Skip to content

the GDPR paperwork, in plain words where we can

Data Processing Agreement

Effective October 24, 2026

The short version

When your church uses SignUpChurch to collect volunteer sign-ups, your church controls that information and we process it only to run the Service for you. This agreement sets out the promises the GDPR and UK GDPR require: we follow your instructions, keep the data secure and confidential, use only the subprocessors we list, help you answer people’s requests, tell you about breaches, and delete the data when you leave. It’s part of our Terms of Service, so there’s nothing to sign. If you’d like a countersigned copy, email support@signupchurch.com.

1. About this agreement

This Data Processing Agreement (“DPA”) is between Katie Allred Consulting LLC, which operates SignUpChurch (“we” or “us”), and the church or organization that holds a SignUpChurch account (“you”). It forms part of our Terms of Service and applies whenever we process Customer Personal Data that is subject to Data Protection Law.

For Customer Personal Data, you are the controller (or a processor acting for another controller) and we are your processor. Where we decide on our own why and how to use personal data — for example, administrator account and billing details, marketing email, and our own analytics — we act as a controller, and our Privacy Policy applies instead of this DPA.

If this DPA conflicts with the Terms of Service, this DPA wins. If the Standard Contractual Clauses (section 7) conflict with this DPA, the Standard Contractual Clauses win.

2. Definitions

  • Data Protection Law means the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, and any law implementing or supplementing them, as they apply to the processing.
  • Customer Personal Data means personal data we process on your behalf in providing the Service, described in Annex I — mainly the information volunteers give when they sign up on your sheets.
  • Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • Subprocessor means a third party we engage to process Customer Personal Data.
  • “Controller,” “processor,” “data subject,” “personal data,” “processing,” and “supervisory authority” have the meanings given in Data Protection Law.

3. Processing only on your instructions

We process Customer Personal Data only to provide the Service and only on your documented instructions. Your instructions are this DPA, the Terms of Service, and the choices you make in the Service — for example, the fields your sheets ask for, the emails and texts you have us send, and the ChMS you connect. We may also process it where the law requires us to; if so, we’ll tell you first unless the law forbids it.

If we believe an instruction breaks Data Protection Law, we’ll tell you promptly. We don’t sell Customer Personal Data, use it for advertising, or use it to train AI models.

4. Confidentiality and security

Everyone we authorize to process Customer Personal Data is bound by confidentiality. We maintain the technical and organizational measures in Annex II to protect it, and we may improve them over time as long as we don’t reduce the overall level of protection.

5. Helping you meet your obligations

  • People’s requests. The Service lets you view, export, correct, and delete sign-ups yourself. If you need more help responding to a request from a data subject, we’ll provide reasonable assistance. If a volunteer contacts us directly about your data, we’ll pass the request to you and won’t respond ourselves except to point them to you, unless you ask us to.
  • Assessments and authorities. We’ll give you reasonable information and help with data protection impact assessments and consultations with supervisory authorities, to the extent they relate to our processing.

6. Subprocessors

You give us general authorization to use the subprocessors listed in Annex III and on our Subprocessors page. Each one is bound by a written agreement with data protection obligations at least as protective as this DPA, and we remain responsible to you for their performance.

We’ll email your account owner and update the Subprocessors page at least 30 days before a new subprocessor starts processing Customer Personal Data. If you object on reasonable data protection grounds, tell us within that notice period and we’ll work with you in good faith to resolve it. If we can’t, you may close your account, and we’ll refund any fees you’ve prepaid for the period after it closes.

7. International transfers

We and our subprocessors process Customer Personal Data in the United States. Where that involves a transfer out of the European Economic Area, the UK, or Switzerland that Data Protection Law restricts, the following apply and are incorporated into this DPA:

  • EU transfers: the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 (“SCCs”) — Module Two (controller to processor), or Module Three (processor to processor) where you are a processor. You are the data exporter and we are the data importer. Clause 7 (docking) does not apply. Under Clause 9(a), Option 2 applies with the 30-day notice period in section 6. The optional language in Clause 11(a) does not apply. Under Clause 17, Option 1 applies and the governing law is Irish law. Under Clause 18(b), disputes are resolved by the courts of Ireland. Annexes I, II, and III of the SCCs are completed by Annexes I, II, and III of this DPA.
  • UK transfers: the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (“UK Addendum”). Table 1 is completed with the parties’ details in Annex I, Table 2 with the SCC options above, and Table 3 with Annexes I to III of this DPA. For Table 4, either party may end the UK Addendum as set out in its Section 19.
  • Swiss transfers: the SCCs as above, with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority and references to the GDPR read as references to the Swiss Federal Act on Data Protection.

8. Personal data breaches

If we become aware of a Personal Data Breach, we’ll notify your account owner without undue delay, and within 72 hours at the latest. We’ll share what we know — what happened, the data and people likely affected, the likely consequences, and what we’re doing about it — and keep you updated as we learn more, so you can meet your own notification duties. Notifying you isn’t an admission of fault.

9. Deleting or returning data

You can export your sign-ups from the Service at any time. When your account is closed, we’ll delete Customer Personal Data within 30 days, unless the law requires us to keep it. Copies in backups are overwritten as those backups expire.

