Privacy Policy

Effective Date: 10/10/2024  |  Last Updated: 1/09/2025

1. Who We Are

nfphub is a cloud-based Software-as-a-Service platform that helps not-for-profit organisations manage their boards and committees more effectively. This Privacy Policy explains how we handle your information when you use our platform.

2. Data Protection Roles

nfphub acts as the data controller for account and billing information that you provide directly to us. For user-generated content such as meeting documents, minutes, and action items, nfphub acts as a data processor on behalf of your organisation.

3. Information We Collect

We collect information you provide when creating an account, such as your name, email address, and organisation details. We also collect content you upload to the platform and automatically collected data including IP addresses, browser type, device information, and usage patterns.

4. How We Use Your Information

We use your information to provide and maintain the service, authenticate your identity, analyse usage to improve the platform, communicate important updates, and comply with legal obligations. We do not use your content for purposes unrelated to service delivery without your consent.

5. Information Sharing

We may share information with trusted service providers who assist in operating the platform, third-party integrations you choose to enable, and legal authorities when required by law. We never sell your personal information to third parties.

6. International Data Transfers

If your data is transferred outside the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission to ensure an adequate level of data protection. We assess the laws of the recipient country and implement supplementary measures where necessary.

7. Data Security

We protect your data using industry-standard security measures including TLS 1.2+ encryption in transit, AES-256 encryption at rest, least-privilege access controls, and comprehensive audit logging. We regularly review and update our security practices to address emerging threats.

8. Data Retention

Active content is retained for the duration of your subscription. Upon account deletion, your data is removed from production systems within 30 days and from backups within 90 days. We may retain certain records longer where required by law.

9. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data, request data portability, restrict or object to processing, and withdraw consent at any time. To exercise any of these rights, please contact us using the details below.

10. Cookies & Analytics

We use essential cookies required for the platform to function, functional cookies that remember your preferences, and analytics cookies that help us understand how the service is used. You can manage your cookie preferences through your browser settings.

11. Third-Party Links

Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those external sites. We encourage you to review the privacy policies of any third-party service before providing your information.

12. Children's Privacy

nfphub is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 16, we will take steps to delete it promptly.

13. Policy Changes

We may update this Privacy Policy from time to time. We will provide at least 30 days' notice of material changes via email or an in-app notification. Your continued use of the service after the updated policy takes effect constitutes your acceptance of the changes.

14. Contact Information

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at privacy@nfphub.io. You may also reach our Data Protection Officer at dpo@nfphub.io.