DONOR BRIDGE INC.
Privacy Policy
This Privacy Policy ("Policy") describes how Donor Bridge Inc. ("Donor Bridge", "we", "us" or "our") collects, uses, discloses, retains and protects personal information when you visit, access or use our websites, applications, donor and organization portals, donation workflows, BridgeIQ, organization-branded giving experiences, communications and other services that link to this Policy (collectively, the "Services").
This Policy is intended to apply to visitors, donors, prospective donors, organization representatives, administrators, contacts and other individuals who interact with Donor Bridge. It is designed for a Canada-first launch and to support U.S. operations from inception. Additional notices may be presented when you use a specific feature, connect a financial account, interact with a third-party provider or exercise privacy rights.
Donor Bridge provides technology and workflow support. Donor Bridge does not itself receive, hold, custody, liquidate or transfer donated funds or assets, and participating organizations - not Donor Bridge - are responsible for issuing official charitable donation receipts or U.S. charitable acknowledgments. Our Terms of Service describe the Platform and giving workflows in more detail.
1. Scope and Our Privacy Roles
Depending on the context, Donor Bridge may handle personal information in different roles. When we determine why and how personal information is used for our own donor accounts, platform operations, security, fraud prevention, support, compliance, analytics and direct donor-facing services, Donor Bridge generally acts as the organization responsible for that information (often called a "controller" or "business" under privacy laws).
When a participating organization uses Donor Bridge tools to collect or manage personal information for that organization's own purposes, Donor Bridge may process certain information on the organization's behalf as a service provider or processor. Those activities are governed by the applicable Organization Services Agreement and Data Processing Addendum ("DPA"). A participating organization may also independently control personal information it receives for its own receipting, stewardship, fundraising, legal or compliance purposes.
This Policy does not govern the independent privacy practices of a recipient organization, brokerage, bank, payment processor, cryptocurrency processor, donor-advised fund provider, employer-matching provider or other third party. We encourage you to review their privacy notices where applicable.
2. Key Definitions
"Personal Information" means information about an identified or identifiable individual, or substantially similar concepts such as "personal data" or "personal information" under applicable privacy law.
"Sensitive Personal Information" means personal information that applicable law treats as sensitive, which may include financial account information, account credentials, government identifiers, precise geolocation, certain authentication information and other categories designated by law.
"Giving Transaction" means a supported stock donation, cryptocurrency donation, cash/card or bank donation, donor-advised fund grant request, employer-match request or related giving workflow initiated, submitted, authorized or tracked through the Services.
"Recipient Organization" means a charity, qualified donee, U.S. tax-exempt charitable organization or other eligible organization approved for a supported giving workflow.
"Third-Party Provider" means a brokerage, financial institution, financial-data provider, payment processor, cryptocurrency processor, DAF provider, employer-matching provider, identity or verification provider, cloud provider, CRM provider, communications provider, analytics provider or other third party used in connection with the Services.
3. Personal Information We Collect
The information we collect depends on how you interact with Donor Bridge, the giving method you select, the organization you represent and the Third-Party Providers involved. We seek to limit collection to information reasonably necessary for the identified purposes.
|
Category |
Examples |
|---|---|
|
Account and profile information |
Name, email address, mailing address, phone number where provided, account preferences, country or region, account identifiers, organization affiliation and profile information. |
|
Authentication and security information |
Email-based one-time-passcode events, login timestamps, device/session information, security alerts, access logs and information used to protect your account. |
|
Donation and transaction information |
Recipient Organization, campaign or designation, gift type, amount or quantity, date, transaction status, settlement information, acknowledgments, refund/error information and related communications. |
|
Brokerage and investment information |
Connected brokerage or financial institution, account identifiers, account owner information, holdings, security name/symbol, quantity, selected securities, balance or transaction information where relevant, and transfer-related details needed to prepare or track a stock donation. |
|
Cryptocurrency information |
Supported asset, network, amount, transaction identifier/hash, wallet or destination information where supplied by the processor, transaction status and other information needed to facilitate or track a crypto donation. |
|
Payment information |
Payment method type, amount, billing information, processor transaction identifiers, authorization/settlement status, refund/chargeback information and fraud signals. Full card numbers and security codes are intended to be collected and handled by the payment processor rather than stored by Donor Bridge. |
|
DAF information |
DAF provider, fund name, requested grant amount, donor contact information, grant status and related transaction information. DAF credentials are intended to be handled as a secure pass-through by the applicable DAF provider and not stored by Donor Bridge, subject to final integration confirmation. |
