Data Processing Agreement (DPA)
This DPA sets out how CharityIQ Ltd processes personal data on your behalf when you use the CharityIQ platform. It forms part of the agreement between you (the controller) and us (the processor) under UK GDPR Article 28.
Last reviewed: 26 April 2026. Effective: on the date you accept our Terms of Service.
1. Definitions
- “Controller” — your charity, which determines the purposes and means of processing personal data through the platform
- “Processor” — CharityIQ Ltd, which processes personal data on your behalf
- “Personal Data” — has the meaning given in UK GDPR Article 4
- “Sub-processor” — a third-party processor we engage to help deliver the Service
- “UK GDPR” — the UK General Data Protection Regulation, as amended
2. Subject and duration
We process Personal Data on your behalf to provide the Service. Processing continues for the duration of your subscription, and for up to 90 days after termination (the data retention window before deletion).
3. Nature and purpose of processing
We process Personal Data to:
- Operate your CharityIQ account
- Generate AI-drafted grant applications, compliance documents, and impact reports
- Match your charity to UK funders (Grant Finder)
- Provide audit trails for your platform activity
- Provide customer support
- Maintain platform security and prevent fraud
4. Categories of data subjects and Personal Data
Data subjects may include: your staff, trustees, volunteers, beneficiaries (if uploaded), donors (if uploaded), and contacts.
Personal Data categories may include: contact details, employment role, beneficiary demographic data, donor giving history, application records. The exact categories depend on what you upload.
5. Our obligations as Processor
We will:
- Process Personal Data only on your documented instructions (using the Service constitutes such instruction)
- Ensure persons authorised to process the data are bound by confidentiality
- Implement appropriate technical and organisational security measures (see Section 7)
- Engage sub-processors only with your prior consent (Section 8)
- Assist you with data subject rights requests, DPIAs, and prior consultations as required
- Notify you without undue delay of any personal data breach affecting your data
- Delete or return Personal Data on termination, at your choice
- Make available all information necessary to demonstrate compliance with this DPA
6. Your obligations as Controller
- Have a lawful basis for the Personal Data you upload
- Provide appropriate privacy notices to your data subjects
- Comply with UK GDPR in your own right
- Apply data minimisation — only upload Personal Data necessary for your purposes
7. Technical and organisational measures
We implement:
- Encryption — data at rest (AES-256), data in transit (TLS 1.3)
- UK data residency — all customer data stored in AWS London (eu-west-2)
- Access controls — role-based access; principle of least privilege; multi-factor authentication for staff access
- Backup and recovery — encrypted daily backups, 30-day retention
- Monitoring — security logging, anomaly detection
- Vulnerability management — dependency scanning, patch management, periodic penetration testing
- Staff training — UK GDPR awareness training for all team members
- Incident response — documented procedures with clear breach notification timelines
8. Sub-processors
We use the following sub-processors. By accepting this DPA, you give general consent. We will notify you of changes at least 30 days in advance and you may object on reasonable grounds.
- Amazon Web Services (AWS) — UK (eu-west-2) — infrastructure hosting
- Anthropic — UK / EU region routing — AI inference for drafting outputs
- Stripe Payments UK Ltd — UK — payment processing
- Postmark (ActiveCampaign) — UK / EU region — transactional email delivery
- Sentry — EU region — error monitoring (no Customer Data sent)
- Plausible Analytics — EU (Germany) — privacy-respecting product analytics
Each sub-processor is bound by data protection terms equivalent to those in this DPA.
9. International transfers
We do not transfer Customer Data outside the UK or EEA. Where a sub-processor operates infrastructure in the EEA only, transfers occur on the basis of UK adequacy regulations.
10. Audit rights
We will respond to reasonable audit requests in writing. For controller audits requiring on-site access, we may charge our reasonable costs and require 30 days’ notice. We will share third-party audit reports (when available) on request.
11. Personal data breach notification
We will notify you of any personal data breach affecting Customer Data without undue delay, and within 72 hours wherever feasible. The notification will include:
- Nature of the breach
- Categories and approximate number of data subjects affected
- Likely consequences
- Measures taken or proposed
12. Termination and data return
On termination of the Service, you may export your Customer Data through the platform’s export function. After 90 days, we securely delete all Customer Data unless legally required to retain longer.
13. Contact
For DPA-related queries: office@charityiq.co.uk.