CharityControl

Trust Centre

Last updated 17 July 2026 · Live platform status · Security questions: security@charitycontrol.co.uk · Data protection: privacy@charitycontrol.co.uk

Charities trust CharityControl with sensitive information — safeguarding notes, DBS records, and people's contact and employment details. This page sets out, plainly, how we keep that data safe, who we share it with to run the service, and where we stand on compliance. We say what is true today and mark what is still in progress, rather than claim more than we can evidence.

Security overview

Your data is kept separate

Every charity's records live in their own separate database. Data is never pooled with other organisations, so one charity can never see another's records. If your charity leaves, we hand back everything as a single export and delete it in full on request.

Encryption

Access control

Hosting, backups and recovery

The application and every charity's database are hosted in the EU (Hetzner, in Finland). We stream continuous encrypted backups off-site to Cloudflare R2 in the European Union, with a rolling 30-day retention window and daily snapshots. We have tested restoring an individual charity's database from these backups.

AI features

Our AI assistant only ever sees the information the person using it is already permitted to see. It makes suggestions; it never changes your records on its own; and everything it does is recorded. Our AI provider does not train its models on data we send.

Data protection & UK GDPR

For the data in your workspace, your charity is the data controller and CharityControl is the processor: we process it only to provide the service, on your instructions. We offer a Data Processing Agreement to customers who need one — see privacy@charitycontrol.co.uk. Our privacy policy sets out what we hold and why.

Subprocessors

To run the service we rely on a small number of trusted third parties who process personal data on our behalf. This is the current list.

SubprocessorPurposeData categoriesLocation / transfer basis
Hetzner Online GmbHCloud hosting and compute for the application and each tenant's database.All workspace and account data at rest and in processing.Helsinki, Finland (EU/EEA). No transfer outside the EEA.
Cloudflare, Inc.DNS, TLS certificates, network protection, and inbound email routing (catch-all forwarding).Connection metadata (IP address, request headers); content and addresses of email sent to our @charitycontrol.co.uk inboxes.Global edge network with EU processing options. US company; UK/EU transfers under the UK IDTA / EU Standard Contractual Clauses.
Cloudflare R2 (EU jurisdiction)Encrypted, off-site database backups streamed continuously by Litestream.Full encrypted copies of the control and tenant databases (i.e. all workspace and account data).European Union jurisdiction bucket. Data stored in the EU.
Resend (Plus Five Five, Inc.)Delivery of transactional email — sign-in links, notifications and reminders.Recipient name and email address; the content of the message being sent.US. Transfers under the UK IDTA / EU Standard Contractual Clauses.
Stripe Payments Europe, Ltd. / Stripe, Inc.Subscription billing and card payment processing.Billing contact name and email, plan and subscription status. Card details are entered directly into Stripe's hosted checkout and never reach our servers.Stripe Payments Europe (Ireland, EU) with onward processing in the US under Stripe's SCCs / UK IDTA.
Anthropic PBCAI assistant and drafting features (onboarding suggestions, mapping proposals, regulatory-news triage, meeting recaps, quiz generation).Only the workspace data the requesting user is already permitted to see, sent per request. Anthropic does not train its models on data submitted through its API.US. Transfers under the UK IDTA / EU Standard Contractual Clauses.

We give at least 30 days' notice before a new subprocessor starts handling personal data, so you have time to raise any objection. This page and the published list are the source of truth; email privacy@charitycontrol.co.uk to be notified of changes.

Customer-connected integrations

These are not our subprocessors: you connect them with your own account, and you decide what data flows to a service you already control. We list them for transparency. Video meetings are self-hosted on our own infrastructure and use no third-party video provider.

IntegrationPurposeData categoriesLocation / transfer basis
XeroOptional accounting integration the customer connects with their own Xero login (read-only).We read the financial figures needed for the charity's reports from the customer's own Xero organisation.The customer's own Xero account governs where Xero holds their data.
Intuit QuickBooks OnlineOptional accounting integration (an alternative to Xero) the customer connects with their own Intuit login.We read the financial figures needed for the charity's reports from the customer's own QuickBooks company.The customer's own Intuit account governs where Intuit holds their data.
MailchimpOptional member-communications integration the customer connects with their own Mailchimp account.Member contact details the customer chooses to sync to their own Mailchimp audience.The customer's own Mailchimp account governs where Mailchimp holds their data.

We also read public data from the Charity Commission register, Companies House and regulator news feeds to pre-fill and cross-check records. This is public information; we do not send your personal data to these sources.

Compliance status

We believe in being straight about where we are. We are a small UK team building to a high bar, and we will not claim a certification we do not hold.

Reporting a security issue

If you believe you have found a security vulnerability, please tell us — we welcome responsible disclosure and will work with you in good faith.

See also our security summary, privacy policy and terms of service.