|
Employer matching information |
Employer or matching-program information, donation confirmation, match request information, eligibility/status information and contact details needed to submit or track a match. |
|
Receipt and tax-document information |
Copies of receipts or acknowledgments uploaded by Recipient Organizations, receipt identifiers, donor name/address, donation date, amount/value and other information contained in the document. |
|
Organization representative information |
Name, title, email, phone number, organization name, charity registration number or EIN, authorized-representative status, verification information, organization financial destination details and account-administrator activity. |
|
Communications and support information |
Information you submit through forms, email, chat, support requests, surveys, demos, webinars, calls or other communications, including the content and nature of your inquiry. |
|
Device, usage and website information |
IP address, browser/device type, operating system, approximate location derived from IP, pages/screens viewed, clicks, referral source, session duration, cookie identifiers, diagnostics and other usage information. |
|
Compliance, fraud and risk information |
Information reasonably necessary to verify identity or authority, validate organizations, investigate suspected fraud or misuse, respond to sanctions or legal requirements, and protect the Services. |
|
BridgeIQ information |
Questions, prompts, feedback and interaction metadata submitted to BridgeIQ, together with outputs and technical logs needed to provide, secure and improve the feature. At launch, Donor Bridge does not use connected brokerage data or individual giving-transaction data to train general-purpose AI models. |
4. Sources of Personal Information
- Directly from you, when you create an account, enter information, initiate a Giving Transaction, submit a form, contact us or otherwise interact with the Services.
- From connected financial institutions and financial-data providers when you authorize a connection to retrieve information for a supported stock or financial workflow.
- From Recipient Organizations, including organization profile information, receipt/acknowledgment information, donation status, campaign information and donor stewardship or reconciliation information.
- From payment, cryptocurrency, DAF and employer-matching providers in connection with the transaction or request you initiate.
- From public and governmental sources, such as Canadian charity registries, U.S. tax-exempt organization information and other public records used to validate organizations or prevent fraud.
- Automatically from your browser, device and use of the Services through cookies, pixels, logs, analytics and similar technologies.
- From service providers and other third parties that help us with identity, security, fraud prevention, analytics, communications, hosting, CRM, customer support and legal/compliance functions.
5. How We Use Personal Information
- Provide, operate, maintain and support the Services and your Donor Bridge account.
- Facilitate and track Giving Transactions, prepare or transmit donation documentation or instructions, display transaction status and support reconciliation.
- Connect to authorized brokerage or financial-account information and display eligible holdings or other information needed for a supported workflow.
- Provide donation confirmations and make charity-issued receipts or acknowledgments available in donor profiles.
- Provide Recipient Organizations with donor and transaction information they are permitted to receive, including information needed for receipting, reconciliation, stewardship and legally permitted communications.
- Facilitate DAF grant requests and employer-matching requests and communicate related status information.
- Create and administer organization accounts, verify organization eligibility and authorized representatives, and manage organization-branded giving experiences.
- Authenticate users, detect and prevent fraud, investigate misuse, monitor security, enforce agreements and protect Donor Bridge, users, organizations and Third-Party Providers.
- Provide customer support, respond to inquiries, troubleshoot errors and communicate service, security, legal or account updates.
- Operate BridgeIQ and other informational or analytics features and improve their usability, reliability and safety.
- Measure usage, understand how the Services are used, perform research and analytics, improve existing services and develop new features.
- Create aggregated, de-identified or anonymized information where permitted by law for analytics, planning, security, service improvement and business reporting.
- Send marketing or educational communications where permitted by law and consistent with your choices.
- Comply with applicable law, regulatory requirements, court orders, lawful requests, audit obligations and contractual obligations, and establish, exercise or defend legal claims.
We do not use personal information for a materially different purpose without providing additional notice or obtaining consent where required by law.
6. Financial Account Connectivity and Consent
If you choose to connect a brokerage or other financial account, Donor Bridge may will use an approved financial-data provider to facilitate the connection. Depending on the provider and feature, information made available may include account identifiers, account-owner information, holdings, security names or symbols, quantities, balances, transactions and other investment-account information needed for the supported workflow.
You control whether to initiate a connection and must have lawful authority over the account. Donor Bridge will present or rely on appropriate consent and authorization flows. We maintain records of consents and authorizations where reasonably necessary to demonstrate the scope, time and purpose of the access and to comply with legal or contractual requirements.
