Legal

Privacy Policy

Effective date: 14 August 2026 (Version 1.0) · Applies to the Service at donordesk.online

1. Who we are

DonorDesk.Online (“DonorDesk”, “we”, “us”, or “our”) provides a cloud-based platform that helps non-governmental organizations, humanitarian programmes, and their teams turn field evidence, activity records, and logframe data into audit-ready donor reports. We operate the website and service at https://donordesk.online (the “Service”).

This Privacy Policy explains what personal information we process, why we process it, how long we keep it, who we share it with, and the rights you have. We designed the Service to operate globally and to respect applicable data protection laws wherever our users are located.

For any privacy question or request, contact our privacy team at legal@donordesk.online.

2. Scope of this policy

This policy applies to personal information processed by DonorDesk when you visit our website, create an account, or use the Service, including personal information our customers (organizations) upload or enter on behalf of their beneficiaries, staff, and partners.

The Service is a multi-tenant platform. Organizations that subscribe to the Service (“Customers”) control the workspaces, projects, templates, logframes, evidence files, activity records, and reports they create. In most cases, the Customer is the controller (or equivalent role under applicable law) of the personal information inside its workspace, and DonorDesk acts as a processor (or equivalent role) on the Customer's instructions. DonorDesk is the controller of the information we collect about the Customer's own users (such as account and usage data) as described below.

This policy does not create rights enforceable by third parties. If you are a beneficiary, donor, or other individual whose information appears inside an organization's workspace, you should first contact that organization about your data.

3. Information we collect

We collect the following categories of personal information:

  • Account and identity data. Name, email address, job title, organization name, language preference, and authentication credentials (including password hashes and, if enabled, third-party sign-in identifiers such as Google or organization SSO accounts).
  • Workspace and content data. Information entered or uploaded into the Service by or on behalf of a Customer, including project details, donor templates, logframes, indicators, activity updates, evidence files (documents, spreadsheets, images, and other records), comments, report drafts, compliance records, and export artifacts. This content may contain personal information about staff, partners, beneficiaries, and other individuals, including — where a Customer chooses to include it — special-category data such as health, racial or ethnic origin, or other sensitive information collected for humanitarian purposes.
  • AI-assisted drafting data. The prompts, source references, and content generated when you use AI-assisted drafting features. We record the model used, the prompt version, and source citations for every generated output so that outputs remain traceable and reviewable.
  • Usage and technical data. IP address, device and browser type, operating system, pages visited, features used, timestamps, request identifiers, and error logs, collected automatically when you use the Service.
  • Communication data. If you contact support or our teams, the content of your communications and any information you choose to provide.

We do not require you to provide special-category or sensitive data. Where Customers choose to process such data in the Service, they are responsible for ensuring they have an appropriate legal basis and any required consents, and for configuring the Service in a manner consistent with the sensitivity of the data.

4. How we use information

We use the information we collect for the following purposes:

  • Providing and operating the Service. Creating and managing accounts and workspaces; enabling projects, evidence management, reporting, compliance, export, and collaboration features; and delivering the functionality you request.
  • AI-assisted drafting. Generating source-linked draft narrative from content and evidence you provide, so that drafts remain reviewable, editable, and tied to verified sources.
  • Security and integrity. Detecting, preventing, and responding to abuse, unauthorized access, fraud, and security incidents; maintaining the immutable audit trail that records who did what in a workspace; and enforcing multi-tenant isolation so one organization can never access another's data.
  • Support and communication. Responding to enquiries, providing product updates relevant to your use of the Service, and sending operational notices (for example, about availability or changes to the Service).
  • Improvement and analytics. Understanding how the Service is used, measuring performance, and improving features and reliability.
  • Legal compliance. Complying with legal obligations, resolving disputes, and enforcing our Terms of Service.

We do not sell personal information and we do not use workspace content to advertise to third parties.

6. AI-assisted features

DonorDesk includes AI-assisted drafting that generates source-linked narrative based on content in your workspace. Important principles:

  • Content you provide may be transmitted to a third-party AI service provider solely to generate the draft you request. We select and configure AI providers with the sensitivity of humanitarian data in mind and require them to process data only for the purpose of providing the generation service.
  • Every AI output is recorded with the model used, prompt version, and source references, so that generated content is traceable, editable, and subject to human review and approval before use.
  • AI-assisted features are assistive only. They do not make automated decisions that produce legal effects on individuals, and no report is final until reviewed and approved by your team.
  • If your organization or your donor requires that data never leave a specific jurisdiction or that AI features be disabled, contact us to discuss configuration options.

7. Sharing and disclosure

We share personal information only in the following circumstances:

  • Service providers. With third parties who help us operate the Service, such as infrastructure and hosting providers, storage providers (which may include per-tenant file storage), AI service providers, error monitoring, and email delivery providers. These providers are bound by confidentiality and data protection obligations and may process data only on our documented instructions.
  • Within your workspace. With the users of your organization's workspace, in accordance with the role-based permissions your organization configures.
  • Legal requirements. Where we are required to do so by law, regulation, legal process, or a government request, or where disclosure is necessary to protect the rights, property, or safety of DonorDesk, our users, or others.
  • Business transactions. In connection with a merger, acquisition, reorganization, or sale of assets, in which case we will require the receiving party to honor the commitments in this policy.
  • With consent. Where you have given us consent to share your information for a specific purpose.

We do not sell, rent, or trade personal information, and we do not share workspace content with advertisers. A current list of our service providers and sub-processors is available on request from legal@donordesk.online.

