Legal
Last updated: 17 April 2026
This Privacy Policy explains how Impacturi (operated by Clickonic Ltd, trading as Impacturi) collects, uses, and protects personal data. It is written to comply with the UK General Data Protection Regulation and the Data Protection Act 2018.
The data controller for the information we hold about you as a user of this platform is Clickonic Ltd, a company registered in England & Wales. Our trading name is Impacturi. You can contact us at dermot@clickonic.co.
When you upload donor records to the platform, you are the data controller for that donor data and we are the data processor acting on your instructions. The terms of that processing relationship are set out in our Data Processing Agreement.
As a user of the platform we collect:
| Purpose | Legal basis |
|---|---|
| Provide and operate the platform | Contract (Article 6(1)(b)) |
| Take payment and manage subscriptions | Contract (Article 6(1)(b)) |
| Keep the platform secure, monitor for abuse and errors | Legitimate interests (Article 6(1)(f)) |
| Comply with tax, accounting, and anti-money-laundering law | Legal obligation (Article 6(1)(c)) |
| Send service notifications (e.g. renewal due, security alerts) | Contract and legitimate interests |
We do not sell your personal data. We share it only with the sub-processors listed in our Data Processing Agreement, which are required to provide the platform. These include Supabase (hosting, database, authentication, encrypted key vault. Ireland), Vercel (application hosting. EU and US edge), Stripe (payments. UK and EU), OpenAI (AI writing assistant. US, under appropriate transfer safeguards), and Sentry (error monitoring. EU).
Primary data storage is in the Republic of Ireland. Where a sub-processor is based outside the UK or EU (for example OpenAI, for the AI writing feature), transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or an equivalent safeguard.
Set out in full in our Data Retention Policy. In summary: we keep account and donor data while your subscription is active and delete within 30 days of closure. Billing records are kept for 7 years (HMRC requirement). Error logs are held on a rolling 90-day window.
Under UK GDPR you have the right to:
To exercise any of these rights, email dermot@clickonic.co. We will respond within 30 days.
We use a minimal set of cookies. A session cookie set by Supabase keeps you signed in (strictly necessary). A small browser-storage flag records that you have seen our cookie notice. We do not use advertising cookies, analytics cookies, or cross-site tracking.
The technical and organisational measures we take to protect your data are described in our Data Security Policy. In the event of a personal data breach affecting you, we will notify you within 72 hours of discovery, in line with our Incident Response Plan.
We may update this policy from time to time. Material changes will be notified by email to account holders at least 30 days in advance of the change taking effect. The “Last updated” date at the top of this page is authoritative.
Questions about this policy, or to exercise any of your rights, email dermot@clickonic.co.