Skip to content
ChurchBright
  • Product

    Run your church

    • Church managementMembers, families and records
    • First-timer follow-upWelcome guests, keep new converts
    • Events & check-inRegistration, tickets and QR check-in
    • Groups & cellsCells, fellowships and departments
    • Serve & service planningTeams, rotas and run sheets
    • Multi-branch & denominationsHQ, regions, zones and parishes

    Reach & engage

    • MessagingSMS, WhatsApp, voice and email
    • Member appYour church in every pocket
    • Website builderA beautiful church website
    • AI assistantDrafts, summaries and insights
    • CompetitionsBible quizzes and challenges

    Giving, media & platform

    • Online givingLocal payments in your currency
    • Finance & remittancesAccounting from branch to HQ
    • Media & livestreamSermons, podcasts, live and TV
    • API & integrationsConnect your other tools
    See every feature →How we compareBook a demo
  • Pricing
  • Resources
    • BlogGuides for church leaders
    • Help centerHow-to articles
    • CompareWhat makes us different
    • PartnersResellers and ambassadors
    • SecurityHow we protect your data
    • System statusIs everything running?
  • About
Log in Start free

Legal

Data processing agreement

Terms of servicePrivacy policyCookie policyData processing agreement

Template for legal review. This document is a starting point prepared for ChurchBright. It has not been reviewed by a lawyer and must be checked and completed (every item in [square brackets]) by qualified legal counsel before it is relied on.

Last updated: [date]

This data processing agreement ("DPA") forms part of the Terms of service between the church or organisation using the service ("controller") and [Company legal name] ("processor").

1. Subject matter and duration

The processor processes personal data on behalf of the controller to provide the service for the duration of the agreement and any agreed post-termination period for data export and deletion.

2. Nature and purpose

Hosting, storage, organisation, retrieval, transmission (including SMS, WhatsApp, voice, email and push messages requested by the controller), display and deletion of church data in order to provide the service.

3. Categories of data subjects and data

  • Data subjects: members, visitors, first-time guests, children and their guardians, donors, volunteers, staff and team members of the controller.
  • Personal data: names, contact details, dates of birth, family relationships, attendance, giving records, group membership, notes, messages and any other data the controller chooses to store.
  • Special categories: religious affiliation is implied by the nature of the service. The controller may also record prayer requests or pastoral notes. The controller is responsible for having a lawful basis for this processing.

4. Processor obligations

The processor will:

  1. Process personal data only on the controller's documented instructions, including these terms and the controller's use of the service.
  2. Ensure that personnel with access are bound by confidentiality.
  3. Implement appropriate technical and organisational security measures (see section 6).
  4. Engage sub-processors only as set out in section 5.
  5. Assist the controller, taking into account the nature of processing, in responding to data subject requests and in meeting its security, breach-notification and impact-assessment obligations.
  6. Notify the controller without undue delay, and in any event within [48] hours, after becoming aware of a personal data breach affecting church data.
  7. At the end of the service, allow the controller to export its data and then delete it from live systems within [30] days and from backups within [period], unless the law requires retention.
  8. Make available information reasonably necessary to demonstrate compliance and allow for audits as set out in [audit clause].

5. Sub-processors

The controller authorises the processor to use sub-processors for hosting, email, SMS and voice delivery, payment processing and support, as listed at [sub-processor list URL]. The processor will give [30] days' notice of new sub-processors, during which the controller may object.

6. Security measures

Including: encryption in transit (HTTPS); encryption of stored payment-gateway and messaging credentials; logical separation of each church's data with automated checks; role-based access with branch-level restrictions; two-factor sign-in; audit logs of sensitive actions; rate limiting of sign-in and public forms; re-encoding of uploaded images to remove location metadata; and regular backups [describe frequency and retention].

7. International transfers

Where church data is transferred outside the controller's jurisdiction, the processor will use appropriate safeguards [for example standard contractual clauses].

8. Liability

Each party's liability under this DPA is subject to the limitations in the Terms of service, [except where the law does not permit].

9. Precedence

If this DPA conflicts with the Terms of service regarding personal data, this DPA prevails.

ChurchBright

Church management, giving, messaging, media and apps — built for churches in Africa, the diaspora and everywhere else.

Start free

Product

  • Church management
  • First-timer follow-up
  • Messaging
  • Online giving
  • Finance & remittances
  • Events & check-in
  • Groups & cells
  • Serve & service planning
  • All features

Resources

  • Pricing
  • Compare
  • Blog
  • Help center
  • System status
  • Security

Company

  • About us
  • Contact
  • Book a demo
  • Partner program

Legal

  • Terms of service
  • Privacy policy
  • Cookie policy
  • Data processing agreement

© 2026 ChurchBright. Made for churches everywhere.

EnglishFrançaisPortuguêsEspañol