Brokerage usernames, passwords, security answers, one-time passcodes and similar credentials are intended to be handled by the financial institution or approved connectivity provider rather than received or stored by Donor Bridge. The final technical implementation and provider agreement control, and this statement must be confirmed before publication.
If you revoke permission for future connected-account access, Donor Bridge and the applicable provider will stop future access to the extent required by law and technically supported. Revocation does not undo a transaction or transfer instruction you already authorized and does not require deletion of transaction, consent, audit, security or compliance records that we are permitted or required to retain.
7. Giving Methods and Privacy
7.1 Stock Donations
For a stock donation, Donor Bridge may collect identity/contact information, connected-account information, brokerage identifiers, investment holdings, the selected security and whole-share quantity, transfer details, Recipient Organization information, status, settlement information and receipt-related information. Donor Bridge uses this information to facilitate the donor-authorized workflow and does not itself execute or settle the securities transfer.
7.2 Cryptocurrency Donations
Crypto donations may be processed by an approved crypto provider. Donor Bridge may receive the asset, amount, recipient, processor transaction identifier, blockchain status, wallet/destination information where applicable, and related metadata needed to display or reconcile the transaction. The processor may independently collect additional information under its own privacy policy and legal obligations.
7.3 Cash, Card and Bank Donations
Cash/card or bank-payment transactions may be processed an approved payment provider. The provider may collect card, bank, authentication, fraud and billing information. Donor Bridge is designed not to store full payment-card numbers or card security codes where the processor handles those details directly. We may receive limited transaction, billing, risk, refund, chargeback and status information needed to provide the Services.
7.4 Donor-Advised Funds
U.S. DAF grant requests may be facilitated through an approved provider. Credentials are used as a one-time secure pass-through and are not stored by the provider. Donor Bridge is designed not to receive or store those credentials in the intended integration; final production behavior must be confirmed. Donor Bridge may receive donor-identifying and transaction information needed to initiate, track and reconcile the grant request.
7.5 Employer Matching
For employer matching, Donor Bridge may share donation confirmation, donor contact information and other information required by the employer or matching-program provider. The employer or provider independently determines eligibility and may collect additional information under its own privacy practices.
8. How We Disclose Personal Information
We may disclose personal information in the following circumstances and only to the extent reasonably necessary for the relevant purpose:
- Recipient Organizations. To process or track a Giving Transaction, issue or upload a receipt or acknowledgment, reconcile donations, respond to donor requests and support stewardship or communications where permitted. Once an organization receives information for its own purposes, it may act as an independent organization responsible for that information.
- Financial and transaction providers. To brokerages, banks, financial-data providers, payment processors, crypto processors, DAF providers, employer-matching providers and related institutions needed to provide the feature you requested.
- Service providers and subprocessors. To vendors that provide cloud hosting, CRM, email/OTP, security, logging, analytics, customer support, communications, professional services and other functions on our behalf. We require appropriate contractual or other safeguards where required.
- Professional advisers. To lawyers, auditors, accountants, insurers, consultants and other advisers where reasonably necessary for professional services, legal compliance, audits or risk management.
- Authorities and legal process. To regulators, courts, law enforcement or other authorized persons when required or permitted by law, or where reasonably necessary to protect rights, safety, security, property or the integrity of the Services.
- Business transactions. In connection with a proposed or completed merger, financing, acquisition, reorganization, sale of assets or similar transaction, subject to applicable confidentiality and privacy requirements.
- At your direction or with your consent. Where you instruct us to disclose information, choose to make information public, or consent to another disclosed purpose.
Donor Bridge does not sell personal information. We do not disclose connected brokerage information, financial-account information, receipt information or individual Giving Transaction details to third parties for their independent advertising or marketing purposes.
9. Anonymous and Private Giving Preferences
The Services may allow a donor to request anonymity or limit recognition and stewardship use. "Anonymous" does not necessarily mean anonymous to Donor Bridge, the Recipient Organization, a brokerage, processor, financial institution, DAF provider or other provider where identity information is required to process the transaction, prevent fraud, satisfy legal obligations, maintain records or issue a receipt or acknowledgment.
Where the feature permits, an anonymity preference may limit public display of the donor's identity, recognition by the Recipient Organization, or use of donor information for stewardship communications. Required operational, legal, compliance and receipting disclosures may still occur. The giving flow will provide any material feature-specific choices available to the donor.
10. Participating Organizations and Donor Information
Donor Bridge may make donor information available to a participating organization only as permitted by the Services, the donor's choices, the organization's verification status, applicable law and the Organization Agreement. An organization that receives donor personal information must comply with its own privacy obligations and applicable restrictions on donor data.
