Data Processing Agreement (DPA)
This agreement forms part of the Terms of Service and applies whenever the platform processes personal data on behalf of a customer church. The church is the controller; the platform is the processor, under UK GDPR.
1. Subject matter and duration
Processing of the data described in the Privacy Policy (buyers, guests, team), exclusively to provide the service, for the duration of the contract.
2. Instructions
The platform processes data only on the church’s documented instructions — normal use of the product constitutes that instruction. We never use buyers’ data for our own purposes.
3. Confidentiality and security
Access is limited to platform operators under confidentiality duties. Technical measures include: encryption in transit, payment credentials encrypted at the application layer (AES-256-GCM, key held outside the database), per-customer isolation in the database, and administrative access records.
4. Sub-processors
The church authorises the sub-processors listed in the Privacy Policy (Supabase, Vercel, Resend, Stripe, SumUp). Changes are notified with reasonable notice and a right to object.
5. Assistance and breaches
The platform assists the church with data-subject requests (access, erasure, portability) and notifies the church of any data breach without undue delay after becoming aware.
6. End of processing
On termination, data is returned (full export) and then deleted, unless a legal retention duty applies. Deletion is confirmed in writing on request.