Data Processing Agreement

Effective: July 2026 · Version 1.0

This DPA forms part of, and is incorporated into, Ekkleo's Terms of Service. By accepting the Terms of Service, the church (Data Controller) also accepts this Data Processing Agreement. No separate signature is required.

1. Definitions

  • "Controller" means the church or faith organisation that uses Ekkleo to manage its congregation and has accepted these terms.
  • "Processor" means Ekkleo (the platform operator).
  • "Data Subjects" means congregation members, visitors, volunteers, and any other individuals whose personal data is entered into the platform by or on behalf of the Controller.
  • "Personal Data" has the meaning given in UK GDPR Article 4.
  • "Special Category Data" includes health information (medical notes for children's ministry, DBS records) and, where applicable, religious beliefs held about individuals.
  • "Services" means the Ekkleo platform including all modules described in the Terms of Service.
  • "UK GDPR" means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018.

2. Roles and responsibilities

The Controller and Processor acknowledge that:

  • The Controller (the church) determines the purposes and means of processing congregation data and bears primary responsibility for lawful processing under UK GDPR.
  • The Processor (Ekkleo) processes personal data only on the documented instructions of the Controller and only for the purpose of providing the Services.
  • The Controller is responsible for obtaining a lawful basis for processing (e.g. consent, legitimate interests, or legal obligation) before inputting data into the platform.
  • The Controller is responsible for informing data subjects (congregation members) about processing activities and their rights, typically through the church's own privacy notice.

3. Categories of data processed

Ekkleo processes the following categories of personal data on behalf of the Controller:

CategoryExamplesPurpose
IdentityName, date of birth, profile photoMember directory, identification
ContactEmail, phone, addressCommunication, event reminders
Church membershipAttendance, ministry roles, giving historyPastoral care, community management
VolunteeringSkills, availability, rota assignmentsVolunteer coordination
FinancialGiving amounts, Gift Aid declarationsDonation processing, HMRC reporting
Health (children)Medical notes, allergies, DBS referencesSafeguarding, children's ministry
Consent recordsGDPR consent date, marketing consentCompliance audit trail
CommunicationsMessages, prayer requests, pastoral notesPastoral care, community engagement

4. Processor obligations

Ekkleo undertakes to:

  • Process personal data only on the Controller's documented instructions (these Terms and the configuration of the Services).
  • Ensure that persons authorised to process data are subject to appropriate confidentiality obligations.
  • Implement technical and organisational security measures appropriate to the risk (see Section 6).
  • Not engage sub-processors without prior written authorisation from the Controller (the sub-processor list in Section 8 constitutes general authorisation for those listed).
  • Assist the Controller in responding to data subject rights requests insofar as technically possible (see Section 7).
  • Notify the Controller without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach.
  • Delete or return all personal data at the end of the Services upon the Controller's written request, subject to the retention exceptions in Section 9.
  • Provide all information necessary to demonstrate compliance with this Agreement and allow for audits conducted by the Controller or an authorised third party with 30 days' notice.

5. Controller obligations

The Controller undertakes to:

  • Ensure a lawful basis exists for all personal data entered into the platform before doing so.
  • Provide a compliant privacy notice to congregation members describing how their data is used.
  • Obtain explicit consent for any special category data (e.g. medical information for children's ministry).
  • Promptly forward any data subject rights request to Ekkleo where Ekkleo's technical assistance is needed.
  • Keep account credentials secure and notify Ekkleo immediately of any unauthorised access.
  • Ensure church administrators and staff who access the platform have a legitimate need for that access.

6. Security measures

Ekkleo implements the following technical and organisational measures:

  • Encryption in transit: All data transmitted between users and the platform uses TLS 1.2 or higher.
  • Encryption at rest: All data is stored encrypted using AES-256 or equivalent.
  • Access controls: Role-based access control ensures users can only access data relevant to their role. Church admins cannot access other churches' data.
  • Authentication: Secure authentication with session management, OAuth 2.0 support, and session expiry controls.
  • Backups: Regular automated backups with point-in-time recovery capability.
  • Vulnerability management: Regular dependency updates and security patching.
  • Audit logging: Administrative actions are logged for accountability.
  • Data minimisation: We do not collect or process data beyond what is required to deliver the Services.

