Important limitations

Keep donor information out of ordinary handover notes and worksheets

Last materially reviewed 2026-09-30

Quick answerUse references to approved records instead of copying sensitive donor information into every working note.
Likely to work well when

✓ Small nonprofit handovers

✓ Recurring-gift administration

✓ Requirement-led platform comparison

Important limitations

— Payment execution

— Tax or legal advice

— Donor profiling

— A substitute for the nonprofit’s support team

What to know

Recognize the boundary of this website

Donor Continuity Desk has no need for names, email lists, card details, bank information or exported donor records. Its worksheets use anonymous counts and assumptions only. Do not paste private material into a contact message or try to upload it here. This is a publication, not your organization’s secure case-management system. NCSC guidance emphasizes appropriate controls for SaaS data and sharing; it does not certify any particular nonprofit’s setup or establish that a product name alone makes a workflow safe.

What to know

Write a useful note with less copied data

Our editorial pattern is task, status, owner, next action and a reference to the approved record location. A general handover might say “three receipt exceptions await the finance owner” rather than reproducing each donor’s address. The authorized person can follow the private reference inside the organization’s system. Do not put secret URLs or credentials into shared task titles. Reducing unnecessary copies also makes corrections easier: a changed source record should not leave several contradictory versions in unrelated spreadsheets and inboxes.

What to know

Check recipients and storage before exporting

Before an authorized export or share, establish who needs the information and whether the intended location is approved for it. Avoid assuming a link is private because it is long or difficult to guess. Ask the responsible administrator to explain access and retention controls when they are unclear. This checklist does not set legal retention periods, determine a lawful basis for processing or promise compliance with a regulation. Those decisions need the organization’s applicable policies and qualified advice, not invented answers from a generic guide.

What to know

Treat mistakes as an escalation, not a quiet cleanup

If information reaches the wrong recipient or location, follow the organization’s incident process and preserve enough detail for the responsible team to assess it. Do not independently erase evidence or make promises about legal consequences. A fictional anonymous worksheet can help explain counts without exposing the underlying people; it cannot sanitize an actual donor database. Keep the access-review guide beside the export-snapshot process so that changing staff responsibilities also triggers a review of where working copies and unresolved cases remain.

Source boundary

Where the safety evidence stops

This guide draws on NCSC: using SaaS securely, 4aGoodCause contact import. Merchant-controlled records describe the provider’s own capabilities, terms or standards; they do not independently validate those claims. Other cited records provide additional context. A different publisher or a research, regulatory or certification label does not by itself establish independence, relevance or product validation.

Verify any current price, plan limit, label direction, compatibility rule, or commercial term that would materially change the decision. The dated source ledger shows the underlying records so this conclusion can be checked and updated.

Sources used for this page

These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.

  1. NCSC: using SaaS securely — Research study · ncsc.gov.uk · Publisher independence not verified · checked 2026-09-30
  2. 4aGoodCause contact import — Merchant documentation · help.4agoodcause.com · Merchant-controlled · checked 2026-09-30