Donor Bridge may communicate donor privacy preferences, unsubscribe requests, correction requests or other relevant instructions to a participating organization where appropriate. Organizations are expected to honour those preferences and are prohibited from selling donor lists obtained through Donor Bridge or using donor information for purposes not permitted by the Organization Agreement, subject to applicable law.
Where Donor Bridge processes personal information solely on behalf of an organization, the DPA will address instructions, permitted processing, confidentiality, subprocessors, security, privacy-rights assistance, breach notification, data return/deletion and related obligations.
11. BridgeIQ and Artificial Intelligence
BridgeIQ may process questions, prompts, context supplied by you, usage information and outputs to provide general Q&A, donor education, platform guidance and organization dashboard/analytics assistance. At launch, BridgeIQ is not intended to make decisions that produce legal or similarly significant effects about individuals.
At launch, Donor Bridge does not use connected brokerage information, account credentials, individual Giving Transaction details or charity-issued tax-receipt information to train general-purpose AI models. Donor Bridge may use de-identified, aggregated or operational information to evaluate and improve service quality where permitted by law.
Where a third-party AI or cloud provider is used to process BridgeIQ interactions, that provider may process prompts, outputs and technical data on Donor Bridge's behalf under applicable contractual terms. We will maintain such providers in our vendor/subprocessor governance process. Users should avoid including unnecessary sensitive information in free-text prompts.
12. Cookies, Analytics and Similar Technologies
Donor Bridge and our service providers may use cookies, pixels, local storage, software development kits, log files and similar technologies to operate the Services, authenticate users, remember preferences, measure performance, understand usage, prevent fraud and, where permitted, support marketing.
Cookies may include strictly necessary, functional, analytics/performance and advertising/marketing technologies. Where required by law, non-essential cookies will be used only after appropriate consent, and you will be able to manage preferences through a cookie-management tool or other available settings.
We may use HubSpot and other approved analytics or marketing technologies on public website pages. We do not use connected brokerage information or individual Giving Transaction details for third-party cross-context behavioural advertising. If Donor Bridge engages in activity that constitutes "sharing" for cross-context behavioural advertising or "targeted advertising" under applicable U.S. law, we will provide the required notice and opt-out mechanism.
Browser-based "Do Not Track" signals are not uniformly defined. Where applicable law requires recognition of an opt-out preference signal, such as Global Privacy Control, Donor Bridge will process the signal as required.
13. Marketing and Electronic Communications
We may send service-related communications concerning authentication, account administration, security, transaction status, receipts, support, legal notices and other operational matters. These messages are necessary to provide or protect the Services and may continue even if you opt out of marketing.
We may send marketing, educational or promotional communications where permitted by law and, where required, with consent. You may unsubscribe using the link or instructions in the message or by contacting us. We will maintain suppression information as reasonably necessary to honour your request. Canadian commercial electronic messages will be managed in accordance with applicable anti-spam requirements, including CASL where applicable.
14. De-Identified and Aggregated Information
We may create aggregated, de-identified or anonymized information that cannot reasonably be linked to an identifiable individual, subject to applicable legal standards. We may use such information for analytics, benchmarking, security, product improvement, research, service planning and business reporting. We will not attempt to re-identify information that is treated as de-identified under applicable law except as permitted for security, testing or compliance purposes.
15. Data Location and Cross-Border Processing
Donor Bridge intends to use region-specific hosting for core platform environments, with Canadian core production data hosted in Canada and U.S. core production data hosted in the United States. However, some Third-Party Providers, support personnel or subprocessors may process or access information in other jurisdictions, including Canada and the United States, depending on the service.
When personal information is processed in another jurisdiction, it may be subject to the laws of that jurisdiction and may be accessible to courts, law enforcement or government authorities in accordance with those laws. Donor Bridge uses contractual, security and governance measures appropriate to the circumstances and will conduct assessments or enter into agreements required by applicable privacy law, including where Quebec law requires an assessment before certain transfers outside Quebec.
We do not promise that every piece of information will remain exclusively within the country where it was collected, because integrated service providers may create lawful cross-border processing or support access. Our final subprocessor list and data-flow documentation will reflect the production architecture.
16. Retention and Deletion
Donor Bridge retains personal information only for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, satisfy legal or contractual requirements, support audits and receipting, resolve disputes, prevent fraud and establish or defend legal claims. Retention periods differ by record type and sensitivity.
