Skip to content

Trust and growth

Security and governance

An organisation is accountable for its donors' money and its donors' data. The platform is built so that it can be.

  • Payments through licensed providers
  • Roles and permissions per organisation
  • Strict data separation

What applies

The following describes how the system works. It is not a claim of certification or licensing.

01

Licensed payment providers

Card processing runs through licensed payment providers. Donation POS is not a bank and not a payment institution.

02

Its own account per organisation

Amounts settle to the organisation's own payment account.

03

Roles and permissions

Each organisation defines who can see and who can act, with platform and organisation users kept separate.

04

Session control

User sessions can be revoked centrally when a role changes or an account is deactivated.

05

Boundaries between organisations

Every data query is scoped to the session's organisation, never to an identifier supplied by the request.

06

Personal data protection

Personal data is processed under the GDPR (EU 2016/679), on a purpose and minimum-access basis.

How a donation is protected

  1. 01

    The payment

    The transaction is executed by the licensed payment provider.

  2. 02

    The record

    The gift is recorded against that specific organisation and that specific point.

  3. 03

    The access

    Only authorised users of the organisation can see its data.

  4. 04

    The reconciliation

    Amounts are agreed against the provider's data, so the financial picture is auditable.

What we do not claim

Credibility is lost faster by one overstated claim than by a missing badge.

  • We are not a bank

    Donation POS is not a bank and not a payment institution.

  • We are not a public authority

    We are not a state or EU body and we grant no official approval.

  • Verified is a platform programme

    Verification is carried out by us and does not replace state licensing or certification.

  • We take on no tax responsibility

    The issuer of every document and every certificate is the organisation itself.

Frequently asked questions

Who holds the money?

The organisation's payment account. Donations are not pooled into a shared account with other organisations.

Can one organisation see another's data?

No. Access is scoped to the organisation of the user's session.

Are you PCI DSS certified?

Card processing is performed by the licensed payment providers, which operate under their own compliance standards.

  • Content confirmation required Per-provider detail (compliance standards, processing location) is provided on request and confirmed per country.

Ask for the detail

If your organisation has specific security or data-protection requirements, raise them with us.