Legal
Privacy notice
What Paytron holds about you, why, who else sees it, and how to get it back or have it removed. Written so a donor, a funded group and a data protection officer can each find their answer.
Last updated 4 September 2026
1. Who we are
Paytron is operated by Zero Point One Ventures Ltd, a company registered in England and Wales under company number 17398629. Our registered office is Collingwood Buildings, 38 Collingwood Street, Newcastle Upon Tyne, NE1 1JF. In these pages, "we", "us" and "our" mean Zero Point One Ventures Ltd.
Paytron is sold to UK community foundations. A foundation using it is our customer; its donors, its grantees and its staff are the people who use the product day to day. Where a document says something different applies to each of them, it says so.
You can reach us at [CONTACT EMAIL], or by post at our registered office.
2. Which of us is answerable for your data
This matters, because it tells you who to ask. Under UK data protection law there is a controller, who decides what happens to personal data, and a processor, who acts on the controller's instructions.
- Your community foundation is the controller for its donors, its grantees and its staff. It decides who is invited, what is sent and what is published.
- We are the processor for that data. We hold it and act on the foundation's instructions, under a written data processing agreement, and we do not use it for anything of our own.
- We are the controller for the small amount of data that is ours: the enquiry form on this website, correspondence with us, and the records of who at a customer foundation administers the account.
So if you are a donor or a grantee, start with the foundation you deal with. Ask us at [DATA PROTECTION CONTACT] if you cannot reach them, or if your question is about how the software itself works, and we will help.
3. What we hold, and why
On behalf of a foundation, Paytron holds:
- Donors: name, email address, the funds they hold, their donations and dates, Gift Aid declaration details (title, name, house name or number, postcode), their share of each grant payment, what has been sent to them and whether they opened it, and any message they send to a funded group.
- Grantees: the organisation's name and registered numbers, a contact name, email address and phone number, the grants they hold, and the updates they send: their own words, photographs, video, counts, and the sharing level they chose.
- Anyone appearing in an update: whatever the funded group's photograph, video or words show or say about them.
- Foundation staff: email address, role, and a record of what they approved, changed or downloaded.
- Everyone: a magic link record (the token itself is stored only as a hash), and abuse counters keyed to a salted hash rather than to your address.
For ourselves, we hold what you type into the enquiry form (your foundation, your name, work email, role, an indication of funds under management, timescale and your note) so that we can reply, and our correspondence with you.
We do not hold card or bank details. We do not record your IP address. We do not put donor or grantee data into application logs or into analytics, because there is no analytics.
4. Why we are allowed to hold it
Our lawful bases, in the language of UK GDPR Article 6:
- Contract, for running the service a foundation has bought and a donor has signed up to.
- Legitimate interests, for showing a donor what their giving funded, for keeping the service secure, and for replying to an enquiry from a work address. We have weighed these against your interests and are happy to share the reasoning.
- Consent, for an update and its media. The funded group chooses who may see it and can withdraw that choice. Where an update names or shows a person, that person's agreement is what the group is relying on when it sends it.
- Legal obligation, for Gift Aid records, finance records and the audit trail a foundation's auditors and regulator expect.
Special category data (health, for example) can appear in a grantee's words about the people they support. The product is not designed to collect it, and the reviewer is prompted to take it out. Where it stays in an update, the group's explicit consent to that update is the Article 9 condition.
5. Where your data lives
The database, the sign-in service and the media store are hosted in London. Photographs, donor records and grantee contact details stay in the UK or the EU.
Two exceptions are worth naming rather than burying. Video is processed by Mux, which processes in the United States unless an EU region is agreed, and the consent wording shown to a group before it uploads covers this. Our AI provider processes in its own region under its own terms. Nothing about a donor is ever sent to the AI provider, and what is sent about a grantee is their answers, their counts, and up to three video frames for the safeguarding check.
6. Who else sees it
We use these companies to run the service, and no others:
- Supabase, for the database, sign-in and file storage (London).
- Mux, for video handling and captions.
