Clear information before you decide
Volunteeria recognises that the confidentiality, integrity and availability of your organisation's data are vital to your operations and to the privacy of your volunteers. Security and data protection are built into the platform from the ground up - not bolted on afterwards - and our protocols are reviewed regularly.
We also believe in being straightforward. If your trustees, board or procurement team have questions, we are happy to give honest, plain-English answers and complete your security or data-protection questionnaire.
Before you sign up, we can send you a Data Protection Impact Assessment (DPIA) support pack and a pre-contract copy of our Customer Agreement, including the Data Processing Agreement (DPA). Together, these give decision-makers the practical, security and contractual detail they need to make a fully informed choice.
We do not look at your data, and we never sell it
This is the question charities ask us most, so here is the plain answer. Volunteeria is a tool you use - not a business built on your information. Your volunteers' details are yours. We have no interest in them, no commercial use for them, and no intention of ever looking at them.
Never sold, never shared
Your data and your volunteers' personal details are never sold, rented, licensed or passed to data brokers, advertisers or anyone else for their own purposes. There is no version of Volunteeria where that happens.
Nobody browses your records
In normal running, your data is simply stored and served back to your own authorised users. No one at Volunteeria reads, reviews or analyses your volunteer records, messages or documents.
Support access only when you ask
If you report a problem we cannot diagnose any other way, we ask your permission first, look only at what is needed to fix that specific issue, and stop as soon as it is resolved. You can always decline and ask us to work from screenshots or a call instead.
Never used to train AI
Your organisation's data is never used to train or fine-tune AI or machine-learning models, ours or anyone else's, and never used for research, benchmarking or product analytics.
We never market to your volunteers
We do not contact your volunteers to promote anything. Any email a volunteer receives is the result of your organisation using the software - not us reaching out.
It stays yours, and you can take it
Export everything to CSV whenever you like, with no charge and no permission needed. If you leave, your data is deleted - you are never locked in by your own records.
These commitments are written into our legal terms, so they are contractual promises and not just a statement on a web page.
Data Isolation
Each organisation's data lives in its own isolated PostgreSQL schema. There is no shared database space, no risk of data leakage between tenants, and no possibility of one organisation accessing another's volunteers, tasks, or messages.
- One schema per organisation
- Complete separation of volunteer records
- No cross-tenant queries possible
Encryption
All data transmitted between your browser and Volunteeria is encrypted in transit with HTTPS (TLS). Passwords are never stored in plain text - they are salted and hashed with scrypt, a deliberately slow, memory-hard algorithm that makes stolen hashes impractical to crack. Nobody at Volunteeria can read or recover a password, including us. Uploaded files are stored securely with access restricted to authenticated users within your organisation.
- TLS encryption for all traffic
- Salted scrypt password hashing
- Encrypted at rest on managed infrastructure
- Secure, access-controlled file storage
Access Control
Organisation admins retain control over staff roles and safeguarding nominations. All authorised staff can use the wider safeguarding-readiness overview, while concern reports, alerts and handling records are restricted to the nominated Primary and Secondary Safeguarding Leads. Volunteers can see their own report and its status, but never internal staff action notes. Access can be revoked instantly.
- Admin and coordinator roles
- Per-organisation permission boundaries
- Configurable administrator-only location mapping
- Named Primary and Secondary Safeguarding Leads
- Lead-only concern records and handling actions
- Instant access revocation
Infrastructure
Volunteeria runs on Render's managed enterprise cloud infrastructure with Cloudflare protection in front and private Cloudflare R2 storage for uploaded files. The PostgreSQL database is not exposed to the public internet, and automated daily database backups reduce the risk of data loss.
- Managed enterprise cloud hosting
- Cloudflare DDoS, SSL and private EU file storage
- Database isolated from the public internet
- Automated daily backups
Audit & Compliance
Every significant change is logged. View per-volunteer audit trails, organisation-wide activity logs, and system audit records. Staff must accept terms of service, with legal acceptance tracked including timestamp and IP address.
- Full audit trails per volunteer
- Organisation activity logs
- Separately authorised export users
- Terms acceptance tracking
- GDPR data export and deletion
Session Security
Sessions expire after one hour of inactivity. Cryptographically random session tokens prevent stale requests from maintaining access after logout. CSRF protection guards against cross-site request forgery on all forms.
- 1-hour inactivity timeout
- Cryptographic session tokens
- CSRF protection on all forms
- HttpOnly, Secure, SameSite cookies
- Rate limiting on sensitive endpoints
Data Residency & Hosting
Volunteeria's application, account and database records are hosted by Render in Frankfurt, Germany. Uploaded file content is stored in a private Cloudflare R2 bucket restricted to the European Union jurisdiction. Both locations are inside the European Economic Area, data is encrypted in transit and at rest, and the database is kept off the public internet. If you have a requirement for a different location, ask us before you commit.
- Encrypted in transit and at rest
- Application and database hosting in Frankfurt
- Private uploaded-file storage within the EU jurisdiction
- Other regions arranged on request
- Data Processing Agreement (DPA) available
- Data Protection Impact Assessment (DPIA) support pack available
- Pre-contract Customer Agreement available for review
- Happy to complete your security questionnaire
Who else touches your data
Running Volunteeria needs a small number of specialist providers - for hosting, security, file storage, payments and email. These are our sub-processors. They handle only the part of the service they provide, are bound by their own data protection obligations, and are never permitted to use your data for their own purposes. We publish the full list because your trustees and IT advisers should be able to check it without having to ask.
| Provider | What they do | Where |
|---|---|---|
| Render | Hosting and database | EEA - Frankfurt, Germany |
| Cloudflare | Network security, DDoS protection, encrypted delivery and private uploaded-file storage | Global edge network for traffic; EU jurisdiction for stored files |
| Zoho | Transactional email, such as invitations and notifications | EEA - Netherlands |
| Stripe | Subscription payments. Handles your billing details only - never volunteer records | EEA / UK |
| Sentry | Error monitoring. Reports are scrubbed before they are sent, so no passwords, tokens, cookies, email addresses or IP addresses leave the platform | No personal data transmitted |
That is the complete list. We will tell you before we add or replace a sub-processor, so you always have the chance to raise a concern first.
Additional security practices
Error monitoring
Sentry error tracking monitors the platform for issues. All error reports are scrubbed of PII before transmission - passwords, tokens, cookies, email addresses, and IP addresses are never sent to external services.
Database migrations
Schema changes are applied automatically and safely. New columns are added only when missing, with no destructive operations. This ensures data integrity is preserved during platform updates.
Email verification
All staff and volunteer accounts require email verification before full activation. Password reset tokens expire after 24 hours. Staff invitation tokens expire after 7 days.
Data policy
We provide clear data policies for both staff and volunteers. Organisations can export volunteer data at any time. Volunteers can request account deletion, with staff approval workflows ensuring responsible data handling.
If something goes wrong
No provider can promise a breach will never happen, so what matters is what follows. If we become aware of a personal data breach affecting your organisation, we will tell you without undue delay and in any event within 72 hours, and give you what you need to assess it and meet your own obligations to the ICO and to the people affected.
No lock-in
You can export everything you hold in Volunteeria at any time, in full, at no cost and without asking our permission. If you ever leave, your data is deleted - you are never dependent on us to keep a usable copy of your own records.