Your board will ask, your accountant will ask, and a grantmaker doing due diligence will ask. Here are the answers on one page, in language you can forward.
Nothing leaves the European Economic Area. That is a design decision, not a setting.
The part boards get wrong most often, and the part that decides who is liable.
Everybody who can technically touch the data, and why.
Most incidents are not hackers. They are somebody in the office seeing something they should not.
Recorded per channel, because that is how the law works and how donors think.
Everybody has an incident eventually. What matters is what happens in the first day.
The best proof that you are not locked in is that leaving is documented.
Read this bit especially if you are comparing us with a larger supplier.
Yes. Ask and we send it, unsigned, for your board to read at their own pace. It also comes with the standard terms, so you are not agreeing to something separate later.
Send them this page. If they want the hosting provider's ISO certificate, ask us and we will forward it. If they want a completed security questionnaire, we fill those in — tell us the deadline.
A fair question to ask a small supplier, and one most will dodge. You can export everything at any moment without us, which is the practical answer. Ask us about escrow arrangements if your board needs more than that.
No. Your donor file is not a training set, not for us and not for anyone we pass it to. If that ever changes it will be an explicit, opt-in choice with a contract change — not a line added quietly to a policy.
That is what it is for. If they come back with a question this page does not answer, tell us — the answer belongs here rather than in a private email.