Your supporters trusted you with their data. Here’s how we protect it.
Charities hold some of the most sensitive data there is — donor details, safeguarding records, case notes about vulnerable people. A CRM isn’t just a productivity tool for your charity; it’s a custodian of the trust your supporters and beneficiaries placed in you. This page sets out, plainly, how we look after it.
How we protect your data
UK-hosted
Alder’s infrastructure is UK-based. Your data doesn’t leave UK jurisdiction as part of normal operation — straightforward for GDPR compliance, and important for charities with safeguarding obligations.
Encrypted at rest and in transit
All data is encrypted in transit and at rest. Sensitive fields — safeguarding and case records — are protected so that having a copy of the underlying storage isn’t the same as being able to read it.
Backed up hourly
Automatic backups on a rolling hourly, daily, and monthly schedule, stored separately from live data, with a tested disaster recovery policy. You should never have to think about whether your records are backed up. They are.
Role-based access
Not everyone in your charity needs to see everything. Case notes, safeguarding records, and financial data are visible only to the people who need them for their role.
If something ever goes wrong
No system is unbreachable, and any provider who tells you otherwise isn’t being straight with you. What we can promise is how we’d handle it: we will tell you plainly and promptly if your charity’s data is ever affected, we will tell you what we know and what we don’t yet know, and we will not wait until we have a polished statement to start telling you. You have your own notification obligations — to supporters, beneficiaries, regulators — and you can’t meet them if we’re not straight with you first.
Reviewed, not just built
We undergo annual security audits, and your data is replicated across multiple UK data centres for added resilience. We’re not yet ISO 27001 or Cyber Essentials certified — formal certification is a serious ongoing investment, and most CRM providers serving charities your size aren’t certified either — but we’re committed to achieving ISO 27001 compliance by the time we’ve onboarded our first 100 charities. We believe charities deserve enterprise-grade security without enterprise pricing.
Compliance built in, not bolted on
Consent management, data retention policies, subject access request handling, audit trails — these are built into Alder as product features, not just backend safeguards. Charities are expected to demonstrate GDPR compliance, not just have it in theory, and Alder’s compliance tools exist to make that demonstrable.
Questions about how Alder handles your data?
We’d rather answer this directly than have you guess. Get in touch and we’ll walk you through it.