Legal
Sub-processors
Effective date: 7 October 2026 (Version 1.0) · Applies to the Service at donordesk.online
This list names the third parties that may process personal data in a customer workspace on DonorDesk's behalf. It forms part of our Data Processing Addendum.
1. Always used
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Contabo GmbH | Servers and database hosting for the Service | All workspace data and backups | Contabo data centre |
| Creem | Payment processing and subscriptions (merchant of record) | Billing contact and payment details (card data is handled by Creem, not stored by us) | Per Creem's policy |
| Postmark (ActiveCampaign) | Transactional email: invitations, password resets, notices | Recipient email, name, message content | United States |
| Sentry | Error monitoring (only when enabled) | Technical error data; no workspace content by design | Per Sentry's policy |
2. AI providers
AI-assisted drafting sends the text needed for a request (for example report sections, source excerpts and prompts) to an AI provider. Personal identifiers can be redacted before sending (a built-in privacy filter). We normally use Z.ai (GLM) or Anthropic (Claude). Our platform administrators can select other providers for a workspace. Only the provider configured for your workspace receives its data.
| Provider | Models | Notes |
|---|---|---|
| Z.ai (Zhipu AI) | GLM | Normal default |
| Anthropic | Claude | Normal default |
| OpenAI | GPT | Available on request |
| Gemini | Available on request | |
| DeepSeek | DeepSeek | Available on request |
| MiniMax | MiniMax | Available on request |
| Self-hosted (Ollama) | Open models on our own servers | No third party receives data |
We do not authorise providers to train models on your data and require them to process it only to return the result. Ask us before enabling AI if your donor forbids third-party AI or requires data to stay in a region; AI can be disabled or switched to self-hosted. Contact privacy@donordesk.online for the provider configured for your workspace.
3. Used only if you enable them
| Provider | Purpose | Data |
|---|---|---|
| Cloudflare (R2) | Managed file storage if you choose DonorDesk-managed uploads | Uploaded evidence files |
| Slack, Microsoft Teams, WhatsApp | Notifications you configure | Notification text and recipients |
These are your choices. Where you connect your own account, your agreement with that provider also applies.
4. Your own Google Drive
Our recommended setup is that you connect your organisation's Google Drive and your evidence, templates and exports are stored in your Drive. Google is then your service provider, under your own agreement with Google, and not a DonorDesk sub-processor for the files stored there. DonorDesk accesses your Drive only through the permissions you grant (files DonorDesk creates or you open with it, file and folder names, and read-only access to spreadsheets you choose), to create project folders, save and read files you upload or link. What DonorDesk itself keeps on Contabo: references to your files, text extracted for search and AI drafting, report drafts, indicator and activity records, and the audit log. Text from your files is also sent to the configured AI provider when you use AI drafting.
5. Changes and objections
We will update this page before adding or replacing a sub-processor, and notify customers with a DPA by email at least 30 days ahead where practicable. You may object on reasonable data-protection grounds within that period; if we cannot accommodate the objection, you may stop using the affected feature or terminate the affected subscription. Contact privacy@donordesk.online.