Where your donor file actually lives.

Your board will ask, your accountant will ask, and a grantmaker doing due diligence will ask. Here are the answers on one page, in language you can forward.

Hosting and location

Nothing leaves the European Economic Area. That is a design decision, not a setting.

Where the data sits
Amsterdam (AMS3), within the EEA. Backups stay in the same region.
Hosting provider
DigitalOcean, ISO 27001 certified. Their certificate is available on request, and we will tell you plainly that they are a US-incorporated company hosting in a Dutch data centre — ask us if that matters to your funder.
Separation
Every charity has its own workspace on its own subdomain, with data separated at the database level. One customer cannot query another's records.
Encryption
TLS 1.2 or better in transit. Encrypted at rest, including backups.
Backups
Daily, retained 30 days, restore tested monthly into a separate environment. A restore has been performed successfully on [date of your first test].
Availability
We aim for 99.5% monthly uptime — about three and a half hours a year. We could write 99.9% on this page; we could not honour it at three in the morning with the team we have. Planned maintenance is announced 48 hours ahead and kept outside 08:00–18:00 CET on weekdays.
One thing here is still yours The date of your first successful restore test. Run one, write the date in, and never publish a tested-restore claim before you have actually done it.

Who is who under the GDPR

The part boards get wrong most often, and the part that decides who is liable.

You are
The controller. It is your donor file, your legal basis, your decisions about what to collect and how long to keep it.
We are
The processor. We process on your instruction and for no other purpose. We do not sell, rent, share or mine your data, and we do not use it to train anything.
Processing agreement
A verwerkersovereenkomst is part of the contract and comes with the standard terms. You do not have to ask for it and you do not have to negotiate it item by item.
Sub-processors
Named on this page, with what each one does. We tell you 30 days before we add or change one, and you can object.
Data subject requests
Access, correction, deletion and portability are buttons in the product. A donor asking to be forgotten is a job for the person on duty, not a ticket to us.

Sub-processors

Everybody who can technically touch the data, and why.

Hosting
DigitalOcean (Amsterdam) — infrastructure and managed database. Cannot read application data in normal operation.
Email delivery
Mailgun (EU region) — sends your campaigns and system mail. Sees recipient address and message content.
WhatsApp
Meta Platforms Ireland, through 360dialog — only when you switch the WhatsApp module on, and only for the numbers you message.
Payments
Not a sub-processor of ours. Mollie, Stripe, PayPal and Tikkie are your own contracts, in your own name, paying into your own account. We hold the reference, not the money.
Error monitoring
Sentry (EU data region) — technical error logs, configured to strip personal data before it leaves the server.
Keep this list current An out-of-date sub-processor list is worse than none — it is what a serious due diligence check catches first. If you add an AI service, a search service or an analytics tool later, it goes on this list before it goes live, with 30 days' notice to customers.

Access and roles

Most incidents are not hackers. They are somebody in the office seeing something they should not.

AdministratorEverything, including users, providers and export. Keep it to two people.
FundraiserDonors, gifts, campaigns and fundraisers. No payment settings, no user management.
MarketingSegments and campaigns. Sees contact details, not bank details.
FinanceGifts, mandates, collection runs and reports. No campaign sending.
Read onlyFor your accountant, your board and an auditor. Cannot change anything.
DonorTheir own record only, through the portal. Cannot see anybody else, ever.
Audit log
Every change to a donor record, mandate or setting is logged with who and when, and you can read it yourself.
Our access
Support staff can only enter your workspace with your explicit approval, per session. Every such session is logged and visible to you in your own audit log. There is no standing back-door.
Two-factor
Required for Administrators, available to everyone else.

Consent and retention

Recorded per channel, because that is how the law works and how donors think.

Per channel
Email, WhatsApp, SMS and post are separate permissions with their own timestamp and source. Someone who takes your newsletter has not agreed to be messaged on WhatsApp.
Campaigns respect it
A segment only counts and only reaches people who consented to that channel. It is not a checkbox you can override in a hurry.
Unsubscribing
One click, honoured immediately across every module, and recorded.
Retention
You set the period per category and the platform enforces it. Financial records generally need seven years under Dutch tax law even after someone asks to be forgotten — the product separates what must be kept from what must go.
Deletion
A deletion request anonymises the person while leaving the accounting trail intact, and writes down that it happened.

When something goes wrong

Everybody has an incident eventually. What matters is what happens in the first day.

We tell you
Within 24 hours of establishing a breach affecting your data — with what we know, what we do not yet know, and what we are doing.
You report
As controller you decide on notifying the Autoriteit Persoonsgegevens, within 72 hours of becoming aware. We give you everything you need for that report and we do not make you chase it.
Afterwards
A written account of what happened and what changed, whether or not you ask for one.
Write the runbook before you need it Twenty-four hours is chosen because it is honourable on a Saturday. Now write the actual procedure — who is called, what is checked, who drafts the message — while nothing is on fire.

Getting your data back

The best proof that you are not locked in is that leaving is documented.

Export, any time
Donors, gifts, mandates, campaigns and logs as CSV, without asking us and without a fee.
On leaving
One month's notice, a full export in a usable format, no exit fee, no holding the donor file while terms are discussed.
Then deletion
Your data is deleted from live systems within 30 days of the contract ending, and from backups within 30 days after that as they rotate. You get written confirmation.
Mandates travel
SEPA mandates stay valid when the administration moves, provided the signature date and reference come with them. Both are in the export.

What we do not claim

Read this bit especially if you are comparing us with a larger supplier.

Certification
DNH is not ISO 27001 or SOC 2 certified. Our hosting provider is; we are not, and we will not imply otherwise by putting their badge on our page. If your funder requires certification from the supplier itself, we are not a fit yet.
Penetration testing
Never, so far. We would rather write that than imply otherwise. One is budgeted once we have a handful of customers, and we will publish the date and the firm here when it happens.
Size
We are a small company. That means you get a named person who knows your setup, and it means we do not have a 24/7 security operations centre. Both of those are true at once and you should weigh them.
This section is the reason the page works Everyone else's security page is a list of things they are good at. A due diligence reviewer who finds one honest limitation believes the rest of the page. Do not delete this section when it starts to feel awkward — that is the moment it is doing its job.
Asked by boards

The four questions that actually come up.

Can we get the processing agreement before we sign anything?

Yes. Ask and we send it, unsigned, for your board to read at their own pace. It also comes with the standard terms, so you are not agreeing to something separate later.

Our funder wants to know where the data is hosted.

Send them this page. If they want the hosting provider's ISO certificate, ask us and we will forward it. If they want a completed security questionnaire, we fill those in — tell us the deadline.

What happens to our data if you go out of business?

A fair question to ask a small supplier, and one most will dodge. You can export everything at any moment without us, which is the practical answer. Ask us about escrow arrangements if your board needs more than that.

Do you use our data to train AI?

No. Your donor file is not a training set, not for us and not for anyone we pass it to. If that ever changes it will be an explicit, opt-in choice with a contract change — not a line added quietly to a policy.

Send this page to whoever has to approve it.

That is what it is for. If they come back with a question this page does not answer, tell us — the answer belongs here rather than in a private email.