Privacy

Privacy Policy

This Policy explains how Donexia collects, uses, shares, retains and protects information when you visit our website or use our NGO CRM.

Effective and last updated: 22 July 2026

Privacy at a glance

We use information to provide and secure Donexia, support customers, enable requested integrations and comply with law. NGOs control the donor information they enter into their accounts and are responsible for collecting and using it lawfully.

01

Scope and who we are

This Privacy Policy applies to the Donexia website, web application, customer onboarding, support and related services operated by Datfuslab Technologies Private Limited (“Donexia”, “we”, “us” or “our”).

It covers personal data we process about website visitors, trial users, customer representatives, Authorized Users, support contacts and other people who interact directly with us. It also explains our role when an NGO customer uploads information about donors, volunteers, staff, beneficiaries or other people to Donexia.

This Policy should be read with our Terms and Conditions and any specific order, data-processing agreement or notice presented when data is collected.

02

Our privacy roles

Our role depends on why information is processed:

Donexia as Data Fiduciary

We determine the purpose and means of processing for our website, account administration, billing, security, support and direct business communications.

Donexia as Data Processor

For donor and operational data an NGO places in its CRM account, the NGO generally determines the purpose and Donexia processes that data on its instructions.

If you are a donor, volunteer, beneficiary or employee of a Donexia customer, first direct questions about that NGO’s use of your data to the NGO. We will support the NGO in handling requests where required and technically possible.

03

Information we collect

Account information

Name, email, mobile number, role, login details, preferences and account status.

Organization information

NGO name, type, address, website, registration or tax details, team and plan information.

Donor and donation records

Donor contact details, donation amount and date, campaign, receipt, communication and payment-reference data.

Compliance information

Identifiers or details an NGO chooses to collect for receipt, tax, reporting or record-management workflows.

Billing and transaction data

Subscription invoices, payment status, gateway transaction reference, amount, date and limited settlement metadata.

Technical and usage data

IP address, browser, device, timestamps, pages or features used, error reports, logs and security events.

Support and communication

Demo requests, support tickets, calls, emails, WhatsApp messages, feedback and training records.

Integration data

Tokens, configuration, status and data exchanged with services enabled by an authorized customer.

The exact information depends on the modules used, customer configuration and information voluntarily provided. We ask customers not to upload unnecessary sensitive information or credentials to free-text fields.

04

Sources of information

We may receive information:

  • directly from you through signup, demo, forms, account settings, support or communications;
  • from an NGO customer or its Authorized Users when they create records or import data;
  • automatically from your browser, device, cookies, logs and security systems;
  • from payment gateways, messaging platforms and other integrations enabled by the Customer;
  • from referrals, implementation partners or public business sources where lawful; and
  • from service providers helping us operate, secure, support or analyze Donexia.
05

Why and how we use information

We process information where permitted by applicable law to:

  • create accounts, authenticate users and provide purchased or requested features;
  • store, organize, display, export and transmit Customer Data according to customer instructions;
  • generate donation records, receipts, reports and communications requested by Authorized Users;
  • provide demos, onboarding, migration, training, customization and customer support;
  • manage subscriptions, invoices, renewals, payments and business records;
  • monitor reliability, diagnose errors, prevent fraud and protect accounts and systems;
  • improve usability, performance, documentation and features using appropriately limited data;
  • send service notices and, where permitted, relevant product or marketing communications;
  • establish, exercise or defend legal claims and enforce our agreements; and
  • comply with applicable law, valid legal process and regulatory obligations.

Depending on the context and applicable law, processing may be based on your consent, your voluntary provision of data for a specified purpose, compliance with law, or another lawful use permitted under applicable law. Where processing is based on consent, you may withdraw it using the method provided, subject to processing already completed and other lawful retention requirements.

06

NGO-controlled donor and operational data

NGO customers decide which donor, volunteer, staff, campaign, beneficiary and operational information to enter into Donexia, why to use it, how long it is required, who may access it and which communications to send.

Each NGO customer is responsible for:

  • providing required privacy notices and obtaining valid consent where required;
  • collecting only information needed for lawful, clearly stated purposes;
  • keeping donor and compliance information accurate and updated;
  • handling access, correction, erasure, withdrawal and grievance requests from its data subjects;
  • configuring user permissions and removing access when staff or volunteers leave; and
  • complying with fundraising, tax, accounting, FCRA and communications requirements applicable to it.
If an NGO has contacted you using Donexia, the NGO—not Donexia—normally controls the relationship and should be your first contact for questions about the information in that NGO’s account.
07

Cookies, local storage and analytics

Donexia may use cookies, local storage and similar technologies for account login, session continuity, security, preferences, performance measurement and analytics. Cookies may be placed by us or by service providers whose tools are enabled on the website.

Typical categories

  • Strictly necessary: authentication, security, load balancing and essential website operation.
  • Preference: language, interface and user settings.
  • Analytics: aggregated information about visits, navigation, performance and errors.
  • Marketing: campaign attribution or advertising measurement, only if such tools are enabled and permitted.

You can control many cookies through browser settings. Blocking necessary cookies may prevent login or cause parts of Donexia to stop working. Where required, a consent interface will be provided for non-essential cookies.

