How we protect your data
Charities hold some of the most sensitive data there is — donor details, safeguarding records, case notes about vulnerable people. A CRM isn’t just a productivity tool for your charity; it’s a custodian of the trust your supporters and beneficiaries placed in you. This page sets out, plainly, how we look after it.
How we protect your data
UK-hosted
Your CRM data lives in the UK — the application, the database, your uploaded files and your backups all sit in UK regions. A few supporting services process data in the EU, such as email delivery and error monitoring, always under UK transfer safeguards and every one of them named on our sub-processors page. Straightforward for GDPR, and important for charities with safeguarding obligations.
Encrypted at rest and in transit
All data is encrypted in transit and at rest. Sensitive fields — safeguarding and case records — are protected so that having a copy of the underlying storage isn’t the same as being able to read it.
Backed up hourly
Automatic backups on a rolling hourly, daily, and monthly schedule, stored separately from live data, with a tested disaster recovery policy. You should never have to think about whether your records are backed up. They are.
Role-based access
Not everyone in your charity needs to see everything. Case notes, safeguarding records, and financial data are visible only to the people who need them for their role.
Security by design
Safeguarding notes and case records are encrypted at field level. Every sensitive action is audit-logged. Your workspace is isolated from every other charity’s — multi-tenancy built properly, not bolted on after launch.
Encryption and standards
TLS 1.3 in transit, AES-256 at rest. Hourly rolling backups stored separately from live data, with a tested disaster recovery plan. Built to meet the expectations of trustees, regulators, and the ICO.
If something ever goes wrong
No system is unbreachable, and any provider who tells you otherwise isn’t being straight with you. What we can promise is how we’d handle it: we will tell you plainly and promptly if your charity’s data is ever affected, we will tell you what we know and what we don’t yet know, and we will not wait until we have a polished statement to start telling you. You have your own notification obligations — to supporters, beneficiaries, regulators — and you can’t meet them if we’re not straight with you first.
If you find a problem, tell us
We publish a responsible disclosure policy so that anyone who spots a security problem in Alder knows exactly where to send it and exactly what protection they have for doing so. It gives good-faith researchers a written safe harbour, sets out what is in scope, and commits us to response times we can be held to. Our contact details are also published in machine-readable form at /.well-known/security.txt. A finding nobody feels safe reporting stays available to whoever finds it next, which is the whole reason that page exists.
Reviewed, not just built
We commission an independent penetration test every 12 months, and your backups are held in a separate UK data centre from the live system — so a failure in one place doesn’t take both. We believe charities deserve enterprise-grade security without enterprise pricing — so we build it in from the ground up, not as an optional extra.
Compliance built in, not bolted on
Consent management, data retention policies, subject access request handling, audit trails — these are built into Alder as product features, not just backend safeguards. Charities are expected to demonstrate GDPR compliance, not just have it in theory, and Alder’s compliance tools exist to make that demonstrable.
Questions about how Alder handles your data?
We’d rather answer this directly than have you guess. Get in touch and we’ll walk you through it.