Data Processing Agreement (DPA) — Ministrium
Last updated: September 24, 2026
Version: 1.0
This Data Processing Agreement ("DPA") forms part of the Ministrium Terms of Service (https://ministrium.com/terms) (the "Terms") and is entered into between Judah Creative Agency LLC, operating the Ministrium brand ("Ministrium," "we," or the "Processor"), and the church, ministry, or organization that subscribes to the Service (the "Customer" or the "Controller"). By accepting the Terms, Customer accepts this DPA.
Capitalized terms not defined here have the meaning given in the Terms or the Privacy Policy (https://ministrium.com/privacy).
1. Definitions
- "Customer Personal Data": personal data that Customer or its users upload, create, or manage in the CRM and other modules of the Service, and that Ministrium processes on Customer's behalf.
- "Data Protection Laws": laws applicable to the processing, including, as relevant, the California CCPA/CPRA and other U.S. state privacy laws, COPPA, the EU GDPR, and the UK GDPR.
- "Controller," "Processor," "Data Subject," "Processing," "Sub-processor": have the meanings given in Data Protection Laws. "Business" and "Service Provider" have the meanings given in the CCPA/CPRA.
- "Security Incident": a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- "Data Subject Request" (DSR): a request by a Data Subject to exercise rights of access, rectification, erasure, portability, objection, restriction, or other rights provided by law.
2. Roles of the parties
2.1. With respect to Customer Personal Data, Customer is the Controller (or "Business") and Ministrium is the Processor (or "Service Provider"), consistent with Section 3.2 of the Terms and Section 1 of the Privacy Policy.
2.2. Ministrium acts as a Controller only for platform login account, billing, and Service usage data that it processes for its own purposes under the Privacy Policy. This DPA does not cover that processing.
2.3. Customer is responsible for having a lawful basis, notices, and, where required, consents (including verifiable parental consent for children) for the personal data it uploads to the Service.
3. Subject matter, duration, nature, and purpose
3.1. Subject matter: providing the Ministrium church and ministry management Service under the Terms.
3.2. Duration: for the term of the Terms and the return and deletion period in Section 11.
3.3. Nature: hosting, storage, organization, retrieval, communications (email, SMS, WhatsApp), payment processing, AI features, backup, and deletion.
3.4. Purpose: solely to provide, maintain, secure, and support the Service, and to follow Customer's documented instructions.
3.5. Categories of Data Subjects: members; visitors and first-time guests; children enrolled in the Kids module; donors; Customer's leaders, volunteers, and staff; communication contacts.
3.6. Categories of data: identification and contact data (name, email, phone, address, photo/avatar); demographic and household data; attendance, groups, cells, and districts; pastoral history and notes Customer records; donation data (amounts, dates, descriptions; Ministrium does not store card data, which Stripe processes); in Kids, child and guardian data, check-in, and pickup authorization information; content of messages sent through the Service.
3.7. Special categories: religious affiliation may be inferred from the relationship with Customer, and Customer may record sensitive pastoral notes. Customer must limit such data to what is necessary and rely on an appropriate lawful basis.
4. Customer instructions
4.1. Ministrium will process Customer Personal Data only on Customer's documented instructions. The Terms, this DPA, and Customer's use and configuration of the Service constitute those instructions.
4.2. Ministrium will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend performing it until clarified.
4.3. If law requires Ministrium to process data otherwise, it will inform Customer beforehand unless the law prohibits it.
5. Confidentiality
Ministrium ensures that persons authorized to process Customer Personal Data are bound by contractual or statutory confidentiality obligations and access it only as needed to provide the Service.
6. Security
6.1. Ministrium will implement reasonable technical and organizational measures appropriate to the risk, described in Annex II and consistent with Section 7 of the Privacy Policy.
6.2. The data centers and infrastructure providers Ministrium uses hold their own certifications (for example, SOC 2 or ISO 27001). Ministrium does not claim to hold its own certifications.
6.3. Ministrium may update these measures provided it does not materially reduce the overall level of protection.
7. Sub-processors
7.1. Customer grants Ministrium general authorization to engage the Sub-processors listed in Annex III.
7.2. Ministrium will impose on each Sub-processor data protection obligations substantially equivalent to those in this DPA and remains responsible for their compliance.
