Skip to content

Security

Supporter data is somebody's generosity written down. It gets handled accordingly.

This page states what we do today, not what is on a roadmap. Where a certification is in progress we say so, and where we have not done something we say that too. A nonprofit deciding who to trust with its donor file deserves a page it can forward to a trustee without annotation.
Encryption
In transit and at rest
Access model
Role-based, four roles
Your data
Exportable, deletable on request

Data we process

Two lists, and the second one matters more.

What we hold, because you put it there

  • Supporter names, contact details and postal addresses
  • Giving history, amounts, designations and receipt status
  • Volunteer skills, availability, shifts and logged hours
  • Consent records per channel, with source and timestamp
  • Notes your team writes about the relationship

What we do not hold

  • Card numbers, CVVs or bank credentials of any supporter
  • Government identity numbers, unless you choose to store a receipt reference that contains one
  • Health or caste data as a structured field
  • Anything scraped from outside your own records
  • Supporter data sold, shared or brokered to any third party, under any circumstances

On payments

HOPEAQUE never touches a card or bank credential. Gifts are imported from your payment gateway or donation platform as transaction records, which means the sensitive part of the payment stays with the regulated provider you already chose. What we hold is the fact of the gift, not the instrument that made it.

Retention

How long each kind of data stays, and what ends it.

Retention is where most privacy statements go vague. These are the periods we actually operate.

Active supporter records
Held for as long as your subscription is active and the record is in your file. You delete a record, it is removed from live systems immediately and from backups within 30 days.
Gift and receipt records
Held for the statutory period your jurisdiction requires for financial records, because deleting them earlier would put your own compliance at risk. Deletion requests on a supporter's identity are honoured while the financial record is retained in de-identified form.
Volunteer hours
Held for as long as the programme record they belong to, since certificates and annual filings depend on them.
Relationship notes
Held with the record, deleted with the record. Notes marked sensitive can be deleted separately without deleting the supporter.
After you cancel
Your data stays available for export for 30 days, then is deleted from live systems, then from backups within a further 30 days. We do not keep a copy of your donor file as a growth asset.
System logs
Access and change logs retained for 12 months for audit purposes, holding user identity and action rather than supporter content.

Role-based access

Four roles, defined by what they cannot see.

Most access models are described by permissions granted. The useful description is the opposite one, because that is what a trustee actually wants to know.

Administrator

Can

Full configuration, user management, export, and access to every record and note including restricted ones.

Cannot

Nothing is hidden, which is why this role should be held by one or two people and reviewed.

Staff

Can

Records, gifts, volunteer data, scores, appeals and reports for the supporters or programmes assigned to them.

Cannot

Cannot read notes marked sensitive on relationships they do not own, and cannot export the full file.

Board and trustee

Can

Aggregate views: portfolio and pipeline summaries, appeal performance, and impact reporting at organisation level.

Cannot

Cannot open individual supporter records, relationship notes, or contact details.

Finance

Can

Gifts, fees, designations, disbursement schedules and reconciliation views, with the identity fields needed for receipting.

Cannot

Cannot read engagement notes or volunteer personal detail beyond what receipting requires.

Technical measures

Encryption, isolation and recovery.

In transit
TLS 1.2 or higher on every connection, with HTTP requests redirected rather than served. No supporter data moves over an unencrypted channel.
At rest
Database and file storage encrypted at rest with AES-256. Backups are encrypted with the same standard and stored separately from the primary systems.
Tenant isolation
Each organisation's data is logically isolated, and every query is scoped to the organisation at the data layer rather than only in the interface.
Credentials
Passwords stored as salted hashes using a modern key-derivation function. Administrators can require multi-factor authentication for their organisation.
Backups and recovery
Daily encrypted backups with point-in-time recovery on the database. Restores are tested rather than assumed.
Internal access
Our engineers do not browse customer data. Support access to an organisation's records requires an administrator's explicit grant, is time-limited, and is logged where you can read it.

Compliance posture

Stated as it is today, with no future tense.

Indian data protection

In place

We operate as a data processor for your organisation. Processing purposes, retention and deletion rights are set out in the Terms of Service and honoured on request.

GDPR-style subject rights

Supported

Access, correction, deletion and export requests for individual supporters can be actioned from within the product by an administrator, and we support you as processor on requests you receive.

SOC 2 Type II

Not held

We do not hold a SOC 2 report today and will not imply otherwise. If your board requires one before adoption, tell us and we will give you an honest timeline rather than a reassurance.

ISO 27001

Not held

Not certified. The controls described on this page are implemented and documented, but they have not been audited by an external certification body.

Penetration testing

Scheduled annually

Third-party testing on an annual cycle, with findings tracked to closure. A summary is available to Foundation-tier customers under agreement.

Sub-processors

Disclosed

Hosting, email delivery and error monitoring are the categories we use. The current list of sub-processors is available on request and changes are notified before they take effect.

Reporting something you have found

If you believe you have found a vulnerability in HOPEAQUE, use the contact form and choose the security review topic. We will acknowledge the report, keep you informed while we work on it, and we will not threaten anyone who reports a genuine issue in good faith. Please do not test against another organisation's data.