What we collect, why we collect it, who we share it with, and how we protect it. This applies to custorian.org and to Custorian's membership, donation and payment processes.
Foreningen Custorian (CVR 46399455, Copenhagen, Denmark) is the data controller for personal data processed through custorian.org, its membership and donation forms, and its payment flows. Questions or requests go to info@custorian.org.
We do not knowingly collect personal data from children through this website. It is scoped to adults, organisations and professional contacts; it is not directed at children, and none of Custorian's own web forms are intended for use by a child.
We process membership and donation data under contract / legitimate interest (administering your membership or gift), enquiry data under legitimate interest (responding to you and pursuing our non-profit purpose), and payment confirmation data under contract (fulfilling the membership or donation you requested). Where Danish association law requires us to keep a member register or financial records, that processing rests on legal obligation.
We do not sell, rent, or share personal data with third parties for their own marketing. Data passes to the following processors, each strictly to deliver the service you requested:
| Party | What they receive | Why |
|---|---|---|
| Stripe | Payment and billing details you enter directly on Stripe's checkout page | Processes membership dues and donation payments. Custorian never sees or stores your card number. |
| MobilePay | Payment details you enter directly in the MobilePay app | Alternative Danish payment method for donations (2133) only; not used for membership dues. |
| Web3Forms | Whatever you type into a website form | Relays form submissions by email to info@custorian.org; Web3Forms does not retain submissions after delivery. |
| Supabase | Stakeholder/outreach contact records, access-restricted | Hosts Custorian's internal, login-gated contact log. No public read access. |
| Google Workspace | Email and shared documents | Custorian's operational email and document platform, under Google's own data processing terms (Google for Nonprofits). |
Where a processor is based outside the EU/EEA, that transfer relies on the processor's own GDPR-compliant safeguards (standard contractual clauses or equivalent). Custorian does not itself transfer personal data outside the EU/EEA on its own initiative.
Member data is kept for as long as you are a member, then deleted, subject to Danish bookkeeping law requiring certain financial records to be kept for five years. Donation records are kept as long as required for accounting purposes. Enquiry and outreach data is kept only as long as relevant to the purpose it was collected for, and is reviewed periodically.
Access to membership and stakeholder data is restricted to Custorian's working team through a login-gated internal system with row-level access control and no public write access. Payment card data is handled entirely by Stripe and MobilePay under their own PCI-compliant security standards; Custorian's systems never receive or store it. Financial and banking credentials are held by the chairperson only.
Under GDPR, you can ask us to access, correct, delete, or provide a copy of your personal data, or object to how we use it, by writing to info@custorian.org. We respond within one month. You can also complain to the Danish Data Protection Agency, Datatilsynet.
We will update this page as our data practices change and note the effective date above. Material changes affecting members or donors will be communicated by email.