Five questions to ask any software vendor about your donors' data
Your donor records hold names, addresses, giving history, and sometimes notes about people's lives. Before they go into someone else's software, it's fair to ask how they'll be treated. Here are five questions to ask, and what a good answer sounds like.
1. Where does our data live, and is it encrypted?
A good answer names the company that hosts the servers, says the data is encrypted both where it's stored and while it travels, and says who can get into those servers. "It's in the cloud" doesn't tell you anything.
2. Who at your company can see our records, and will we know when they do?
Look for access limited to named staff who need it, each with their own login and no shared passwords. The best answer is that every time support opens your data, it's logged somewhere you can see.
3. Do you ever sell our data or share it with anyone?
You want a plain no, in writing, in the contract or the privacy policy. If the answer mentions "partners" or "marketing purposes," ask exactly who and for what.
4. How does AI touch our data?
Ask whether your records are used to train AI models, whether any AI feature sends your data to another company, and whether you can use the software without those features. A good answer is specific and leaves the choice with you.
5. What happens if there's a breach?
A good answer is a written incident response plan with a set deadline for telling you what happened, what data was involved and what they're doing about it. "We'd let you know" isn't a plan.
Ask for the answers in writing, and keep them with your contract.
|