Data Processing Addendum
How we process your church's data on your behalf: your church is the controller, we act only on your instructions, and this addendum is part of our Terms of Service.
Before you dig in
The short version
- This is the document that makes “it’s your data” legally binding. Your church is the “controller,” we’re the “processor” — meaning we act only on your instructions, never for our own purposes.
- No signature needed. It takes effect automatically when you accept the Terms, and a countersigned copy is available on request.
- Section 2.4 lists what we will never do with your church’s data: sell it, share it, train AI on it, combine it with other sources, or use it for our own marketing.
- Every vendor that touches your data is public — listed at /subprocessors, with 30 days’ notice before changes and a right to object.
- EU and UK churches are covered — Standard Contractual Clauses and the UK Addendum are built in.
This summary is here to orient you — it isn’t part of the agreement and doesn’t change it. The full text below is what governs. If anything here raises a question, email legal@pastorcenter.com — it goes to a person.
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Pastor Center Terms of Service between Sermon Solutions LLC d/b/a Pastor Center (“Processor,” “we”) and the customer organization (“Controller,” “you”). It applies whenever we process Church Data on your behalf, and it governs over the Terms in the event of conflict as to such processing.
No signature is required. This DPA takes effect automatically on your acceptance of the Terms. A countersigned copy is available on request to legal@pastorcenter.com.
1. Definitions
“Applicable Data Protection Law” means all privacy and data protection laws applicable to the processing, including U.S. state comprehensive privacy laws, the EU General Data Protection Regulation and UK GDPR where applicable, and implementing regulations.
“Church Data” has the meaning given in the Terms and constitutes “personal data” or “personal information” under Applicable Data Protection Law.
“Data Subject” means an individual whose personal data is included in Church Data — including members, attendees, guests, volunteers, donors, minors, and staff of the Controller.
“Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Church Data in our custody. It does not include unsuccessful attempts or routine events such as pings, port scans, or failed login attempts that do not compromise data.
“Subprocessor” means a third party we engage to process Church Data.
Terms such as “controller,” “processor,” “service provider,” “business,” “process,” and “sell” have the meanings given under Applicable Data Protection Law.
2. Roles and Scope
2.1 Allocation of roles
You are the controller (or “business”) of Church Data. We are the processor (or “service provider”) and act only on your documented instructions. For Account Data as defined in the Terms, we act as an independent controller and our Privacy Policy applies.
2.2 Your responsibilities as controller
You are responsible for:
- The lawfulness, fairness, and transparency of your collection and use of Church Data;
- Establishing and documenting a lawful basis for processing, including for data revealing religious beliefs or participation and data about minors;
- Providing all required privacy notices to Data Subjects, including notice that you use third-party service providers such as us;
- Obtaining and maintaining any required consents, including consents required for electronic communications;
- The accuracy of Church Data and of the instructions you give us;
- Configuring roles, permissions, and access controls appropriately, and removing access for departed personnel;
- Deciding what actions to take based on the platform’s output.
2.3 Our instructions
Your instructions to us consist of the Terms, this DPA, the configuration choices you make in the platform, and any further written instructions you give that we agree to. We will not process Church Data for any other purpose. If we believe an instruction violates Applicable Data Protection Law, we will inform you and may suspend that processing.
2.4 Restrictions on our use
We will not:
- Sell or share Church Data, as those terms are defined under U.S. state privacy laws;
- Retain, use, or disclose Church Data outside the direct business relationship with you or for any purpose other than performing the Services;
- Combine Church Data with personal information from other sources, except as necessary to perform the Services or as permitted by law;
- Use Church Data to train, fine-tune, or improve any artificial intelligence or machine learning model, or permit any Subprocessor to do so;
- Use Church Data for our own product development, benchmarking, marketing, or advertising, except in aggregated and de-identified form that cannot reasonably be re-identified.
2.5 Certification
We certify that we understand and will comply with the restrictions in Section 2.4.
3. Confidentiality and Personnel
We limit access to Church Data to personnel who need it to perform the Services. All such personnel are bound by written confidentiality obligations that survive employment, receive privacy and security training, and are subject to background screening where permitted by law. We maintain logs of administrative access to customer environments.
4. Security
4.1 Measures
We implement and maintain the technical and organizational measures described in Annex II, appropriate to the risk, taking into account the sensitivity of Church Data.
4.2 Your obligations
You are responsible for security measures within your control, including credential hygiene, role configuration, multi-factor authentication for your users, and the security of any device or account you use to access the Services.
