Legal
Data Processing Addendum
Effective date: 7 October 2026 (Version 1.0) · Applies to the Service at donordesk.online
This Addendum (“DPA”) forms part of the Terms of Service between DonorDesk.Online (“DonorDesk”, the processor) and the Customer (the controller) and applies when DonorDesk processes personal data in the Customer's workspace and data protection law (such as the GDPR or UK GDPR) applies. It applies automatically; a countersigned copy is available on request from legal@donordesk.online.
1. Scope and roles
The Customer is the controller of personal data it puts in the Service (“Customer Personal Data”); DonorDesk is its processor. DonorDesk is an independent controller of account, billing and usage data, as described in the Privacy Policy. The Customer is responsible for having a legal basis, giving notices and obtaining consents for its data, and for the lawfulness of its instructions.
2. Instructions
DonorDesk processes Customer Personal Data only on the Customer's documented instructions: the Terms, this DPA, and the Customer's use and configuration of the Service. DonorDesk will tell the Customer if it believes an instruction infringes data protection law, but is not obliged to check the lawfulness of instructions. DonorDesk may process data where required by law, informing the Customer where permitted.
3. Confidentiality
DonorDesk ensures that personnel authorised to process Customer Personal Data are bound by confidentiality.
4. Security
DonorDesk applies appropriate technical and organisational measures, including: encryption in transit; tenant isolation enforced in the database (row-level security); role-based access with least privilege; an immutable audit log; access controls and monitoring; and backups. See Security & trust. The Customer is responsible for its own user access, credentials, roles and configuration, and for assessing that these measures suit its data. DonorDesk may update measures if the overall level of protection is not reduced.
5. Sub-processors
The Customer gives general authorisation to the sub-processors listed on /subprocessors. DonorDesk binds them to data protection obligations no less protective than this DPA and remains responsible for their performance. Changes and objections are handled as described on that page.
6. International transfers
Customer Personal Data may be processed outside the Customer's country. Where required, the parties rely on an adequacy decision or the Standard Contractual Clauses (Module 2, controller to processor, and Module 3 where applicable), and the UK Addendum for UK transfers, which are incorporated by reference and completed with the details in section 12 and the sub-processor list. The Customer, not DonorDesk, is responsible for any additional donor or local-law restrictions on data location.
6A. Customer-provided storage (Google Drive)
Where the Customer connects its own Google Drive (or another storage account), that account is the Customer's own service and the Customer is responsible for its security, sharing settings, retention, and its agreement with the provider; the provider is not a DonorDesk sub-processor for files stored there. DonorDesk accesses it only within the permissions the Customer grants (limited file access, file and folder names, and read-only spreadsheet access, as described in our Support Center) and may keep references, extracted text, and derived records in its own systems as described in section 12. If the Customer revokes access or deletes files in its account, related features may stop working and DonorDesk is not responsible for data the Customer holds in that account.
7. Individuals' rights
DonorDesk will, taking into account the nature of processing, give the Customer reasonable assistance through the Service's features (export, edit, delete) to respond to individuals' requests. Requests received directly by DonorDesk will be forwarded to the Customer. Assistance beyond the Service's standard features may be charged at reasonable cost.
8. Personal data breach
DonorDesk will notify the Customer without undue delay (and aim for within 72 hours) after becoming aware of a personal data breach affecting Customer Personal Data, with the information then available, and take reasonable steps to contain it. Notification is not an admission of fault. The Customer is responsible for notifying regulators, donors and individuals.
9. Return and deletion
On termination the Customer may export its data for the transition period in the Terms. After that, DonorDesk deletes Customer Personal Data, except where law requires retention; copies in backups are deleted in the normal backup cycle.
10. Audits
DonorDesk will provide information reasonably needed to show compliance with this DPA. Where that is not sufficient, the Customer may, on 30 days' notice, no more than once a year, and under confidentiality, audit DonorDesk's relevant controls at the Customer's cost, in a way that does not disrupt DonorDesk or expose other customers' data. Regulator audits are permitted as required by law.
11. Liability and order of precedence
Each party's liability under this DPA is subject to the limits and exclusions in the Terms, to the extent the law allows. If this DPA conflicts with the Terms on data protection, this DPA prevails; if it conflicts with the Standard Contractual Clauses, the Clauses prevail.
12. Processing details
- Subject matter and purpose: providing the DonorDesk reporting, evidence-management and AI-assisted drafting service.
- Duration: the term of the Customer's subscription plus the transition period.
- Data subjects: the Customer's staff and partners, beneficiaries, and other individuals named in its records.
- Data types: contact details, activity and evidence records, report content, and any special-category data the Customer chooses to upload.
- Hosting: Contabo data centre. Source files may instead sit in the Customer's own Google Drive (section 6A).
- Contact for data protection: privacy@donordesk.online.