7.3. Notice of changes: Ministrium will keep the current list at https://ministrium.com/dpa and will notify Customer's administrative contact by email, or within the Service, at least 30 days before adding or replacing a Sub-processor, except in urgent cases justified by security or Service continuity.
7.4. Objection: Customer may object on reasonable data protection grounds by writing to privacy@ministrium.com within that period. The parties will work in good faith toward a resolution. If none is reached, Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid, unused fees.
8. Assistance with Data Subject Requests
8.1. Because Customer is the Controller of the CRM, Ministrium will not respond directly to DSRs concerning Customer Personal Data. If it receives one, it will forward it to Customer without undue delay, unless the law requires otherwise, and tell the Data Subject to contact their church or organization.
8.2. Ministrium will make Service features available to Customer (search, edit, export, deactivation, and deletion) and provide reasonable assistance in responding to DSRs.
8.3. Individual account deletion (self-service). When a user deletes their login account from their Profile, under Section 6 of the Privacy Policy and Section 3.4 of the Terms:
a) Ministrium deletes or anonymizes the login account: it deactivates it, replaces the login email with a non-reversible identifier, replaces the password, and invalidates sessions and tokens.
b) On the linked CRM member record, Ministrium clears email, phone, and avatar and marks the record inactive.
c) Ministrium retains, on Customer's instruction, the name, attendance, donations, groups, and pastoral history as the church's record.
d) Customer, as Controller, decides whether those records are deleted or retained and is responsible for handling any further erasure request from the Data Subject. Ministrium will carry out any further deletion Customer instructs, unless the law requires retention.
8.4. Ministrium will provide reasonable assistance with data protection impact assessments and consultations with authorities, taking into account the nature of processing and the information available to it.
9. Security Incidents
9.1. Ministrium will notify Customer without undue delay and in any event within 72 hours after becoming aware of a Security Incident affecting Customer Personal Data.
9.2. The notice will include, to the extent known: the nature of the incident, categories and approximate number of Data Subjects and records affected, likely consequences, measures taken or proposed, and a point of contact. Information may be provided in phases.
9.3. Ministrium will take reasonable steps to contain the incident and mitigate its effects. Unless the law requires otherwise, Customer decides on notifications to Data Subjects and authorities.
9.4. Notice is not an acknowledgment of fault or liability.
10. International transfers
10.1. Ministrium and its Sub-processors process data primarily in the United States.
10.2. Where Customer transfers personal data subject to the EU GDPR, UK GDPR, or Swiss law, the parties agree to the European Commission Standard Contractual Clauses (Decision 2021/914), Module 2 (controller to processor) or Module 3 (processor to processor) as applicable, incorporated by reference, together with the UK Addendum where applicable. For the Clauses: Clause 7 (docking) applies; under Clause 9 the general authorization option applies with the notice period in Section 7.3; the optional language in Clause 11 does not apply; under Clauses 17 and 18, the law and courts of Ireland. Annexes I through III of this DPA complete the Clauses' annexes.
10.3. If this DPA conflicts with the Clauses, the Clauses prevail.
11. Return and deletion on termination
11.1. After the Terms terminate, Customer has 30 days to export its data using the Service's features, under Section 8.3 of the Terms.
11.2. After that period, Ministrium will delete Customer Personal Data from its active systems. Backup copies will be deleted on normal rotation cycles, within no more than 90 days, and will remain protected and out of active use in the meantime.
11.3. Ministrium may retain data where the law requires it, protected by this DPA and only for that purpose.
12. Audits and information
12.1. Ministrium will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including responses to security questionnaires and, where available, the certification reports of its infrastructure Sub-processors.
12.2. If that information is insufficient, or an authority requires it, Customer may request an audit on at least 30 days' notice, no more than once every 12 months (except after a Security Incident or at an authority's request), during business hours, with reasonable scope and duration, under confidentiality, and at Customer's expense. An independent auditor who is not a Ministrium competitor may perform it.
