Back to registration
Policy Version:
Active Legal PolicyVersion 2.0

NGO Link & NGO OS Data Policy

Where Compassion Meets Action, While Protecting Your Privacy

Effective Date13/08/2026
What Changed in Version 2.0?

Updated on 13.08.2026 to reflect NGO Link's expanded NGO OS pilot program (Knowledge Retention, Donor & Impact Reporting, and Strategic Communication) and cloud infrastructure migration to AWS (DynamoDB, S3, and Amazon Bedrock AI).

AWS InfrastructureEU-based DynamoDB & S3 storage encryption
Amazon Bedrock AIZero model training on personal data

Introduction

NGO Link (EU-based) connects volunteers with organizations, and now also helps those organizations retain institutional knowledge, manage donor reporting, and run their strategic communications. We are deeply committed to protecting personal data under GDPR, ensuring transparency and trust. We only collect necessary data, store it securely with strict access controls, communicate clearly about its use, adhere to defined retention periods, and only share data with the processors described below. This policy applies to volunteers, organizations ("NGOs") and their staff, board members, and donors whose contact details NGOs choose to store on the platform.

Data We Collect

Volunteer Data

Applicable to NGO-Link

When you register as a volunteer, we collect:

  • Required: Name, email address, password
  • Optional: Surname, professional role, sector, spoken languages, involvement format, availability hours, tools, expertise area, hard skills, soft skills, profile picture

NGO/Organization Data

Applicable to NGO-Link and NGO-OS

When registering as an NGO, we collect:

  • Organization Information: Organization name, email domain, organization type, focus areas, established year, registration number, website, address details, description, logo, social media links
  • Contact Person: Name, email, password, phone number, role in organization, department, bio, profile picture
  • Verification: Verification status and documents (when applicable)
  • Partner Tier Status: Whether an NGO has been granted "Partner" tier by a platform admin. This is an internal account flag, not personal data about any individual, and only affects which AI features are available (see AI Processing Data below).

Project Data

Applicable to NGO-Link

When creating projects, we collect:

Project name, description, location, time commitment, project duration, required skills, status, maximum volunteers, application deadlines, start/end dates.

Pilot 1: Knowledge Retention Data

Applicable to NGO-OS

To help NGOs preserve institutional memory when staff or volunteers leave, we collect:

  • Meeting Notes & Decisions: Meeting type (project, board, sync), date, attendees, status updates, decision points and who approved them, blockers, and action items with assignees and due dates.
  • Organizational Structure: Departments, roles, reporting lines, and which users are assigned to which roles.
  • Handover Dossiers: An AI-generated summary of an outgoing volunteer's or staff member's contributions, key contacts, and decision history, compiled from the data above at the NGO's request.
  • Collaboration Graph (nice-to-have): Derived, aggregated data showing which users have worked together on which projects, generated automatically from project and meeting records.

Pilot 2: Donor & Impact Reporting Data

Applicable to NGO-OS

To help NGOs report to funders, we collect:

  • Donor Records: Donor/funder name, contact email, grant amount and currency, funded projects, and reporting deadlines. Donor contact details are personal data of the individual the NGO lists as their contact.
  • Impact & Activity Metrics: Activities delivered (e.g. workshops, counts, participant numbers), outputs (beneficiaries reached, milestones completed), and testimonials submitted by the NGO.
  • Financial Records: Budgets, actual expenditure, spending categories, and attached receipts or invoices, which may contain personal data (e.g. a named payee) incidental to their content.
  • Derived KPIs: Cost per Beneficiary, Program Expense Ratio, and Donor Retention Rate — all calculated from the records above and not collected directly.

Pilot 3: Strategic Communication Data

Applicable to NGO-OS

To help NGOs keep their public messaging consistent, we collect:

  • Brand Kit: Organization mission statement, tone-of-voice rules per audience, logo and other visual assets, color palette, and fonts. This is organizational, not personal, data.
  • Social Content Drafts: AI-generated or user-authored post drafts, their target channel and audience, approval status, and any linked image or PDF assets.

