Privacy & Data Protection Policy

This application is used to help manage charitable registration workflows. We take the privacy and security of your organization's data seriously and are committed to using your information in a careful, proportionate, and transparent way.

This page is intended to explain, in plain language, how this tool handles information and what responsibilities remain with you as the organization using it. It does not replace, and should be read together with, any formal contracts, data processing agreements, or enterprise privacy policies that govern your relationship with us.

1. Purpose and scope of this tool

2. Types of information you may store

Depending on how you choose to use it, the application may contain:

You should avoid uploading or entering information that is unrelated to registration workflows or that is unusually sensitive (for example, passwords, payment card information, or unredacted beneficiary health data), unless you have a clear legal basis and appropriate safeguards in place under your own policies.

3. Access control and user responsibilities

4. How data is processed within the tool

The application processes the data you provide in order to:

Where the product uses AI or automated extraction, it does so to assist your team and not to replace legal or compliance review. You should always verify outputs against the underlying source documents and applicable regulatory requirements.

5. Security and data protection measures

We aim to implement reasonable technical and organizational measures to protect the data processed through this tool, including:

No system can be guaranteed to be completely free of risk or immune from unauthorized access, but we design and operate this tool with security as a core priority. You should continue to apply your own organizational security controls (for example, SSO, device management, and network policies) when accessing the application.

6. Data retention and deletion

7. Your review obligations and use of outputs

8. Third-party services and integrations

The application may rely on reputable third-party infrastructure or AI providers to perform certain functions (for example, document storage, logging, analytics, or text extraction). Where that is the case, those providers are selected with security and reliability in mind and are subject to appropriate contractual safeguards.

Your organization's own agreements and procurement processes may govern how these providers are used in your environment. You should consult your legal or procurement teams if you have questions about specific vendors or data flows.

9. Regulatory and contractual alignment

10. Questions and contact points

If you have questions about how data in this application is processed, stored, or deleted, or if you need to exercise rights under applicable data protection laws, please contact your organization's designated privacy, security, or legal contact. They can coordinate with us as needed under your existing contractual arrangements.

This internal tool-level policy is intended to provide transparency about how the product operates from a privacy and security perspective. It does not by itself create legal rights or obligations beyond those set out in the contracts and policies that apply to your organization.

To return to your registrations, go back to the dashboard.