Vasker

Security and compliance

Plain English on where your club’s books live, who can see them, which processors we use, and what happens if you stop paying. Written for treasurers, not lawyers.

Last updated: 31 August 2026

Who is responsible

Tweed Tyne Technologies Ltd (company number SC874131, Scotland) operates Vasker. We are registered with the ICO under number ZC184042.

We are the controller for officer account and service data. For member, donor and Gift Aid records you enter, your organisation is the controller and we process that data under our Data processing addendum. Full detail: Privacy policy.

What we hold

Depending on what you use, that can include organisation details, cash-book transactions, member names and addresses, Gift Aid declarations, donation records, uploaded receipts, and account login details for your officers. We do not store Government Gateway passwords. Those are typed only at the moment of a claim submission and discarded afterwards.

Where the data lives

Production application data is hosted in the European Economic Area on Railway, a US-incorporated cloud provider. Your application, managed PostgreSQL database, Redis and media bucket for uploads are run in Railway’s EU hosting region. Connections use HTTPS. Database connections use TLS in production. Access to production systems is limited to people who need it to run and support the service.

Because Railway is US-incorporated, its platform control plane and support functions may involve the United States even while your primary workloads stay in the EU. We address that through Railway’s customer DPA and transfer safeguards, described in the Privacy policy and DPA.

Processors we rely on

  • Railway — hosting, database, Redis and media storage for the live service.
  • Cloudflare — Turnstile bot protection on signup, login, admin login and selected public forms, so automated abuse is harder. Where configured, Cloudflare Email Routing and Workers also handle inbound Vasker support mail before it reaches our support systems.
  • IDrive e2 — encrypted offsite backups (Postgres and Redis dumps plus a media mirror) stored in object storage in the London region (eu-west-3), separate from the live Railway stack.
  • Transactional email (SMTP) — invites, password resets and service notices are sent via the mail provider configured for Vasker.
  • Google Analytics 4 (Google LLC) — website usage measurement so we can see which pages are used. Google processes technical data such as IP address, browser and device signals, and page URLs. We do not send member, donor or Gift Aid records to Google Analytics. Cookie detail is in the Privacy policy.
  • Meta Pixel (Meta Platforms Ireland Ltd.) — visit and advertising measurement on the website. Meta processes technical data such as IP address, browser and device signals, page URLs, and advertising cookies. We do not send member, donor or Gift Aid records to Meta. Cookie detail is in the Privacy policy.

The formal sub-processor list for Organisation Data is in the DPA. Google Analytics and the Meta Pixel are not on that list because they do not receive Organisation Data.

Backups

Database and related backups run on a regular schedule so a platform failure does not wipe your club’s books. Live provider backups and offsite IDrive e2 copies are encrypted in transit and at rest with the providers’ standard controls. Offsite copies are kept for a limited rolling retention window. If you need a copy for an examiner or a treasurer handover, use the in-product export tools rather than relying on a support request.

Who can see your organisation

Vasker is multi-tenant. Your organisation’s records are scoped so other clubs cannot read them. Within your organisation, access follows the roles you assign (for example treasurer, officer, or independent examiner). Audit logging records sensitive actions so you can see who changed what. Passwords are stored hashed. Public forms that create or open sessions are protected with Cloudflare Turnstile.

If you stop paying

If a paid plan ends, your data is not deleted the same day. You keep read access for a grace period so you can export a handover pack, income and expenditure figures, and Gift Aid records. After the grace period, inactive accounts may be archived and later deleted in line with our retention schedule. If you want deletion sooner, email privacy@vasker.co.uk and we will confirm once it is done.

Export before you leave. The year-end and handover tools are there so the next volunteer is not locked out of the history you built.

Gift Aid and HMRC

HMRC recognition for live Charities Online submission is in progress. Until it clears, you can prepare claims inside Vasker but live gateway submission stays off. That is deliberate: we will not imply HMRC recognition before it is granted.

Compliance posture

We design Vasker around UK GDPR expectations for a small SaaS product: least-privilege access, encryption in transit, tenant isolation, processor contracts, and an ICO registration you can check. We are not claiming ISO certification or a public SOC 2 report. If your trustees need a short questionnaire answered, email support@vasker.co.uk. Safety or security incidents: safety@vasker.co.uk.

Your rights

Individuals whose data you store (members, donors) retain their rights under UK GDPR. You remain responsible for having a lawful basis to hold that data in your club’s books. Contact us at privacy@vasker.co.uk for requests that relate to Vasker’s own account or service processing.

Related policies

Terms of service · Privacy policy · Data processing addendum · Who we are · Start free