Legal

Privacy Policy

How we collect, use, and protect donor and organisational data under POPIA.

1. Who we are

Donor Management is a South African software platform operated by Code Infinity (Pty) Ltd. We provide donor CRM, Section 18A certificate issuance, and SARS IT3(d) submission tooling to registered NPOs, PBOs, charitable trusts, and faith-based organisations.

This policy describes how we handle personal information, including donor records our customers store on our platform, in line with the Protection of Personal Information Act, 2013 ("POPIA").

2. Personal information we collect

Depending on your relationship with us, we may process:

  • Organisation information: name, PBO/NPO registration numbers, banking details, and staff user accounts.
  • Donor information: names, contact details, tax identifiers, donation amounts, and correspondence, stored on behalf of your organisation.
  • Usage information: pages visited, actions taken, session duration, and technical diagnostics for security and reliability.
  • Marketing information: the details you submit on our Contact form (name, email, message content).

3. How we use personal information

  • To operate the platform, issue Section 18A certificates, and generate IT3(d) BRS files.
  • To secure your account, prevent fraud, and diagnose faults.
  • To respond to enquiries submitted through Contact and support channels.
  • To comply with legal obligations, including SARS-directed reporting requirements.

4. POPIA compliance

We follow the eight conditions for lawful processing set out in POPIA: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation.

Where your data lives

Donor personal information is stored on infrastructure hosted within South Africa. Encrypted backups are retained for disaster-recovery purposes only and are not transferred outside the country without your instruction.

Data subject rights

A donor whose information we hold on behalf of a customer may request access to, correction of, or deletion of their personal information. Requests are directed to the organisation that captured the record; we assist that organisation in fulfilling the request.

5. Security

  • All traffic is served over HTTPS with modern TLS ciphers.
  • Passwords are hashed with argon2. Sensitive fields (e.g. stored PDF passwords) are encrypted at rest with per-account keys.
  • Access to production data is restricted to authorised engineers on a least-privilege basis and is logged.
  • We maintain an audit log of privileged actions and review it periodically.

6. Sharing information

We do not sell personal information. We share it only with the third parties strictly required to run the service: for example our email delivery provider and, when you submit an IT3(d) return, SARS eFiling. A current sub-processor list is available on request.

7. Third-party services on this website

This marketing website (donormanagement.co.za) uses two third-party services from Google. Both are covered by the Google Privacy Policy at policies.google.com/privacy and the Google Terms of Service at policies.google.com/terms.

Google Analytics

We use Google Analytics 4 to understand how visitors use this site: which pages are read, how long they stay, which country they visit from. Google Analytics reads a first-party cookie and sends the information to Google as our data processor. We do not use this data to identify individual visitors, and we have disabled the Google Signals cross-device tracking feature. IP addresses are truncated by Google before storage.

You can opt out of Google Analytics on every website you visit by installing the Google Analytics Opt-out Browser Add-on.

Google reCAPTCHA v3

The Contact form on this site is protected by Google reCAPTCHA v3. reCAPTCHA collects hardware and software information, including device and application data, and sends it to Google to distinguish humans from bots. reCAPTCHA does not display any challenge and collects no additional personal information from the form itself.

Product platform

Third-party services used INSIDE the Donor Management product itself (e.g. our SMTP relay, payment processors, SARS eFiling) are described to each customer organisation on activation and listed in the current sub-processor register.

8. Retention

Donor and donation records are retained for as long as required by South African tax law (currently 5 years from date of issue for Section 18A certificates), or until an organisation instructs us in writing to delete them.

9. Contact the Information Officer

For access requests, complaints, or any POPIA-related enquiry, email our Information Officer at privacy@donormanagement.co.za. We respond within 30 days.