Security & Data Protection

The security of your data is our highest priority. Volunteeria is built from the ground up with data isolation, encryption, and privacy at its core.

Clear information before you decide

Volunteeria recognises that the confidentiality, integrity and availability of your organisation's data are vital to your operations and to the privacy of your volunteers. Security and data protection are built into the platform from the ground up - not bolted on afterwards - and our protocols are reviewed regularly.

We also believe in being straightforward. If your trustees, board or procurement team have questions, we are happy to give honest, plain-English answers and complete your security or data-protection questionnaire.

Before you sign up, we can send you a Data Protection Impact Assessment (DPIA) support pack and a pre-contract copy of our Customer Agreement, including the Data Processing Agreement (DPA). Together, these give decision-makers the practical, security and contractual detail they need to make a fully informed choice.

We do not look at your data, and we never sell it

This is the question charities ask us most, so here is the plain answer. Volunteeria is a tool you use - not a business built on your information. Your volunteers' details are yours. We have no interest in them, no commercial use for them, and no intention of ever looking at them.

Never sold, never shared

Your data and your volunteers' personal details are never sold, rented, licensed or passed to data brokers, advertisers or anyone else for their own purposes. There is no version of Volunteeria where that happens.

Nobody browses your records

In normal running, your data is simply stored and served back to your own authorised users. No one at Volunteeria reads, reviews or analyses your volunteer records, messages or documents.

Support access only when you ask

If you report a problem we cannot diagnose any other way, we ask your permission first, look only at what is needed to fix that specific issue, and stop as soon as it is resolved. You can always decline and ask us to work from screenshots or a call instead.

Never used to train AI

Your organisation's data is never used to train or fine-tune AI or machine-learning models, ours or anyone else's, and never used for research, benchmarking or product analytics.

We never market to your volunteers

We do not contact your volunteers to promote anything. Any email a volunteer receives is the result of your organisation using the software - not us reaching out.

It stays yours, and you can take it

Export everything to CSV whenever you like, with no charge and no permission needed. If you leave, your data is deleted - you are never locked in by your own records.

These commitments are written into our legal terms, so they are contractual promises and not just a statement on a web page.

Built for GDPR
Export, deletion and DPA included
HTTPS Everywhere
Encrypted connections
Schema Isolation
Per-organisation data separation

Data Isolation

Each organisation's data lives in its own isolated PostgreSQL schema. There is no shared database space, no risk of data leakage between tenants, and no possibility of one organisation accessing another's volunteers, tasks, or messages.

  • One schema per organisation
  • Complete separation of volunteer records
  • No cross-tenant queries possible

Encryption

All data transmitted between your browser and Volunteeria is encrypted in transit with HTTPS (TLS). Passwords are never stored in plain text - they are salted and hashed with scrypt, a deliberately slow, memory-hard algorithm that makes stolen hashes impractical to crack. Nobody at Volunteeria can read or recover a password, including us. Uploaded files are stored securely with access restricted to authenticated users within your organisation.

  • TLS encryption for all traffic
  • Salted scrypt password hashing
  • Encrypted at rest on managed infrastructure
  • Secure, access-controlled file storage

Access Control

Organisation admins retain control over staff roles and safeguarding nominations. All authorised staff can use the wider safeguarding-readiness overview, while concern reports, alerts and handling records are restricted to the nominated Primary and Secondary Safeguarding Leads. Volunteers can see their own report and its status, but never internal staff action notes. Access can be revoked instantly.

  • Admin and coordinator roles
  • Per-organisation permission boundaries
  • Configurable administrator-only location mapping
  • Named Primary and Secondary Safeguarding Leads
  • Lead-only concern records and handling actions
  • Instant access revocation

Infrastructure

Volunteeria runs on Render's managed enterprise cloud infrastructure with Cloudflare protection in front and private Cloudflare R2 storage for uploaded files. The PostgreSQL database is not exposed to the public internet, and automated daily database backups reduce the risk of data loss.

