Last updated · 2026-07-14
Data Processing Agreement
This Data Processing Agreement (DPA) forms part of the Terms of Service between the church ("Controller") and Assemblea ("Processor") and governs processing of personal data under Article 28 GDPR.
Subject matter and roles
The Processor processes personal data only on the documented instructions of the Controller, to provide the platform. The Controller determines the purposes and means.
Nature of processing
- Data subjects: church members, visitors, donors, staff users.
- Categories: identity & contact data; special category data (religious belief by association, church-acts, prayer requests); financial/giving data; technical data.
- Operations: storage, organisation, retrieval, transmission to sub-processors, erasure.
Processor obligations
- Confidentiality of personnel; appropriate technical and organisational measures (Art. 32).
- Assist the Controller with data-subject requests and with Arts. 32–36 obligations.
- Notify the Controller without undue delay on becoming aware of a personal-data breach.
- Delete or return personal data at the end of the service, save where law requires retention.
- Make available information needed to demonstrate compliance and allow audits.
Sub-processors
The Controller authorises the sub-processors listed on the Sub-processors page. The Processor imposes equivalent data-protection obligations on each and remains liable for their performance. The Processor will give notice of intended changes, allowing objection.
International transfers
Transfers outside the EEA rely on an adequacy decision, the EU–US Data Privacy Framework, or Standard Contractual Clauses, as set out on the Sub-processors page.
Questions about this document or your data? Contact [email protected].