Project Communication Data

Applicable to NGO-Link and NGO-OS

Each project has a private group chat between the NGO and its accepted volunteers. We collect:

  • Chat messages, shared photos and PDF documents, timestamps, and read/unread status used to trigger daily digest emails.
  • Notification metadata: when a volunteer is accepted onto or removed from a project, and the resulting emails sent to them.

AI Processing Data

Our platform uses Amazon Bedrock (Nova Pro) for:

  • [NGO-LINK] Skill Suggestions: AI analyzes skill descriptions to suggest relevant skills for projects
  • [NGO-LINK] Project Tagging: AI automatically categorizes projects based on descriptions
  • [NGO-LINK] Skill Matching: AI compares volunteer skills with project requirements
  • [NGO-LINK] Contextual Recommendations: AI provides personalized skill recommendations
  • [NGO-OS] Meeting Digests: summarizing raw meeting notes into decisions and action items
  • [NGO-OS] Handover Synthesis: compiling a departing member's activity into a handover dossier
  • [NGO-OS] Donor Report Drafting: compiling "What was done / What changed / What was spent" narratives from project and impact data
  • [NGO-OS] Social Content Drafting: turning a project update into on-brand social copy

Two access tiers apply: Standard-tier NGOs use a "Copy AI Prompt" button and run these prompts themselves in a general AI tool of their choosing (e.g. ChatGPT, Claude, Gemini) outside our platform. In that case, the data leaves our systems only because the NGO chose to paste it elsewhere, and this policy does not cover what happens inside that third-party tool. Partner-tier NGOs get 1-click automation, where the data is sent directly to Amazon Bedrock on their behalf.

We also operate an email-driven AI assistant (bot@ai.ngo-link.org, via Amazon SES) that NGOs can email directly with questions; the content of those emails is processed by Amazon Bedrock to generate a reply.

Important: AI processing is done through AWS's infrastructure. Your personal data is not used to train AI models and is processed only for the specific purposes described above.

Data Storage & Security

Database

  • Primary Storage: Amazon DynamoDB, across dedicated tables for users, organizations, projects, jobs, applications, operational events, meeting notes, organizational structure, handover dossiers, donors, impact metrics, brand kits, and social content.
  • File Storage: Amazon S3, for uploaded profile pictures, logos, chat photos/PDFs, receipts/invoices, and brand assets.
  • Event Processing: DynamoDB Streams and Amazon SQS for background processing of platform activity (e.g. triggering notification emails).
  • Authentication: JWT tokens with secure password hashing (bcrypt).
  • Access Control: Role-based permissions with strict access controls.
  • Encryption: All passwords are hashed using industry-standard bcrypt with salt; data at rest in DynamoDB and S3 is encrypted using AWS-managed encryption.

Compute

Backend logic runs on AWS Lambda (Node.js), managed via the Serverless Framework.

Frontend is a Next.js application deployed on AWS Amplify.

Frontend Storage

  • Local Storage: JWT tokens and user session data stored locally in your browser.
  • Session Management: Automatic token refresh and secure logout functionality.

Third-Party Services

Amazon Web Services: Lambda, DynamoDB, S3, SQS, SES, Bedrock, and Amplify — hosting, storage, email delivery, and AI processing. (EU-based infrastructure)

Data Processing Purposes

Core Platform Functions

  • Account Management: Creating and managing user accounts
  • Authentication: Secure login and session management
  • Project Matching: Connecting volunteers with relevant opportunities
  • Communication: Platform messaging between users, including project group chats and notification emails
  • AI Enhancement: Improving skill matching and project recommendations
  • Knowledge Management: Recording meeting outcomes, organizational structure, and handover information so NGOs retain institutional knowledge as people join or leave
  • Donor & Impact Reporting: Tracking donor relationships and reporting deadlines, and compiling activity, output, and financial data into reports for funders
  • Strategic Communication: Storing brand guidelines and drafting on-brand social content for NGOs to review and publish

