Data processing addendum
How we process personal data on your church's behalf: roles, purposes, subprocessors, security, breach notification and deletion.
Last updated September 2026
Template. This document is a starting point written in plain English. Review it with counsel before relying on it, and replace the bracketed placeholders with your legal entity, governing law and contact details.
1. Scope and roles
This addendum forms part of the terms of service between the church (“Customer”, the controller) and Steeple (“Processor”). It applies whenever we process personal data on your behalf in the course of providing the Service. Where data protection law uses different terms (for example “business” and “service provider”), read this addendum accordingly.
- Customer determines the purposes and means of processing and is responsible for having a lawful basis, including consent for text messages and for records about children.
- Processor processes personal data only on Customer's documented instructions, which are the terms, this addendum and the use of the Service's features.
2. Details of processing
- Subject matter: provision of hosted church management software.
- Duration: the term of the agreement plus the deletion period below.
- Nature and purpose: storage, retrieval, display, transmission (email and SMS), reporting and backup of data entered by Customer and its people, so that Customer can run its church.
- Categories of data subjects: members, visitors, donors, volunteers, staff and children of Customer's community; Customer's users.
- Categories of personal data: names, contact details, household relationships, attendance and check-in records, giving history (never full card numbers), messages, form and prayer submissions, staff and HR records, notes and custom fields. Customer may choose to store special categories such as religious affiliation (implied by membership), health notes (allergies) and background-check status.
3. Processor obligations
- Process personal data only on Customer's instructions, and tell Customer if we believe an instruction breaks the law.
- Ensure everyone with access to personal data is bound by confidentiality.
- Implement the security measures in section 5.
- Assist Customer with data-subject requests, impact assessments and consultations with authorities, to the extent the information is available to us.
- Make available the information needed to demonstrate compliance and allow reasonable audits, no more than once a year unless required by an authority or following a breach, on 30 days' notice and subject to confidentiality.
- Delete or return personal data at the end of the agreement as set out in section 7.
4. Subprocessors
Customer authorizes the following subprocessors. Processor has written agreements with each imposing data-protection obligations no less protective than this addendum and remains responsible for their performance.
- Stripe, Inc.: payment processing and payouts on Customer's connected Stripe account. Stripe also acts as an independent controller for payment data under its own terms.
- Twilio Inc.: sending and receiving SMS messages; phone numbers and message content.
- Resend: sending email; recipient addresses, message content and delivery events.
- Anthropic, PBC: optional AI generation invoked by a user; the text the user submits (for example a sermon outline). Not used unless Customer enables and uses the feature.
- [Hosting provider, region]: application hosting, database and encrypted backups.
We will give Customer's owner at least 14 days' notice by email before adding a subprocessor. If Customer objects on reasonable data-protection grounds and we cannot resolve the objection, Customer may terminate the affected service and receive a pro-rated refund of prepaid fees.
5. Security measures
- Encryption in transit (TLS) for all connections; disk-level encryption at rest at the hosting provider.
- Logical separation of each Customer's data by church identifier, enforced in every query.
- Role-based access control with per-request verification of membership; module-level permissions.
- Passwords stored as salted hashes; sessions in HttpOnly cookies; password reset by single-use expiring tokens.
- Payment card data handled exclusively by Stripe through hosted Checkout; Processor stores only tokens and metadata.
- Audit logging of significant actions with user, action, target and time.
- Daily database backups with copies stored off the primary host; periodic restore tests.
- Multi-factor authentication on Processor's infrastructure and provider accounts; access limited to operating personnel.
- Webhook signature verification and idempotency for provider callbacks.
Measures not yet in place, stated for transparency: independent SOC 2 or ISO 27001 certification; customer-managed encryption keys; two-factor authentication for Customer's own users. See the security page, which we keep current.
6. Personal data breach notification
If we become aware of a personal data breach affecting Customer's data, we will notify Customer's owner and admins by email without undue delay and in any case within [48] hours of becoming aware, with the information we have at that time: the nature of the breach, categories and approximate number of records and people affected, likely consequences, and the measures taken or proposed. We will update the notice as we learn more and will cooperate with Customer's own notification obligations.
7. Return and deletion
- Customer may export all personal data at any time from Settings, in JSON and CSV formats.
- On termination or on Customer's deletion of the workspace, we delete personal data from production systems promptly and from backups within [30] days, unless law requires longer retention of specific records.
- On written request we will confirm deletion.
8. International transfers
Personal data is stored in [region]. Where processing by us or a subprocessor involves a transfer that requires a legal mechanism, the parties rely on [standard contractual clauses / other mechanism], which are incorporated by reference. On request we will provide the relevant documentation.
9. General
This addendum prevails over the terms to the extent of any conflict about the processing of personal data. Liability under this addendum is subject to the limitations in the terms. Governing law: [as in the terms]. Contact for data-protection matters: [email protected], [legal entity name and address].