Data Processing Agreement.
Between the parish, as data controller, and Symphonia, as data processor. This is the full agreement, rendered so you can read it, copy it for your records, or print it for signature. Version 1.1.
1. Parties and roles
There are two roles in this agreement, and they carry different duties under data-protection law (GDPR, CCPA, and PIPEDA).
Each parish using Symphonia is the data controller (GDPR Article 4(7)): it determines the purposes and means of processing the personal data belonging to its parishioners and staff.
Ancient Designs LLC, the operator of the Symphonia software, is the data processor (GDPR Article 4(8)). In this agreement it is referred to as "we", "us", or "the processor", and it processes parish personal data strictly on the parish's documented instructions, as captured by the Symphonia subscription agreement and this document.
2. Scope of processing
We process parishioner personal data for the sole purpose of operating Symphonia on the parish's behalf. This includes storing member records, household structure, sacramental records, giving history, communications, holy bread and commemoration submissions, inbox messages, audit logs, and access logs. We do not mine the data for advertising, share it for another party's marketing, or train AI or machine-learning models on it.
Categories of personal data processed:
- Identity (name, saint name, baptismal name).
- Contact (email, phone, mailing address).
- Household structure and family relationships.
- Sacramental records (a special category under GDPR Article 9, as religious data).
- Giving and pledge records (financial data).
- Pastoral notes (clergy-only; encrypted at rest per section 7).
- Communications metadata and delivery state.
- Authentication factors (password hashes, second-factor secrets, push tokens).
Categories of data subject: parishioners, clergy, parish staff, parish council members, and visitors who submit a form on the parish website.
3. Subprocessors
We engage the following subprocessors to deliver the service. This list is authoritative and is updated at least thirty days before any change takes effect.
| Subprocessor | Purpose | Region |
|---|---|---|
| Hetzner Online GmbH | Server hosting (web, studio, database) | Germany, EU |
| Cloudflare, Inc. | DNS, CDN, DDoS mitigation | US / global edge |
| Amazon Web Services (SES) | Transactional email delivery | US |
| Amazon Web Services (KMS) | Encryption-key custody (field-level encryption at rest) | US |
| Telnyx LLC | SMS delivery (opt-in; engaged when texting launches, not yet active) | US |
| Stripe, Inc. | Online donation processing | US |
| Cloudflare R2 | Media and certificate storage | US / global edge |
| Sentry (Functional Software, Inc.) | Server-side error monitoring | US |
4. Our obligations
As processor, we commit to:
- Process personal data only on the parish's documented instructions (this agreement).
- Ensure everyone with access is bound by confidentiality.
- Implement appropriate technical and organisational measures (section 7).
- Help the parish meet its own obligations under GDPR Articles 32 to 36 (security, breach, impact assessment, prior consultation).
- Support data subject rights (access, rectification, erasure, portability); most are already self-service in the member app.
- Delete or return all personal data at the end of the service contract, at the parish's choice.
- Make available the information needed to demonstrate compliance, and submit to audits.
5. Parish obligations
The parish, as controller, commits to:
- Have a lawful basis for the personal data it puts into Symphonia.
- Inform its parishioners about the processing (this agreement is referenced from the parish's privacy notice, and from our own Privacy Policy).
- Capture appropriate consents where required (built into Symphonia's registration and preference flows).
- Restrict staff access to those who need it, and assign roles appropriately (rector, staff, treasurer, and so on).
6. Data subject rights
Parishioners exercise their rights through Symphonia's self-service surfaces:
- Access and portability: export a full copy of the record, in a portable format.
- Rectification: correct contact and family details directly.
- Erasure: request deletion of the record.
- Restriction and objection: set communication preferences, per channel.
We do not respond directly to a rights request received outside these surfaces; we forward it to the parish (controller) without undue delay. The deletion flow respects two carveouts, both explained to the parishioner at the moment of deletion: sacramental records (canonical history) and giving records (tax retention).
7. Security measures
Technical and organisational measures we maintain:
- Transport encryption (TLS 1.3) for all parish traffic; HSTS enforced.
- At-rest encryption for the database volume and object storage.
- Application-layer encryption for sensitive pastoral fields (confession notes, sealed pastoral record), keyed per parish.
- Password hashing with bcrypt, and a second factor available to every role.
- Role-based access control with capability-level gating, and a two-person rule for bulk deletion.
- Audit logging for every state-changing administrative action; an append-only access log records each support session.
- Least-privilege support: the studio refuses writes while an operator is assisting, and pastoral content is redacted by default.
- Vulnerability scanning, security patching, and regular off-site encrypted backups.
- A disaster-recovery runbook with a documented recovery time objective of 24 hours and recovery point objective of 1 hour.
8. Breach notification
In the event of a personal-data breach, we will notify the parish without undue delay and in any event no later than 72 hours after becoming aware. The notification will describe the categories of data and approximate number of records affected, the likely consequences, and the measures taken or proposed.
We operate an automated alert that fires when audit-log heuristics indicate a mass export, unusual cross-parish access, or a sustained attack on the sign-in surface. A parish can request a Data Protection Impact Assessment template through our contact page.
9. International transfers
Personal data is primarily processed in the European Union (Hetzner Online GmbH, Germany). Where a subprocessor (for example Stripe, Amazon SES, or Telnyx) processes data in the United States, transfers are made under the EU-US Data Privacy Framework (where the subprocessor is self-certified) or under Standard Contractual Clauses. We maintain the underlying processor-to-processor clauses on file with each US subprocessor.
10. Term and termination
This agreement is effective for the duration of the parish's Symphonia subscription and ends with it. On termination, we will, at the parish's choice, return or securely delete all personal data within thirty days, except where retention is required by law.
11. Signing this agreement
For most parishes this agreement is incorporated by reference into the Symphonia subscription agreement, and no separate signature is required. If your parish's supervisory authority requires a counter-signed copy, write to legal@ancientdesigns.org with the parish name and address, and we will return a counter-signed copy within five business days.
Questions about this agreement are answered within one business day. Write to us. Version 1.1, last reviewed August 2026. The processor is Ancient Designs LLC, the operator of Symphonia.