Data privacy & security

Member data stays in the European Union, access is scoped by role and chapter, and your organization can export or delete it at any time.

  • Hosted on AWS in Frankfurt, Germany; data does not leave the EU
  • Named admin roles isolated per chapter, with every export and profile change logged
  • Full CSV and API export, no lock-in period, and no selling of member data

Written for the IT, legal, and data protection reviewers inside associations, federations, and nonprofits.

Privacy and security at a glance

Hosting & data residency AWS in Frankfurt, Germany; member data does not leave the European Union. Deployment to another AWS region is possible where national law requires it, arranged per organization
Encryption Passwords and one-time codes hashed one way; up to five custom profile fields encrypted at database level for identifiers such as national ID numbers; file access follows group and role permissions, with public share links an explicit per-file or per-folder choice
Authentication Passwordless one-time email codes by default, so most members never create a password; Google, Microsoft, Apple, and LinkedIn sign-in available and individually switchable
Access control Named roles (admin, HR, HR assistant read-only, financial, communication, event, moderator) replicated and isolated at national, regional, and chapter level
Audit logging Profile changes, document changes, data exports, report generation, and email sends recorded with user, timestamp, and IP address
Data export & ownership CSV export per module, full REST API access, and scheduled database dumps on request; the organization owns its data and Orgo does not sell it to third parties
Deletion & exit Resignation flow removes a member's data; no lock-in period, migration off the platform at any time, and pro-rata refunds for the unused part of a prepaid year
Sub-processors AWS for hosting, file storage, and email delivery; Stripe for payments. Member data is not sent to external AI model providers

Written for organizations that

Run a security review

An IT department or data protection officer signs off before procurement does. Hosting, encryption, roles, and logging are documented, and the Orgo team fills in buyer security questionnaires directly.

Are bound by GDPR

Servers sit inside the EU, so moving to Orgo needs no transfer mechanism and no member-by-member consent, unlike a migration to a US-only platform.

Share data across chapters

Federations give local admins real access without exposing the whole membership. Each chapter admin sees only their own chapter, and children's records never leave it.

How Orgo protects member data

Where your data lives

Orgo runs on AWS in Frankfurt, Germany. Member data stays inside the European Union unless your organization asks for a different region.

All member data is stored on AWS infrastructure in Frankfurt. It does not leave the territory of the European Union. Organizations replacing a US-only platform avoid the consent exercise that a transfer outside the EU would otherwise require from every member.

Orgo's infrastructure is defined as code, so it can be deployed to another AWS region where national law requires data to stay in-country, for example Switzerland or Australia. This is arranged per organization during contracting, not switched on by self-service.

The servers are AWS, operating in Germany. That is the extent of the hosting chain, which matters to organizations reviewing exposure to non-EU jurisdictions.

Files live in AWS S3, and access to them follows the same group, chapter, and role permissions as the rest of the platform rather than being open by default. Sharing a file or folder publicly is an explicit choice made per item. Static assets are distributed through a CDN for speed.

Encryption & credentials

Sensitive values are hashed or encrypted, so database access alone does not reveal them.

The default sign-in method is a six-digit one-time code sent by email, so there is no password to phish, reuse, or reset. Social sign-in is available as an alternative:

  • Google
  • Microsoft
  • Apple
  • LinkedIn

Each provider can be enabled or disabled independently, so a professional association can offer LinkedIn without offering the rest.

Where passwords are used they are hashed one way, as are multi-factor codes. They cannot be read back, including by Orgo. Two-factor authentication is available for members who want it.

Up to five custom profile fields can be encrypted at database level. Organizations use these for national ID numbers, social security numbers, and similar identifiers that compliance rules require to be stored encrypted rather than in plain text.

Votes use a cryptographic, blockchain-like architecture. Nobody can read or alter a ballot, including Orgo developers with database access. Each voter receives an integrity hash to verify that their own ballot was recorded and remains valid, and admins see who voted but never what they voted. The voting system has been externally audited.

Access control & permissions

Admin access is split across named roles rather than one shared account, and each role is scoped to a single level of your organization.

