Privacy & Data Protection Policy
This application is used to help manage charitable registration workflows. We take the privacy and security of your organization's data seriously and are committed to using your information in a careful, proportionate, and transparent way.
This page is intended to explain, in plain language, how this tool handles information and what responsibilities remain with you as the organization using it. It does not replace, and should be read together with, any formal contracts, data processing agreements, or enterprise privacy policies that govern your relationship with us.
1. Purpose and scope of this tool
- The primary purpose of this tool is to help you organize, track, and prepare charitable registration and compliance filings across multiple jurisdictions.
- The application is designed for use by authorized personnel within your organization and their professional advisors (for example, outside counsel or compliance consultants) who support charitable registration work.
- The tool is not intended for use by the general public, donors, or beneficiaries, and should not be used as a system of record for all organizational data.
2. Types of information you may store
Depending on how you choose to use it, the application may contain:
- Organization identifiers (for example, legal name, DBA names, EIN, registration IDs).
- Contact and officer details (for example, names, titles, business contact information).
- Filing and registration history, including prior approvals, revocations, and related correspondence.
- High-level financial information used for registration and reporting (for example, revenue bands or summary figures).
- Supporting documentation that you choose to upload (for example, formation documents, determination letters, or financial statements).
You should avoid uploading or entering information that is unrelated to registration workflows or that is unusually sensitive (for example, passwords, payment card information, or unredacted beneficiary health data), unless you have a clear legal basis and appropriate safeguards in place under your own policies.
3. Access control and user responsibilities
- Access to this tool should be limited to individuals who need it for their job functions (for example, legal, finance, compliance, and authorized advisors).
- You are responsible for managing user accounts, authentication, and permissions within your organization's environment, including promptly removing access for people who change roles or leave the organization.
- You are responsible for ensuring that any information you load into the tool has been collected, used, and shared in accordance with your own internal policies and applicable laws.
4. How data is processed within the tool
The application processes the data you provide in order to:
- Pre-populate registration forms and workflows, where applicable.
- Help you track which states or jurisdictions are relevant, and what information is missing for a given filing.
- Generate drafts or summaries for your review, including where AI-assisted extraction is used on uploaded documents.
Where the product uses AI or automated extraction, it does so to assist your team and not to replace legal or compliance review. You should always verify outputs against the underlying source documents and applicable regulatory requirements.
5. Security and data protection measures
We aim to implement reasonable technical and organizational measures to protect the data processed through this tool, including:
- Use of modern encryption and secure transport protocols for data in transit.
- Logical separation between customer environments and limited access to production systems by authorized personnel only.
- Monitoring and logging designed to detect unusual or unauthorized activity within the application environment.
No system can be guaranteed to be completely free of risk or immune from unauthorized access, but we design and operate this tool with security as a core priority. You should continue to apply your own organizational security controls (for example, SSO, device management, and network policies) when accessing the application.
6. Data retention and deletion
- Data is retained in the application for as long as your organization maintains an active account or as needed to support your charitable registration workflows.
- When you remove information or close your account, associated data will be scheduled for deletion or anonymization in accordance with our operational practices and any governing agreements.
- In some cases, limited information may be retained for backup, audit, or legal compliance purposes, consistent with our legal obligations.
7. Your review obligations and use of outputs
- The tool is designed to assist with drafting and preparation. It does not provide legal, tax, or regulatory advice.
- You remain fully responsible for reviewing and approving any filings, forms, or other outputs generated or assisted by the application before they are submitted to regulators or shared with third parties.
- You should confirm that any filing generated through the tool accurately reflects your organization's activities, financials, and legal positions.
8. Third-party services and integrations
The application may rely on reputable third-party infrastructure or AI providers to perform certain functions (for example, document storage, logging, analytics, or text extraction). Where that is the case, those providers are selected with security and reliability in mind and are subject to appropriate contractual safeguards.
Your organization's own agreements and procurement processes may govern how these providers are used in your environment. You should consult your legal or procurement teams if you have questions about specific vendors or data flows.
9. Regulatory and contractual alignment
- This application is intended to support, not replace, your existing compliance program and regulatory obligations.
- In the event of any conflict between this page and a signed contract or data processing agreement, the terms of the signed agreement will control.
- You are responsible for determining whether your use of the tool complies with applicable privacy and data protection laws in the jurisdictions where you operate.
10. Questions and contact points
If you have questions about how data in this application is processed, stored, or deleted, or if you need to exercise rights under applicable data protection laws, please contact your organization's designated privacy, security, or legal contact. They can coordinate with us as needed under your existing contractual arrangements.
This internal tool-level policy is intended to provide transparency about how the product operates from a privacy and security perspective. It does not by itself create legal rights or obligations beyond those set out in the contracts and policies that apply to your organization.
To return to your registrations, go back to the dashboard.