Last updated · 2026-07-14

Privacy Policy

This notice explains how Assemblea ("the platform", "we") processes personal data, and how each church using the platform processes the data of its members, visitors and donors. Membership of, or contact with, a church can reveal religious or philosophical beliefs, which are "special category" data under Article 9 GDPR and receive heightened protection.

Controller and processor

Each church is the data controller of its members', visitors' and donors' personal data. Assemblea is a data processor acting on the church’s documented instructions, under a Data Processing Agreement (Art. 28).

For account and billing data of the church administrators themselves, Assemblea is the controller.

Privacy contact: [email protected].

What data we process

  • Identity & contact: name, email, phone, address, date of birth, gender, photo.
  • Special category (Art. 9): the fact of membership/visiting/giving to a church, church-acts (baptism, marriage, funeral), prayer requests (which may reveal health), family relationships.
  • Financial: donations and church finance records (integer-cents amounts, currency).
  • Technical: IP address, user agent, session and audit logs.

Purposes and lawful bases

  • Managing church membership and pastoral care — Art. 6(1)(b)/(f); for religious-belief data, Art. 9(2)(d) (not-for-profit religious body, members) or Art. 9(2)(a) (explicit consent, visitors/donors).
  • Visitor follow-up and online giving — explicit consent, Art. 6(1)(a) / Art. 9(2)(a), recorded at the point of collection.
  • Account, security and billing — contract and legitimate interest, Art. 6(1)(b)/(f).
  • Transactional email (receipts, password reset, verification) — contract/legitimate interest. We do not send marketing email without separate consent.

Recipients and sub-processors

We share data with a limited set of sub-processors strictly to operate the service (payments, email, sign-in, file storage, hosting). See the Sub-processors page for the current list, what each receives, location and transfer safeguard.

International transfers

Some sub-processors are outside the EEA. Transfers rely on an adequacy decision, the EU–US Data Privacy Framework, or Standard Contractual Clauses, as listed on the Sub-processors page.

Retention

Personal data is kept only as long as needed for the purpose. Sessions are removed at expiry; audit logs are retained ~24 months; closed support conversations ~12 months; read in-app notifications ~90 days. Church records are kept while the church remains a customer and are deleted or anonymised on account closure or on a valid erasure request.

Your rights

You may request access, rectification, erasure, restriction, portability, and object to processing (Arts. 15–21). For data held by a church, contact that church (the controller); we will assist it as processor. For platform-controlled data, contact us at [email protected]. You may also lodge a complaint with your supervisory authority.

Security

We apply tenant isolation, hashed credentials, encrypted transport, per-tenant access control on files, role-based access to special-category data, and an audit trail of changes (Art. 32).

Exercise your privacy rights

Questions about this document or your data? Contact [email protected].