Our intended retention approach is record-specific rather than a blanket period for all data. Core Giving Transaction and receipt/acknowledgment records may generally be retained for approximately seven years where appropriate for audit, tax-support, contractual and recordkeeping purposes, subject to final legal requirements. Consent/authorization records may be retained for the period reasonably necessary to evidence the authorization and related transaction. Security logs, transient financial-data copies, website analytics, support records and marketing information may have shorter or different periods.
Closing an account or requesting deletion does not require us to delete information that we are legally permitted or required to retain. Information may remain in secure backups for a limited period and may be isolated from ordinary use. At the end of the applicable retention period, information will be securely deleted, destroyed, de-identified or anonymized in accordance with our procedures and applicable law.
Third-Party Providers may maintain their own retention schedules under their legal obligations and privacy policies. A Recipient Organization may also independently retain donation and receipting information.
17. Security Safeguards
Donor Bridge maintains administrative, technical and organizational safeguards designed to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, alteration or destruction, taking into account the sensitivity of the information, the nature of the Services and evolving risks.
Controls may include encryption in transit and at rest, access restrictions, least-privilege controls, email OTP/passwordless authentication, secrets management, logging and monitoring, vulnerability management, protected backups, incident response, vendor-risk management, security awareness training and periodic risk assessment. Personnel and contractors are expected to access personal information only where needed for legitimate responsibilities.
No Internet-based service or security program can guarantee absolute security. If you believe your account or information has been compromised, contact us promptly using the information in Section 25.
Donor Bridge may describe its security program through TrustBridge. Unless and until an independent SOC 2 Type II examination has been completed, Donor Bridge will not represent that it is SOC 2 certified.
18. Privacy and Security Incidents
Donor Bridge maintains incident-response procedures intended to identify, contain, investigate, remediate and document privacy or security incidents. Where a privacy breach creates a legal notification obligation, we will notify affected individuals, regulators, participating organizations or other parties as required by applicable law and contractual obligations.
We maintain records of privacy and security incidents where required by applicable law and as reasonably necessary for compliance, risk management and improvement of our controls.
19. Your Privacy Rights and Choices
Depending on where you reside and the law that applies, you may have some or all of the following rights. These rights are subject to legal exceptions and verification requirements:
- Access / Know. Request access to or information about the personal information we hold about you, the purposes for which it is used and, where required, categories of recipients or disclosures.
- Correction. Request correction of inaccurate or incomplete personal information.
- Deletion. Request deletion of personal information, subject to legal, contractual, security, fraud-prevention, audit, recordkeeping and other permitted exceptions.
- Withdraw consent. Withdraw consent for certain future collection, use or disclosure where processing is based on consent. Withdrawal may limit our ability to provide a requested Service and does not necessarily affect prior lawful processing.
- Data portability. Request a copy or transfer of certain personal information in a structured or commonly used technological format where applicable law provides that right.
- Opt out of marketing. Unsubscribe from marketing communications while continuing to receive necessary service messages.
- Opt out of sale/sharing or targeted advertising. Where applicable U.S. law provides this right and Donor Bridge engages in covered activity, submit an opt-out request or use an applicable opt-out preference signal.
- Limit certain uses of sensitive personal information. Where applicable law provides this right and the relevant use is not necessary to provide the requested Services, request limitation.
- Appeal. Where applicable U.S. state law provides an appeal right, appeal a decision on a privacy-rights request.
- Non-discrimination. Exercise applicable privacy rights without unlawful discrimination or retaliation.
To exercise a right, contact our Privacy Officer using Section 25. We may need information to verify your identity and authority. Authorized agents may submit requests where permitted by law, subject to verification. We will respond within the time required by applicable law.
20. Canada Privacy Rights and Practices
In Canada, Donor Bridge intends to comply with applicable federal and provincial private-sector privacy laws, including PIPEDA where it applies and substantially similar provincial legislation where applicable. Our privacy program is based on accountability, identified purposes, meaningful consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access and a process to challenge compliance.
You may request access to and correction of personal information in our custody or control and may withdraw consent for future uses where consent is the legal basis, subject to applicable exceptions. You may also raise a complaint with our Privacy Officer and, where applicable, with the relevant privacy regulator.
20.1 Quebec
For individuals in Quebec, Donor Bridge will apply applicable requirements under Quebec private-sector privacy law, including requirements concerning a designated privacy officer, privacy governance, meaningful consent, confidentiality incidents, privacy impact assessments where required, transfers outside Quebec and technological privacy settings.
