SoftwareTriad · Version 1.0.2

MyUniVote Privacy Policy

This policy explains how information is collected, processed, stored, protected, shared, and retained across the MyUniVote election platform.

Effective: August 8, 2026

Last updated: August 8, 2026

Section 1

Introduction

Welcome to MyUniVote. MyUniVote (“MyUniVote”, “we”, “our”, or “us”) is a secure digital election platform developed and operated by SOFTWARETRIAD IT SOLUTIONS LTD for educational institutions.

The platform enables universities and other educational institutions to administer transparent, secure, and anonymous electronic elections while protecting the privacy of students, election officials, and institutional administrators.

We design and operate MyUniVote according to the principles of transparency, privacy by design, data minimisation, confidentiality, integrity, and accountability. By accessing or using MyUniVote, you acknowledge that you have read and understood this Privacy Policy.

Section 2

Definitions

Account
A registered MyUniVote user account.
Ballot
A digital voting record submitted during an election.
Data Controller
The educational institution that determines the purposes and means of processing personal data for elections conducted through MyUniVote.
Data Processor
SoftwareTriad, which processes personal data on behalf of the educational institution through the MyUniVote platform.
Educational Institution
A university, college, or other institution using MyUniVote to administer elections.
Election Officer
A student authorised by an educational institution to administer or supervise election activities through MyUniVote.
Personal Data
Information relating to an identified or identifiable individual.
Platform
The MyUniVote mobile applications, administrative dashboards, websites, backend services, APIs, and supporting infrastructure.
Student
An individual registered by an educational institution to participate in elections conducted through MyUniVote.
Super Administrator
Authorised SoftwareTriad personnel responsible for maintaining and supporting the MyUniVote platform.

Section 3

Scope

This Privacy Policy applies to:

  • The MyUniVote mobile applications
  • The MyUniVote administrative dashboard
  • The MyUniVote website
  • Backend services supporting the platform
  • Communication services provided through MyUniVote

It applies to the following users and organisations:

  • Students
  • Election Officers
  • Institutional Administrators
  • Educational Institutions
  • SoftwareTriad Super Administrators, where applicable

Section 4

Roles and Responsibilities

MyUniVote operates using a controller–processor model.

Educational Institution (Data Controller)

The educational institution using MyUniVote is the Data Controller. It determines why personal data is processed and is responsible for:

  • Appointing authorised Election Officers and institutional administrators
  • Determining who is eligible to participate in elections
  • Providing or authorising the import of student information required for election administration
  • Defining offices, positions, and election structure
  • Establishing election rules, eligibility criteria, and institutional policies
  • Ensuring it has legal authority to provide personal data to MyUniVote

Election Officers

Election Officers are authorised representatives of the institution. Depending on their permissions, they may create and configure elections, define positions and categories, manage candidates and election content, monitor participation and turnout, and perform other permitted election functions.

They act under the institution’s authority and do not independently determine the purposes or means of processing personal data.

SoftwareTriad (Data Processor)

SoftwareTriad develops, hosts, maintains, secures, and supports MyUniVote solely on behalf of educational institutions. SoftwareTriad does not conduct elections, determine election outcomes, or decide why institutions process personal data.

Section 5

Privacy by Design Principles

  • Purpose Limitation: Information is processed only to administer elections, provide platform services, maintain security, and fulfil institutional contracts.
  • Data Minimisation: Only information reasonably required to operate the platform and conduct elections is processed.
  • Ballot Secrecy: After a valid vote is submitted, ballot selections are stored separately from voter identity so institutions, officers, administrators, and SoftwareTriad cannot determine how an individual voted.
  • Security by Default: Technical and organisational safeguards protect information from unauthorised access, disclosure, alteration, or loss.
  • Role-Based Access: Users receive only the access required for their authorised responsibilities.
  • Transparency: This policy explains what is processed, why, how it is protected, and who is responsible.

Section 6

Information We Collect

Student Information

Educational institutions may provide:

  • Student ID, first name, and last name
  • Email address and telephone number
  • Gender and nationality
  • Faculty or department and programme of study
  • Current year of study and institution identifier
  • Additional academic information required for election eligibility

Students cannot create independent accounts outside information supplied or authorised by their educational institution.

Election Officer Information

Election Officers are students with elevated election management permissions. Their student information is processed together with role assignments required for administration.

Institutional Administrator Information

MyUniVote processes administrator names and email addresses solely to administer the institution’s elections.

