Last updated · 2026-07-14
Privacy Policy
This notice explains how Assemblea ("the platform", "we") processes personal data, and how each church using the platform processes the data of its members, visitors and donors. Membership of, or contact with, a church can reveal religious or philosophical beliefs, which are "special category" data under Article 9 GDPR and receive heightened protection.
Controller and processor
Each church is the data controller of its members', visitors' and donors' personal data. Assemblea is a data processor acting on the church’s documented instructions, under a Data Processing Agreement (Art. 28).
For account and billing data of the church administrators themselves, Assemblea is the controller.
Privacy contact: [email protected].
What data we process
- Identity & contact: name, email, phone, address, date of birth, gender, photo.
- Special category (Art. 9): the fact of membership/visiting/giving to a church, church-acts (baptism, marriage, funeral), prayer requests (which may reveal health), family relationships.
- Financial: donations and church finance records (integer-cents amounts, currency).
- Technical: IP address, user agent, session and audit logs.
Purposes and lawful bases
- Managing church membership and pastoral care — Art. 6(1)(b)/(f); for religious-belief data, Art. 9(2)(d) (not-for-profit religious body, members) or Art. 9(2)(a) (explicit consent, visitors/donors).
- Visitor follow-up and online giving — explicit consent, Art. 6(1)(a) / Art. 9(2)(a), recorded at the point of collection.
- Account, security and billing — contract and legitimate interest, Art. 6(1)(b)/(f).
- Transactional email (receipts, password reset, verification) — contract/legitimate interest. We do not send marketing email without separate consent.
Recipients and sub-processors
We share data with a limited set of sub-processors strictly to operate the service (payments, email, sign-in, file storage, hosting). See the Sub-processors page for the current list, what each receives, location and transfer safeguard.
International transfers
Some sub-processors are outside the EEA. Transfers rely on an adequacy decision, the EU–US Data Privacy Framework, or Standard Contractual Clauses, as listed on the Sub-processors page.
Retention
Personal data is kept only as long as needed for the purpose. Sessions are removed at expiry; audit logs are retained ~24 months; closed support conversations ~12 months; read in-app notifications ~90 days. Church records are kept while the church remains a customer and are deleted or anonymised on account closure or on a valid erasure request.
Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing (Arts. 15–21). For data held by a church, contact that church (the controller); we will assist it as processor. For platform-controlled data, contact us at [email protected]. You may also lodge a complaint with your supervisory authority.
Security
We apply tenant isolation, hashed credentials, encrypted transport, per-tenant access control on files, role-based access to special-category data, and an audit trail of changes (Art. 32).
Questions about this document or your data? Contact [email protected].