Your members trust you with their data, and we take that seriously
DuesDesk is built for organisations that hold real member information, which is why the way we store, process and protect that data has been treated as a first-class product concern from the very beginning.
Encrypted in transit and at rest
Every request between your browser and DuesDesk travels over TLS, and your data is encrypted at rest on managed UK and EU infrastructure with keys that are rotated automatically on a regular schedule.
Strict tenant isolation
Each organisation lives in its own isolated space enforced at the database level through row-level security policies, so members and staff can never see records that belong to another club or association.
Sensible access controls
You choose who on the committee gets owner, admin or view-only access, and every sign-in, permission change and invoice action is written to an audit log that you can review at any time.
PCI-compliant payments
Card payments on the Pro plan are processed by Stripe, which is certified to PCI DSS Level 1, meaning card numbers never touch DuesDesk servers and your organisation inherits their compliance posture.
Regular encrypted backups
Your workspace is backed up automatically on a rolling schedule with encryption applied end to end, so accidental deletions and data loss events can be recovered without losing meaningful history.
Multi-factor authentication
Owners and admins can turn on multi-factor authentication for their account in a couple of clicks, and we strongly recommend it for anyone holding the treasurer role on a committee.
UK GDPR aligned
DuesDesk is built to be aligned with UK GDPR, which means clear purposes for the data we hold, an easy way to export or delete records, and a data processing agreement available on request.
Responsible disclosure
If a security researcher believes they have found an issue, we welcome a quiet email to security at duesdesk dot co dot uk and commit to acknowledging every report within one working day.
What data we hold, and why
We hold only what is genuinely needed to send invoices and process payments on your organisation's behalf, which typically means member names, contact details, membership categories, invoice history and the metadata around the payments themselves.
Card numbers are never stored on our systems, communications with members are logged only to the extent needed to prove delivery, and your organisation's data is never sold or shared with third parties or used to train external models.
Your rights as the data controller
Under UK GDPR your organisation remains the data controller for its member information, which means you decide what is collected and can export or delete records at any time from within the app.
We are happy to sign a data processing agreement with any organisation that requires one, and can provide sub-processor lists, hosting locations and retention policies on request through the contact page.
Security questions from your committee
If your organisation needs to complete a security review before adopting DuesDesk, we're glad to help walk through it, share our documentation and answer questions in plain language.
Contact our team