Trust
Security and compliance
Last updated: May 22, 2026
Donativus is operated by Aatsin Tech SL (NIF ESB22632491). Foundations and NGOs entrust the platform with donor records, payment data and operational reporting. This page summarizes the controls we operate and the compliance posture you can review during procurement.
Workspace isolation
Each organization operates inside its own workspace. Data is logically isolated per organization and is never visible across workspaces. Role-based access controls gate every module within a workspace.
Encryption
- TLS 1.2+ for all data in transit between clients, the platform and integrations.
- Encryption at rest for primary data stores and backups.
- Secrets and provider credentials stored in a managed secrets layer with rotation.
Access controls
- Role-based access at module level for every user.
- Separation between public donation flows and the backoffice.
- Audit trail of access and configuration changes available to administrators.
Backups and recovery
Regular automated backups are taken from primary data stores. Recovery point and recovery time objectives are documented in the service level agreement executed with each organization.
Payments
Card and bank data are handled by certified payment providers. Aatsin Tech SL does not store full card numbers on the Donativus platform; only reconciliation references and tokens issued by the provider are kept.
Compliance posture
- Aatsin Tech SL is the data controller for marketing data and the data processor for workspace data, under the EU GDPR and UK GDPR.
- Data processing agreement available for every organization on the platform.
- Standard contractual clauses for any cross-border transfer.
- Sub-processor list available on request.
- Independent certifications such as ISO 27001 and SOC 2 are tracked on our roadmap; current status is available on request.
Reporting a vulnerability
Report security issues to administration@aatsin.com .