Data Retention

User Accounts

  • Active Accounts: Retained while account is active
  • Inactive Accounts: Deleted after 2 years of inactivity
  • Account Deletion: All personal data deleted within 30 days of account closure request

Project Data

  • Active Projects: Retained while project is active
  • Completed Projects: Retained for 1 year for reference and feedback
  • Archived Projects: Deleted after 2 years

Pilot 1: Knowledge Retention Data

  • Meeting Notes & Decision Logs: Retained for the life of the related project, then per the Project Data schedule above
  • Organizational Structure: Retained while the NGO account is active; deleted with account closure
  • Handover Dossiers: Retained for 2 years after generation, for continuity purposes

Pilot 2: Donor & Impact Reporting Data

  • Donor Records & Impact Metrics: Retained for the life of the funding relationship, then for 1 year after the final report is submitted
  • Financial Records (receipts/invoices): Retained per applicable financial record-keeping law

Pilot 3: Strategic Communication Data

  • Brand Kit: Retained while the NGO account is active; deleted with account closure
  • Social Content Drafts: Retained for 1 year after publication or rejection, then deleted

Project Communication Data

Chat Messages & Shared Files: Retained for the life of the related project, then deleted after 1 year, consistent with Completed Project retention.

AI Processing Data

  • Prompts sent to Amazon Bedrock: Processed in real-time, not stored permanently
  • Matching Results: Temporary storage for session duration only
  • No Training Data: Your data is not used to train AI models

Your Rights Under GDPR

You have the right to:

  • Access: Request copies of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a structured format
  • Objection: Object to processing for legitimate interests
  • Withdraw Consent: Withdraw consent for optional data processing

Where a donor's contact details are held by an NGO on our platform, that NGO is the controller for that data and is the first point of contact for a donor's rights request; we act as the NGO's processor for that data.

Data Sharing

We Do NOT Share Your Data With:

  • Third-party advertisers
  • Marketing companies
  • Data brokers
  • Social media platforms (except for your own social media links if provided)
  • NGO-Link/NGO-OS Social Media - Instagram and LinkedIn (about the use case and results, not actual data)

Limited Sharing Only For:

  • Essential Services: Amazon Web Services (Bedrock for AI matching and drafting, SES for email delivery, and underlying hosting/storage), each under an AWS data processing addendum
  • Legal Requirements: When required by law or legal process
  • Platform Security: To prevent fraud or abuse

Cookies & Tracking

Essential Cookies

  • Authentication: JWT tokens for secure login
  • Session Management: User preferences and settings
  • Security: CSRF protection and security measures

No Tracking Cookies

  • We do not use advertising cookies
  • We do not use social media tracking pixels
  • We do not use analytics that track individual users

International Transfers

Primary Storage: AWS infrastructure (EU-based)

Data Breach Procedures

In the unlikely event of a data breach:

  • We will notify the relevant supervisory authority within 72 hours
  • We will notify affected users within 24 hours if the breach poses a high risk
  • We will provide clear information about the breach and protective measures

Children's Privacy

Our platform is not intended for users under 16. We do not knowingly collect data from children under 16. If we become aware of such a collection, we will delete the data immediately.

Contact Information

Data Protection Officer

For privacy inquiries, data subject requests, or concerns:

Email: privacy@ngo-link.org

Address: Fluwelen Burgwal 58, 2511 CJ Den Haag

Response Time: We will respond within 30 days

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data properly.

Policy Updates

This policy was created on 22.10.2025 and last updated on 13.08.2026 to reflect the platform's expanded NGO-OS pilot program and its migration from MongoDB/Google AI to AWS DynamoDB/Amazon Bedrock. We will notify users of any material changes via email and platform notifications.