Data Processing Agreement
Last updated: 11 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the charity or non-profit organisation using Givio (the "Customer", the data controller) and CharityOS, the operator of Givio (the "Processor"). It sets out the terms required by Article 28 of the UK GDPR for the personal data the Customer stores and manages in its Givio CRM.
1. Subject matter and duration
The subject matter of the processing is the provision of the Givio charity CRM platform: storing, organising, and processing the Customer's supporter and fundraising data so the Customer can manage donors, donations, campaigns, and Gift Aid.
Processing lasts for the term of the Customer's subscription (including any free trial), plus the 90-day retention period that follows account pause or closure, after which the data is permanently deleted as described in section 8.
2. Nature and purpose of processing
The Processor hosts, stores, backs up, retrieves, displays, analyses, and transmits personal data as necessary to provide the platform's features — donor records, donation and campaign tracking, Gift Aid declaration management, reporting, and communications sent at the Customer's direction. The Processor acts only on the Customer's documented instructions, which are given through the Customer's use of the platform and its settings, unless required to process otherwise by UK law (in which case the Processor will inform the Customer before processing, unless the law prohibits it).
3. Data subjects and categories of personal data
Categories of data subjects:
- Donors and supporters of the Customer
- Volunteers
- The Customer's staff and team members
Categories of personal data:
- Contact details — names, email addresses, postal addresses, phone numbers
- Donation history — amounts, dates, payment references, campaign and fund attribution
- Gift Aid declarations — declaration status, dates, and the taxpayer confirmations they contain
- Communication preferences and correspondence records
The platform is not designed for special category data. The Customer should not store special category data (such as health information) in free-text fields unless it has its own lawful basis to do so; note that recording a donor's support for a religious charity may in context reveal religious belief, and the Customer is responsible for its lawful basis for that.
4. Processor obligations
The Processor will:
- process personal data only on the Customer's documented instructions;
- ensure that everyone authorised to process the data is bound by a duty of confidentiality, whether contractual or statutory;
- implement and maintain the technical and organisational measures in section 5;
- assist the Customer, taking into account the nature of the processing, in responding to data subject rights requests and in meeting its obligations on security, breach notification, and data protection impact assessments;
- make available the information reasonably necessary to demonstrate compliance with Article 28, and allow for audits as set out in section 9; and
- immediately inform the Customer if, in its opinion, an instruction infringes UK data protection law.
5. Security measures
The Processor maintains technical and organisational measures appropriate to the risk, including:
- Schema-per-tenant isolation — each Customer's data is held in its own database schema, so tenants' data is logically separated at the database level, not merely filtered in application code;
- Encryption in transit — all traffic between users, the platform, and subprocessors is encrypted using TLS;
- Multi-factor authentication — available for all user accounts and enforced for the Processor's own staff access;
- Role-based access control — the Customer controls what each of its team members can see and do within its CRM;
- Audit logging — significant actions within the platform are recorded so the Customer can see who did what and when; and
- regular backups, and access to production systems restricted to authorised personnel on a need-to-know basis.
6. Subprocessors
The Customer gives general written authorisation for the Processor to engage the following subprocessors:
| Subprocessor | Purpose |
|---|---|
| Stripe | Payment processing |
| Resend | Email delivery |
| Anthropic | AI features |
| Amazon Web Services | File storage and hosting |
| Twilio | SMS messaging |
The Processor will give the Customer at least 30 days' notice before adding or replacing a subprocessor, giving the Customer the opportunity to object on reasonable data protection grounds. If an objection cannot be resolved, the Customer may terminate its subscription and the deletion terms in section 8 apply. The Processor imposes data protection obligations on each subprocessor equivalent to those in this DPA and remains fully liable to the Customer for the subprocessor's performance.
7. Personal data breaches
The Processor will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Customer's data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it — so far as this information is available at the time, with updates to follow as the investigation progresses. The Processor will cooperate with the Customer and take reasonable steps to mitigate the effects of the breach. Responsibility for notifying the ICO and affected data subjects rests with the Customer as controller.
8. Deletion and return of data
On termination of the subscription, the Customer's data enters the 90-day retention period. During that period the Customer may reactivate its account, or request an export of its data in a commonly used, machine-readable format. At the end of the period the Processor permanently deletes all the Customer's personal data, including from backups within the backup rotation cycle, unless UK law requires continued storage of specific records. The Customer may also request earlier deletion in writing.
9. Audit rights
On written request, no more than once per year unless a breach or supervisory authority requires otherwise, the Processor will make available the information reasonably necessary to demonstrate compliance with this DPA — including summaries of security measures, subprocessor agreements, and relevant certifications or third-party audit reports. Where this is insufficient, the Customer (or an independent auditor it appoints, who is not a competitor of the Processor) may conduct an audit at reasonable notice, during business hours, without disrupting the service, and subject to confidentiality obligations.
10. General
This DPA is governed by the law of England and Wales. If there is a conflict between this DPA and the Terms of Service on a data protection matter, this DPA prevails. Questions about this DPA can be sent to support@giviocrm.com.