7. Data subject rights

Under UK GDPR, data subjects have the following rights, which the Controller is primarily responsible for fulfilling. Ekkleo provides tools to assist:

  • Right of Access (Subject Access Request / SAR): Members can export their own personal data from Settings → Privacy → Export My Data. Church admins can also run a full member data export. We provide the export within 30 days. Ekkleo will assist with SAR requests directed to us within 72 hours.
  • Right to Rectification: Members can correct their own profile data directly from Settings → Profile at any time, without needing to contact anyone.
  • Right to Erasure ("Right to be Forgotten"): Members can request deletion of their account from Settings → Privacy → Delete My Account. This triggers deletion of personal profile data, messages, and membership records.

    ⚠️ Gift Aid Retention Exception

    Gift Aid declarations and associated donation records must be retained for a minimum of 6 years following the tax year in which the donation was made, as required by HMRC (Gift Aid regulations under Finance Act 1990, as amended). Where a member requests erasure, their profile and contact data will be deleted but Gift Aid records will be pseudonymised (name replaced with "Anonymous Donor [reference]") and retained for the legally required period. This exception, and the specific records retained, will be communicated to the data subject at the time of their erasure request.

  • Right to Restriction: Members may request restriction of processing via Settings → Privacy or by contacting hello@ekkleo.church. Processing will be restricted to storage only while the request is considered.
  • Right to Data Portability: Personal data exports are provided in machine-readable JSON/CSV format from Settings → Privacy → Export My Data.
  • Right to Object: Members can withdraw marketing consent and object to automated processing at any time from Settings → Privacy.

8. Sub-processors

Ekkleo uses the following sub-processors to deliver the Services. The Controller provides general authorisation for these sub-processors by accepting this DPA:

Sub-processorPurposeLocation
Base44 / WixPlatform hosting, database, storage, authenticationEU / USA (EU-SCCs)
StripePayment processing for giving and subscriptionsUSA (EU-SCCs)
OpenAI / Google AIAI-powered features (sermon processing, AI assistant)USA (EU-SCCs)
Resend / Email providerTransactional email deliveryUSA (EU-SCCs)

Ekkleo will notify Controllers of any intended changes to sub-processors with at least 14 days' notice. Controllers who object may terminate the Services within that notice period.

9. Retention and deletion

  • Personal data is retained for as long as the church's account is active and the data is needed for the purpose it was collected.
  • Upon account closure or a deletion request, personal data is deleted within 30 days, subject to the exceptions below.
  • Gift Aid declarations and donation records: retained for 6 years from the end of the tax year in which the donation was made (HMRC requirement).
  • Safeguarding incident records: retained indefinitely in accordance with safeguarding best practice (Charity Commission guidance CC29).
  • Audit logs of consent and administrative actions: retained for 3 years for legal accountability purposes.
  • Backup copies may persist for up to 90 days after a deletion request while backup rotation cycles complete.

10. International data transfers

Where personal data is transferred outside the UK or EEA (e.g. to US-based sub-processors), Ekkleo ensures that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) as applicable. Details are available on request.

11. Data breach notification

Ekkleo will notify affected Controllers without undue delay and within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. Notification will include: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the breach.

12. Term and termination

This DPA remains in effect for as long as Ekkleo processes personal data on behalf of the Controller. It terminates automatically upon termination of the Terms of Service. The deletion obligations in Section 9 survive termination.

13. Contact and complaints

For data protection queries, requests, or to exercise rights under this DPA, contact:

Ekkleo Data Protection Contact

privacy@ekkleo.church

We aim to respond to all data protection enquiries within 5 working days. Data subjects also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

© 2026 Ekkleo. Data Processing Agreement v1.0 — Governed by the laws of England and Wales.