Privacy Policy
1. Introduction
At Tholca Digital, operating as NanoNGO, we recognize the critical nature of the data managed by non-profits and mission-driven organizations. This Privacy Policy outlines our secure cloud-based approach to data management and our commitment to safeguarding your information through industry-standard security protocols.
2. Information We Collect
We collect information necessary to provide and improve our software platform. This includes:
- Account Information: Name, email address, organization details, and role designations when you register or are invited to a workspace.
- Billing Information: Payment details required to process subscriptions. Payment processing is managed securely by certified third-party payment gateways; we do not store full credit card numbers on our servers.
- Operational Data: Financial forms, project attachments, and communications submitted through the platform by your organization.
- Usage Data: Standard telemetry (such as IP addresses, browser types, and interaction logs) collected automatically to help us diagnose issues and optimize platform performance.
3. How We Use Your Data
Your data is utilized strictly to deliver the NanoNGO service. We use this information to:
- Authenticate users and enforce granular, role-based access controls.
- Process transactions and send billing notices.
- Provide customer support and technical troubleshooting.
- Prevent fraudulent activity and maintain platform security.
We do not sell, rent, or trade your personal or organizational data to third parties for marketing purposes.
4. Data Controller vs. Data Processor
In the context of global data protection frameworks:
- You (The Organization): Act as the Data Controller. You determine the purpose, parameters, and means of processing personal data within your NanoNGO workspace.
- NanoNGO: Acts strictly as a Data Processor. We provide the secure software infrastructure but do not independently access, mine, or analyze your private operational data.
5. Cloud Architecture & Data Security
NanoNGO operates on a secure, centralized cloud infrastructure:
- Your organizational data is hosted securely in our enterprise-grade cloud environments, ensuring it is redundantly backed up and highly available.
- We utilize robust, industry-standard encryption protocols (TLS/SSL) for data in transit and AES encryption for data at rest to protect your information from unauthorized access.
6. Data Retention and Deletion
We retain your operational data only for as long as your organization maintains an active subscription with us. If you choose to terminate your account, you may request a full export of your data. Following termination, we securely delete your organizational data from our active servers in accordance with our standard data lifecycle policies, barring any data we are legally required to retain for tax or compliance purposes.
7. Third-Party Service Providers
To provide a seamless cloud experience, we utilize trusted third-party service providers for essential functions such as cloud hosting, email delivery (e.g., SMTP notifications), and secure payment processing. These partners are strictly vetted and operate under confidentiality agreements that prohibit them from using your data for any purpose other than providing their specialized service to NanoNGO.
8. Contact Information
For inquiries regarding this Privacy Policy, data management practices, or to exercise your rights regarding your personal information, please contact our support team at [email protected].