Privacy Policy
Effective May 15, 2018
The privacy policy of iDonate LLC (iDonate) begins with our commitment to protecting individual privacy by not sharing personal information with outside parties.
GDPR and personal information collection
In accordance with General Data Protection Regulation (GDPR) standards, of which iDonate has been compliant, this website collects personal information submitted by the site visitor for the sole purpose of follow-up communication or to maintain the integrity and security of donor information within our database. This may include information such as your name, email address, mailing address, phone number, and Social Security number. When you submit personal information to this website, you understand and agree that this information may be transferred across state or national boundaries.
We limit access to non-public personal information to those employees, representatives, and agents who need to know in order to produce compliance reporting, service your donation, and provide you with a broad range of services and products. Our employees, representatives, and agents are required to maintain and protect the confidentiality of your personal information and must follow established privacy procedures. We maintain physical, electronic, and procedural safeguards to protect your personal information.
We strive to keep our customer records complete and accurate.
Your GDPR Rights
Most of the information we have about you is contained in tax forms that you receive from us and information that you submit to obtain our products and services. The information you give us is stored indefinitely unless you request its removal. You have the right to review your information and notify us if you believe any information should be corrected or updated. To initiate a review or raise a concern, contact us at support@idonate.com.
Usage of your personal information
iDonate recognizes and appreciates the importance of responsible use of information collected on this website. We will never sell, trade, or rent your personal information with anyone else, nor send mailings on behalf of other organizations, except in cases in which (a) we employ the use of a mailing company to distribute our own standard communications to you, or (b) we employ the use of a research firm to aid us in collecting your survey responses (in which your participation in such research efforts is purely voluntary on your part).
Additionally, we use the personal information we collect in connection with providing you our services to detect and prevent fraudulent activity. We share this information with a third party service provider to assist us with this effort.
Use of cookies
When you visit this website, you can surf the site anonymously and access information without revealing your identity. Please be aware that we use two kinds of “cookies” to track your visit – i.e., transfer a small amount of data to your browser by a Web server intended to be read by the server that gave it to you. This cookie serves as your identification card, recording information you provide and allowing you to stay logged in. It cannot be executed as code or deliver viruses. We also use third-party cookies for the purposes of analytics, advertising, integrated social media and functional services.
Most browsers are initially set to accept cookies. You can set your browser to notify you when you receive a cookie, giving you the chance to decide whether to accept it. In some instances, accepting a cookie is not optional. If you choose not to accept the cookie, you may not be able to participate in the related action.
Other information
Our Web servers automatically log the IP/Internet address of your computer, the browser type, and browser version you are using. Forms you submit to us may also automatically log this information, as well as the date and time the form was submitted. Under no circumstances does this information identify you personally. You remain anonymous unless you have otherwise provided this website with personal information.
By accessing or using this website, you agree to the Privacy Policy presented here. If you do not agree to these terms, please do not access or use this site. iDonate reserves the right to change the Privacy Policy from time to time at its sole discretion. Your use of this site will be subject to the most current version at the time of such use.
Customer Responsibilities and Obligations
- Providing Required Materials: The customer must provide all necessary materials to the SaaS provider to enable efficient service delivery. This includes obtaining required consents from authorized users to allow both the customer and the provider to engage in activities related to the services.
- Data Integrity: The customer is responsible for using reasonable efforts to ensure the integrity of any data submitted to the SaaS provider.
- Access to Environment: The customer must permit the SaaS provider and its personnel reasonable access to the customer’s environment to facilitate the delivery of the services.
- Authorized Users and Access Control: Only authorized users and personnel of the customer are allowed to access and use the SaaS services, and such use must align with the terms of the SaaS license.
- Customer Environment: The customer is responsible for making any changes to their environment (e.g., technical setup) required to support the SaaS services.
- Prohibited Activities: The customer is prohibited from using the SaaS services to:
- Break any laws or infringe on the rights of others.
- Publish or transmit defamatory, offensive, or unwanted material.
- Damage, interfere with, or interrupt the supply of the services.
- Account Security: The customer is responsible for maintaining the security of their account and passwords. The provider is not liable for any losses resulting from security breaches due to customer negligence.
- Account Activity: The customer is responsible for all content posted and activities that occur under their account. This includes content posted by third parties who may have account access.
- Transmission of Data: The technical processing and transmission of service-related content may be transferred over various networks and may require adaptation to meet technical requirements.
- Assistance for Service Changes: If the SaaS provider requires changes to the customer environment to maintain or enhance service delivery, the customer must cooperate or implement the necessary changes.
Prohibited Use of SaaS Services
- Legal Compliance: The customer and authorized users must not use the SaaS services in violation of any legal rights or laws, including intellectual property rights, and they must not introduce malicious programs into the SaaS provider’s system (e.g., viruses, worms).
- Security Breaches: Activities such as logging into unauthorized accounts, corrupting data, or disrupting network services are prohibited.
- Unsolicited Messaging: The SaaS services must not be used to send unsolicited emails or messages in breach of spam regulations.
- Privacy Violations: The customer is prohibited from using the services to breach anyone’s privacy or engage in identity theft or phishing.
iDonate has specific responsibilities and commitments regarding the security, availability, and confidentiality of its SaaS platform, as outlined. These commitments include regular audits, safeguarding personal data, ensuring system availability, and protecting against potential security breaches. iDonate takes comprehensive steps to ensure the security, availability, and confidentiality of the SaaS platform.
Here’s a breakdown of iDonate's obligations:
- Security Commitments
- iDonate emphasizes the importance of data security and has several measures in place to protect both donor and customer data.
- iDonate conducts annual SOC 2 Type 2 audits, which examine how data is managed and ensure that its processes and systems meet the strictest security standards.
- Penetration tests are regularly carried out to simulate cyberattacks, helping to identify and close any vulnerabilities in the system.
- iDonate commits to maintaining physical, electronic, and procedural safeguards to protect personal information. This includes restricting access to sensitive information to authorized personnel only.
- Availability Commitments
- iDonate commits to making the system available 24 hours a day, 7 days a week, with the following exceptions:
- Planned Downtime: Scheduled maintenance occurs between 10:00 p.m. Saturday and 2:00 a.m. Sunday (CST) and requires 8 hours of prior electronic notice to the subscriber.
- Emergency Downtime: In the event of unforeseen circumstances, emergency downtime may occur without prior notice, though iDonate will aim to minimize disruption.
- iDonate takes commercially reasonable efforts to ensure uninterrupted availability of its platform, except during the defined downtimes.
- Confidentiality Commitments
- iDonate acknowledges the sensitivity of customer and donor data. The system is designed to protect confidential information, including personal data like names, addresses, and payment details.
- Confidential User Data (e.g., personally identifiable information) is protected, and iDonate agrees not to sell or disclose such data outside of the system’s operational requirements.
- Any sharing of confidential information must be authorized or necessary for the operation of the system and within the scope of the agreement.
iDonate also has a policy in place for handling GDPR compliance, ensuring that customer data is handled in accordance with international data protection laws.