Last reviewed September 2026Questions info@easygovernance.ie
EasyGovernance holds the records an organisation is trusted to protect — board papers,
governance documents, donor details and financial history. This page sets out, in plain terms, how
that data is kept safe, where it lives, and who can reach it.
If your board or a professional adviser needs a deeper technical review or a formal Data Processing
Agreement, we're glad to provide one — details at the end.
Where your data lives
Your platform data — documents, board records, donor and financial information — is stored and
processed entirely within the European Union, in Amazon Web Services'
Ireland region. It does not leave the EU in the normal course of operation.
Encryption, in transit and at rest
Every connection to the platform is encrypted with TLS, so data in motion can't be read in transit. Data at rest is held on encrypted
storage.
The most sensitive fields go further: PPS numbers are individually encrypted with
AES-256 at the application layer and can be decrypted only by an authorised administrator of
your organisation, never by ordinary users and never in bulk.
One organisation can never see another's data
EasyGovernance is multi-tenant — many organisations share the same platform — so this is the
boundary that matters most. It's enforced by Row-Level Security in the database
itself, on every table, not merely in the application. Your organisation's records are
invisible to any other organisation at the deepest level, so even an application error cannot leak
data across that line. This isolation is re-verified automatically on every release.
People see only what their role allows
Access is granted by role and capability: an owner or administrator, a board
member, a treasurer, someone who handles income. Each person reaches only the areas their role
permits, and the system is fail-closed — if a permission hasn't been
explicitly granted, access is denied by default rather than allowed. Administrators manage their own
team's access from within the platform.
Sign-in and account security
Accounts are protected by a managed authentication service. We never see or store
your password in readable form. Team invitations use single-use links tied to a specific
person, and password resets are self-service — so access can be granted and revoked cleanly as your
team changes.
Payments never touch our servers
All card payments are handled by Stripe, a PCI-DSS Level 1 provider. Card numbers are entered directly into Stripe's secure
systems and never pass through or rest on EasyGovernance. We record that a
payment happened, not the card that made it.
A complete, tamper-evident audit trail
The platform keeps an append-only record of who did what, and when — across
documents, board meetings, donor records and consent actions. Entries are added, never quietly
edited or removed. This is what lets you produce evidence on demand for a regulator, auditor or the
board, and show not just the current state but how you got there.
Backups and continuity
Your documents in the vault are backed up automatically every night to separate,
encrypted storage in the EU, so they can be restored in the event of a failure. The database
that runs the platform is additionally protected by our cloud provider's managed daily backups.
Security built into every release
Security isn't a one-off review. Automated checks run in our build pipeline and
block insecure changes from ever shipping — verifying that data-isolation
rules cover every table, that database functions can't be reached by anyone unauthorised, and that
no view exposes data across organisations. A strict content-security policy limits what can run in
the browser.
Your data is yours
The document vault belongs to your organisation. Your records remain
yours, and you can export your data and reports at any time.
Your minutes, policies and evidence are always yours to read and download.
Export documents, reports and regulator forms whenever you need them.
Requests for access, correction or erasure of personal data are supported, as GDPR requires.
The services that process your data
Service
What it does
Where
Supabase / AWS
Database, file storage and hosting — the core platform and your vault
EU · Ireland
Stripe
Card payment processing (PCI-DSS Level 1)
EU / global
Resend
Delivery of transactional email — invitations, reminders, notifications
USA
Cloudflare R2
Encrypted off-site backup storage
EU
A deeper review, whenever your board wants one
We're happy to walk your board or a professional adviser through any of the above in more detail,
provide a Data Processing Agreement, or answer
specific diligence questions.