13. Service Provider terms (CCPA/CPRA)
For personal information subject to the CCPA/CPRA, Ministrium:
a) does not sell or share (as those terms are defined) Customer's personal information;
b) does not retain, use, or disclose it for any purpose other than the business purposes specified in the Terms and this DPA, including cross-context behavioral advertising;
c) does not retain, use, or disclose it outside the direct business relationship with Customer;
d) does not combine it with personal information from other sources, except as permitted for a Service Provider;
e) will comply with applicable CCPA/CPRA obligations and provide the same level of privacy protection the law requires;
f) will notify Customer if it determines it can no longer meet these obligations;
g) allows Customer to take reasonable and appropriate steps to stop and remediate unauthorized use.
Ministrium does not use Customer Personal Data to train AI models, and requires the same of its AI providers, consistent with Section 3 of the Privacy Policy.
14. Children (COPPA)
14.1. The Kids module lets Customer record data about children under 13. Customer is responsible for obtaining verifiable parental consent and providing the notices required by COPPA and other applicable laws.
14.2. Ministrium will process such data only to provide the Service to Customer, will not use it for advertising or profiling, and will assist Customer when a parent or guardian asks to review or delete the child's data.
15. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except where the law does not allow them.
16. Order of precedence
In case of conflict, the following prevail in this order: (1) the Standard Contractual Clauses, where applicable; (2) this DPA, as to the processing of Customer Personal Data; (3) the Terms; (4) the Privacy Policy. In all other respects the Terms govern, including their governing law (State of Georgia, USA) and dispute resolution clause (prior mediation and arbitration administered by the AAA, seated in Atlanta, Georgia). Where the Standard Contractual Clauses apply, their governing law and forum (Ireland) prevail for the matters they govern.
17. Changes and contact
Ministrium may update this DPA to reflect legal or Service changes by posting the new version at https://ministrium.com/dpa with reasonable prior notice. Changes will not materially reduce the protection of Customer Personal Data.
Privacy contact: privacy@ministrium.com. Support: support@ministrium.com.
Annex I — Details of processing
- Data exporter / Controller: Customer (contact details as in its account).
- Data importer / Processor: Judah Creative Agency LLC (Ministrium), 211 River Park North Dr, Woodstock, GA 30188, USA, privacy@ministrium.com.
- Data Subjects, data categories, nature, and purpose: as in Section 3.
- Frequency: continuous, for the term of the Service.
- Retention: for the term and as set out in Sections 8.3 and 11.
Annex II — Technical and organizational measures
- Encryption in transit (TLS) for all connections to the Service.
- Storage-level encryption at rest, provided by the managed database provider.
- Logical separation of each Customer's data (multi-tenant) and role-based access controls within the Service.
- Hashed password storage; session and token invalidation on account deletion.
- Ministrium personnel access limited to what is necessary, with multi-factor authentication on access to production systems (hosting, database, code repository, and payments).
- Point-in-time restore provided by the database provider, within its retention window.
- Event logging and error and security monitoring.
- Secrets and keys managed outside source code.
- Security review of code and dependencies.
- Card data processed only by Stripe; Ministrium does not store it.
- AI providers under agreements that prohibit training on Customer data.
- Incident response procedure per Section 9.
Annex III — Authorized Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Neon, Inc. | Managed PostgreSQL database | U.S. (AWS us-east-1) |
| Railway | Application hosting | U.S. |
| Cloudflare, Inc. (R2) | File storage (avatars, logos, documents, and attachments) | Global / U.S. |
| Stripe | Payments, subscriptions, and donations | U.S. |
| OpenAI | Artificial intelligence features (assistants and chat) | U.S. |
| Resend | Transactional email to members and staff | U.S. |
| SignalWire | SMS delivery | U.S. |
| Meta Platforms (WhatsApp Cloud API) | WhatsApp messaging, only if Customer connects it | U.S. / global |
| Sentry (Functional Software, Inc.) | Error monitoring (with data redaction; may receive personal data in error traces) | U.S. |
Optional integrations enabled by Customer. If Customer connects Intuit QuickBooks Online, Ministrium syncs aggregate donation amounts, funds, and dates, without donor names or emails. These integrations are enabled on Customer's instruction; Customer contracts directly with the provider and may disable them at any time.