Privacy Policy
CharityIQ Ltd (“CharityIQ”, “we”, “us”) respects your privacy. This policy explains what personal data we collect, how we use it, and your rights under UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025.
Last reviewed: 26 April 2026.
Who we are
CharityIQ Ltd is a company registered in England and Wales. We are the data controller for personal data we collect about you when you use charityiq.co.uk or the CharityIQ platform.
For data protection enquiries, contact office@charityiq.co.uk.
What we collect
Account data
When you create a CharityIQ account, we collect: your name, work email address, role at your charity, and your charity’s registration number. We use this to set up and operate your account.
Charity profile data
To provide grant matching and AI drafting services, we pull your charity’s public Charity Commission record and store the elements of your charity profile that you confirm. You can choose to add beneficiary numbers, programme outcomes, and past application history; this data stays in your account and is not shared with other customers.
Usage data
We log how you interact with the platform — pages visited, features used, time stamps, IP address, device type, browser. This is used to improve the product, diagnose bugs, and prevent abuse.
Billing data
If you subscribe to a paid plan, we collect billing details (name, billing address, VAT number where applicable). Payment card details are processed by our payment provider (Stripe) and never stored on our servers.
Communications
We keep a record of emails you send us and our replies, support tickets, and product feedback you submit.
Why we collect it (lawful basis)
- Contract performance (UK GDPR Article 6(1)(b)) — to deliver the service you’ve signed up for
- Legitimate interests (Article 6(1)(f)) — to improve the product, prevent fraud, and communicate about your account
- Consent (Article 6(1)(a)) — for optional marketing emails (you can withdraw consent at any time)
- Legal obligation (Article 6(1)(c)) — for tax records, audit requirements, and regulatory enquiries
Where we store your data
All customer data is stored in the United Kingdom — AWS London region (eu-west-2). Our application servers are UK-based. We do not transfer customer data outside the UK or EEA.
For specific operational tools (e.g., email delivery, error monitoring), data may be processed by sub-processors. The full list is published in our Data Processing Agreement.
How long we keep it
- Active accounts — for as long as your subscription is active
- Closed accounts — 90 days after closure (recovery window), then deleted unless legally required to keep longer
- Billing records — 6 years (UK tax law requirement)
- Marketing consent records — until you withdraw consent
Your rights
Under UK GDPR, you have the right to:
- Access — get a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Restriction — limit how we process your data
- Portability — get a machine-readable copy of your data
- Object — object to processing based on legitimate interests
- Withdraw consent — for any processing based on consent
To exercise any of these rights, email office@charityiq.co.uk. We respond within one calendar month.
Cookies
We use cookies sparingly. See our Cookie Policy for full details.
Right to complain
If you believe we’ve handled your data incorrectly, please email us first — we’ll try to put it right. If you remain unhappy, you can complain to the UK Information Commissioner’s Office (ico.org.uk).
Changes to this policy
We may update this policy. Material changes will be communicated by email to active customers at least 30 days before taking effect. The “Last reviewed” date at the top reflects the most recent revision.