Where Quebec law applies, you may have rights concerning access, rectification and, where legally available, computerized portability of personal information. Donor Bridge will provide any specific notice required if it uses technology that identifies, locates or profiles an individual or if it makes a decision based exclusively on automated processing. At launch, BridgeIQ is not intended to make decisions that produce legal or similarly significant effects about individuals.
21. United States Privacy Rights
Residents of certain U.S. states may have privacy rights under state consumer privacy laws when those laws apply to Donor Bridge. Depending on the state, rights may include access/know, correction, deletion, portability, opt-out of sale, opt-out of sharing or targeted advertising, limitation of certain sensitive-data uses, appeal and non-discrimination.
Donor Bridge does not sell personal information. We do not use financial-account information, connected brokerage data, receipt information or individual Giving Transaction data for third-party targeted advertising. If our use of website advertising technologies is treated as "sharing" or targeted advertising under an applicable state law, we will make the required opt-out mechanism available and honour applicable opt-out preference signals.
Sensitive Personal Information, including financial-account information, is used for purposes such as providing the Services you request, authentication, fraud prevention, security, compliance and related operational purposes. Donor Bridge does not intend to use sensitive financial information to infer characteristics about you for advertising purposes.
22. California Privacy Notice
This Section is intended to provide supplemental information for California residents if and to the extent the California Consumer Privacy Act, as amended ("CCPA"), applies to Donor Bridge. The categories below reflect the information Donor Bridge expects to collect in connection with the Services. Final launch disclosures should be confirmed against actual production data flows and the preceding 12-month period.
|
CCPA category |
Examples in Donor Bridge |
Business purposes |
Typical disclosures |
|---|---|---|---|
|
Identifiers |
Name, email, address, phone, IP, account identifiers, organization ID |
Accounts, transactions, support, security, verification |
Recipient Organizations; service providers; transaction providers |
|
Customer records / financial information |
Billing details, brokerage identifiers, financial-account and donation information |
Facilitate giving, reconciliation, fraud prevention, compliance |
Financial-data providers; processors; Recipient Organizations as necessary |
|
Commercial information |
Donation history, gift type, amount, campaign, settlement/status |
Provide dashboards, receipts, analytics, support |
Recipient Organizations; processors; service providers |
|
Internet / network activity |
Device, browser, logs, page activity, cookie identifiers |
Security, analytics, authentication, service improvement |
Hosting, analytics, security and communications providers |
|
Professional / organization information |
Employer, job title, organization affiliation, organization contact role |
B2B onboarding, employer matching, account administration |
Recipient Organizations; employer-match providers; service providers |
|
Inferences / analytics |
General service-use insights and aggregated patterns |
Improve Services, security and analytics |
Service providers; aggregated/de-identified reporting |
|
Sensitive personal information |
Financial-account access information and credentials handled by providers; account identifiers; security/authentication data |
Provide requested services, authentication, security, fraud prevention, compliance |
Approved financial/transaction providers; service providers as necessary |
Donor Bridge does not sell personal information. If Donor Bridge has engaged in CCPA-defined "sharing" through covered advertising technologies during the relevant 12-month period, the final public version will identify the applicable categories and provide a "Do Not Sell or Share My Personal Information" or equivalent opt-out mechanism as required. Donor Bridge does not knowingly sell or share personal information of individuals under 16.
23. Children and Minors
The Services are not directed to children. Donor Bridge requires users of transactional or organization features to be at least 18 years old and legally capable of entering a binding agreement. We do not knowingly collect personal information from children for donor accounts or Giving Transactions. If we learn that we collected information from a child in a manner not permitted by law, we will take appropriate steps to delete or otherwise address it.
24. Changes to This Policy
We may update this Policy from time to time to reflect changes in our Services, technology, vendors, legal obligations or privacy practices. We will post the updated Policy and revise the "Last Updated" date. Where required by law or where a change is material, we may provide additional notice or seek consent before applying the change to affected processing.
25. Privacy Officer; Questions, Complaints and Requests
Donor Bridge is accountable for the personal information under its control and will designate a person responsible for privacy compliance. Questions, complaints or privacy-rights requests may be directed to:
Donor Bridge Inc.
Attention: Privacy Officer / CEO
jason@donorbridge.com
Canada
We will investigate privacy complaints and respond in accordance with applicable law. If you are not satisfied with our response, you may have the right to contact the privacy regulator in your jurisdiction.