Legal
Last updated: 6 August 2026. Reviewed weekly; next full review of this page: 6 November 2026.
This policy describes how Impacturi (operated by Clickonic Ltd) protects the personal data and donor information entrusted to us by our customers. We handle data belonging to charities and their donors, and we take that responsibility seriously.
All data transmitted between users and the platform is encrypted using TLS. This includes browser sessions, API calls, CRM sync connections, and file uploads. We do not support unencrypted HTTP connections.
All data stored in the database is encrypted at rest using AES-256, provided by the hosting infrastructure. Uploaded files (logos, photos) are stored in Supabase Storage with the same encryption standards.
When a charity connects an external CRM (such as Beacon or Donorfy), the API credential is encrypted at rest in a dedicated secrets vault, separate from the ordinary application tables. It is decrypted only in memory, only for the duration of that charity's own sync, and is never returned to the browser. Access is restricted to the charity that created it, and that ownership is proved on the server before any operation runs, including disconnection.
We also limit what a connected CRM can expose if something goes wrong upstream. Error responses from a CRM are recorded by status code only, never by content, so a fault at the CRM's end cannot copy supporter records into our logs or our error monitoring. Credentials and personal data are stripped from anything sent to our error-monitoring provider. Every sync is bounded, so no single connection can be used to exhaust the platform.
Disconnecting is immediate and complete: the stored credential is destroyed at the point you disconnect. You can also revoke the key at your CRM at any time, without involving us, and the connection stops working straight away.
Database backups are managed automatically by Supabase. Backups are encrypted and retained according to the hosting provider's backup policy. We do not maintain separate backup infrastructure.
Since 6 August 2026 our security review runs as an automated job every Monday at 08:00 rather than as a periodic manual exercise. Each run is recorded, and a failure raises an alert the same morning.
We maintain an Incident Response Plan that defines how we detect, respond to, and communicate about security incidents. In the event of a personal data breach, Clickonic (as Processor) will notify the affected charity (as Controller) within 24 hours of discovery. The charity is then responsible for assessing ICO notification requirements within the statutory 72-hour window.
All individuals with access to production systems are bound by confidentiality obligations. Access is granted on a need-to-know basis and reviewed regularly.
Our infrastructure providers hold the following certifications:
Impacturi is working towards Cyber Essentials certification. This page will be updated when certification is achieved.
As a customer, you are responsible for:
For security questions, to report a vulnerability, or to request a copy of this policy in PDF format, contact:
Security Team, Clickonic Ltd
security@impacturi.com
Dermot Dennehy, Founder, Clickonic Ltd
security@impacturi.com
This policy is reviewed and updated regularly. The "last updated" date at the top of this page reflects the most recent revision.