Data Processing Agreement

1. Parties

This Data Processing Agreement (“DPA“) is between:

  • the charity, mosque, or other organisation using the FundSorted service (“Controller“, “you“); and
  • AQNTech, trading as FundSorted (“Processor“, “we“, “us“),

and forms part of, and is incorporated into, the agreement under which you use the FundSorted service (the “Service Agreement“).

2. Subject matter and duration

This DPA governs our processing of personal data on your behalf for as long as we provide the FundSorted service to you, plus any period afterwards during which we retain data under Section 10 (Retention and deletion).

3. Nature and purpose of processing

We process personal data on your instructions to:

  • administer donation collection through your connected payment provider (donations themselves are paid directly into your own account and never pass through us — see our Privacy Policy);
  • prepare, check and submit Gift Aid and Gift Aid Small Donations Scheme (GASDS) claims to HMRC on your behalf;
  • send donor communications by email and WhatsApp, including receipts, campaigns and (where you use it) AI-assisted donor messaging; and
  • maintain the records needed to support the above, including the retention required by HMRC.

4. Types of personal data and categories of data subjects

Data subjects: your donors and supporters.

Personal data: name, address and postcode, email address, phone number, donation amounts and dates, Gift Aid declaration status, payment metadata (excluding full card numbers, which we never receive), and the content of WhatsApp and email communications between you and your donors.

We are not aware of this processing involving any special category data as its purpose, though we recognise that a donation to a religious organisation can itself be capable of revealing religious belief. We do not use donor data to infer, profile, or act on religious belief, and we recommend you consider this in your own organisation’s records of processing.

5. Our obligations as Processor

We will:

  • process personal data only on your documented instructions, including regarding international transfers, unless required to do otherwise by law (in which case we’ll tell you first, unless the law prohibits this);
  • ensure everyone with access to the data is bound by confidentiality;
  • implement appropriate technical and organisational security measures (see Section 8);
  • only engage a sub-processor with your general authorisation (see Section 6) and under an equivalent written contract;
  • assist you, so far as reasonably possible, in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection);
  • assist you in meeting your own obligations around security, breach notification, and data protection impact assessments, taking into account the nature of processing and information available to us;
  • at your choice, delete or return all personal data at the end of the Service Agreement, subject to Section 10; and
  • make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits under Section 9.

6. Sub-processors

You give us general authorisation to engage the sub-processors listed on our Sub-processors page, which we keep up to date. If we intend to add or replace a sub-processor, we’ll notify you in advance and give you the opportunity to object on reasonable data protection grounds. We remain fully responsible to you for any sub-processor’s performance of its obligations.

Services you connect yourself — such as your own Stripe account, your own WhatsApp Business Account, or your own Anthropic (Claude) API key — are not sub-processors under this DPA. Where you provide us with credentials for a third-party service you hold directly, our software acts on your instruction within your own account, but that provider processes data under its own contract and terms with you, not on our instruction. You remain responsible for your own arrangements with those providers, in the same way you would for any other third-party tool connected to your organisation’s systems.

7. International transfers

Where processing personal data involves transferring it outside the UK — for example, to a sub-processor based in the United States — we ensure an appropriate transfer mechanism is in place first, such as the UK International Data Transfer Addendum or Standard Contractual Clauses, consistent with our obligations under Section 5.

8. Security measures

We maintain technical and organisational measures appropriate to the risk, including: encrypted connections (HTTPS) across the service, restricted and logged access to production systems, separation of donor financial data from payment card details (which we never store), and regular review of access permissions. We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with enough information to let you meet your own 72-hour notification obligation to the ICO where one applies.

9. Audits

You may request information reasonably necessary to verify our compliance with this DPA. Where a physical audit is genuinely necessary and information alone isn’t sufficient, we’ll agree reasonable scope, notice and confidentiality terms with you rather than disrupting the service for our other clients.

10. Retention and deletion

On request, or at the end of the Service Agreement, we will delete or return personal data we hold on your behalf — except where we’re required to retain it by law. In particular, HMRC requires Gift Aid records to be retained for 6 years after the end of the tax year they relate to; where a donor’s data underpins a submitted Gift Aid or GASDS claim, we retain only what that requirement covers (their name, address, and the relevant donation records) until that period expires, and delete or anonymise everything else. This mirrors the approach we take when a donor exercises their own right to erasure directly.

11. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Service Agreement. Nothing in this DPA limits either party’s liability for matters which cannot be limited under UK GDPR.

12. Governing law

This DPA is governed by the law of England and Wales, consistent with the Service Agreement.