Privacy Policy

Synergize SL

Jaume I, 65 (Local Esquerra) - 08470 Sant Celoni (Barcelona) ESPAÑA

E-mail: [email protected]

Privacy Policy

We operate in accordance with the principles set out below:

We undertake to comply with the statutory provisions on data protection and endeavor to always observe the principles of data avoidance and data minimization.

1. The Controller

Who is the controller of your personal data?

Synergize S.L. is the data controller responsible for processing personal data in compliance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD). Vocdoni App is designed and operated in accordance with the principles of lawfulness, fairness, transparency, data minimization, and integrity, integrating privacy by design and by default.

2. For what purpose do we process your personal data?

We process your personal data to operate the Vocdoni App (hereinafter the «APPLICATION»), which provides secure, verifiable, and privacy-preserving voting and participation processes.

  • (a) Administrators: process identification, contact, and authentication data to manage voting processes.
  • (b) Voters: process credentials or access codes provided by their organization. Votes are recorded on the Vocdoni blockchain using cryptographic mechanisms ensuring anonymity.
  • (c) Technical data: device, browser, and IP may be processed for security monitoring and non-identifiable analytics.

All processing follows the principle of data minimization: only the information strictly necessary to operate the service is collected. Sensitive data is stored in encrypted form to enhance confidentiality and protection.

3. Why can we process your personal data?

The processing of your data is legitimated on the basis of:

  • Contractual necessity (Art. 6(1)(b) GDPR)
  • Explicit consent (Art. 6(1)(a) GDPR) for optional features
  • Legitimate interest (Art. 6(1)(f) GDPR) for security and fraud prevention

4. For how long will we keep your personal data?

  • Data of registered users (administrators) and the data uploaded by them (e.g., membership lists) will be kept as long as they maintain their account and contractual relationship with Synergize SL, and thereafter during the applicable legal limitation periods.
  • Voters' data remains within the organization's member list database and is never transferred outside of it. Credentials are used solely to generate an address that gives the right to vote and that is not linked to any personal data. Members' data will be retained for as long as the administrator maintains the member list or until the contractual relationship with Synergize SL comes to an end.
  • Voters are obfuscated and stored on the blockchain in an immutable and permanent way, without any link to personal data.

When data are no longer necessary for these purposes, they will be deleted with appropriate security measures for complete destruction.

5. To whom do we disclose your personal data?

Your personal data may be disclosed to:

  • Public Administrations and authorities when legally required.
  • Service providers that need access to personal data to deliver services to Synergize SL (e.g. payment processors, analytics). These providers act as processors under contracts that comply with Article 28.3 GDPR.

Specifically:

  • Within the APPLICATION, analytics are performed using Plausible, a privacy-first analytics platform that does not use cookies and does not collect or store personally identifiable information. For further details, you can review plausible.io/privacy.
  • The landing page of vocdoni.app uses Google Analytics for web traffic analysis. Data collected through this tool is processed in a dissociated way (without personal identification) and used exclusively for internal statistical purposes. The APPLICATION may collect, store or compile certain non-personal information regarding its use. Google Analytics is governed by Google's General Terms and Conditions google.com/analytics/terms/us.html and Google's Privacy Policy policies.google.com/privacy.

6. What are your rights as a registered user?

Your rights include the following, but are not limited to:

  • Right to request information in accordance with Art. 15 GDPR
  • Right to request rectification under Article 16 GDPR
  • Right of deletion of your personal data, provided that further processing is not necessary for any of the reasons stated under Art. 17 GDPR
  • Right to request the restriction of processing of your personal data for any of the reasons stated under Art. 18 GDPR
  • Right of transmission of your data in a structured, commonly used, and machine-readable format.
  • Right to revoke your consent at any time in accordance with Art. 7 (3) GDPR
  • Right to file a complaint with the Spanish supervisory authority (www.aepd.es) if you consider that the processing does not comply with current legislation.

Contact information to exercise their rights:

Synergize SL. Jaume I, 65 (Local Esquerra) - 08470 Sant Celoni (Barcelona).
E-mail: [email protected]

Consult our privacy-policy / Consult our cookies-policy

7. SECURITY MEASURES

In accordance with the provisions of the current regulations on the protection of personal data, the CONTROLLER is complying with all the provisions of the GDPR and LOPDGDD regulations for processing the personal data for which they are responsible, and is manifestly complying with the principles described in Article 5 of the GDPR, by which they are processed in a lawful, fair and transparent manner in relation to the data subject and are appropriate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.

Synergize SL guarantees that appropriate technical and organizational policies have been implemented to apply the security measures established by GDPR and LOPDGDD in order to protect the rights and freedoms of the users.

  • All communications between the APPLICATION and servers are encrypted (HTTPS/TLS).
  • Sensitive data (e.g. authentication credentials, membership lists) are stored in encrypted form.
  • The design of the APPLICATION minimizes the collection of personal data, focusing on data strictly necessary for functionality.
  • Votes are anonymized by design and recorded in the Vocdoni blockchain without any link to the voter's identity.

This Privacy Policy was released on September 26, 2025 and is effective as of that date. For more information on the guarantees of your privacy, you can contact Synergize SL at [email protected].

8. Data Protection Officer (DPO)

Synergize S.L. has appointed 4Dlegal S.L. as its Data Protection Officer (DPO) in accordance with Articles 37–39 of the GDPR.

You can contact the DPO at [email protected] regarding any questions, concerns, or requests related to personal data processing or the exercise of your data protection rights.

The DPO acts independently and reports to Synergize's senior management.

All communications received by the DPO are treated confidentially and will be responded to within one month, extendable by up to two additional months if necessary due to the complexity or number of requests.

9. Updates to this Policy

This Privacy Policy is reviewed periodically and whenever there are relevant legal, technical, or organizational changes affecting the processing of personal data.

Material updates will be communicated through the APPLICATION or by email to registered users and administrators.

Each version of the Policy will include its revision date and effective date.

The current version was last reviewed on October 16, 2025.