Ask Our Church
  • How it works
  • About
  • Pricing
  • Start free trial
    • EN
    • PL
Last updated: 19th of August 2026

Data processing Agreement

1. Subject matter and roles

1.1. In providing the Service (AskOurChurch, powered by Compendi), the Processor processes Personal Data on behalf of and under the documented instructions of the Controller. The Controller determines the purposes and means of processing its members’ and visitors’ Personal Data; the Processor processes such data only to provide the Service.

1.2. This DPA is concluded pursuant to Article 28 GDPR and gives effect to the parties’ data-protection obligations. Where the Terms of Service and this DPA conflict on data protection, this DPA prevails.

1.3. Capitalized terms not defined here have the meaning given in the GDPR or the Terms of Service.

2. Details of processing (Art. 28(3) GDPR)

  • Subject matter: processing of Personal Data necessary to provide the Service.
  • Duration: for the term of the Customer’s use of the Service, until deletion or return of data under Section 10.
  • Nature and purpose: retrieval of connected video data via a third-party provider, hosting, storage, transcription, indexing, semantic search, generation of AI-assisted responses, display on the Customer’s public page and widgets, support, and related operations.
  • Types of Personal Data: identification and contact data contained in church profile and content (e.g., names, roles, contact details of pastors/staff appearing in videos, documents, or profile); End-User/visitor data (e.g., IP address, device/usage data, queries submitted through search/chat, cookie identifiers); administrator account data.
  • Categories of data subjects: the Controller’s staff and volunteers, members and congregation, and public-page/widget visitors.
  • Special categories: the Service is not intended for special-category data (Art. 9 GDPR). To the extent religious-belief information is inherent in church content the Controller chooses to publish, the Controller is responsible for its lawful basis and any required conditions. The Controller shall not submit other special-category data unless separately agreed.

3. Processor obligations

The Processor shall:

a) process Personal Data only on documented instructions from the Controller, including this DPA, the Terms, and the Controller’s configuration/use of the Service, unless required by EU or Member State law (in which case it will inform the Controller unless legally prohibited);

b) ensure persons authorized to process Personal Data are bound by confidentiality;

c) implement appropriate technical and organizational measures under Art. 32 GDPR (Annex 2);

d) respect the conditions for engaging sub-processors (Section 5);

e) taking into account the nature of processing, assist the Controller by appropriate measures to respond to data-subject requests (Section 6);

f) assist the Controller in ensuring compliance with Art. 32–36 GDPR (security, breach notification, data-protection impact assessments, prior consultation), taking into account the information available to the Processor;

g) at the Controller’s choice, delete or return Personal Data after the end of the provision of services (Section 10);

h) make available information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits (Section 8).

4. Controller obligations

4.1. The Controller warrants that it has a valid legal basis for the Personal Data it connects, uploads, publishes, or collects through the Service, and that its instructions comply with data-protection law.

4.2. The Controller is responsible for providing required notices to its members and visitors (e.g., its own privacy information) and for handling data-subject requests directed to it as controller.

4.3. The Controller shall not instruct the Processor to process data in a manner that violates the GDPR or other applicable law.

5. Sub-processors

5.1. The Controller provides general authorization for the Processor to engage sub-processors to provide the Service (e.g., hosting/cloud infrastructure, the video-data provider Supadata.ai, transcription, AI/content-processing, email delivery, analytics, payment processing).

5.2. A current list of sub-processors is available on request at Contact. The Processor will inform the Controller of intended changes (additions/replacements) and give the Controller the opportunity to object on reasonable data-protection grounds within 7 days. If an objection cannot be resolved, the Controller may terminate the affected part of the Service.

5.3. The Processor imposes data-protection obligations on sub-processors substantially equivalent to those in this DPA and remains liable for their performance.

6. Assistance with data-subject rights

Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, objection). Where a data subject contacts the Processor directly regarding data processed for a Controller, the Processor will, where lawful, refer them to the Controller or forward the request.

7. Personal data breaches

7.1. The Processor shall notify the Controller no later than 24 hours after becoming aware of a Personal Data breach affecting the Controller’s data, and in any event without undue delay to enable the Controller to meet any obligation under Art. 33 GDPR.

7.2. The notification shall include, to the extent available, the nature of the breach, likely consequences, and measures taken or proposed. The Processor shall cooperate and take reasonable steps to mitigate the breach.

8. Audits

8.1. The Processor shall make available information reasonably necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

8.2. To minimize disruption, audits shall be conducted on reasonable prior notice (at least 7 days), no more than twice per year except where required by a supervisory authority or following a breach, during business hours, subject to confidentiality. The Processor may satisfy audit requests by providing relevant certifications, reports, or documentation where these reasonably address the Controller’s request.

9. International transfers

9.1. Where the Processor or a sub-processor transfers Personal Data outside the EEA, it shall ensure an appropriate transfer mechanism under Chapter V GDPR, primarily the Standard Contractual Clauses (SCCs) and/or an adequacy decision, together with any necessary supplementary measures.

