GDPR Compliance

Your rights under GDPR and how DonorDesk complies.

DonorDesk is designed to help NGOs meet data-protection duties. This page explains how, and what remains your responsibility.

Roles

For the content you put into DonorDesk (beneficiary and staff data in evidence, activities and reports), your organisation is the data controller and DonorDesk is the processor. For account and billing data about your users, DonorDesk is a controller.

A Data Processing Agreement (DPA) is available to Growth and Enterprise customers: email privacy@donordesk.online or use the sales contact form.

Features that help

NeedHow DonorDesk helps
Data minimisationLink-first Google Drive storage; no need to copy files into DonorDesk.
Access controlSeven roles and per-project assignments.
ConfidentialitySensitive / Highly sensitive labels withhold files from AI drafting and gate exports.
AccountabilityImmutable audit log of actions, decisions and exports.
Data locationData-residency setting (Platform default, EU, US, Africa, Asia).
PortabilityExport reports, indicators, checklists and evidence packs at any time.
AI transparencyModel and prompt version recorded for every generation; AI can be switched off.

Data-subject requests

If a person asks to access, correct or delete their data, you are responsible for responding, and we help.

  1. Find the records (evidence, activities, reports) in your workspace and Drive.
  2. Correct or delete what you can yourself. Admins can delete evidence.
  3. For anything you cannot do, or to delete a user or your whole workspace, email privacy@donordesk.online with details. We handle requests as required by law.

Good practice for your team

  • Record a lawful basis for the personal data you collect.
  • Collect the minimum: aggregate where you can, and avoid names in report text.
  • Mark beneficiary data Sensitive or Highly sensitive.
  • Keep original files in your Google Drive under your own retention rules.
  • Tell your Data Protection Officer that DonorDesk and its subprocessors are in use. See Data security.

This page is guidance, not legal advice.