Privacy Policy

Global Data Privacy Policy | TrustBridge Global Foundation

TrustBridge Global Foundation

Global Data Privacy Policy

Public Privacy Notice

1. About TrustBridge and this notice

TrustBridge Global Foundation ("TrustBridge", "we", "us" or "our") is a Swiss tax-exempt charitable foundation (Stiftung). TrustBridge is the controller when it decides why and how personal data is processed. Contact: TrustBridge Global Foundation, Zelglistrasse 10, 3608 Thun, Switzerland; admin@trustbridgeglobal.com.

This notice applies to personal data processed online and offline through trustbridgeglobal.com, GivingSpace, TrustBridge-branded or authenticated portals, Foundation Fund and Charity Fund applications, contributions, grants, investments, non-cash and legacy gifts, events, communications and related charitable services. It covers donors, prospective donors, fund holders, advisors, successors, charity representatives, governing persons, professional advisors and other contacts.

Swiss law, including the Federal Act on Data Protection (FADP), is our primary framework. The EU GDPR, UK GDPR and Data Protection Act 2018 as amended, applicable U.S. state privacy laws and other local laws also apply where their requirements are met. If local law gives an individual greater protection, that law prevails. A TrustBridge network member or partner may be a separate or joint controller for its own processing and may provide an additional notice.

2. Personal data we collect and where it comes from

Depending on the relationship and service, we may collect:

  1. Identity, contact and relationship data: names, titles, signatures, dates of birth, citizenship or residence, addresses, contact details, organization and role; fund holders, co-holders, advisors, authorized persons, successors and family relationships; and identity or tax identifiers and verification results where required.

  2. Fund, contribution, grant and financial data: fund instructions, charitable and investment preferences, anonymity and recognition choices, donation and grant history, currencies, receipts, bank and payment details, tax residency, source-of-funds or source-of-wealth information, and information about securities or other non-cash assets.

  3. Charity, governance and program data: registration and tax status, purposes and religious affiliation where relevant, programs and proposed use of funds, governing documents, financial statements, bank details, directors, officers, governing members, key personnel, control relationships, safeguarding information and grant reports.

  4. Due-diligence and risk data: identity and authority checks, sanctions and politically exposed person screening, adverse media, anti-money-laundering and counter-terrorism-financing checks, background-check results, conflicts, fraud, cybersecurity and transaction-risk indicators, and supporting evidence.

  5. GivingSpace technical and communications data: account credentials and permissions, authentication status, portal activity and audit logs, IP address, device and browser data, security events, forms, emails, call notes, support requests, electronic signatures, website use, cookie identifiers and communication preferences.

Some of this information is sensitive or specially protected, including government identifiers, financial account data, citizenship, religious affiliation, background-check information, health or safeguarding information and data about minors. We process it only when necessary and when an additional lawful condition applies, such as explicit consent, legal or regulatory duties, substantial public interest, vital interests or legal claims.

We obtain data from you; fund holders, advisors, successors, charities and other representatives; TrustBridge Network Members; banks, payment, investment, custody and grantmaking partners; public registers, regulator and charity databases and other lawful public sources; due-diligence, identity-verification, sanctions, fraud-prevention and cybersecurity providers; and your browser or device. If you provide another person's data, you must be authorized to do so, make this notice available to them and ensure the disclosure is lawful.

3. How and why we use personal data

  1. Provide charitable services. To assess, establish and administer funds; process contributions, grants, distributions, investments and other transactions; manage fund access and succession; provide receipts, statements and reports; and respond to requests. Grounds include steps at your request, performance of an agreement, legal duties and legitimate interests in operating charitable services.

  2. Conduct due diligence and compliance. To verify identity and authority; vet donors, assets, charities, governing persons and transactions; prevent fraud, money laundering, terrorist financing, sanctions breaches, corruption and misuse; protect beneficiaries; and meet tax, audit, regulatory and reporting duties. Grounds include legal duties, public interest where recognized, legitimate interests and additional conditions for sensitive data.

