GDPR Compliance
Your rights under GDPR and how DonorDesk complies.
DonorDesk is designed to help NGOs meet data-protection duties. This page explains how, and what remains your responsibility.
Roles
For the content you put into DonorDesk (beneficiary and staff data in evidence, activities and reports), your organisation is the data controller and DonorDesk is the processor. For account and billing data about your users, DonorDesk is a controller.
A Data Processing Agreement (DPA) is available to Growth and Enterprise customers: email privacy@donordesk.online or use the sales contact form.
Features that help
| Need | How DonorDesk helps |
|---|---|
| Data minimisation | Link-first Google Drive storage; no need to copy files into DonorDesk. |
| Access control | Seven roles and per-project assignments. |
| Confidentiality | Sensitive / Highly sensitive labels withhold files from AI drafting and gate exports. |
| Accountability | Immutable audit log of actions, decisions and exports. |
| Data location | Data-residency setting (Platform default, EU, US, Africa, Asia). |
| Portability | Export reports, indicators, checklists and evidence packs at any time. |
| AI transparency | Model and prompt version recorded for every generation; AI can be switched off. |
Data-subject requests
If a person asks to access, correct or delete their data, you are responsible for responding, and we help.
- Find the records (evidence, activities, reports) in your workspace and Drive.
- Correct or delete what you can yourself. Admins can delete evidence.
- For anything you cannot do, or to delete a user or your whole workspace, email privacy@donordesk.online with details. We handle requests as required by law.
Good practice for your team
- Record a lawful basis for the personal data you collect.
- Collect the minimum: aggregate where you can, and avoid names in report text.
- Mark beneficiary data Sensitive or Highly sensitive.
- Keep original files in your Google Drive under your own retention rules.
- Tell your Data Protection Officer that DonorDesk and its subprocessors are in use. See Data security.
This page is guidance, not legal advice.