Permissions are granted by role, not by exception:

  • Orgo administrator, for platform-level configuration
  • Admin, with full rights inside their scope
  • HR, for member records; HR assistant is the read-only version
  • Financial manager, for fees, donations, and revenue
  • Communication manager, for newsletters and moderation
  • Event manager, for events and attendees
  • Moderator, for discussions

File access, menu items, analytics scope, and member data visibility all follow the role automatically, so there is no second permission system to keep in sync.

Every role that exists nationally also exists at regional and chapter level, with access limited to that level's data. A chapter financial manager sees their own chapter's money and nobody else's. Parent-level admins inherit rights over the chapters beneath them, and nothing above or sideways.

Where an organization holds records on under-18s, the platform restricts them by default:

  • Children's profiles are visible only inside their own chapter
  • Members without the right permission cannot see or browse minors at all
  • Minors are excluded from event networking views and cannot receive direct messages
  • Guardians see only their own children, and that visibility can be narrowed to a single service unit

Custom fields can be marked admin-only, which is how organizations hold disciplinary notes, safeguarding records, and medical information without exposing them to other members. Board-level discussions sit in private groups that non-members of the group cannot see exist.

Admins can view the platform exactly as a given member or permission level sees it, which is how support questions get answered without asking anyone for their login. The permission is granted at database level rather than from the admin interface.

Member privacy controls

Members decide how visible they are to other members, inside limits an admin has already set.

Each profile field carries its own visibility setting, covering name, email, phone, age, town, photo, profession, and social links. Members can narrow visibility further than the organization's default, never expand past it.

A member can set their profile to admin-visible only. Other members then see nothing, which matters for organizations where membership itself is sensitive information.

Appearing on the member map is opt-in, and members place their own pin. The full member directory does not have to be shown to everyone; visibility is a setting your organization chooses.

The first-login flow asks each member for their privacy settings and notification preferences before the platform starts sending automated notifications, so communication runs on consent rather than assumption.

Audit logs & traceability

Orgo records who did what and when, across profiles, documents, exports, and communications. The logs are not optional and run as part of normal operation.

Every change to a member's profile is recorded with the person who made it and the time. The same profile holds a complete log of every email the platform sent to that member.

Exporting member data writes a log entry with the user, the timestamp, and the IP address, so an admin downloading the membership list is a recorded event rather than an invisible one. Large exports of sensitive data trigger a warning prompt before the download starts.

Beyond profiles, Orgo logs:

  • Data imports, with row-level results
  • Email delivery, including bounces and complaints
  • Webhook deliveries, with status code and response
  • Report and query generation

Past votes and their results are archived permanently, and every signed document lands in a searchable registry. Governance decisions stay traceable years later, which is what an auditor asks for.

GDPR mechanics

Your organization is the data controller. Orgo handles the mechanics that obligation turns into, inside the platform rather than through a separate manual process.

Registration forms carry consent checkboxes with the relevant document linked, and the privacy policy and terms are accepted before an account is used. Documents can be made mandatory to sign at registration, at first login, or before continued access, which is how organizations collect and re-collect GDPR consents.

Any profile field can be switched off, so the platform collects what your organization actually needs rather than a fixed schema. Fields you never enable are fields you never have to protect, explain, or delete.

A member can export the data held about them. At organization level the same data comes out three ways:

  • CSV export per module, from members and payments to events and courses
  • Full REST API access across roughly 400 documented endpoints
  • Scheduled database dumps, arranged on request

A resignation request runs as a workflow with an optional exit questionnaire, and the member's data is removed through it rather than by a manual database edit. Account statuses also allow access to be suspended immediately while a case is decided.

Every newsletter carries an unsubscribe link, recipients manage their own subscription preferences, and hard bounces are unsubscribed automatically. Local admins can only send to their own chapter's people, which limits how far a mistake travels.

Ask Orgo answers natural-language questions against your own database without sending member data to external AI model providers. Connecting an outside AI assistant through the MCP server is a separate decision your organization makes and controls.

Resilience & track record

After "where is the data", the two questions an IT reviewer asks are whether it stays available and whether it can be recovered.

Point-in-time database backups run with per-second granularity and can be restored up to four days back, so recovery targets a moment rather than last night's snapshot.

Orgo runs multiple AWS instances with database replication and automatic failover. The one outage that prompted this design has not recurred since replication was added.