- Postmark, for email, with EU data residency turned on.
- Twilio, for text messages, on an EU number.
- Stripe or GoCardless, for payments, who hold the card and bank details we never see.
- An AI provider, for drafting and safeguarding checks, on the terms above.
- Xero, read only, for the figures on a fund statement. No personal data goes to it.
- Companies House and the Charity Commission, sent a charity or company number only, to verify a funded group against the public registers.
We do not sell data, we do not share it for advertising, and one foundation can never see another's. That last one is enforced by the database itself rather than by application code, and it is covered by an automated test suite that runs on every change. The trust page explains how.
We will disclose data where the law requires it, or where there is a safeguarding concern that needs reporting. A foundation may also publish grant data as open data (360Giving) or file a Gift Aid schedule with HMRC. Neither of those contains donor data in the first case, and the second is a statutory return.
7. How long we keep it
- Donor and grantee records: while the foundation's own system of record holds them, or until the foundation asks us to anonymise or delete them.
- Payment and Gift Aid records: seven years, because finance rules require it.
- Updates: until withdrawn. A withdrawn update loses its media and stops being shown, and the record that it existed is kept so the ledger still reconciles.
- Magic links: valid for seven days, the record kept for ninety days to spot abuse.
- Records of AI use: twelve months, holding a hash of the input rather than the input.
- Abuse counters: twenty four hours.
- The audit log: the life of the foundation's account, because it can never be edited.
- Enquiries to us: [ENQUIRY RETENTION PERIOD].
8. Your rights
Under UK GDPR you can ask for:
- a copy of what is held about you, and to take it elsewhere in a usable format;
- a correction, if something is wrong;
- deletion, in the circumstances the law allows;
- a restriction on what is done with it, or an objection to it;
- consent to be withdrawn, where consent is what we are relying on.
A donor can do the first of these without asking anyone: the settings page exports everything held about you, and closes your account. Closing it replaces your name and email with a code and keeps which grants your past giving funded, so the foundation's accounts and its statements still add up. A funded group withdraws an update from its own link, or asks the foundation.
For anything else, ask the foundation, or ask us at [DATA PROTECTION CONTACT] and we will pass it on and help answer it. We aim to reply within one month, which is the period the law gives.
If you are unhappy with the answer, you can complain to the Information Commissioner's Office, the UK regulator, at ico.org.uk. We would rather you came to us first.
9. Children, and safeguarding
Paytron is not for children to use. Children do appear in what funded groups share, which is the point of a youth project's update, so an image that may identify a child holds the update automatically. Releasing one takes a named person at the foundation, a recorded reason and their initials. Nothing about it is automatic.
If you are concerned about an image or a description of a child on a Paytron page, tell us at [REPORT A PROBLEM EMAIL]. We will take it down while it is looked at.
10. Decisions, and where AI is used
No decision about you is made by a machine alone. AI drafts a headline and a short summary from a funded group's own answers, and screens images for anything that might identify a child. It cannot publish, send an email or decide anything, and a named person approves every word that reaches a donor or a public page.
Words the AI added that are not in the group's own answers are highlighted for the reviewer, and every call is logged with the prompt version that ran, so a decision can be traced back a year later.
11. Keeping it safe
- Separation between foundations enforced by the database, and tested on every change.
- Sign-in by emailed link, with no passwords to leak, and one device per grantee link.
- Media served by links that expire, between one and seventy two hours.
- Tokens stored as hashes, never in the clear.
- An append-only audit log of what staff did.
- Security headers and rate limits on every public route.
Paytron has no external security audit or formal certification yet: [CERTIFICATION STATUS]. We would rather you heard that from us. Our data protection impact assessment notes are available on request, and we will complete your own supplier questionnaire.
13. Changes, and the law that applies
We update this notice when the product or the law changes, and the date at the top tells you when it last changed. Where a change affects you materially we will tell the foundation, and the donors or grantees concerned.
We are established in England. This notice is governed by the law of England and Wales, and by UK GDPR and the Data Protection Act 2018.