Industries
IT for not-for-profits
More done, on less, safely.
happier IT supports Canadian charities and not-for-profits across Alberta, British Columbia and Ontario. The constraint here is budget rather than complexity, so the work is deciding which few things genuinely have to be done properly, saying plainly which do not, and making sure the grants you already qualify for are actually claimed.
Who it's for
The systems a not-for-profit actually runs.
Usually a donor database, an accounting package, Microsoft 365 or Google Workspace, and more spreadsheets than anyone would like to admit.
Donor and constituent databases
Blackbaud Raiser’s Edge NXT, Salesforce’s nonprofit tooling, DonorPerfect, Keela. The most sensitive data you hold, and frequently the least protected.
Online giving and event platforms
CanadaHelps and similar services, plus whatever a campaign added last year. Each holds donor records, and each has accounts nobody has reviewed since.
Fund accounting
QuickBooks, Sage 50 or a dedicated fund accounting package. The audit is a fixed date, so changes get scheduled around it.
Microsoft 365 or Google Workspace
Email, files and meetings for staff, board and volunteers. Both vendors run programmes for eligible nonprofits, which is where the licensing conversation should start.
What's included
What actually goes wrong.
Nothing dramatic. The things that create an uncomfortable board meeting or a difficult letter to donors.
-
Donor data living outside the donor database
An export for a mailing becomes a spreadsheet, then eleven spreadsheets on four laptops and a personal cloud drive. Nobody did anything wrong, and nobody can now say where donor information is.
-
Volunteers who left, accounts that stayed
Turnover is high by design and offboarding depends on someone remembering. An account left active is both a privacy exposure and a licence you keep paying for.
-
Grant licences claimed once and never reviewed
Nonprofit programmes have eligibility rules, and vendors change their terms. Organizations end up with seats for people who left, or an eligibility status nobody re-confirmed.
-
One long-serving person holding everything
Every small organization has someone who knows all the systems and holds all the passwords. A shared password manager and written procedures are the cheapest resilience available at this size.
-
Free tools chosen under budget pressure
A free file-sharing account, a personal-tier survey tool, a messaging app nobody administers. Each is reasonable alone, and together they move constituent data outside anything you control.
-
Records that have to be produced
A registered charity must keep books and records, including duplicate donation receipts, available in Canada for the Canada Revenue Agency on request. In practice that is a backup and retention requirement.
How it works
How we start with a not-for-profit.
The first phase is designed to find money, not to spend it.
-
Find the data, and the spend
Where constituent and donor information actually sits, and every subscription and licence being paid for, with renewal dates. Small organizations regularly find duplicate tools and seats for departed staff here.
-
Claim what you are entitled to
We check eligibility for the nonprofit programmes the major vendors run and help with verification. Terms and the mix of donated versus discounted product change, so we confirm the current position.
-
Make the basics routine
Multi-factor authentication, a second check, usually on a phone, before a login is accepted, on email and the donor system, a tested backup, and a joiner and leaver checklist that covers volunteers.
What it costs
What you are accountable for, and to whom.
Not-for-profits answer to more parties than most businesses their size, and each asks a slightly different question.
Registered charities must keep books and records, including duplicate donation receipts, and make them available in Canada to the Canada Revenue Agency on request, for the retention periods the CRA publishes. Technically that means backups you can restore from and knowing where the records live.
Personal information is generally covered by PIPEDA, the federal Personal Information Protection and Electronic Documents Act, with PIPA, the Personal Information Protection Act, in Alberta and British Columbia. If you take donations by card, PCI-DSS, the payment card industry’s security standard, applies to that flow, a strong argument for letting a payment provider handle card data.
CASL, Canada’s Anti-Spam Legislation, governs your email appeals. Registered charities have an exemption where the message’s primary purpose is raising funds, and it is narrower than most organizations assume.
On doing less, deliberately
An organization with a small budget should not buy the same security stack as a bank, and any provider suggesting otherwise is not paying attention.
We will tell you which controls give almost all of the benefit at almost none of the cost. So does the free assessment.
Why us for this
What we can back up, and what is missing.
happier IT works with organizations of roughly 15 to 200 people, the size band most charities sit in.
Verifiable today: certifications across Microsoft, Cisco, Dell, HP/HPE, VMware, CompTIA and Red Hat, and a Canadian security operations centre staffed by our own employees.
Questions
What people ask before they sign anything.
Are there free or discounted software licences for Canadian nonprofits?
Yes. Microsoft and Google both run programmes for eligible nonprofit organizations, combining donated and discounted products. Eligibility rules and what each includes change, Microsoft in particular has revised its nonprofit offer, so the useful answer is the current one.
How do we protect donor data without a real budget?
Concentrate on four things: get donor information back into the donor database and out of spreadsheets, turn on multi-factor authentication for email and the donor system, limit who can export the full list, and test that you can restore a backup.
What records does the CRA expect a charity to keep?
A registered charity must keep adequate books and records, including duplicate donation receipts, and be able to produce them in Canada if asked. Retention periods are set by the Canada Revenue Agency and differ by record type, so check the current requirements with them or with your auditor.
How should we handle volunteers coming and going?
With the same checklist you use for staff, kept shorter. On arrival: an account with access to only what the role needs, and a note of who approved it. On departure: the account disabled that week, any shared password changed, and the licence returned.
Our board wants an IT update. What should it contain?
Four things, on one page: what we spend and on what, what data we hold and where it is, what would happen if we lost access to it for a day, and what we plan to change next year. Boards do not need ticket counts.
Related
Where to go next.
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.