5. Security Incidents
5.1 Notification
We will notify you of a Security Incident affecting your Church Data without undue delay and in any event within 72 hours of confirming it. Notice will go to your designated security contact and, if none is designated, to your account administrator.
5.2 Content
Notice will describe, to the extent known: the nature of the incident, the categories and approximate volume of data and Data Subjects affected, likely consequences, measures taken or proposed, and a contact point. We will supplement as information becomes available.
5.3 Assistance
We will provide reasonable cooperation to help you meet your own notification obligations to regulators and Data Subjects. You are responsible for determining whether notification is required and for making it — we will not notify Data Subjects directly without your prior written instruction, except where required of us by law.
5.4 No admission
Notification is not an acknowledgment of fault or liability.
6. Subprocessors
6.1 Authorization
You give general authorization for us to engage Subprocessors. Our current list is maintained at pastorcenter.com/subprocessors and includes, for each, the name, purpose, and processing location.
6.2 Notice of changes
We will give at least 30 days’ notice before adding or replacing a Subprocessor that processes Church Data. Subscribe to notifications at pastorcenter.com/subprocessors.
6.3 Objection
You may object on reasonable data protection grounds within the notice period by emailing legal@pastorcenter.com with your reasons. We will work in good faith to offer an alternative. If we cannot, you may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees as your exclusive remedy.
6.4 Our responsibility
We enter written agreements with each Subprocessor imposing data protection obligations no less protective than this DPA, and we remain fully liable to you for their performance.
6.5 AI Subprocessors
AI model providers are Subprocessors. Our agreements with them prohibit use of submitted data for model training and require deletion or limited retention consistent with Section 2.4. Where zero-retention terms are available, we use them.
6.6 Connected Services are not Subprocessors
A third-party service you independently authorize — Planning Center, Clearstream, a giving platform — is not our Subprocessor. It is a separate controller or processor with which you have your own relationship, and we are not responsible for its processing.
7. Data Subject Rights
7.1 Requests to you
Where a Data Subject exercises rights against you, you will handle the request. The platform provides functionality to access, correct, export, and delete individual records. We will provide reasonable additional assistance at your request, at no charge for reasonable volumes.
7.2 Requests to us
If we receive a request from a Data Subject relating to your Church Data, we will not respond substantively. We will promptly forward it to you and, unless prohibited, advise the individual to contact you.
8. Assistance and Cooperation
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
9. Audit and Verification
9.1 Documentation
On request, no more than once per twelve months, we will provide information reasonably necessary to demonstrate compliance with this DPA, including our security documentation, a completed security questionnaire, and any third-party audit reports or certifications we hold.
9.2 Audits
If the documentation in Section 9.1 is insufficient and Applicable Data Protection Law requires a further audit, you may conduct one no more than once per twelve months (or after a Security Incident affecting your data), on at least 30 days’ written notice, during business hours, without unreasonable disruption, subject to confidentiality, and at your expense. Audits may not include penetration testing of production systems or access to other customers’ data, our source code, or model weights.
10. International Transfers
Where the GDPR or UK GDPR applies, the parties incorporate the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (Controller to Processor), and the UK International Data Transfer Addendum, as follows:
- Clause 7 (docking): included
- Clause 9 (subprocessors): Option 2, general written authorization, 30 days’ notice
- Clause 11 (redress): optional independent dispute resolution not included
- Clause 17 (governing law): the law of Ireland
- Clause 18 (forum): the courts of Ireland
- Annex I and Annex II below populate the corresponding SCC Annexes
- UK Addendum Table 4: neither party may terminate on approved-addendum change
Where a conflict exists between the SCCs and this DPA, the SCCs prevail.
11. Return and Deletion
On termination, or earlier at your written request, we will delete or return Church Data as described in the Terms: export available for 30 days after termination; deletion or de-identification within 60 days thereafter, except where retention is required by law. Backup copies are purged on our ordinary rolling schedule. On request we will certify deletion in writing.
12. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms, including the aggregate cap. Nothing in this Section limits liability that cannot be limited under Applicable Data Protection Law or any Data Subject’s rights under the SCCs.
13. General
This DPA takes effect on acceptance of the Terms and continues while we process Church Data. We may update it to reflect changes in law or our practices, on 30 days’ notice; if an update materially reduces your protections, you may terminate the affected Services. Except as modified here, the Terms remain in full effect.
