [Founder input needed: retention and deletion commitments (F8)].
Your requests
Your organization can correct most of your information. To ask about, correct, or delete your information, contact [Founder input needed: privacy-request address — planned, not yet active; published after the mailbox is set up and legal review (F6)].
Age
The service is intended for people aged [Founder input needed: minimum age (F9)] and over.
Security
Connections to the service and to its database are encrypted, the application uses a restricted database account, and sensitive actions ask you to confirm your identity again. [Legal review needed: security and incident-notification language]
Changes to this notice
This notice takes effect on [Founder input needed: effective date (F2)]. Changes will be announced by [Founder input needed: how changes are announced (F2)].