Back to diDo

diDo mobile and platform

Privacy Notice

How diDo collects, uses, shares and keeps your personal data — and, importantly, who at your organisation can read what you write.

In force from 17 September 2026. Last updated 17 September 2026. Read the Terms of Service

Data controller

diDo, operated by Jules D'Oca

Established in

Romania

Privacy contact

jules@didof2f.com

1.Who we are

diDo is a mobile learning app and course creation platform for face-to-face fundraising teams. This notice explains how we handle personal data.

The controller for the personal data described here is diDo, operated by Jules D'Oca, established in Romania. As an establishment in the European Union we are subject to the General Data Protection Regulation (EU) 2016/679 ("GDPR") and to Romanian data protection law.

We do not operate a public office. The fastest way to reach us on anything in this notice — including a data access, correction or deletion request — is by email at jules@didof2f.com, and we will give a postal address on request.

Where your employer or the organisation that invited you assigns you training on diDo, that organisation generally determines why your data is processed, and diDo processes it on their instructions. If you have a question they cannot answer, contact us directly at jules@didof2f.com.

2.What we collect

We collect what is needed to run learner accounts and deliver assigned training:

CategoryWhat it includes
AccountEmail address and password
ProfileName, phone number if you give one, and the organisation, team and role you belong to
Learning activityWhich courses and modules you have opened and completed, and when
AssessmentQuiz attempts, answers and scores
RecognitionPoints, rank and achievements earned
Written responsesReflections and notes you type into a course, including the prompt they answer and coursework assembled from linked notes
Engagement recordsDonation and shift information you enter yourself in the engagement tracker
Device storageA copy of your account, course, progress and written-work data held on your device so learning loads quickly and works offline

We do not collect location data, contacts, photos or microphone audio. The app asks for camera access only to scan an organisation invite QR code during onboarding; no image is stored, and you can type an invite code instead.

3.Who can see your written reflections

This section matters most, so it is stated plainly.

When you write a reflection or a note inside a course, your team leader and your organisation's administrators can read the full text of what you wrote. They can also see your progress, your quiz scores and your engagement records. Written responses may be included when an organisation exports its training records.

This is how diDo is designed to work: reflections are part of coaching, and leaders use them to support your development. Every place in the app where you can write a reflection tells you this before you type.

Because your responses are read by people at your organisation, please do not write anything about your health, your religious or political beliefs, your sex life or sexual orientation, your ethnic origin, or your trade union membership. Course prompts are written to avoid asking about these things.

Other learners cannot see your written responses. Leaders can only see the learners in their own team; administrators can see learners in their own organisation.

4.Why we process your data, and our lawful basis

PurposeLawful basis
Creating your account, signing you in, and keeping it securePerformance of a contract
Showing you the courses your organisation has assigned and saving your progressPerformance of a contract
Letting your team leader and administrators see your progress, scores and written responses for coaching and training administrationLegitimate interests of your organisation in training and developing its team
Keeping the service working, diagnosing faults and preventing abuseLegitimate interests in operating a secure and reliable service

Where we rely on legitimate interests, we have weighed those interests against your rights. You can object to that processing at any time using the contact details below.

We do not rely on consent for the core functioning of the service, because training is assigned to you by your organisation.

5.Artificial intelligence

diDo uses AI to help course authors write course content. This happens before any learner uses the course, and it works only on the source material the author supplies.

Your personal data is never sent to an AI provider. Your reflections, notes, quiz answers, scores and progress are not used to generate content, are not used to train any AI model, and are not shared with any AI provider.

6.Who we share data with

Within your organisation: as described above.

With service providers who help us run diDo:

ProviderWhat they doWhat they handle
SupabaseAuthentication, database and file storageAll learner account and learning data — stored in the European Union (Ireland)
VercelWebsite and application hostingTechnical request data including IP address
ResendSending account emails — sign-in, password reset and invitationsYour email address
SentryError monitoring on the course-building platformDiagnostic error data, with email addresses and phone numbers removed before it is sent
Anthropic, fal.ai, Unsplash, GIPHYCourse authoring and imageryAuthor-supplied course material only — no learner data

These providers act on our instructions and are bound by contract. We do not sell your personal data, and we do not use it for advertising.

Your learner data is stored in the European Union. Some of the providers above that support the service — rather than store your learning records — are based outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on the safeguards permitted by Chapter V of the GDPR: an adequacy decision of the European Commission where one applies, and otherwise the EU Standard Contractual Clauses together with the supplementary measures those clauses require.

We may also disclose data where we are legally required to.

7.How long we keep it

We keep your account and all data associated with it for as long as your account is open.

When your account is deleted — at your request, or when your organisation removes you — your account, progress, quiz records, written responses and engagement records are deleted within 30 days. The short delay is a safeguard against accidental deletion, not an archive.

Your organisation may separately keep its own record that you completed a course, for their training and compliance purposes. That record is theirs, and their own retention rules apply to it.

8.Your rights

Under the GDPR you have the right to:

  • ask for a copy of the personal data we hold about you
  • ask us to correct data that is wrong or incomplete
  • ask us to delete your data
  • ask us to restrict how we use your data
  • receive your data in a portable format, or have it sent to another provider
  • object to processing we carry out on the basis of legitimate interests
  • withdraw consent, where we have relied on it

To exercise any of these, email jules@didof2f.com. We will respond within one month. There is no charge.

Deletion and access requests are handled by our team rather than through a button in the app. We are a small team and we handle these personally.

If you are unhappy with how we have handled your data you can complain to the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), at dataprotection.ro. You may also complain to the data protection authority in the European Union country where you live or work.

9.Security

Access to learner data is controlled at the database level, so the app can only return data to people entitled to see it. Data is encrypted in transit and at rest by our infrastructure providers.

A small number of diDo staff can access the underlying database in order to operate and support the service. This includes written responses. We limit this to what is necessary to run and support diDo.

10.Children

diDo is built for adults working or volunteering in fundraising. It is not intended for anyone under 16, and we do not knowingly collect data about children. If you believe a child has an account, contact us and we will delete it.

11.Changes to this notice

If we change how we handle personal data we will update this page and change the date at the top. Where a change materially affects you, we will tell you in the app or by email before it takes effect.