Data Processing Addendum
1. Parties and precedence
This Data Processing Addendum (“DPA”) is between [Church legal name and address] (“Customer”) and [Veil operator legal name and address] (“Veil”), and supplements [service agreement/order form and date]. If this DPA conflicts with that agreement on personal-data processing, this DPA controls.
2. Roles and documented instructions
For Customer Data whose purposes and means are determined by Customer, Customer is the controller and Veil is the processor. Veil will process Customer Data only to provide, secure and support the service under the agreement and on Customer’s documented instructions, including the instructions in Annex 1, unless applicable law requires otherwise. Veil will notify Customer before legally required processing unless prohibited by law.
Each party remains independently responsible for processing for which it determines the purposes and means. Personal confessions and journals that a user stores for their own use are not automatically Church Data or disclosed to Customer.
3. Confidentiality and security
- Access to Customer Data is limited to authorised persons bound by confidentiality.
- Veil will maintain the technical and organisational measures in Annex 2 and will not materially reduce their overall protection during the term.
- Veil will notify Customer without undue delay after confirming a personal-data breach affecting Customer Data and provide available information reasonably needed for Customer’s response.
4. Data-subject requests and compliance assistance
Taking account of the nature of processing, Veil will provide reasonable assistance for access, correction, deletion, restriction, portability and objection requests, security obligations, breach notifications, impact assessments and regulator consultations. If Veil receives a request relating to Customer Data, it will direct the requester to Customer unless authorised to respond.
5. Subprocessors
Customer gives general written authorisation for the subprocessors in Annex 3. Veil will provide notice before adding or replacing a subprocessor so Customer can raise a reasonable data-protection objection. Veil will impose data-protection obligations providing substantially equivalent protection and remains responsible for its subprocessors’ performance to the extent required by applicable law.
6. International transfers
The service uses processors outside Korea and may process data outside the EEA/UK. Where GDPR Chapter V applies and no adequacy decision covers a transfer, the parties will incorporate the applicable European Commission Standard Contractual Clauses or another valid transfer mechanism in the signed agreement. This public template does not claim that SCCs are already executed.
7. Return, deletion and audit
During the term, Customer may export Customer Data using available service tools. On termination or written instruction, Veil will delete or return Customer Data unless law requires retention. The parties must set the operational and backup deletion period in Annex 1 before signing.
Veil will make information reasonably necessary to demonstrate compliance available to Customer. Audits should first use documentation and remote review; an on-site audit may occur when that evidence is insufficient, subject to confidentiality, security, reasonable notice and no unreasonable disruption.
8. Liability, term and governing law
This DPA lasts while Veil processes Customer Data. Liability and governing-law terms follow the main agreement unless mandatory data-protection law requires otherwise. Governing law and venue: [complete before signature].
Annex 1 — Processing details
| Subject and duration | Provision of Veil church administration and member-engagement features for the service term, plus the agreed deletion period. |
|---|---|
| Nature and purpose | Hosting, organising, displaying, exporting, securing and supporting church records at Customer’s instruction. |
| Data subjects | Church staff, administrators, members, invitees and contacts entered by Customer. |
| Data types | Names, contact details, membership/group data, attendance, prayer requests intentionally shared with the church, contribution records entered by Customer, account identifiers and audit metadata. Special-category religious-belief data may be inferred from church membership and activity. |
| Excluded by default | A user’s private confession or journal text is not automatically shared with Customer and is not Church Data merely because the user belongs to the church. |
| Retention | [Customer and Veil must complete operational and backup deletion periods before signing.] |
| Customer instructions/contact | [Name, role and email] |
Annex 2 — Security measures
- TLS for data in transit through the hosted service; provider-managed encryption at rest.
- Supabase authentication, row-level access controls and church-scoped membership/administrator checks.
- Separation between identity and content in the anonymous confession-review schema; the review table has no user-id column.
- Least-privilege service credentials kept in server environment variables; raw Stripe card numbers are not stored by Veil.
- Restricted operator access for support, safety, abuse investigation or legal obligations, with audit records as described in the privacy policy.
- Personal-record export and scoped deletion endpoints, rate limiting on sensitive APIs, and no external web-font request. Full Auth-account and provider-backup deletion is not yet implemented.
- Customer-specific measures or gaps to record before signature: [complete].
Annex 3 — Current subprocessors
The current list, purposes, data and processing locations is maintained in the Veil subprocessor table. At publication it includes Supabase, Vercel, Google Gemini, Google Sign-In, Stripe, getBible and conditionally PostHog.
Signatures
Legal name: ____________________
Name/title: ____________________
Signature/date: ____________________
Legal name: ____________________
Name/title: ____________________
Signature/date: ____________________