  3. Operate securely. To create and protect accounts, authenticate users, maintain audit trails, provide support, investigate incidents and improve reliability. Grounds include performance of an agreement, legal duties and legitimate interests in secure and efficient operations.

  4. Manage relationships and communications. To communicate with donors, charities, advisors and partners; administer events and surveys; send service updates; maintain records; and, where permitted, send optional newsletters or invitations. Grounds include an agreement or request, legitimate interests and consent where required.

  5. Protect legal and organizational interests. To obtain advice, conduct audits, manage governance, insurance, claims or reorganizations, enforce terms and respond to lawful requests. Grounds include legal duties and legitimate interests in protecting TrustBridge and others.

Where we rely on legitimate interests, we assess necessity and the impact on individuals and apply safeguards. You may withdraw consent at any time without affecting earlier lawful processing. If required information is not provided, we may be unable to open or administer a fund, process a contribution or grant, provide GivingSpace access, issue a receipt or complete legal and compliance checks.

4. When we disclose personal data

We disclose only what is reasonably necessary to:

  1. TrustBridge Network Members and charitable partners that support cross-border giving, receipting, fund administration, charity onboarding, grantmaking and local compliance;

  2. financial and transaction parties, including banks, payment processors, custodians, brokers, investment managers, appraisers, charities and grant intermediaries;

  3. service providers supporting portals, hosting, cloud storage, CRM, documents, communications, analytics, e-signature, identity verification, screening, fraud prevention, cybersecurity, printing, support and surveys;

  4. professional and oversight parties, including auditors, accountants, lawyers, consultants, insurers, regulators, tax authorities, courts and law enforcement; and

  5. people you authorize and organizational successors involved in an approved service transfer, restructuring or similar event.

Recipients may act as processors, joint controllers or separate controllers depending on their role. We do not sell or rent donor lists or disclose personal data to unrelated organizations for their own direct marketing. We may disclose data when required by law or reasonably necessary to protect TrustBridge, users, beneficiaries or the public.

If you request an anonymous grant or donation, we do not ordinarily identify you to the recipient charity or publish your identity, although TrustBridge must still process it and may disclose it to banks, partners, auditors or authorities for compliance. A Charity Fund may choose whether its organization name or public profile appears in TrustBridge's directory or GivingSpace. Personal contact details are published only with authorization or where already lawfully public and appropriate to publish.

5. International processing, retention and security

TrustBridge is based in Switzerland and operates internationally. Personal data may be processed in Switzerland, the European Economic Area, the United Kingdom, the United States, Australia, Singapore and the Philippines, and in the country of a donor, charity, bank, network member or provider involved in a transaction. Where a destination is not recognized as adequate, we use an approved transfer mechanism where required, such as adapted standard contractual clauses, the UK International Data Transfer Agreement or Addendum, binding corporate rules or a lawful exception, together with appropriate contractual, organizational and technical safeguards.

We keep data only as long as reasonably necessary for the stated purposes and legal, accounting, tax, audit, sanctions, anti-fraud, dispute and regulatory needs. Fund, contribution, grant, tax and accounting records are normally retained for the relationship and 10 years after the relevant transaction or closure. Charity and due-diligence records may be retained for a similar period, but raw identity copies and highly sensitive evidence should be kept for a shorter verified need. Unsuccessful applications are normally retained for up to 24 months; portal and security logs normally for 12 to 24 months; and marketing data until consent is withdrawn, you opt out or the program ends. Legal holds or mandatory duties may require longer retention.

We use measures appropriate to the sensitivity and risk of the data, including role-based and least-privilege access, multifactor authentication, encryption in transit and at rest where appropriate, logging, monitoring, backups, vendor review, confidentiality duties, staff training, secure disposal and incident response. If a personal-data breach occurs, we assess and document it and notify affected individuals and authorities when applicable law requires.