Contracts commit to at least 99.5% availability, with 99.9% as the operating target. Across all of 2025 the total recorded downtime was five minutes, caused by scheduled AWS maintenance on the database servers.

AWS firewalls detect attack traffic and ban the source addresses while keeping the platform up. During a Romanian presidential campaign run on Orgo, the platform absorbed a distributed denial-of-service attack with zero downtime.

Orgo has been audited by Bitdefender, and has passed security due diligence for political parties, a presidential campaign, and enterprise organizations. The platform follows SOC 2 practices; it does not hold a SOC 2 or ISO 27001 certificate, and the team will say so in a questionnaire rather than imply otherwise.

Across more than ten years of operating membership platforms, including scouting organizations whose records are largely children's data, Orgo has had no data leak.

“I appreciate the reliability that comes with using an established product like Orgo, which is developed by people who understand our organizational context and can provide ongoing support and development. The focus on community building enhances its utility, transforming it from just a membership management tool into a robust community platform. I'm very satisfied with the service and would highly recommend it!”

Photo of Manuel Pimenta

Manuel Pimenta

President, Escoteiros de Portugal

Data privacy & security FAQ

On AWS infrastructure in Frankfurt, Germany. Member data does not leave the territory of the European Union. Where national law requires data to stay in a specific country, Orgo's infrastructure can be deployed to another AWS region, for example Switzerland or Australia. That is arranged per organization during contracting rather than offered as a self-service setting.

GDPR compliance is shared. Your organization is the data controller and decides what it collects and why; Orgo provides the mechanics. In practice that means EU hosting, consent capture at registration and first login, the ability to disable any profile field you do not need, encrypted storage for sensitive identifiers, member-controlled profile visibility, full data export, a resignation workflow that removes member data, and an audit trail covering changes and exports.

Yes. Buyer security questionnaires are a normal part of Orgo procurement, and the team completes them directly with your IT or data protection contact. Data processing terms are agreed as part of the contract. Organizations that have run this process include political parties, a national presidential campaign, and enterprise associations.

Only the roles you grant, at the level you grant them. Admin, HR, HR assistant (read-only), financial, communication, event, and moderator roles exist separately at national, regional, and chapter level, and each is isolated to that level's data. A chapter admin sees their own chapter and nothing else. Members additionally control field-by-field visibility on their own profile, and can restrict it to admins entirely.

Profiles of under-18s are visible only inside their own chapter, and members without the required permission cannot browse them at all. Minors are excluded from event networking views and cannot receive direct messages. Guardians see only their own children, and that visibility can be narrowed further to a single service unit. See multi-chapter management for how the chapter boundaries themselves are configured.

Yes, at any time. CSV export is available per module, the REST API covers roughly 400 documented endpoints, and scheduled database dumps can be arranged. The organization owns its data, Orgo does not sell it to third parties, and there is no lock-in period. If you leave partway through a prepaid year, the unused period is refunded pro rata.

No. Orgo follows SOC 2 practices but does not hold a SOC 2 or ISO 27001 certificate. What does exist is an external security audit by Bitdefender, completed security due diligence for political and enterprise clients, and a record of no data leak across more than ten years of operation. If a certificate is a hard procurement requirement, it is better to establish that early.

No. Ask Orgo answers natural-language questions against your own database without passing member data to an external model provider. If your organization chooses to connect an outside AI assistant through the MCP server, that connection is yours to configure, authorize, and revoke.

Database backups are point-in-time with per-second granularity, restorable up to four days back. Infrastructure runs across multiple AWS instances with database replication and automatic failover. Contracts commit to at least 99.5% availability with 99.9% as the target; across all of 2025 the total recorded downtime was five minutes, caused by scheduled AWS maintenance. AWS firewalls also absorbed a live distributed denial-of-service attack during a presidential campaign with no downtime.

Review Orgo's data protection with your own DPO

  1. 1 Pick a 30-minute slot. You talk to the people who built Orgo, not an account executive working from a script.
  2. 2 We set up Orgo on your real organization during the call and walk through consent records, retention rules, and the DPA with whoever owns compliance.
  3. 3 You keep the sandbox to evaluate with your team, plus a written plan for migrating the data you already have.
Get a demo