Privacy Policy
Your donors trusted you with their details. This explains what happens to them here.
Two kinds of personal data, handled differently
Almost every privacy question about HOPEAQUE has a different answer depending on whose data is being discussed, so this policy separates them from the start.
Account data is information about the people who use the product: the staff member who signs up, their name, work email, role and organisation. We decide how that data is used, which makes us the controller of it.
Supporter data is information about your donors, volunteers, grantees and other supporters, which your organisation enters or imports. Your organisation decides what to collect, why, and how long to keep it. You are the controller of that data. We process it on your instructions and for no purpose of our own.
Account data we hold, and why
When someone signs up or writes to us, we collect the organisation name and type, the individual's name, role and work email, the approximate record count, the plan of interest, and anything written in the message or migration fields. It is used to create and support the workspace, to apply nonprofit concession pricing correctly, to invoice, and to answer the question that was asked.
We do not build advertising profiles, we do not sell account data, and we do not add people who contacted us with a support or security question to a marketing sequence. If you would like your account data corrected or removed, ask and we will do it.
Supporter data: what we do and do not do with it
Supporter data is used to run the features you asked for: holding records, calculating engagement scores, producing lapse-risk flags and suggested actions, tracking appeals and volunteer hours, and assembling impact reports. All of that processing happens inside your own workspace and is scoped to your organisation at the data layer.
We do not sell, rent, broker or share supporter data with any third party. We do not use one organisation's donor file to improve results for another organisation, and we do not pool supporter records into a shared dataset. If we ever want to publish aggregate findings about retention patterns, we will ask participating organisations to opt in explicitly and in writing first.
Our staff do not browse customer records. Support access to your workspace requires an administrator in your organisation to grant it, is limited in time, and is logged where you can read the log.
Sensitive information and the notes your team writes
Fundraising records accumulate genuinely sensitive material: a bereavement, financial strain, a programme a donor will not fund, or a beneficiary story told in confidence. HOPEAQUE gives you somewhere to record those things because pretending they do not exist is what causes a tactless ask at the worst possible moment.
Notes can be marked sensitive, which restricts them to the relationship owner and administrators and keeps them out of board-level and finance views. Beneficiary stories used in impact reporting should carry recorded consent, and HOPEAQUE has a field for that consent because the report draft will otherwise flag its absence.
We do not provide structured fields for health status, caste, religion or political affiliation, and we recommend against recording them in free text.
Payment information
HOPEAQUE never receives or stores card numbers, CVVs or bank credentials for your supporters. Gifts arrive as transaction records imported from the payment gateway or donation platform your organisation already uses, so the regulated part of the payment stays with the regulated provider.
What we hold is the fact and shape of the gift: amount, date, designation, fee, and whether a mandate succeeded or failed. Distinguishing a failed mandate from a donor decision is the reason that last field matters.
Sub-processors
We use third parties in three categories: cloud hosting and database infrastructure, transactional email delivery, and application error monitoring. Each is bound by contractual confidentiality and data-protection obligations, and each receives only what it needs to perform its function.
The current list of sub-processors, with the category and location of each, is available on request. Where we add or replace a sub-processor that handles supporter data, we notify organisations before the change takes effect so that any objection can be raised in time to matter.
How long data is kept
Supporter records are held for as long as your subscription is active and the record exists in your file. Deleting a record removes it from live systems immediately and from backups within thirty days.
Gift and receipt records are retained for the statutory period your jurisdiction requires for financial records, because deleting them earlier would compromise your own compliance. Where a supporter asks your organisation to erase their identity, the financial record can be retained in de-identified form.
After a subscription ends, your data remains available for export for thirty days, is then deleted from live systems, and is removed from backups within a further thirty days. Access and change logs are kept for twelve months for audit purposes and record user identity and action rather than supporter content.
Supporter rights, and who answers them
When one of your donors or volunteers asks for access to their data, a correction, deletion, or a copy of what you hold, that request belongs to your organisation as the controller. HOPEAQUE gives administrators the tools to action it: retrieve everything held about one person, correct it, export it in a portable format, or delete it.
Where a request reaches us directly, we will not act on it unilaterally. We pass it to your organisation's administrators and support you in responding, because deciding what happens to your donor record is not our call to make.
For your own account data, where we are the controller, you can ask us directly for access, correction, export or deletion.
How automated processing is used
Engagement scores, lapse-risk flags, suggested next steps and report drafts are produced by automated processing of the data in your own workspace. They are decision support, not decisions. Nothing is sent to a supporter automatically, and no supporter is removed, downgraded or excluded by the system on its own.
The signals behind every score, and their weights, are visible to you and adjustable by you. Every flag can be traced to the reading that produced it. If a score is wrong about someone you know well, that is information about the weights rather than about the supporter, and it can be corrected.
Where data is processed
Data is processed in the regions our infrastructure providers operate in, under contractual protections appropriate to each transfer. Organisations with a specific data-residency requirement, which foundations and institutional funders often have, should raise it before migrating, because it is a configuration decision rather than something that can be adjusted afterwards.
Security measures
Connections use TLS 1.2 or higher, data at rest is encrypted with AES-256, backups are encrypted and stored separately, credentials are held as salted hashes, and each organisation's data is logically isolated with every query scoped at the data layer. The Security page sets out the full position, including the certifications we do not currently hold.
Children and beneficiary data
HOPEAQUE is a tool for staff, and product accounts are not intended for anyone under eighteen.
Programmes serving children often generate beneficiary data, and outcome figures feed impact reports. Aggregate outcome data belongs in HOPEAQUE. Identifiable information about a child should only be recorded where your organisation has a lawful basis and recorded consent, and it should never be placed in a donor-facing report field without that consent noted against it.
Changes to this policy
Where a change materially affects how supporter data is processed, we notify organisation administrators directly before it takes effect, so a change can be objected to rather than discovered. Minor clarifications that do not alter how data is handled are made to this page as our practice is refined.
Questions about anything on this page are worth asking before you migrate a donor file rather than after. Use the contact form and we will answer in writing.
Ask a question