Trust Centre
Charities trust CharityControl with sensitive information — safeguarding notes, DBS records, and people's contact and employment details. This page sets out, plainly, how we keep that data safe, who we share it with to run the service, and where we stand on compliance. We say what is true today and mark what is still in progress, rather than claim more than we can evidence.
Security overview
Your data is kept separate
Every charity's records live in their own separate database. Data is never pooled with other organisations, so one charity can never see another's records. If your charity leaves, we hand back everything as a single export and delete it in full on request.
Encryption
- In transit: all traffic is served over HTTPS/TLS. Certificates are issued and renewed automatically.
- At rest: off-site backups are stored encrypted. Sensitive integration tokens (for example your Xero connection) are encrypted with a key derived from a server secret before they are stored.
Access control
- People sign in with a secure, time-limited link sent to their email — there is no password to be guessed or leaked, and access can be revoked instantly.
- Everyone sees only what their role allows. A volunteer, a trustee and the treasurer each get a different, appropriate view. We enforce this on our servers on every request, so it cannot be worked around in the browser.
- Every change is recorded in an audit history you can review: who changed what, and when.
Hosting, backups and recovery
The application and every charity's database are hosted in the EU (Hetzner, in Finland). We stream continuous encrypted backups off-site to Cloudflare R2 in the European Union, with a rolling 30-day retention window and daily snapshots. We have tested restoring an individual charity's database from these backups.
AI features
Our AI assistant only ever sees the information the person using it is already permitted to see. It makes suggestions; it never changes your records on its own; and everything it does is recorded. Our AI provider does not train its models on data we send.
Data protection & UK GDPR
For the data in your workspace, your charity is the data controller and CharityControl is the processor: we process it only to provide the service, on your instructions. We offer a Data Processing Agreement to customers who need one — see privacy@charitycontrol.co.uk. Our privacy policy sets out what we hold and why.
- Data residency: workspace data is hosted and backed up in the EU. We do not move it outside the EEA to run the core service.
- Data-subject rights: we help you respond to access, rectification, erasure and portability requests. Each charity's data exports or deletes as one unit.
- No sale of data, ever, and no advertising trackers.
Subprocessors
To run the service we rely on a small number of trusted third parties who process personal data on our behalf. This is the current list.
| Subprocessor | Purpose | Data categories | Location / transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | Cloud hosting and compute for the application and each tenant's database. | All workspace and account data at rest and in processing. | Helsinki, Finland (EU/EEA). No transfer outside the EEA. |
| Cloudflare, Inc. | DNS, TLS certificates, network protection, and inbound email routing (catch-all forwarding). | Connection metadata (IP address, request headers); content and addresses of email sent to our @charitycontrol.co.uk inboxes. | Global edge network with EU processing options. US company; UK/EU transfers under the UK IDTA / EU Standard Contractual Clauses. |
| Cloudflare R2 (EU jurisdiction) | Encrypted, off-site database backups streamed continuously by Litestream. | Full encrypted copies of the control and tenant databases (i.e. all workspace and account data). | European Union jurisdiction bucket. Data stored in the EU. |
| Resend (Plus Five Five, Inc.) | Delivery of transactional email — sign-in links, notifications and reminders. | Recipient name and email address; the content of the message being sent. | US. Transfers under the UK IDTA / EU Standard Contractual Clauses. |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Subscription billing and card payment processing. | Billing contact name and email, plan and subscription status. Card details are entered directly into Stripe's hosted checkout and never reach our servers. | Stripe Payments Europe (Ireland, EU) with onward processing in the US under Stripe's SCCs / UK IDTA. |
| Anthropic PBC | AI assistant and drafting features (onboarding suggestions, mapping proposals, regulatory-news triage, meeting recaps, quiz generation). | Only the workspace data the requesting user is already permitted to see, sent per request. Anthropic does not train its models on data submitted through its API. | US. Transfers under the UK IDTA / EU Standard Contractual Clauses. |
We give at least 30 days' notice before a new subprocessor starts handling personal data, so you have time to raise any objection. This page and the published list are the source of truth; email privacy@charitycontrol.co.uk to be notified of changes.
Customer-connected integrations
These are not our subprocessors: you connect them with your own account, and you decide what data flows to a service you already control. We list them for transparency. Video meetings are self-hosted on our own infrastructure and use no third-party video provider.
| Integration | Purpose | Data categories | Location / transfer basis |
|---|---|---|---|
| Xero | Optional accounting integration the customer connects with their own Xero login (read-only). | We read the financial figures needed for the charity's reports from the customer's own Xero organisation. | The customer's own Xero account governs where Xero holds their data. |
| Intuit QuickBooks Online | Optional accounting integration (an alternative to Xero) the customer connects with their own Intuit login. | We read the financial figures needed for the charity's reports from the customer's own QuickBooks company. | The customer's own Intuit account governs where Intuit holds their data. |
| Mailchimp | Optional member-communications integration the customer connects with their own Mailchimp account. | Member contact details the customer chooses to sync to their own Mailchimp audience. | The customer's own Mailchimp account governs where Mailchimp holds their data. |
We also read public data from the Charity Commission register, Companies House and regulator news feeds to pre-fill and cross-check records. This is public information; we do not send your personal data to these sources.
Compliance status
We believe in being straight about where we are. We are a small UK team building to a high bar, and we will not claim a certification we do not hold.
- UK GDPR / Data Protection Act 2018: the service is built to meet UK GDPR as processor. A Data Processing Agreement is available.
- ICO registration: In progress registration with the Information Commissioner's Office as a data controller for account and marketing data. [CONFIRM: ICO registration number once issued]
- ISO 27001 / SOC 2: we do not hold these certifications and do not claim to. If your funder or board needs a security questionnaire completed, get in touch and we'll complete it with you.
- Payments: card payments are handled by Stripe, a PCI-DSS Level 1 service provider. Card details never reach our servers.
Reporting a security issue
If you believe you have found a security vulnerability, please tell us — we welcome responsible disclosure and will work with you in good faith.
- Email security@charitycontrol.co.uk with enough detail to reproduce the issue.
- Please give us reasonable time to investigate and fix before any public disclosure, and avoid accessing or changing other people's data.
- We aim to acknowledge reports promptly and will keep you updated on the fix.
See also our security summary, privacy policy and terms of service.