  • Managed enterprise cloud hosting
  • Cloudflare DDoS, SSL and private EU file storage
  • Database isolated from the public internet
  • Automated daily backups

Audit & Compliance

Every significant change is logged. View per-volunteer audit trails, organisation-wide activity logs, and system audit records. Staff must accept terms of service, with legal acceptance tracked including timestamp and IP address.

  • Full audit trails per volunteer
  • Organisation activity logs
  • Separately authorised export users
  • Terms acceptance tracking
  • GDPR data export and deletion

Session Security

Sessions expire after one hour of inactivity. Cryptographically random session tokens prevent stale requests from maintaining access after logout. CSRF protection guards against cross-site request forgery on all forms.

  • 1-hour inactivity timeout
  • Cryptographic session tokens
  • CSRF protection on all forms
  • HttpOnly, Secure, SameSite cookies
  • Rate limiting on sensitive endpoints

Data Residency & Hosting

Volunteeria's application, account and database records are hosted by Render in Frankfurt, Germany. Uploaded file content is stored in a private Cloudflare R2 bucket restricted to the European Union jurisdiction. Both locations are inside the European Economic Area, data is encrypted in transit and at rest, and the database is kept off the public internet. If you have a requirement for a different location, ask us before you commit.

  • Encrypted in transit and at rest
  • Application and database hosting in Frankfurt
  • Private uploaded-file storage within the EU jurisdiction
  • Other regions arranged on request
  • Data Processing Agreement (DPA) available
  • Data Protection Impact Assessment (DPIA) support pack available
  • Pre-contract Customer Agreement available for review
  • Happy to complete your security questionnaire

Who else touches your data

Running Volunteeria needs a small number of specialist providers - for hosting, security, file storage, payments and email. These are our sub-processors. They handle only the part of the service they provide, are bound by their own data protection obligations, and are never permitted to use your data for their own purposes. We publish the full list because your trustees and IT advisers should be able to check it without having to ask.

Provider What they do Where
Render Hosting and database EEA - Frankfurt, Germany
Cloudflare Network security, DDoS protection, encrypted delivery and private uploaded-file storage Global edge network for traffic; EU jurisdiction for stored files
Zoho Transactional email, such as invitations and notifications EEA - Netherlands
Stripe Subscription payments. Handles your billing details only - never volunteer records EEA / UK
Sentry Error monitoring. Reports are scrubbed before they are sent, so no passwords, tokens, cookies, email addresses or IP addresses leave the platform No personal data transmitted

That is the complete list. We will tell you before we add or replace a sub-processor, so you always have the chance to raise a concern first.

Additional security practices

Error monitoring

Sentry error tracking monitors the platform for issues. All error reports are scrubbed of PII before transmission - passwords, tokens, cookies, email addresses, and IP addresses are never sent to external services.

Database migrations

Schema changes are applied automatically and safely. New columns are added only when missing, with no destructive operations. This ensures data integrity is preserved during platform updates.

Email verification

All staff and volunteer accounts require email verification before full activation. Password reset tokens expire after 24 hours. Staff invitation tokens expire after 7 days.

Data policy

We provide clear data policies for both staff and volunteers. Organisations can export volunteer data at any time. Volunteers can request account deletion, with staff approval workflows ensuring responsible data handling.

If something goes wrong

No provider can promise a breach will never happen, so what matters is what follows. If we become aware of a personal data breach affecting your organisation, we will tell you without undue delay and in any event within 72 hours, and give you what you need to assess it and meet your own obligations to the ICO and to the people affected.

No lock-in

You can export everything you hold in Volunteeria at any time, in full, at no cost and without asking our permission. If you ever leave, your data is deleted - you are never dependent on us to keep a usable copy of your own records.

Questions about security?

We are happy to discuss our security practices in detail. Get in touch and we will provide honest, thorough answers.

Book a demo