OneDonateOneDonate
    Back to Home

    Information Security Policy

    Last updated: 14 August 2026

    One Donate Ltd (trading as OneDonate)

    Company Number: 16454442 (registered in England & Wales)

    Website: https://onedonate.co.uk

    1. Purpose and Scope

    This Information Security Policy sets out the principles, responsibilities, and controls that One Donate Ltd ("the Company") applies to protect the confidentiality, integrity, and availability of all information assets. It applies to all employees, contractors, and third-party service providers who access Company systems, data, or infrastructure.

    The scope of this policy covers:

    • Personal data of donors, charity partners, and platform users
    • Internal business data and intellectual property
    • Cloud-hosted infrastructure, applications, and integrations
    • All devices and networks used to access Company systems

    2. Data Protection Principles

    The Company processes personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We adhere to the following principles:

    • Lawfulness, fairness, and transparency: Data is processed lawfully with clear communication to data subjects.
    • Purpose limitation: Data is collected for specified, explicit, and legitimate purposes only.
    • Data minimisation: Only data that is necessary for the stated purpose is collected and processed.
    • Accuracy: Reasonable steps are taken to ensure personal data is kept accurate and up to date.
    • Storage limitation: Data is retained only for as long as necessary to fulfil its purpose.
    • Integrity and confidentiality: Appropriate security measures are applied to protect data against unauthorised access, loss, or damage.
    • Accountability: The Company maintains records and evidence of compliance with these principles.

    3. Access Control and User Authentication

    Access to Company systems and data is governed by the principle of least privilege. Controls include:

    • Role-based access control (RBAC) applied across all internal and production systems
    • Multi-factor authentication (MFA) required for all administrative and production environment access
    • Unique user accounts for all personnel - shared credentials are prohibited
    • Access reviews conducted quarterly; permissions revoked promptly upon role change or departure
    • Privileged access restricted to authorised senior engineering personnel only

    4. Technical Security Measures

    Encryption

    • All data in transit is encrypted using TLS 1.2 or higher
    • Sensitive data at rest is encrypted using AES-256 or equivalent industry-standard algorithms
    • Payment data is processed through PCI DSS-compliant third-party providers and is not stored on Company systems

    Secure Hosting

    • The OneDonate platform is hosted on reputable cloud infrastructure providers with ISO 27001 and SOC 2 certifications
    • Production environments are logically separated from development and staging environments
    • Network firewalls, intrusion detection, and DDoS mitigation are in place

    Patching and Vulnerability Management

    • Critical security patches are applied within 48 hours of release
    • Non-critical patches are applied within 14 days as part of the regular maintenance cycle
    • Automated dependency scanning is used to identify known vulnerabilities in application libraries

    5. Incident Response and Breach Notification

    The Company maintains a documented incident response plan covering identification, containment, eradication, recovery, and post-incident review. Key commitments include:

    • All suspected security incidents are reported internally within 4 hours of discovery
    • The Information Commissioner's Office (ICO) will be notified within 72 hours of becoming aware of a qualifying personal data breach, as required under UK GDPR Article 33
    • Affected data subjects will be notified without undue delay where a breach poses a high risk to their rights and freedoms
    • Post-incident reviews are conducted to identify root causes and implement corrective actions
    • Incident logs are maintained for a minimum of 24 months

    6. Third-Party Service Providers and Integrations

    The Company engages third-party providers for hosting, payment processing, analytics, and communication services. All third parties that process personal data on behalf of the Company are subject to:

    • Due diligence assessments prior to engagement, including review of security certifications and data processing practices
    • Written Data Processing Agreements (DPAs) in compliance with UK GDPR Article 28
    • Contractual obligations to notify the Company promptly of any security incidents
    • Periodic review of third-party compliance and security posture

    7. Data Retention and Secure Deletion

    Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The Company's retention practices include:

    • Donor transaction records retained for 7 years in line with HMRC requirements for Gift Aid
    • User account data deleted or anonymised within 30 days of account closure, unless a longer retention period is required by law
    • Automated processes to identify and purge data that has exceeded its retention period
    • Secure deletion methods applied to all data removed from production systems, including overwriting and cryptographic erasure where applicable

    8. Policy Review and Governance

    This policy is reviewed at least annually, or following a significant security incident, a material change in processing activities, or updates to relevant legislation. Governance responsibilities include:

    • The Company's leadership team is accountable for information security strategy and resourcing
    • A designated data protection lead oversees compliance with UK GDPR and this policy
    • All personnel receive security awareness training upon onboarding and annually thereafter
    • Policy changes are communicated to all relevant staff and, where appropriate, to partners and users

    For enquiries regarding this policy, please contact us at info@onedonate.co.uk.

    One Donate Ltd - trading as OneDonate