Educational Institution Information

  • Institution name, full legal name, short name, and branch or campus name
  • Country, region or state, city, and website address
  • Official registration number, institutional logo, and official contact email
  • Approved institutional email domains and primary administrator details

Election Information

  • Election, category, and school identifiers
  • Ballot number, participation status, voter type, and participation timestamp
  • Vote selections and candidate vote totals
  • Registered and accredited voter counts
  • Turnout percentages, faculty turnout, category totals, and result summaries

Election statistics are used only to administer elections and publish authorised results.

Technical Information

  • Mobile operating system (Android or iOS)
  • Firebase Cloud Messaging token
  • Application-generated device identifier
  • Notification preferences
  • IP address and related connection information used for security, abuse prevention, routing, rate limiting, performance, and reliability

MyUniVote does not intentionally collect:

  • GPS or precise location
  • Advertising identifiers
  • Camera or microphone recordings
  • Contact lists
  • Broad device storage contents

Permissions and Images

On supported devices, election administrators may use the photo picker only to select candidate photographs or election cover images. General storage access is not requested where platform-provided photo selection is available.

Authentication Information

Students authenticate with Google Sign-In. The Google account does not have to be institution-managed, but its email must match an address registered or authorised by the institution. Institutional administrators use their registered email and password. Passwords are securely hashed and never stored in plain text.

Successful student and Election Officer login events are kept for security and auditing. MyUniVote does not intentionally retain failed login attempts, failed authentication records, application-level server access logs, or application-level API request logs. Infrastructure providers may process connection information under their own privacy policies.

Section 7

How We Collect Information

Information is obtained through:

  • Information supplied by educational institutions
  • Authentication through Google Sign-In
  • Administrator registration by authorised institutional personnel
  • Election participation by authorised users
  • Images uploaded by authorised election administrators
  • Technical information required for notifications and platform operation

MyUniVote does not collect personal information through advertising technologies or behavioural tracking.

Section 8

How We Use Information

Student Information

  • Verify election eligibility and authenticate users through Google Sign-In
  • Show each student the appropriate elections and apply institutional eligibility rules
  • Prevent duplicate voting and record voter participation
  • Deliver election notifications and provide support
  • Maintain platform security and integrity

Student information is not used for advertising, behavioural profiling, or commercial marketing.

Election Officer Information

  • Verify authorised election administrators and assign permissions
  • Administer and monitor elections on behalf of institutions
  • Manage candidates, election content, and published results
  • Maintain election administration audit records

Institutional Administrator Information

  • Authenticate administrators and manage institutional settings and accounts
  • Communicate service information and provide customer support
  • Maintain platform security

Educational Institution Information

  • Configure and identify institutions within MyUniVote
  • Support institutional branding
  • Verify authorised administrators
  • Manage subscriptions and platform services

Election Information

  • Generate ballots and record anonymous votes
  • Calculate results, turnout, category statistics, and faculty participation reports
  • Determine election outcomes and support authorised recounts
  • Preserve election integrity

Election information is never used for advertising or unrelated commercial purposes.

Technical Information

  • Deliver push notifications and maintain secure sessions
  • Identify registered devices for notifications
  • Diagnose issues and improve reliability
  • Protect against misuse and maintain service availability

Section 9

Ballot Privacy and Election Integrity

Once a valid ballot is submitted, individual choices cannot be associated with the voter’s identity. Educational institutions, Election Officers, institutional administrators, and authorised SoftwareTriad personnel cannot determine how an individual voted.

Voter identity is separated from ballot selections after successful submission. Anonymous ballot records may contain election identifiers, candidate selections, and audit information, but they are maintained separately from identifiable participation records.

Published results contain aggregated totals, turnout information, and statistical reports. MyUniVote records whether an eligible voter participated to prevent duplicate voting, but participation records remain separate from anonymous ballot data.

Section 10

Legal Basis for Processing

Where applicable, information is processed because:

  • Processing is necessary for a public-interest task or the exercise of official authority by an educational institution
  • Processing is necessary to perform contractual obligations between SoftwareTriad and the institution
  • Processing is necessary to comply with legal obligations
  • Processing supports legitimate interests in securely operating, maintaining, and improving MyUniVote, where those interests do not override individual rights and freedoms

SoftwareTriad processes information according to the documented instructions of the educational institution acting as Data Controller.

Section 11

Disclosure and Sharing of Information

MyUniVote does not sell, rent, or trade personal information.

Educational Institutions, Officers, and Administrators

Relevant information is available to the institution that owns and administers the election. Election Officers and institutional administrators receive only the access necessary for authorised responsibilities under role-based, least-privilege controls.

