Last updated: 29 August 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Use between Stack Snap Ltd ("we", "us", "our") and the customer ("you", "your") and governs our processing of personal data on your behalf when we provide the hosted Rallly service at rallly.co.
This DPA is incorporated into the Terms of Use by reference and applies automatically. No signature is required for it to take effect. If your procurement process requires a signed copy, email support@rallly.co and we will countersign an execution copy of this DPA.
1.1 In this DPA:
2.1 For Customer Data, you are the controller and we are the processor. Where you act as a processor for another organization, we act as your sub-processor and you warrant that your instructions to us are authorized by the relevant controller.
2.2 We act as an independent controller, not as your processor, for personal data we process for our own purposes: managing accounts and billing, securing and improving the Service, and communicating with users. That processing is described in our Privacy Policy.
2.3 This DPA applies for as long as we process Customer Data. If there is a conflict between this DPA and the Terms of Use, this DPA controls with respect to the processing of personal data.
We will:
5.1 We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data. To the extent the information is available to us, the notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point for further information.
5.2 We will document personal data breaches and cooperate with you in remediation and in meeting your own notification obligations.
6.1 You provide a general written authorization for us to engage the Sub-processors listed in Annex 2 and to add or replace Sub-processors in accordance with this Section.
6.2 We will impose data protection obligations on each Sub-processor by written contract that are no less protective than those in this DPA, and we remain fully liable to you for the performance of each Sub-processor's obligations.
6.3 We will update Annex 2 on this page at least 30 days before a new or replacement Sub-processor first processes Customer Data. To receive Sub-processor change notices by email, send a request to support@rallly.co with "Subprocessor notifications" in the subject line and we will notify the address you provide of future changes.
6.4 You may object to a new or replacement Sub-processor on reasonable data protection grounds by notifying us within 30 days of the notice. We will work with you in good faith to find an alternative. If no alternative is reasonably available, you may terminate your subscription for the affected Service and we will refund any prepaid fees covering the remainder of the term after the date of termination.
7.1 Customer Data is processed in the locations listed in Annex 2, which include the United States and the European Union.
7.2 Where Customer Data protected by UK or EU Data Protection Laws is transferred to a country that has not received an adequacy decision, we ensure appropriate safeguards under Article 46 of the GDPR: the relevant Sub-processor is certified under the EU-US Data Privacy Framework (including the UK Extension), or the transfer is governed by the applicable Standard Contractual Clauses or the UK International Data Transfer Addendum. The mechanism relied on for each Sub-processor is listed in Annex 2.
8.1 We will make available to you the information reasonably necessary to demonstrate compliance with this DPA. We support this primarily through documentation: this DPA, our security page, our publicly auditable source code, our public real-time status page, and the audit reports and certifications of our Sub-processors, which are available from each provider.
8.2 Where that documentation is not sufficient to demonstrate compliance, you, or an independent auditor appointed by you that is not a competitor of ours, may audit our compliance with this DPA no more than once in any 12-month period, on at least 30 days written notice, during normal business hours, without disrupting our operations, subject to reasonable confidentiality obligations, and at your own cost.
9.1 On request, we will provide you with a copy of Customer Data in a structured, commonly used, machine-readable format.
9.2 Deleting a poll through the Service deletes the associated Customer Data. Account deletion starts a 7 day recovery window, after which the data is permanently erased. On written request at the end of the provision of the Service, we will delete all remaining Customer Data and confirm deletion in writing, unless applicable law requires us to retain it.
9.3 Residual copies of deleted Customer Data in encrypted backups expire on our database provider's retention schedule and in any event within 35 days of deletion.
9.4 Short-lived copies of Customer Data used in access-restricted preview environments are deleted automatically no later than 7 days after they are created.
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms of Use, except to the extent liability cannot be limited under Data Protection Laws.
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it.
The measures below describe how we protect Customer Data. Further detail is published on our security page.
We use the following Sub-processors to provide the Service. Changes to this list are notified as set out in Section 6.
| Provider | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Vercel | Application hosting | United States | EU-US DPF + UK Extension (SCCs fallback) |
| Neon | Managed PostgreSQL database | United States | EU-US DPF + UK Extension, certified under Databricks, Inc. (SCCs fallback) |
| Upstash | Session data, rate limiting | United States | EU-US DPF + UK Extension (SCCs + UK Addendum fallback) |
| Amazon Web Services | Transactional email, object storage | United States | EU-US DPF + UK Extension, certified under Amazon.com, Inc. (SCCs fallback) |
| Stripe | Payment processing (billing contact data only) | United States | EU-US DPF + UK Extension (SCCs + UK Addendum fallback) |
| PostHog (EU) | Product analytics | European Union | EU data residency (no US transfer) |
| Sentry | Error monitoring | United States | EU-US DPF + UK Extension (SCCs + UK Addendum fallback) |
Stripe, PostHog, and Sentry primarily support processing for which we act as a controller (billing, product analytics, and error monitoring) and are included above for transparency. For payment transactions, Stripe acts as an independent controller under its own terms.
Questions about this DPA, requests for a countersigned copy, and Sub-processor notification requests can be sent to support@rallly.co.
Post:
Stack Snap Ltd.
The Gallery
14 Upland Road
London SE22 9EE
United Kingdom