NONPROFIT

IT support for nonprofits

Restricted funding is a technical constraint, not a budget one.

Grant terms decide what can be bought and when. Donation and discount programs exist for organizations that qualify and are consistently underclaimed, because working them is nobody’s job. And the obligations attached to donor data do not scale down for a small organization.

The result is a familiar shape: an organization paying retail for something it could have had at a fraction, running infrastructure sized for an operation it no longer has, and holding data under rules nobody on staff has read.

Curved timber-lined interior beneath a glazed rooflight

Start with the number

Count your paid licenses. Count your people.

If those two numbers are not close, you already know the answer and the only question is the size of it. Most organizations have never put the two numbers on the same page.

Free, takes a minute, and you do not have to speak to anyone.

Four things that cost nonprofits money, in order of how much

01

Eligibility that is assumed rather than established

Every major vendor runs a nonprofit program. Every one of them carries conditions, and those conditions change without notice or announcement.

The failure mode is not that organizations are refused. It is that nobody checks.

An organization that qualified two years ago may not qualify now, because the terms moved.

An organization that never applied may have qualified the whole time.

A tier that was free can be retired, moving you onto something priced, and the first notice is the invoice.

That last one is not hypothetical. Microsoft retired a nonprofit tier and the organizations affected discovered it at renewal. The security consequences were larger than the licensing consequences, because the retired tier carried protections the replacement did not, and nobody mapped the difference.

02

Donor data, and the state law nobody mentions

Small organizations tend to assume comprehensive privacy statutes are aimed at large companies. In most states that is roughly right, because most state privacy laws exempt nonprofits.

New Jersey does not.

The New Jersey Data Protection Act contains no nonprofit exemption. It is a deliberate outlier among state comprehensive privacy statutes. And the exemption it does contain runs the other way from what people expect: state agencies, political subdivisions and their instrumentalities are exempt.

So a public school district is outside the Act, and the nonprofit working alongside it is inside, if it meets the processing thresholds.

If you operate in New Jersey and have been told a comprehensive privacy statute does not reach you, that advice was probably correct for a different state.

03

Artificial intelligence, and the boundary that runs the wrong way

The single most expensive misconception in nonprofit technology right now is that paying for a tool buys you privacy protections.

It does not. On every major platform, the boundary that decides whether your input can be used to improve a model runs between consumer and business accounts, not between free and paid tiers. A paid consumer account sits on the wrong side of it. A free business account sits on the right side.

Nothing in the interface tells a member of staff which side they are on.

So the question for your organization is not whether you are paying for the good version. It is which account the person is actually signed into, and that is a question you can only answer by asking.

Which brings the second problem. An assistant inside your tenant surfaces what your permissions already allowed, retrievable in natural language at conversational speed. When that turns out to be more than anyone intended, the finding is never about the AI. It is about a permissions model that was only ever protected by things being hard to find. Deploying an assistant does not create the exposure. It makes it searchable.

04

Infrastructure sized for an organization you no longer are

Funding changes shape. Headcount moves with it. Infrastructure rarely does, because nobody owns the job of shrinking something that already works.

The cost is not the servers. It is the licensing attached to them, the support contracts renewing on autopilot, and the architecture decisions that made sense for a grant cycle that ended two years ago and now require replacement rather than adjustment.

What we do

Qwalora establishes what is true about your environment, your entitlements and your obligations, and states it in writing. Every finding cites the vendor’s own published term or the governing rule, with the date it was read. Where something cannot be verified, we say so rather than estimate it.

We also supply. Qwalora holds reseller and distribution arrangements with technology vendors and earns margin on products it supplies. We earn no margin from you on any product named in a report delivered to you, during the engagement and for twelve months afterward. Supply is a separate agreement, and you are free to act on every finding through any reseller you choose.

Most firms that can tell you what you are overpaying for have a reason not to. We wrote that reason out of the contract.

The engagements

Licensing Review

Fixed fee, ten business days. Your entitlement against your spend against the programs you qualify for. What is recoverable, what is exposed at your next renewal, what you are paying for twice. We need your invoices, your license assignment export and your headcount, and most organizations can produce all three in a morning.

AI Exposure Review

Fixed fee, fourteen calendar days. Which AI services are in use including the ones nobody approved, what terms apply at the tier each one is on, whether staff reach them on work or personal accounts, and what an assistant grounded in your own files would surface to an ordinary member of staff.

The evidence

We publish the research these engagements rest on, in full, with every source named and dated.

Where the donor file goes. Research Note 2026-01. Fourteen pages on donor data and AI privacy in nonprofit organizations. Every vendor term quoted from the vendor’s own page with the date it was read, including the consumer-versus-business boundary described above, and a list of the figures in common circulation that the paper declines to repeat because no primary source supports them.

Why the advice does not transfer. Research Note 2026-04. Sixteen pages, twenty-seven primary sources, including the New Jersey Data Protection Act analysis and its treatment of nonprofits.

Microsoft’s nonprofit licensing change was a security change. What happened when a tier was retired and nobody wrote to tell anyone.

One-time money buys recurring obligations. What grant and capital purchases cost every year afterward, and why the purchase gets scrutinized while the obligation does not.

Before you contact us

Ask what your organization has already stated about how it handles data, on an insurance application, a funder questionnaire or a board paper.

Then ask who verified it before it was signed.

Those are representations. If nobody checked them, that is the single highest-value hour available to you and it requires no technology at all.

Book a thirty minute scoping call

We establish what is in scope, what we would need from you, and whether this is the right engagement at all. You receive a fixed quote in writing afterward. No obligation and no follow-up sequence.