08

How we share information

We may share limited information with:

  • Customer administrators and Authorized Users according to account permissions;
  • Service providers supporting hosting, storage, security, communications, analytics, support, billing and operations;
  • Integrations selected by the Customer when an Authorized User enables or uses the integration;
  • Professional advisers such as auditors, accountants, insurers and legal advisers under appropriate duties;
  • Government or legal authorities when disclosure is required by applicable law or valid legal process;
  • Business transaction participants in a merger, financing, acquisition, reorganization or transfer, subject to appropriate safeguards; and
  • Other parties when you direct us or give valid consent.

We do not sell donor lists or Customer Data. We do not authorize service providers to use Customer Data for their own unrelated marketing purposes.

09

Payment and donation transaction information

Subscription payments and donations may be handled through third-party payment gateways. Card numbers, bank credentials, UPI authorization or other payment credentials entered on a gateway’s interface are processed under that provider’s privacy policy and terms.

Donexia may receive and store limited transaction information such as gateway name, transaction reference, status, amount, currency, date, payer details made available to the Customer, refund status and reconciliation metadata. We use this information to display payment status, generate requested records, provide support and prevent fraud.

10

Data locations and international transfers

Donexia and its service providers may process information in India and in other locations where they operate. When information is processed outside India, we will take reasonable contractual, organizational and technical steps appropriate to the data and comply with transfer restrictions that apply at the relevant time.

The location of data may also depend on the hosting, communications, payment or integration providers selected or approved for the Customer’s implementation.

11

How long we retain information

We retain personal data only for as long as reasonably needed for the stated purpose, an active customer relationship, account administration, security, dispute resolution, enforcement, backups and legal or financial recordkeeping.

Retention depends on factors including:

  • the type and sensitivity of the information;
  • the Customer’s subscription status, instructions and available account controls;
  • the period needed to provide support, prevent fraud or resolve disputes;
  • applicable tax, accounting, corporate, employment or regulatory requirements; and
  • technical backup cycles and secure-deletion processes.

NGO customers should export required records before account closure. When data is no longer required, we will delete, anonymize or securely isolate it, subject to legal obligations and technically necessary backup periods.

12

How we protect information

We use reasonable technical and organizational safeguards designed for the nature of the Services and the information processed. Measures may include role-based access, authentication controls, encrypted network transmission, logging, backups, access review, vulnerability management and service-provider assessment, as appropriate.

No internet service, transmission or storage system is completely secure. Customers must protect credentials, assign suitable permissions, maintain secure devices and report suspicious activity promptly.

If we identify a personal-data breach, we will investigate, take reasonable containment and remediation steps, and provide notifications required by applicable law.

13

Your privacy rights and choices

Depending on the relationship, applicable law and any exemptions, you may request to:

  • receive information about the personal data being processed and relevant sharing;
  • access available personal data associated with your account or direct relationship with Donexia;
  • correct inaccurate information or complete and update incomplete information;
  • erase personal data that is no longer necessary, subject to lawful retention;
  • withdraw consent where processing depends on consent;
  • opt out of non-essential marketing communications;
  • raise a grievance and receive a response through our grievance process; and
  • nominate another individual to exercise applicable rights in the circumstances provided by law.

Send requests to info@donexia.in using the subject “Privacy Request”. We may request information reasonably necessary to verify identity, authority and the relevant account before acting. We will respond within the period required by applicable law.

If your request concerns data held in an NGO customer’s Donexia account, contact that NGO first. We may forward the request to the NGO or act on its verified instructions.
14

Children’s personal data

Donexia is a business platform intended for organizations and authorized adult users, not for children to create independent accounts. An NGO may use Donexia for programs involving children only when it has lawful authority, provides required notices, obtains verifiable parental or guardian consent where required and applies suitable access controls.

Customers should avoid entering children’s information unless it is necessary for a legitimate program and supported by their legal and safeguarding procedures. Contact us promptly if you believe children’s data has been entered without proper authority.

15

Service and marketing communications

We may send necessary account, security, billing, support and service notices. These are operational messages and may continue while an account is active.

Where permitted, we may also send product news, event invitations, educational material or offers. You may opt out using the unsubscribe method in the message or by contacting us. Opting out of marketing does not stop necessary service communications.

Communications sent by an NGO customer to its donors are controlled by that NGO. Direct opt-out or consent questions about those messages to the sending NGO.

17

Changes to this Privacy Policy

We may update this Policy when our Services, providers, practices or legal obligations change. The revised version will display a new “last updated” date. If a change materially affects how we handle personal data, we will provide an appropriate additional notice through the website, application, email or another suitable channel.

18

Privacy grievance and contact details

For privacy questions, rights requests, consent withdrawal, complaints or concerns about Donexia’s processing, contact our Privacy and Grievance Contact:

Emailinfo@donexia.in Phone+91 7004063385
CompanyDatfuslab Technologies Private Limited
Postal addressB12, Sector 16B, Noida, Uttar Pradesh, India

Please describe the concern, identify the relevant account or NGO where possible and provide a reliable method for us to respond. We may need to verify identity and authority. We will acknowledge and address grievances within the period required by applicable law.

Back to top