6. Websites, cookies, marketing and automated tools

Our sites and portals generate technical, security and usage data. Strictly necessary technologies support security, authentication, load balancing, form submission, session continuity and preferences. Where consent is required, non-essential analytics, embedded-media, social-media or advertising technologies are not activated until you choose them. Cookie Settings or a separate cookie notice provides current provider, purpose, duration and choice information. We honor legally recognized universal opt-out signals, such as Global Privacy Control, where required. A general Do Not Track signal is handled only where applicable law recognizes it or our Cookie Settings state otherwise.

Service communications, including receipts, security alerts and fund or grant updates, are not marketing. Optional newsletters and invitations include an unsubscribe method. We use consent where required and otherwise only a lawful charitable soft opt-in or legitimate interest with an effective opt-out. Core charitable services are not conditioned on consent to unrelated marketing.

Automated tools may help match records, detect risk, screen sanctions and politically exposed persons, prevent fraud, secure accounts and prioritize due diligence. They assist trained personnel. TrustBridge does not ordinarily make decisions producing legal or similarly significant effects solely by automated means. If that changes, we will provide any additional notice and rights required by law, including appropriate human review and a way to challenge the decision.

7. Children and minors

Our services are not directed to children. A person under 18, or under the age of majority where they live, should not submit an application or open a GivingSpace account without a parent or legal guardian. We do not knowingly collect personal data online directly from a child under 13 without verifiable parental consent where required. TrustBridge may process limited data about a minor named as a successor, family member, honoree or beneficiary, but restricts access and works through an authorized adult until the minor can act lawfully for themselves. We do not sell children's data or use it for targeted advertising.

8. Your rights and choices

Subject to applicable law and lawful exceptions, you may ask us to:

  1. confirm whether we process your personal data and provide access to it and related information;

  2. correct inaccurate or incomplete data;

  3. delete data, restrict processing or object to processing, including direct marketing and processing based on legitimate interests;

  4. provide data you supplied in a portable, commonly used format or transmit it to another controller where feasible;

  5. withdraw consent and, where applicable U.S. law provides, opt out of sale, legally defined sharing, targeted advertising or qualifying profiling, limit certain sensitive-data uses, and appeal a refusal;

  6. obtain meaningful information and human review where a solely automated significant decision is used; and

  7. complain to TrustBridge or a competent supervisory, data-protection or consumer-protection authority.

TrustBridge is a nonprofit foundation, so some U.S. consumer-privacy laws may not apply or may apply only above statutory thresholds. We nevertheless extend the core rights above worldwide where reasonably feasible. We do not sell personal data for money or exchange donor lists for value. If an online disclosure is legally treated as sale, sharing or targeted advertising, the required opt-out will be available through Cookie Settings, a conspicuous link, a recognized universal signal or another designated method. We do not discriminate against you for exercising a right.

9. Requests, complaints and changes

Email admin@trustbridgeglobal.com with the subject "Privacy Request" or "Data Protection Complaint", or write to the address in section 1. Describe your request and relevant relationship or account, but do not email sensitive supporting documents unless we provide a secure method. We may make proportionate checks to verify identity and an agent's authority.

We respond within applicable periods, ordinarily one month for EU, UK or Swiss requests and 45 days under many U.S. state laws, subject to permitted extensions. Requests are normally free, although lawful fees or refusals may apply to manifestly unfounded, excessive or repetitive requests. You may appeal a denial by replying to our decision. Rights are not absolute; we may retain or use data for legal duties, requested transactions, security, fraud prevention, another person's rights or legal claims.

We accept complaints through the same channels, acknowledge them within 30 days, investigate, keep you informed and communicate the outcome without undue delay. You may also complain to the Swiss FDPIC, an EU/EEA supervisory authority, the UK ICO, an applicable U.S. state attorney general or another competent local authority.

Regulators: Swiss FDPIC | EU/EEA authorities | UK ICO

We review this notice regularly and update it when our practices, services or legal duties change. We will post the current version and effective date and provide additional notice for material changes where appropriate. A privacy notice is informational and is not made binding merely through continued website use.