Legal · Draft
Data Processing Addendum
How StGatherly processes personal data on behalf of churches under UK GDPR Article 28. This is a draft for review and is not yet in force.
Last updated: Draft, not yet published
01Introduction and scope
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Church”, “Controller”) and Appnable Ltd, trading as Kokoodi (“StGatherly”, “Processor”) for the use of the StGatherly platform (the “Service”), as set out in our Terms of Service (the “Agreement”).
It applies where StGatherly processes personal data on the Church’s behalf in the course of providing the Service, and reflects the parties’ obligations under UK GDPR Article 28 and applicable data protection law. Where this DPA conflicts with the Agreement in relation to the processing of personal data, this DPA prevails.
02Definitions
Terms such as “controller”, “processor”, “data subject”, “personal data”, “special category data”, “processing”, and “personal data breach” have the meanings given in applicable data protection law.
- Applicable data protection law means the UK GDPR, the Data Protection Act 2018, and any other laws that apply to the processing of personal data under the Agreement.
- Church Personal Data means personal data that StGatherly processes on behalf of the Church under the Agreement.
- Sub-processor means any third party engaged by StGatherly to process Church Personal Data.
03Roles of the parties
For Church Personal Data, the Church is the controller and StGatherly is the processor. Each party is responsible for complying with its own obligations under applicable data protection law. The details of the processing (subject matter, duration, nature, purpose, types of personal data, and categories of data subjects) are set out in Annex A.
04Processing on documented instructions
StGatherly will process Church Personal Data only on the Church’s documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case StGatherly will inform the Church of that legal requirement before processing, unless the law prohibits it).
The Church’s instructions are set out in the Agreement, this DPA, and the Church’s use of the Service’s features and settings. StGatherly will inform the Church if, in its opinion, an instruction infringes applicable data protection law.
05Confidentiality
StGatherly ensures that persons authorised to process Church Personal Data are bound by an appropriate duty of confidentiality and are trained on their data protection responsibilities. Access to Church Personal Data is limited to personnel who need it to provide or support the Service.
06Security measures
StGatherly implements appropriate technical and organisational measures to protect Church Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, having regard to the state of the art and the risks of the processing. A description of these measures is set out in Annex B.
07Sub-processors
The Church provides general authorisation for StGatherly to engage sub-processors to process Church Personal Data. A current list of sub-processors is available at our sub-processor page.
StGatherly will impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable for its sub-processors’ performance. StGatherly will give the Church at least [CONFIRM: notice period, e.g. 30 days] advance notice of any intended addition or replacement of a sub-processor, during which the Church may object on reasonable data protection grounds.
08Assistance with data subject requests
Taking into account the nature of the processing, StGatherly will assist the Church by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. The Service provides tools that allow the Church to access, export, correct, and delete member data. If StGatherly receives a request directly from a data subject relating to Church Personal Data, it will promptly forward the request to the Church and will not respond to it itself except on the Church’s instructions or as required by law.
09Personal data breach
StGatherly will notify the Church without undue delay, and in any event within [CONFIRM: timeframe, e.g. 72 hours] of becoming aware of a personal data breach affecting Church Personal Data. The notification will include, to the extent available, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it, so that the Church can meet its own obligations under applicable data protection law.
10Data protection impact assessments
Taking into account the nature of the processing and the information available to it, StGatherly will provide reasonable assistance to the Church with data protection impact assessments and prior consultation with the supervisory authority, where required by applicable data protection law.
11International transfers
The StGatherly application runs on Microsoft Azure in the United Kingdom, and Church Personal Data is stored in our Supabase database in the United Kingdom (London). Where providing the Service involves transferring Church Personal Data outside the UK (for example, to AI or messaging sub-processors in the United States), StGatherly will ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard.
12Return and deletion of data
On termination or expiry of the Agreement, StGatherly will, at the Church’s choice, delete or return Church Personal Data, and delete existing copies unless retention is required by law. Church Personal Data is available for export for [CONFIRM: export window, e.g. 30 days] after termination, after which it is deleted from active systems, with residual backup copies removed within [CONFIRM: backup window, e.g. 90 days].
13Audits and information
StGatherly will make available to the Church information reasonably necessary to demonstrate compliance with its obligations under this DPA, and will allow for and contribute to audits, including inspections, conducted by the Church or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits. StGatherly may satisfy this obligation by providing summaries of relevant third-party certifications or security reports where available.
14General
This DPA is governed by the same law as the Agreement. Except as amended by this DPA, the Agreement remains in full force. Any liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
15Annex A: Details of processing
- Subject matter: provision of the StGatherly church communications and community management platform.
- Duration: the term of the Agreement, plus the retention periods described above.
- Nature and purpose: hosting, storage, and processing of Church Personal Data to provide communications, contacts, giving, check-in, rota, booking, member portal, and AI-assisted features.
- Types of personal data: names, contact details, organisation roles, tags and notes, giving records, attendance and check-in records, rota assignments, message content, and, where the Church provides it, special category data (data revealing religious belief; children’s health, dietary, or safeguarding information).
- Categories of data subjects: the Church’s staff users, members, visitors, volunteers, children, and other contacts the Church chooses to store.
16Annex B: Technical and organisational measures
StGatherly maintains technical and organisational measures including:
- Encryption of data in transit.
- [CONFIRM: encryption at rest (confirm scope: DB, backups, storage)]
- Logical separation between church accounts so that one church’s data is not accessible to another.
- Role-based access controls and least-privilege access.
- Authentication controls and audit logging.
- [CONFIRM: backup and recovery procedures]
- [CONFIRM: vulnerability management / testing cadence]
This annex reflects StGatherly’s current measures and may be updated as the Service evolves, provided the level of protection is not materially reduced.
17Contact
Questions about this DPA, or requests to execute a countersigned copy, can be sent to hello@stgatherly.com. StGatherly is operated by Appnable Ltd, trading as Kokoodi, [CONFIRM: registered address and company number].