Mentions légales
Accord de traitement des données
Template for legal review. This document is a starting point prepared for ChurchBright. It has not been reviewed by a lawyer and must be checked and completed (every item in [square brackets]) by qualified legal counsel before it is relied on.
Last updated: [date]
This data processing agreement ("DPA") forms part of the Terms of service between the church or organisation using the service ("controller") and [Company legal name] ("processor").
1. Subject matter and duration
The processor processes personal data on behalf of the controller to provide the service for the duration of the agreement and any agreed post-termination period for data export and deletion.
2. Nature and purpose
Hosting, storage, organisation, retrieval, transmission (including SMS, WhatsApp, voice, email and push messages requested by the controller), display and deletion of church data in order to provide the service.
3. Categories of data subjects and data
- Data subjects: members, visitors, first-time guests, children and their guardians, donors, volunteers, staff and team members of the controller.
- Personal data: names, contact details, dates of birth, family relationships, attendance, giving records, group membership, notes, messages and any other data the controller chooses to store.
- Special categories: religious affiliation is implied by the nature of the service. The controller may also record prayer requests or pastoral notes. The controller is responsible for having a lawful basis for this processing.
4. Processor obligations
The processor will:
- Process personal data only on the controller's documented instructions, including these terms and the controller's use of the service.
- Ensure that personnel with access are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see section 6).
- Engage sub-processors only as set out in section 5.
- Assist the controller, taking into account the nature of processing, in responding to data subject requests and in meeting its security, breach-notification and impact-assessment obligations.
- Notify the controller without undue delay, and in any event within [48] hours, after becoming aware of a personal data breach affecting church data.
- At the end of the service, allow the controller to export its data and then delete it from live systems within [30] days and from backups within [period], unless the law requires retention.
- Make available information reasonably necessary to demonstrate compliance and allow for audits as set out in [audit clause].
5. Sub-processors
The controller authorises the processor to use sub-processors for hosting, email, SMS and voice delivery, payment processing and support, as listed at [sub-processor list URL]. The processor will give [30] days' notice of new sub-processors, during which the controller may object.
6. Security measures
Including: encryption in transit (HTTPS); encryption of stored payment-gateway and messaging credentials; logical separation of each church's data with automated checks; role-based access with branch-level restrictions; two-factor sign-in; audit logs of sensitive actions; rate limiting of sign-in and public forms; re-encoding of uploaded images to remove location metadata; and regular backups [describe frequency and retention].
7. International transfers
Where church data is transferred outside the controller's jurisdiction, the processor will use appropriate safeguards [for example standard contractual clauses].
8. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of service, [except where the law does not permit].
9. Precedence
If this DPA conflicts with the Terms of service regarding personal data, this DPA prevails.