Annex I — Description of Processing
A. Parties
Data exporter / Controller: the customer organization identified in the account.
Data importer / Processor: Sermon Solutions LLC d/b/a Pastor Center, 11184 Sand Pine Ct, Fort Myers, FL 33913. Contact: legal@pastorcenter.com.
B. Categories of Data Subjects
Church members and attendees; first-time and returning guests; volunteers and serving team members; small group participants and leaders; donors; minors, including children whose attendance is recorded through check-in; church staff and Authorized Users; prospective contacts entered by the Controller.
C. Categories of Personal Data
Identity and contact details (name, email, phone, postal address, date of birth, photograph); household and family relationships; attendance, check-in, and event participation records; group and serving team membership, schedules, and responses; membership, baptism, and milestone status; pastoral notes, contact logs, follow-up assignments, and tasks; assessment responses and results; giving records (amount, date, fund, designation, pledge status, donor identity); communications content, delivery status, and opt-out status; engagement signals and scores derived from the above; system identifiers and timestamps.
D. Sensitive Data
The processing involves data revealing religious beliefs and religious participation, financial giving information, and personal data of children.
Additional safeguards: role-based access with giving data restricted to designated giving administrators; encryption in transit and at rest; least-privilege internal access with logging; contractual prohibition on model training and on use for advertising or profiling for our purposes; data minimization in transmissions to AI Subprocessors; no automated decision-making producing legal or similarly significant effects.
E. Frequency of Transfer
Continuous — event-driven synchronization from Connected Services with a scheduled full refresh, and on-demand processing when a user initiates an action.
F. Nature and Purpose of Processing
Hosting, storage, synchronization, retrieval, structuring, analysis, and derivation of engagement signals; generation of drafted communications, summaries, and recommendations via AI Subprocessors; transmission of Controller-approved writes to Connected Services, and delivery of Controller-approved message content to the Controller’s own messaging account for sending; backup, security monitoring, and technical support. Sole purpose: providing the Services to the Controller.
G. Retention
For the subscription term, plus 30 days’ export window and deletion within 60 days thereafter. Backups purged on a rolling schedule generally within 90 days. Security logs up to 24 months.
H. Subprocessors
Cloud hosting and storage; database and search infrastructure; AI model inference; transactional email delivery; error monitoring and observability; customer support tooling; payment processing (Account Data only). Current list with names, purposes, and locations: pastorcenter.com/subprocessors.
I. Competent Supervisory Authority (SCCs only)
The supervisory authority of the EU member state in which the data exporter is established, or, where the exporter is not established in the EU, the authority of the member state where its Article 27 representative is established.
Annex II — Technical and Organizational Measures
Access control. Role-based access control across the platform, scoped so that leaders see only the individuals they are responsible for. Giving data is visible only to designated giving administrators and is excluded from engagement scoring. Multi-factor authentication available for all accounts. Least-privilege internal access, granted on documented business need, reviewed periodically, and revoked on role change or departure.
Encryption. TLS 1.2 or higher for all data in transit. Encryption at rest for databases, object storage, and backups. Integration credentials and OAuth tokens encrypted with managed key infrastructure.
Network and infrastructure. Reputable cloud infrastructure providers with their own security certifications. Network segmentation, firewalling, and restricted administrative access. Production separated from development and test environments; production Church Data is not used in non-production environments.
Application security. Secure development practices, code review, dependency scanning, and patching of known vulnerabilities on a risk-prioritized schedule. Input validation and protection against common web vulnerabilities.
Logging and monitoring. Application and infrastructure logging, administrative access logging, anomaly and error monitoring, and alerting on suspicious activity.
AI processing controls. Data minimization — only data relevant to the requested task is transmitted to AI Subprocessors. Contractual prohibition on model training. Zero-retention or minimum-retention terms where available. Human-in-the-loop approval required before any write or outbound message.
Backup and resilience. Automated regular backups with periodic restoration testing. Documented business continuity and disaster recovery procedures.
Incident response. Documented incident response plan with defined roles, escalation paths, forensic preservation, and customer notification within 72 hours of confirming a Security Incident.
Vendor management. Security and privacy review before onboarding any Subprocessor; contractual data protection obligations no less protective than this DPA; periodic reassessment.
Personnel. Confidentiality agreements; security and privacy training at onboarding and annually; background screening where permitted; prompt access revocation on departure.
Deletion. Documented data deletion and de-identification procedures, with written certification available on request.
Version 1.0 — Effective August 10, 2026