Privacy Policy
1. Who we are
Poll the Room is operated by Mar&Co Management B.V., registered in the Netherlands, Chamber of Commerce (KvK) number 94664404, trading as "Poll the Room" ("we", "us", "our"). We are the data controller for the processing described in this policy unless it says otherwise. You can contact us about privacy at hi@polltheroom.com.
This policy explains what personal data we process, why, on what legal basis, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG).
2. Who this policy covers, and our two roles
Poll the Room is a live-interaction tool. Presenters build decks with live polls, word clouds, quizzes, Q&A and similar questions on top of their slides, and present them. Their audience joins on a phone with a 6-digit code or a QR code. Our role depends on whose data it is.
Presenters and their teams. For the personal data of people who have a Poll the Room account, such as their sign-in details, team membership, billing details and use of the AI assistant, we are the controller. Most of this policy describes that processing.
The audience in a presenter's room. The presenter decides to run a room, which questions to ask, whether to run a quiz with standings, and what happens to the results. For the nicknames and answers collected in that room, the presenter, or the organisation they present for, is the controller. We act as their processor. We handle that data only to run the room and give the results to the presenter, and never for our own purposes. The presenter is responsible for telling their audience how answers are used. The same applies to personal data that a presenter puts in their own slides. If your organisation needs a data processing agreement with us, email hi@polltheroom.com.
Section 4 still describes what the audience sends, so that anyone who joins a room can see exactly what is collected.
3. What we collect from presenters
Your account.
- Your name and email address, and whether your email address has been confirmed.
- Your password, which we store only as a one-way hash, never in readable form. If you sign in with Google or Microsoft instead, see section 5.
- A profile picture, if you upload one or your sign-in provider supplies one.
- If you turn on two-factor sign-in, the secret for your authenticator app and your backup codes.
Your sign-ins. For each device you sign in on, we keep a session record with the IP address and the browser description (user agent) it was created from. You can see these records and end any of them in your account settings.
Your team. The team name and logo, who the members are and their roles, and invitations, which hold the email address of the person invited. If you ask us to fetch a logo from a website, our server requests the icon from that website directly.
Your decks and sessions.
- The PDF or PowerPoint files you upload, the page images we render from them, and everything you add in the editor, such as text, questions, images and uploaded fonts.
- If you import from Google Slides by pasting a public link, our server downloads the public PDF version of that presentation from Google. This does not use your Google account.
- Deck titles, sharing with your team, starred decks and the bin.
- The sessions you run from a deck, the names you give them, and their results (see section 4).
The AI assistant. If you use it, what you type and what it returns. Section 6 explains this in full.
API keys. If your team creates API keys, we keep a name, a short visible prefix, the permissions, and when each key was last used. We store only a hash of the key itself, so we cannot show it again.
Billing, if your team buys a paid plan.
- The name on the invoice, the billing email address, street address, postal code, city and country, whether you buy as a business, and your VAT number.
- If you give a VAT number, we check it with the European Commission's VIES service and record when it was confirmed.
- The references Mollie gives us for your customer record, payment authorisation and subscription, and the payments made. To help you recognise your payment method, Mollie may return a masked detail such as the last digits of a card or account number. Full card and bank details are handled by Mollie and never stored by us.
- A reference to each invoice, which is created in our accounting system (Odoo) from your billing details.
Reports you send us. Presenter screens have a report button for telling us something is wrong. A report contains the note you write, a screenshot of the whole page as it looks on your screen, which can include deck content and audience results that are on that page, and what the screen knew about itself at that moment, such as the open deck, step, selection or room. It also contains technical details about your browser and device (such as browser type, screen size, language and time zone), recent error messages and failed requests, and the labels of the buttons and fields you recently used. It never contains what you typed into those fields. We mask anything that looks like a key or password. A report is stored with your email address, user ID and team ID. People in your team who can read reports, and the people at Poll the Room who fix problems, can read it.
Emails. We send the emails the service needs, such as email confirmation, password reset, confirmation of a changed email address, and team invitations.
4. What we collect from audience members
You do not create an account to join a room, and we do not ask for your name, email address or phone number.
When you join a room, we store the following for that room.
- A nickname. One is chosen for you automatically. You can change it, up to 24 characters. The presenter can see it, and it can appear on the big screen, for example in a quiz leaderboard or a draw from the names in the room. We recommend a nickname rather than your full name.
- A random identifier that is saved in your browser, so you keep the same nickname and answers if the page reloads.
- Your answers to the questions the presenter asks. Depending on the question these can be choices, numbers, ratings, words, free-text answers, questions you submit in a Q&A and the questions you upvote, a country you type, or a pin you place on a map. For a quiz we also keep your score and how quickly you answered.
- When you joined, when you were last active, and when you answered.
Emoji reactions are shown live on the screen and are not stored. We do not store your IP address with your nickname or answers, and we do not read your phone's location. A map pin is only where you choose to put it.