10. Information and audits

We’ll make available the information reasonably needed to show that we comply with this DPA, including answering reasonable security questionnaires. If that information isn’t enough to meet your obligations or a supervisory authority’s request, you may audit our compliance once a year, on at least 30 days’ written notice, during business hours, at your own cost, and in a way that protects other customers’ data and our confidential information.

11. Your responsibilities

You’re responsible for having a lawful basis for the personal data you collect with SignUpChurch, for telling volunteers how you use it, and for only collecting what you need.

Signing up with a church can reveal someone’s religious beliefs, which Data Protection Law treats as a special category of personal data. You’re responsible for having a valid condition for processing it — for many churches, that’s the condition for not-for-profit religious bodies processing data about their members and regular contacts. Please don’t use custom questions or notes to collect health or other special category data (for example, detailed medical information) unless you need it and have a lawful basis for it.

12. Liability, term, and changes

Each party’s liability under this DPA is subject to the limitations in the Terms of Service, except where Data Protection Law or the SCCs don’t allow that. This DPA lasts as long as we process Customer Personal Data for you. We may update it to reflect changes in the law or the Service, but we won’t reduce the protection it gives Customer Personal Data without your agreement.

Annex I — Details of the processing

A. Parties. Data exporter (controller): the church or organization named on the SignUpChurch account, contact via the account owner’s email address. Data importer (processor): Katie Allred Consulting LLC, PO Box 31, Nolensville, TN 37135, USA, support@signupchurch.com. Activities: providing the SignUpChurch sign-up sheet service. Signature and date: accepted by agreeing to the Terms of Service.

B. Description of the transfer and processing.

  • Data subjects: volunteers and other people who sign up on your sheets or join a waitlist; your administrators and team members.
  • Categories of personal data: names, email addresses, phone numbers, the slots and quantities people sign up for, notes, answers to your custom questions, RSVP and carpool details, text-message opt-ins, and technical data such as IP address and browser used for bot checks and security.
  • Special categories: sign-ups with a church may reveal religious beliefs. Custom questions and notes may contain other special category data if you ask for it (see section 11). Protected by the measures in Annex II.
  • Frequency: continuous, for as long as you use the Service.
  • Nature and purpose: hosting and storing sign-up sheets and sign-ups; showing sheets to volunteers; sending confirmations, reminders, and messages you trigger by email and text; syncing sign-ups to a ChMS you connect; and otherwise providing and supporting the Service.
  • Retention: for as long as you keep the data in the Service, then as described in section 9.
  • Transfers to subprocessors: as listed in Annex III, for the purposes, data, and duration stated there.

C. Competent supervisory authority. The supervisory authority determined under Clause 13 of the SCCs. For UK transfers, the UK Information Commissioner.

Annex II — Security measures

  • All traffic to the Service is encrypted in transit with HTTPS.
  • Data is stored in a managed database (Neon) that is encrypted at rest. ChMS credentials are also encrypted at the application level.
  • Administrator passwords are stored only as bcrypt hashes, and administrators can turn on two-factor authentication.
  • Every account’s data is scoped to its church, and access within an account is limited by role (owner or admin).
  • Login and public forms are protected by rate limiting and Cloudflare Turnstile bot checks, and failed sign-in attempts are logged and monitored.
  • Access to production data is limited to the people who need it to run the Service, and sensitive staff actions are recorded in an audit log.
  • Development and test environments use separate databases and are blocked from connecting to production.
  • Volunteer pages run no analytics or tracking scripts, and volunteers get no cookies.
  • Subprocessors are bound by written agreements with confidentiality and security obligations (section 6).

Annex III — Subprocessors

The current list, also published on our Subprocessors page. Each subprocessor processes data for as long as it provides its service to us.

  • Vercel, Inc.

    Purpose
    Application hosting and serverless functions
    Data
    All data processed by the Service, in transit and while it is being processed
    Location
    United States
  • Neon, Inc.

    Purpose
    Database hosting
    Data
    All data stored by the Service: accounts, sheets, sign-ups, and settings
    Location
    United States (AWS us-east-1)
  • Resend, Inc.

    Purpose
    Email delivery
    Data
    Recipient names and email addresses, and email content such as sign-up details and reminders
    Location
    United States
  • Twilio Inc.

    Purpose
    Text-message reminders
    Data
    Mobile numbers and reminder content, only for volunteers who opted in to texts
    Location
    United States
  • Cloudflare, Inc.

    Purpose
    Bot protection (Turnstile) on public forms
    Data
    Technical signals such as IP address and browser details — not what people type
    Location
    Global network (United States-based company)
  • PostHog, Inc.

    Purpose
    Product analytics and error tracking on the website and admin dashboard
    Data
    Administrator usage data (pages, clicks, errors, session recordings) and account identifiers; no analytics on volunteer pages
    Location
    United States
  • Anthropic, PBC

    Purpose
    AI sheet builder
    Data
    The description an administrator types into the AI sheet builder
    Location
    United States
  • Stripe, Inc.

    Purpose
    Payment processing for paid plans
    Data
    Billing contact details and payment information for paying accounts
    Location
    United States