SoftwareTriad Personnel

Authorised personnel may access information when reasonably necessary for technical support, issue investigation, security, system maintenance, or legal compliance. They cannot determine how an individual voted.

Service Providers

Providers process information only as required to deliver their services and must safeguard it. Current providers include:

  • Google Firebase for object storage and push notifications
  • Google Authentication services
  • MongoDB Atlas for database hosting, where applicable
  • Upstash Redis
  • Cloudflare
  • Render
  • Namecheap hosting services
  • SendGrid
  • Sentry

SoftwareTriad may change or replace providers where appropriate.

Legal Requirements and Business Transfers

Information may be disclosed when required by law, regulation, court order, or another lawful request. Only information reasonably necessary to comply will be disclosed. If SoftwareTriad undergoes a merger, acquisition, restructuring, or asset sale, information may transfer subject to legal requirements and safeguards.

Section 12

Cookies and Similar Technologies

Web services may use cookies to:

  • Authenticate authorised users
  • Maintain active sessions
  • Remember preferences where applicable
  • Enhance security
  • Improve web-service performance and reliability

MyUniVote does not use cookies for behavioural advertising or cross-site tracking. Refusing essential cookies may affect platform functionality.

Section 13

International Data Transfers

MyUniVote uses infrastructure located in the United States. Information may therefore be transferred to, stored, or processed outside the user’s or institution’s country.

SoftwareTriad takes reasonable measures to ensure providers use safeguards consistent with applicable law and contracts. Institutions acknowledge that cloud services may involve international transfers.

Section 14

Data Security

Security measures include, where applicable:

  • HTTPS/TLS encryption in transit
  • Industry-accepted password hashing
  • Role-based access controls
  • Multi-factor authentication for privileged accounts
  • JSON Web Token authentication
  • Encrypted database storage and backups
  • Audit logging
  • Rate limiting and abuse prevention
  • Cloud-provider infrastructure security
  • Authorised error reporting and platform stability monitoring

No electronic transmission or storage method is completely secure, so absolute security cannot be guaranteed.

Section 15

Data Retention

Information is kept only as long as needed to provide MyUniVote and fulfil institutional contracts. Generally:

  • Personal and election information is retained during the institution's active subscription
  • Successful authentication records are retained for security and auditing during that period
  • Technical information is retained only where operationally required

When an institution’s subscription ends:

  1. Election data is prepared for export.
  2. The export is made available to the institution.
  3. Hosted institutional data is removed within a reasonable period unless law or contract requires retention.

Limited non-identifiable or legally required records may remain to comply with law, resolve disputes, enforce contracts, preserve audit integrity, or protect anonymous ballots and election integrity.

Section 16

Your Privacy Rights

Rights depend on applicable law and the user’s role. Students and Election Officers can view their profile and delete their account through the application.

Educational institutions, as Data Controllers, handle requests involving access, correction, deletion, restriction, objections, and other applicable rights. SoftwareTriad may refer a direct request to the relevant institution for handling.

Section 17

Account Deletion

Students and Election Officers can delete their account through the MyUniVote application. Users without app access can securely request deletion through the public account-deletion page.

When an account is deleted:

  • Profile information is removed from the active platform
  • Authentication credentials and identifiers are removed
  • Registered notification tokens are removed
  • Account access is revoked
  • Other associated personal information is deleted or anonymised, subject to lawful or permitted retention

Account deletion does not remove anonymous ballots or election audit information that must remain to preserve completed-election integrity or satisfy legal or contractual obligations.

Section 18

Children's Privacy

MyUniVote is intended for educational institutions, some of which may enrol students below the age of majority. Institutions are responsible for having legal authority to provide student data and authorise platform use under applicable law.

SoftwareTriad does not knowingly collect information directly from children outside services provided to authorised educational institutions.

Section 19

Changes to this Privacy Policy

SoftwareTriad may update this policy to reflect:

  • Changes in applicable law
  • Changes to MyUniVote
  • Changes to data-processing practices
  • Improvements to privacy and security practices

Where changes are material, reasonable steps will be taken to notify affected institutions or users before the updated policy takes effect. The latest version will remain available on the MyUniVote website or application.

Section 20

Contact Information

Questions, requests, or concerns may be directed to:

SoftwareTriad

Email: support@myunivote.com

Website: www.myunivote.com

For information controlled by an educational institution, users may also contact that institution directly as the Data Controller.

Document title: MyUniVote Privacy Policy · Version 1.0.2 · Effective August 8, 2026 · Last updated August 8, 2026 · © SoftwareTriad. All rights reserved.