Privacy Policy
Last updated: 2 July 2026
This policy is pending final legal review. Its content may be refined before formal adoption.
Data we collect
We collect and process the following categories of data: the email address used to create and operate your account; information about your organization, such as its name, projects, contacts, and compliance records entered into the platform by your team; the names and identifying attributes of contacts or beneficiaries that your organization submits for sanctions screening; and technical usage logs, such as authentication events and audit records of screening decisions.
We do not collect more data than is needed to operate the service.
Legal basis for processing
We process account and organization data to perform our contract with you: providing the platform your organization signed up for. We process screening data on the basis of your organization's legitimate interest in meeting its compliance obligations. We process usage and audit logs on the basis of our legitimate interest in keeping the service secure and traceable. Where the law requires consent for a specific processing activity, we ask for it separately.
Where your data is stored
Your data is stored on Supabase infrastructure in the European Union, in the eu-central region (Frankfurt, Germany). The application is served by Vercel at charityos.ai. Data is encrypted in transit using TLS and encrypted at rest by Supabase using AES-256.
Retention and deletion
We retain your data for as long as your organization maintains an active account, and for as long as applicable compliance rules require audit records to be kept. You can request deletion of your account and the personal data associated with it at any time by writing to privacy@charityos.ai. We respond to such requests within the timeframes set by applicable data protection law.
Sharing with third parties
When your organization runs a sanctions screening, the searched name and entity attributes are transmitted to OpenSanctions (yente API) for matching. Only the data needed to perform the search is sent. Screening results are stored with full audit fields: reviewer, decision, written reason, and timestamp.
We do not sell personal data, and we do not share it with third parties for advertising purposes.
Your rights under the GDPR
If you are in the European Economic Area, you have the right to access the personal data we hold about you, to have inaccurate data rectified, to request erasure, and to receive your data in a portable format. You also have the right to lodge a complaint with your supervisory authority. To exercise any of these rights, contact us at privacy@charityos.ai.
Security
Every table in our database is protected by row-level security scoped to your organization, and these access rules are covered by automated tests. All traffic is encrypted. A more detailed summary of our security measures is available on our security page.