8. International data transfers

DonorDesk serves organizations globally. Data you provide may be processed on infrastructure located outside your country, including by service providers in other jurisdictions. Where personal information is transferred across borders, we rely on appropriate safeguards, including recognized adequacy decisions, standard contractual clauses (SCCs), or equivalent transfer mechanisms recognized under applicable law.

If you would like to know more about the safeguards we apply to international transfers, or to obtain a copy where available, contact legal@donordesk.online.

9. Data retention

We retain personal information only for as long as necessary to fulfill the purposes described in this policy, to provide the Service, to comply with legal obligations, and to resolve disputes. In particular:

  • Account data is retained while your account is active and deleted or anonymized within a reasonable period after account closure, unless we are legally required to retain it.
  • Workspace content is retained for as long as the Customer maintains it and is deleted upon Customer instruction or after the Customer's agreement terminates, subject to applicable legal requirements and any backup recovery obligations.
  • Audit trail data is retained as long as required for security, compliance, and dispute-resolution purposes, consistent with the immutable and verifiable nature of the audit chain.
  • Technical logs are retained for a limited period (typically no longer than 12 months) unless a security investigation or legal obligation requires longer retention.

When retention is no longer required, we delete or irreversibly anonymize the information in line with applicable law and our backup procedures.

10. Data security

We apply technical and organizational measures appropriate to the sensitivity of the data we process, including:

  • Encryption of data in transit (TLS) and at rest where supported by our storage infrastructure.
  • Multi-tenant architecture with tenant-scoped access control and row-level security, so that one organization's data is never visible to another.
  • Role-based access controls and least-privilege permissions for both our users and our staff.
  • An immutable, chained audit log that records every mutation with checksums, supporting verification and accountability.
  • Access controls, security monitoring, and incident-response procedures designed to detect and respond to security events.

No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security, and you are responsible for safeguarding your own credentials and for the configuration of your workspace.

11. Your rights

Depending on where you live, you may have rights over the personal information we hold about you, including the right to:

  • Access a copy of your personal information.
  • Correct inaccurate or incomplete information.
  • Request erasure of your personal information.
  • Restrict or object to certain processing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email legal@donordesk.online. We will respond within the time period required by applicable law (typically 30 days, with extensions permitted by law) and may ask you to verify your identity or your authority to make the request.

If you request access to or deletion of information inside an organization's workspace, we will verify that the request is authorized by the Customer that controls that workspace before acting. We will not delete a Customer's workspace content on the request of an individual unless we are legally required to do so or the Customer instructs it.

12. California residents

If you are a resident of California, the California Consumer Privacy Act (CCPA/CPRA) and related regulations provide additional rights. In the preceding 12 months we have collected the categories of personal information described in Section 3 and disclosed them for business purposes as described in Section 7. We do not sell or share personal information as those terms are defined by the CCPA, and we do not use sensitive personal information for purposes other than those permitted.

California residents may request that we disclose the categories and specific pieces of personal information we have collected, delete personal information (subject to lawful exceptions), and correct inaccurate information. You may also exercise these rights through an authorized agent. Contact legal@donordesk.online to make a request. We will not discriminate against you for exercising your privacy rights.

13. Children's privacy

The Service is intended for use by organizations and professionals and is not directed to children. We do not knowingly collect personal information directly from children. If a Customer works with data about children (for example, beneficiary records), the Customer is responsible for complying with all applicable laws and obtaining any required parental or guardian consent, and for using the Service in a manner consistent with child-protection obligations.

If you believe we have unintentionally collected personal information from a child, contact legal@donordesk.online and we will take reasonable steps to delete it.

14. Third-party links and services

The Service may contain links to third-party websites and services (for example, file storage providers or donor portals). This policy does not apply to those third parties. We are not responsible for their practices, and we encourage you to review their privacy policies.

15. Cookies and similar technologies

We use cookies and similar technologies (such as local storage and session identifiers) to operate and secure the Service. We use:

  • Essential cookies, required for authentication, session management, and security. These cannot be disabled without breaking the Service.
  • Preference cookies, such as your theme (light/dark) selection and language preference.
  • Analytics cookies, where used, to understand aggregate usage so we can improve the Service.

We do not use advertising or third-party tracking cookies for cross-site advertising. You can control or delete cookies through your browser settings; however, blocking essential cookies may prevent you from using the Service. Some browsers transmit “Do Not Track” signals; because there is no common standard, we currently do not change our practices in response to these signals, except where required by law.

16. Security incidents and vulnerability disclosure

If we become aware of a security incident that affects your personal information or your workspace, we will assess the impact and notify affected Customers without undue delay where required by applicable law, including a description of the nature of the incident and the steps we are taking to address it.

We welcome responsible disclosure of security vulnerabilities in the Service. If you discover a potential vulnerability, please report it privately to legal@donordesk.online with sufficient detail to allow us to reproduce and assess it. Please do not test in a way that degrades the Service or accesses other users' data. We will respond to valid reports and will not pursue legal action against researchers who act in good faith and in accordance with this clause.

17. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will post the updated policy on this page and update the effective date above, and we will notify you by email or in-product notice where we have a way to reach you. Continued use of the Service after the effective date of the updated policy constitutes acceptance of the changes.

18. Contact us

If you have questions, concerns, or complaints about this policy or our privacy practices, contact us at:

DonorDesk.Online — Privacy Team

Email: legal@donordesk.online

Service: https://donordesk.online

We will acknowledge your request promptly and respond within the timeframe required by applicable law. You also have the right to lodge a complaint with the data protection authority in the country where you reside, where you work, or where an alleged infringement took place.