1.1. In providing the Service (AskOurChurch, powered by Compendi), the Processor processes Personal Data on behalf of and under the documented instructions of the Controller. The Controller determines the purposes and means of processing its members’ and visitors’ Personal Data; the Processor processes such data only to provide the Service.
1.2. This DPA is concluded pursuant to Article 28 GDPR and gives effect to the parties’ data-protection obligations. Where the Terms of Service and this DPA conflict on data protection, this DPA prevails.
1.3. Capitalized terms not defined here have the meaning given in the GDPR or the Terms of Service.
The Processor shall:
a) process Personal Data only on documented instructions from the Controller, including this DPA, the Terms, and the Controller’s configuration/use of the Service, unless required by EU or Member State law (in which case it will inform the Controller unless legally prohibited);
b) ensure persons authorized to process Personal Data are bound by confidentiality;
c) implement appropriate technical and organizational measures under Art. 32 GDPR (Annex 2);
d) respect the conditions for engaging sub-processors (Section 5);
e) taking into account the nature of processing, assist the Controller by appropriate measures to respond to data-subject requests (Section 6);
f) assist the Controller in ensuring compliance with Art. 32–36 GDPR (security, breach notification, data-protection impact assessments, prior consultation), taking into account the information available to the Processor;
g) at the Controller’s choice, delete or return Personal Data after the end of the provision of services (Section 10);
h) make available information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits (Section 8).
4.1. The Controller warrants that it has a valid legal basis for the Personal Data it connects, uploads, publishes, or collects through the Service, and that its instructions comply with data-protection law.
4.2. The Controller is responsible for providing required notices to its members and visitors (e.g., its own privacy information) and for handling data-subject requests directed to it as controller.
4.3. The Controller shall not instruct the Processor to process data in a manner that violates the GDPR or other applicable law.
5.1. The Controller provides general authorization for the Processor to engage sub-processors to provide the Service (e.g., hosting/cloud infrastructure, the video-data provider Supadata.ai, transcription, AI/content-processing, email delivery, analytics, payment processing).
5.2. A current list of sub-processors is available on request at Contact. The Processor will inform the Controller of intended changes (additions/replacements) and give the Controller the opportunity to object on reasonable data-protection grounds within 7 days. If an objection cannot be resolved, the Controller may terminate the affected part of the Service.
5.3. The Processor imposes data-protection obligations on sub-processors substantially equivalent to those in this DPA and remains liable for their performance.
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, objection). Where a data subject contacts the Processor directly regarding data processed for a Controller, the Processor will, where lawful, refer them to the Controller or forward the request.
7.1. The Processor shall notify the Controller no later than 24 hours after becoming aware of a Personal Data breach affecting the Controller’s data, and in any event without undue delay to enable the Controller to meet any obligation under Art. 33 GDPR.
7.2. The notification shall include, to the extent available, the nature of the breach, likely consequences, and measures taken or proposed. The Processor shall cooperate and take reasonable steps to mitigate the breach.
8.1. The Processor shall make available information reasonably necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
8.2. To minimize disruption, audits shall be conducted on reasonable prior notice (at least 7 days), no more than twice per year except where required by a supervisory authority or following a breach, during business hours, subject to confidentiality. The Processor may satisfy audit requests by providing relevant certifications, reports, or documentation where these reasonably address the Controller’s request.
9.1. Where the Processor or a sub-processor transfers Personal Data outside the EEA, it shall ensure an appropriate transfer mechanism under Chapter V GDPR, primarily the Standard Contractual Clauses (SCCs) and/or an adequacy decision, together with any necessary supplementary measures.
9.2. The Controller authorizes such transfers as necessary to provide the Service, subject to Section 9.
9.3. The applicable Standard Contractual Clauses framework is set out in Annex 4.
10.1. Upon termination of the Service or on the Controller’s request, the Processor shall, at the Controller’s choice, delete or return all Personal Data processed on the Controller’s behalf and delete existing copies, unless EU or Member State law requires storage.
10.2. Following workspace deletion, deletion will be completed within 14 days, subject to routine backup cycles from which data is purged in the ordinary course.
11.1. Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service, to the extent permitted by applicable law and without limiting rights of data subjects or supervisory authorities.
11.2. This DPA is governed by the law of Poland. Where a conflict exists between this DPA and the SCCs regarding transfers, the SCCs prevail for the relevant transfer.
11.3. If required, the parties will execute a further, signed version of this DPA (for example, for Enterprise customers) that may include additional or amended terms.
Current list available on request at hello@askourchurch Categories include: cloud hosting/storage; video-data retrieval (Supadata.ai) — fetches video lists, metadata, and transcripts from connected YouTube channels; transcription; AI/content processing; email delivery; analytics; payment processing (e.g., Stripe).
European Commission Implementing Decision 2021/914 of 4 June 2021
| Element | Detail |
|---|---|
| SCC Decision | EC Implementing Decision (EU) 2021/914 of 4 June 2021 |
| Module | Module 2 — Transfer controller to processor |
| Data exporter role | The Customer — data controller |
| Data importer role | Studio DR sp. z o.o. — data processor |
| Transfer direction | EEA controller to non-EEA processor (US-based sub-processors) |
| Governing law (Clause 17) | Law of the Republic of Poland (Option 1) |
| Forum (Clause 18) | Courts of Poland; data subjects may also bring proceedings in their Member State of habitual residence |
Not activated. The SCCs apply solely between the Client and Studio DR. Sub-processors are bound by separate back-to-back processor agreements.
Option 2 (general written authorization) applies. The Client grants general written authorization for Studio DR to engage and replace sub-processors, subject to advance notification and a 14-day objection period. Current sub-processors and their transfer mechanisms are listed in the Data Processing Agreement.
The optional redress clause is not activated. Data subjects exercise their rights directly against the Client as controller, or through the competent supervisory authority.
The competent supervisory authority for Studio DR (data importer, established in Poland) is:
Prezes Urzędu Ochrony Danych Osobowych (UODO) Stawki 2, 00-193 Warsaw, Poland | https://uodo.gov.pl/
The competent supervisory authority for the Customer (data exporter) is the authority of the Customer’s EEA Member State of establishment.
Option 1 applies: the SCCs are governed by the law of the Republic of Poland, an EU Member State that permits third-country beneficiaries to enforce the SCCs.
Disputes arising from the SCCs shall be resolved before the courts of Poland. Data subjects may additionally bring proceedings in the courts of the Member State where they habitually reside.
Where processing under the Data Processing Agreement takes place exclusively within the EEA and does not involve any transfer to a third country, the SCC Module 2 framework referenced above serves as the contractual basis for the Art. 28 GDPR processor arrangement between the Client and Studio DR, without constituting a cross-border transfer mechanism in that scenario.
Full details of data transfers to third countries, including the list of sub-processors and applicable safeguards, are available upon request. For this or any other questions regarding data processing — including requests for a copy of the full DPA — please contact our Data Protection Officer at Contact.