Email for foundations and associations

The challenge in an organisation that runs on volunteers
A foundation or association exists thanks to people who come and go. The board is periodically re-elected, volunteers stop, new ones step in. With email that catches up with you faster than you'd think. Often the organisation's mail hangs off the private address of one board member, or everyone uses the same free account with one shared password.
As long as the same people stay on, it doesn't stand out. The problem surfaces at a handover: the old treasurer leaves and takes the entire mail history along in their private mailbox, or no one dares change the password anymore because too much depends on it. The organisation's knowledge slowly leaks away, year after year.
A quick note on terms, because they differ per country. In the Netherlands you speak of a foundation (stichting) or an association (vereniging); in Belgium the non-profit form is usually a vzw (association without a profit motive). The email challenge is the same for all three: preserving continuity while the people change.
What the rules require
As soon as you keep a membership list or donor file, you're processing personal data, and then privacy law (the GDPR) applies. Your members' names, addresses, email addresses and payment details are protected; you may only use them for their intended purpose and you should secure them appropriately. That applies to a small association just as much as to a large foundation.
In practice that means: don't store member data in a volunteer's private mailbox, don't share it more widely than necessary, and make sure former board members no longer have access to it after they leave. The Belgian [Data Protection Authority](https://www.gegevensbeschermingsautoriteit.be) explains which rules come with this. This is informative explanation, not legal advice; consult a specialist when in doubt.
What your email then needs to do
For a volunteer organisation, this is what counts above all:
- Role addresses on your own domain.
secretary@,treasurer@andboard@belong to the role. If the role changes hands, the address comes along, together with the earlier correspondence. - No shared passwords. Every board member works with their own access; no one knows anyone else's password.
- A clean handover at a change of board. You grant access to whoever is new and revoke that of the person leaving, without emptying the mailbox itself.
- European, GDPR-compliant hosting, so member data falls under European rules.
- Security and backups: optional two-step verification, filtering against phishing and malware, and automatic backups so the organisation's history isn't lost.
If you want to understand exactly how such an address passes to the successor, read role email addresses and handover. If you're torn between a shared mailbox and a forwarding address, what is a shared mailbox explains it calmly.
Email for foundation and association: why Mailflux fits
Mailflux is professional email on your own domain, hosted in Europe and GDPR-compliant, exactly what an organisation with member data needs. You set up role addresses under your own domain and link them to the people who currently fill that role. Every plan includes antivirus, antispam and antimalware, automatic backups and optional two-step verification. Every board member works via webmail in the browser or via their own mail program, without installation.
At a change of board you only adjust the access; the organisation's mail stays put. If you get stuck somewhere, you get real, personal support. If you're specifically a Belgian vzw, also take a look at email for your association or vzw. An overview of all audiences is on who Mailflux is for.
FAQ
Frequently asked questions
What happens to the email when the board changes?
Because the addresses belong to the role and not to the person, they carry over to the new board member, including the earlier correspondence. You grant the successor access and revoke that of the person leaving. That way the organisation's history is preserved.
Do we have to share the mailbox password?
No, and that's exactly the point. Every board member has their own access to the role addresses that belong to their role. That way you always know who has access and you can cleanly revoke it when someone leaves, without one weak password opening everything.
Does member data fall under the GDPR?
Yes. Your members' names, addresses and contact details are personal data and you must secure them appropriately. Don't store them in a private mailbox and limit access to those who need it. When in doubt about your obligations, consult a specialist.