9.2. The Controller authorizes such transfers as necessary to provide the Service, subject to Section 9.

9.3. The applicable Standard Contractual Clauses framework is set out in Annex 4.

10. Return and deletion of data

10.1. Upon termination of the Service or on the Controller’s request, the Processor shall, at the Controller’s choice, delete or return all Personal Data processed on the Controller’s behalf and delete existing copies, unless EU or Member State law requires storage.

10.2. Following workspace deletion, deletion will be completed within 14 days, subject to routine backup cycles from which data is purged in the ordinary course.

11. Liability and miscellaneous

11.1. Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service, to the extent permitted by applicable law and without limiting rights of data subjects or supervisory authorities.

11.2. This DPA is governed by the law of Poland. Where a conflict exists between this DPA and the SCCs regarding transfers, the SCCs prevail for the relevant transfer.

11.3. If required, the parties will execute a further, signed version of this DPA (for example, for Enterprise customers) that may include additional or amended terms.

Annex 1 — Description of processing

  • Categories of data subjects: Controller’s staff/volunteers; members/congregation; public-page and widget visitors.
  • Categories of Personal Data: contact and identity data; content-embedded personal data (names/roles in videos, documents, profile); visitor technical data (IP, device, usage); search/chat queries; cookie identifiers; administrator account data.
  • Special categories: not intended (see Section 2); any religious-belief information inherent in published church content is the Controller’s responsibility.
  • Nature/purpose: as in Section 2.
  • Duration: term of Service use + deletion/return period (Section 10).

Annex 2 — Technical and organizational measures (Art. 32)

  • Access control (least privilege, authentication, role-based access to workspaces);
  • Encryption of data in transit (TLS) and, where applicable, at rest;
  • Logging and monitoring; separation of environments;
  • Sub-processor due diligence and contractual controls;
  • Backup and recovery procedures; secure deletion practices;
  • Incident detection and response, including breach notification workflow;
  • Staff confidentiality commitments and security awareness.

Annex 3 — Sub-processors

Current list available on request at hello@askourchurch Categories include: cloud hosting/storage; video-data retrieval (Supadata.ai) — fetches video lists, metadata, and transcripts from connected YouTube channels; transcription; AI/content processing; email delivery; analytics; payment processing (e.g., Stripe).

Annex 4 — Standard Contractual Clauses – Applicable Module and Selected Clauses

1. Legal Basis

European Commission Implementing Decision 2021/914 of 4 June 2021

2. Applicable Module

Element Detail
SCC Decision EC Implementing Decision (EU) 2021/914 of 4 June 2021
Module Module 2 — Transfer controller to processor
Data exporter role The Customer — data controller
Data importer role Studio DR sp. z o.o. — data processor
Transfer direction EEA controller to non-EEA processor (US-based sub-processors)
Governing law (Clause 17) Law of the Republic of Poland (Option 1)
Forum (Clause 18) Courts of Poland; data subjects may also bring proceedings in their Member State of habitual residence

3. Elections under Optional and Multi-Option Clauses

Clause 7 — Docking clause

Not activated. The SCCs apply solely between the Client and Studio DR. Sub-processors are bound by separate back-to-back processor agreements.

Clause 9 — Use of sub-processors

Option 2 (general written authorization) applies. The Client grants general written authorization for Studio DR to engage and replace sub-processors, subject to advance notification and a 14-day objection period. Current sub-processors and their transfer mechanisms are listed in the Data Processing Agreement.

Clause 11 — Redress

The optional redress clause is not activated. Data subjects exercise their rights directly against the Client as controller, or through the competent supervisory authority.

Clause 13 — Supervision

The competent supervisory authority for Studio DR (data importer, established in Poland) is:
Prezes Urzędu Ochrony Danych Osobowych (UODO) Stawki 2, 00-193 Warsaw, Poland | https://uodo.gov.pl/

The competent supervisory authority for the Customer (data exporter) is the authority of the Customer’s EEA Member State of establishment.

Clause 17 — Governing law

Option 1 applies: the SCCs are governed by the law of the Republic of Poland, an EU Member State that permits third-country beneficiaries to enforce the SCCs.

Clause 18 — Choice of forum and jurisdiction

Disputes arising from the SCCs shall be resolved before the courts of Poland. Data subjects may additionally bring proceedings in the courts of the Member State where they habitually reside.

4. Note on Intra-EEA Processing

Where processing under the Data Processing Agreement takes place exclusively within the EEA and does not involve any transfer to a third country, the SCC Module 2 framework referenced above serves as the contractual basis for the Art. 28 GDPR processor arrangement between the Client and Studio DR, without constituting a cross-border transfer mechanism in that scenario.

5. Further Information

Full details of data transfers to third countries, including the list of sub-processors and applicable safeguards, are available upon request. For this or any other questions regarding data processing — including requests for a copy of the full DPA — please contact our Data Protection Officer at Contact.

Ask Our Church

Your church's years of teaching, finally findable — answered from your church's own teaching.

Site map

How it works Pricing About

Legal

Terms of service Privacy policy Data processing AI disclosure Payment & Subscription Terms Cookie preferences

Get started

Start free trial Talk to us

© Studio DR by DeoLink Association

Powered by Compendi