Privacy
What we hold, why, and what we will never do with it
Beneora processes donor data on behalf of nonprofits. That makes the organization the controller of its donor records and Beneora the processor acting on its instructions.
This page describes our practices in plain language. It is not legal advice, and it is not a data processing agreement. A DPA is being prepared for design partners and will be published when it is reviewed.
Last updated March 1, 2026
Data we hold for an organization
- Donor contact details, household structure, recognition preferences and consent state.
- Gift, pledge, recurring plan, receipt, allocation and fulfillment records.
- Financial reconciliation records: transactions, fees, payouts, deposits and exceptions.
- Audit records of who changed what and when.
Data we hold about platform users
- Account email, name and authentication identifiers.
- Role and organization membership.
- Operational logs needed to run and secure the service.
Commitments
- We do not sell donor data, and we do not share it between organizations.
- We do not use tenant or donor data to train AI models by default.
- We do not enrich donor records with purchased third-party data.
- We do not use donor personal data for our own marketing.
Donor rights requests
Active buildAccess, correction, suppression and deletion requests are handled by the organization that holds the relationship. Beneora provides the tools to action them and records that the action was taken.
Where a receipt or financial record must be retained for legal reasons, deletion of the surrounding personal data is possible while the financial record and its audit history remain.
Retention and export
Active buildAn organization can export its donors, gifts, pledges, funds and reconciliation records in full. Data retention is not our business model, and export is a Release 1 requirement rather than a paid feature.
On account closure, data is deleted after a defined window that will be stated in the agreement before any organization commits.
Subprocessors
DesignedWe use managed cloud hosting and a managed database provider to run the service, and a model provider for the AI features that are enabled. A named subprocessor list will be published alongside the DPA rather than described vaguely here.
Something here unclear, or a claim you think we cannot support? Tell us — correcting this page is cheaper than defending it.
Design-partner program
Judge us on the mechanisms, not the marketing
We are working with a small number of US and Canadian nonprofits who feel the reconciliation and donor-data pain most acutely. Partners shape the sequence, see the honest status of every module, and are never charged for a capability that is still a prototype.