Last updated · 2026-09-17

Privacy Policy

This document is shown in English; a translation in your language is in preparation.

This notice explains how Assemblea ("the platform", "we") processes personal data, and how each church using the platform processes the data of its members, visitors and donors. Membership of, or contact with, a church can reveal religious or philosophical beliefs, which are "special category" data under Article 9 GDPR and receive heightened protection.

Controller and processor

Each church is the data controller of its members', visitors' and donors' personal data. Assemblea is a data processor acting on the church’s documented instructions, under a Data Processing Agreement (Art. 28).

For account and billing data of the church administrators themselves, Assemblea is the controller.

Privacy contact: [email protected].

What data we process

  • Identity & contact: name, email, phone, address, date of birth, gender, photo.
  • Special category (Art. 9): the fact of membership/visiting/giving to a church, church-acts (baptism, marriage, funeral), prayer requests (which may reveal health), family relationships.
  • Financial: donations and church finance records (integer-cents amounts, currency).
  • Technical: IP address, user agent, session and audit logs, and when an account last used the app.
  • Service usage metrics: aggregate counts of which features are used (feature, route pattern, role, day). No content, no record ids, no IP address, no user identifier.
  • Public website visits (assemblea.app): aggregate daily counts of pages viewed, the site or campaign a visit came from (referring domain, utm tags), country, device type, site language and steps of the sign-up form. No cookie and no identifier; the IP address is only used in memory (see the Cookie Policy).
  • Sign-up attribution: for a church that registers, where that visit came from (source, campaign, first page) is saved with the church’s account.

Purposes and lawful bases

  • Managing church membership and pastoral care — Art. 6(1)(b)/(f); for religious-belief data, Art. 9(2)(d) (not-for-profit religious body, members) or Art. 9(2)(a) (explicit consent, visitors/donors).
  • Visitor follow-up and online giving — explicit consent, Art. 6(1)(a) / Art. 9(2)(a), recorded at the point of collection.
  • Account, security and billing — contract and legitimate interest, Art. 6(1)(b)/(f).
  • Transactional email (receipts, password reset, verification) — contract/legitimate interest. We do not send marketing email without separate consent.
  • Service emails to account holders — legitimate interest, Art. 6(1)(f): a Monday summary of the church’s week (counts only, never names), which becomes a reminder with suggestions when the account has not been used for a while (weekly for the first four weeks, then every four weeks); and, about every two weeks, a short “what’s new” email about improvements to the features the account can use. Each church is the controller of its weekly summary, we are the controller of the product news. Neither promotes plans or upgrades. Every email has a one-click unsubscribe link; both can be switched off in Settings → Notifications, and a church administrator can switch the weekly summary off for the whole church (Art. 21).
  • Improving the service — aggregate service-usage metrics, legitimate interest, Art. 6(1)(f). We are the controller for these metrics. Distinct users are estimated with a one-way sketch, so no user identifier is stored. A church administrator can switch them off in Settings (Privacy & compliance), which also deletes what was collected; anyone can object by writing to [email protected].
  • Measuring the audience of our public website and how the sign-up form performs — legitimate interest, Art. 6(1)(f), for our own statistics only; we are the controller. The visitor’s IP address and browser identification are used in memory to derive the country and a daily count of unique visitors (a hash mixed with a random value deleted after 48 hours) and are never stored. Browsers sending Global Privacy Control or Do Not Track are not measured; anyone can object by writing to [email protected].
  • Knowing which channels bring new churches — legitimate interest, Art. 6(1)(f): the source, campaign and first page of the visit that ended in a registration are stored with the new church account (organisation data, never used to profile a person) and deleted with it. The aggregate website statistics are never linked to it.

Recipients and sub-processors

We share data with a limited set of sub-processors strictly to operate the service (payments, email, sign-in, file storage, hosting). See the Sub-processors page for the current list, what each receives, location and transfer safeguard.

International transfers

Some sub-processors are outside the EEA. Transfers rely on an adequacy decision, the EU–US Data Privacy Framework, or Standard Contractual Clauses, as listed on the Sub-processors page.

Retention

Personal data is kept only as long as needed for the purpose. Sessions are removed at expiry; audit logs are retained ~24 months; closed support conversations ~12 months; read in-app notifications ~90 days; aggregate usage metrics and public website statistics ~24 months. Church records are kept while the church remains a customer and are deleted or anonymised on account closure or on a valid erasure request.

Your rights

You may request access, rectification, erasure, restriction, portability, and object to processing (Arts. 15–21). For data held by a church, contact that church (the controller); we will assist it as processor. For platform-controlled data, contact us at [email protected]. You may also lodge a complaint with your supervisory authority.

Security

We apply tenant isolation, hashed credentials, encrypted transport, per-tenant access control on files, role-based access to special-category data, and an audit trail of changes (Art. 32).

Exercer vos droits RGPD

Questions about this document or your data? Contact [email protected].