The presenter sees the results and can export them, for example as a PowerPoint or PDF. After a room has ended, its results can be shown on a results page to anyone who has the room code. For a quiz, those results include the standings with nicknames.
A presenter can also start a room without signing in. The person who started it still decides what is asked, as described in section 2.
5. Signing in with Google or Microsoft
Presenters can create an account and sign in with Google or Microsoft instead of a password.
What we receive. From Google we request only your basic profile, using the openid, email and profile permissions. That gives us your name, your email address and your profile picture. From Microsoft we receive the same three things. The sign-in tokens that Google or Microsoft issue are stored with your account record so the link between the two accounts works.
How we use it. We use this information only to create your Poll the Room account, to sign you in, and to show your name and picture inside the app. We do not use the tokens to read your email, contacts, calendar, files or any other data in your Google or Microsoft account.
What we never do with it. We do not sell this information. We do not use it for advertising, and we do not use it to build profiles or to train AI models. We do not share it with anyone, except the service providers in section 8 that host and run Poll the Room for us, or where the law requires it. Nobody at Poll the Room reads it unless you ask us to, or we need to for security or to meet a legal obligation.
Poll the Room's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Removing access. You can remove Poll the Room's access in your Google account at myaccount.google.com/permissions, or in your Microsoft account settings. When you delete your Poll the Room account, the stored link and its tokens are deleted with it.
Google and Microsoft process your sign-in under their own privacy policies, and they know that you signed in to Poll the Room.
6. The AI assistant
Signed-in presenters can ask an AI assistant to create or change questions on a slide. The audience never uses it.
What the assistant reads.
- The slide you are on, as a picture, when your request needs it. A pure styling change to a question that is already on the slide sends no picture.
- Your words, and what is already on the slide as data, such as the questions, text boxes and shapes.
- Images you attach to a message, and the column headers and first three rows of a spreadsheet you attach. The spreadsheet file itself never leaves your browser.
Where it goes. To Mistral AI, a French company, which runs the model in the European Union.
What we keep. Your messages and the questions that came back, as text and structured data, for as long as your account exists, along with any thumbs up or down you give. They are deleted with your account. We read them to make the assistant better. We never keep the picture of a slide, an attached image, or a spreadsheet's rows. We also keep a usage record for each request, with the model used, the amount of text processed and the cost, but not the content. To avoid paying twice for the same request, recent answers are held briefly in our server's memory and are gone when it restarts.
Your team's choice. A team owner can set the assistant to on, text only, or off for the whole team. Text only means no picture of a slide is ever sent, whatever anyone asks.
The assistant suggests content. It does not make decisions about you, and we do not use it for automated decisions that have legal or similarly significant effects.
7. Why we process your data, and our legal basis
To provide the service you signed up for. This covers creating and running your account and team, storing your decks, running rooms and showing results, the AI assistant when you use it, sending the emails the service needs, and taking payment for a paid plan. Legal basis is performance of our contract with you (GDPR Article 6(1)(b)).
To keep the service secure. This covers keeping session records with IP addresses, limiting repeated sign-in attempts, and investigating misuse. Legal basis is our legitimate interest in protecting the service and its users (Article 6(1)(f)).
To fix and improve the service. This covers reading the reports you send, reading AI assistant messages to improve its answers, and keeping AI usage records to control costs. Legal basis is our legitimate interest in a working, affordable product (Article 6(1)(f)). We limit this by never keeping slide pictures or attachments, and by masking keys in reports.
To meet legal obligations. This covers keeping invoices and the records behind them for as long as tax law requires, and answering lawful requests from authorities (Article 6(1)(c)).
Audience data. When we process nicknames and answers in a room as a processor, we do so on the presenter's instructions (Article 28). The presenter, as controller, needs their own legal basis for asking.
We do not sell personal data, and we do not use it for advertising.
8. Service providers
We use the following service providers to run Poll the Room. They process personal data only on our instructions.
| Provider | What they do for us | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application, the database, uploaded files and backups | Germany (EU) |
| Mistral AI | Running the AI assistant's model | France (EU) |
| Mollie B.V. | Payments for paid plans | Netherlands (EU) |
| Resend | Sending the service's emails, such as password resets and team invitations | United States |
Some other organisations receive limited data as part of how the service works, but under their own responsibility.
- Google and Microsoft, when you choose to sign in with them (section 5).
- The European Commission's VIES service, which receives a VAT number you give us so we can check it.
- The OpenStreetMap Foundation's place search (Nominatim), which receives the place name a presenter types when setting up a map question. It is sent from our server, not from your device.
We will update this list before we start using a new service provider for personal data.
9. Content your browser loads from other services
Some parts of Poll the Room are loaded by your browser directly from another service. Like any web request, this shares your IP address and basic browser information with that service. We do not send them your name, your account details or your answers.
- Google Fonts (Google). The typefaces used in decks are loaded from Google on every page of the app, including the audience's join and answer screens.
- OpenStreetMap map tiles (OpenStreetMap Foundation, United Kingdom). Loaded when a slide has a map question.
- Country flag images from media.api-sports.io. Loaded when a question shows country flags.
- jsDelivr. Loads the interactive API reference on our developer pages.
10. International transfers
Poll the Room is hosted in Germany, and our AI provider and payment provider are in the European Union, so no international transfer arises there.
Our email provider, Resend, is in the United States. We rely on the EU-US Data Privacy Framework as the safeguard for that transfer, with the European Commission's Standard Contractual Clauses as a fallback. The services in section 9 may be outside the EU. Google is certified under the EU-US Data Privacy Framework, and the United Kingdom, where the OpenStreetMap Foundation is based, has an EU adequacy decision. You can ask for a copy of the relevant safeguards at hi@polltheroom.com.
11. How long we keep your data
- Your account is kept for as long as it exists. When you delete it in your account settings, we delete your account, your password or linked Google or Microsoft sign-in, your sessions, your two-factor settings, your team memberships and your AI assistant messages.
- Decks and results that belong to a team are part of that team's workspace. Decks you shared with your team stay with the team when you delete your account. Email us if you want other decks or results removed.
- Sign-in sessions expire 30 days after you last used them.
- Deleted decks go to the bin first. They are deleted for good, with their files, from 30 days after you deleted them.
- Rooms close automatically after 24 hours without activity. Their results, including audience nicknames and answers, are kept so the presenter can read and export them later.
- Team invitations expire after 7 days.
- AI assistant messages are kept for as long as your account exists. Usage records without content are kept for cost accounting and are no longer linked to you after you delete your account.
- Reports you send are kept until the problem they describe has been dealt with.
- Invoices and billing records are kept for seven years, as Dutch tax law requires.
- Backups of the database are made every night and kept for 14 days, so deleted data can remain in a backup for up to 14 days.
We may keep limited data for longer where the law requires it.
12. How we protect your data
We use appropriate technical and organisational measures. These include the following.
- Hosting in the European Union, and encrypted connections (HTTPS) between your device and our servers.
- Passwords stored only as a one-way hash, with a minimum length of 10 characters.
- Optional two-factor sign-in with an authenticator app.
- Limits on repeated sign-in, sign-up and password reset attempts.
- API keys stored only as a hash.
- A list of your active sessions, so you can sign out a device you no longer use.
- Audience identities that are random and not linked to any account.
No system is perfectly secure, but we work to protect your data and to meet our breach notification duties under the GDPR.
13. Cookies and local storage
Poll the Room sets no analytics, advertising or tracking cookies.
Presenters. When you sign in, we set a session cookie that keeps you signed in. Short-lived cookies are also used while you complete two-factor sign-in and while you sign in with Google or Microsoft, to protect the sign-in against forgery.
Local storage. The app also saves a few things in your browser's own storage.
- On an audience member's phone, the random identifier and nickname for each room joined, so a reload keeps the same identity.
- On a presenter's device, the host key for rooms started there, so that device can control the room, and a remembered editor style.
- Decks made before accounts existed may still sit in an older presenter's browser. The app reads them once to move them into the account.
All of these are needed for the service you asked for, so they do not require consent. You can clear them at any time in your browser settings, which signs you out and ends your identity in a room.
14. Your rights
Under the GDPR you have the following rights.
- Access the personal data we hold about you and receive a copy.
- Have inaccurate data corrected.
- Have your data erased.
- Restrict our processing.
- Object to processing based on our legitimate interest, such as security logging, reports and improving the assistant.
- Data portability, which means receiving your data in a structured, machine-readable format.
Presenters can change their name, picture, email address and password, end sessions, and delete their account in the account settings. For anything else, email hi@polltheroom.com and we will respond within the time the GDPR allows.
If you were in the audience, the presenter who ran the room is the controller of your answers, so it is best to ask them first. We will help them respond. Because we hold no contact details for audience members, we can only find your answers if you tell us the room and your nickname.
You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the supervisory authority where you live.
15. Children
Poll the Room is not directed at children under 16. You must be 16 or older to create a presenter account, which is the age of consent for online services under the UAVG. If we learn that we hold account data of a child under 16, we will delete it.
A presenter may run a room for an audience that includes people under 16, for example a teacher with a class. We do not ask audience members for their age or for identifying details, and a nickname is chosen for them automatically. In that situation the presenter, or their school or organisation, is the controller. They are responsible for having a lawful basis, for informing pupils and parents where required, and for not asking children to give identifying information in their answers.
If you believe a child has given us personal data that we should not have, contact hi@polltheroom.com and we will act promptly.
16. Changes to this policy
We show the effective date at the top of this policy. If we make a material change to how we use personal data, we will tell presenters before it takes effect, for example by email or with a notice in the app.
17. Contact and complaints
For any privacy question or request, email hi@polltheroom.com. Our postal details are on record with the Dutch Chamber of Commerce under KvK number 94664404. If you are not satisfied with our response, you can contact the Autoriteit Persoonsgegevens.