Data Processing Agreement

The agreement that governs how Cendance processes personal data on behalf of customer organizations, including security commitments, subprocessors, and international transfer safeguards.

Version 1.0.0Effective September 1, 2026Permanent link to this versionWhat has changed

This Data Processing Agreement ("DPA") forms part of the agreement between Cendance ("Cendance", "we", "us") and the customer organization identified in the applicable order, subscription, or account registration ("Customer") governing Customer's use of the Cendance services (the "Agreement"). It reflects the parties' agreement on the processing of personal data that Cendance performs on Customer's behalf.

If Customer uses the services under the Cendance Terms and Conditions, this DPA is incorporated into those terms and applies automatically, without a signature, from the date Customer first uses the services or the effective date of this version, whichever is later. If the parties have executed a separate written agreement, this DPA supplements that agreement, and in the event of a conflict concerning the processing of personal data, this DPA controls.

1. Introduction and applicability

1.1. This DPA applies to Cendance's processing of Customer Personal Data (defined below): personal data that Customer or its members, visitors, donors, volunteers, and staff submit to the services and that Cendance processes on Customer's behalf and on its instructions.

1.2. This DPA does not apply to personal data that Cendance processes as an independent controller for its own purposes, such as the account records of Customer's administrators, billing and subscription records, website analytics, and support correspondence. That processing is described in the Cendance Privacy Policy.

1.3. This DPA is versioned. The version you are reading, its effective date, and all prior versions are identified on this page. Section 18 describes how new versions are published and when they take effect.

2. Definitions

2.1. "Data Protection Laws" means all laws and regulations applicable to the processing of personal data under the Agreement, including, to the extent applicable: Regulation (EU) 2016/679 (the "GDPR"); the GDPR as incorporated into United Kingdom law (the "UK GDPR") and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"); the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"); the Australian Privacy Act 1988 (Cth); and the Nigeria Data Protection Act 2023 ("NDPA").

2.2. "Customer Personal Data" means personal data described in Schedule 1 that Cendance processes on Customer's behalf in providing the services.

2.3. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914, as described in Section 14 and Schedule 4.

2.4. "Subprocessor" means a third party engaged by Cendance to process Customer Personal Data in providing the services.

2.5. The terms "controller", "processor", "data subject", "personal data", "personal data breach", and "processing" have the meanings given to them in the GDPR, and equivalent terms under other Data Protection Laws (such as "business", "service provider", and "consumer" under the CCPA) are to be read accordingly.

3. Roles and scope of processing

3.1. As between the parties, Customer is the controller of Customer Personal Data and Cendance is a processor acting on Customer's behalf. Where Customer itself acts as a processor for a third-party controller, Cendance acts as Customer's subprocessor, and Customer warrants that its instructions to Cendance are consistent with that controller's instructions.

3.2. The subject matter, duration, nature, and purpose of the processing, the categories of personal data, and the categories of data subjects are described in Schedule 1.

3.3. Cendance will process Customer Personal Data only to provide, maintain, secure, and improve the services in accordance with the Agreement, and will not sell Customer Personal Data, use it for advertising, or use it to train generalized artificial intelligence models.

4. Customer instructions

4.1. Cendance will process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law to which Cendance is subject. In that case, Cendance will inform Customer of the legal requirement before processing, unless the law prohibits doing so on important grounds of public interest.

4.2. The Agreement, this DPA, and Customer's use of the services' features and settings constitute Customer's complete documented instructions. Additional instructions require prior written agreement between the parties.

4.3. Cendance will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Cendance is not obligated to perform a legal review of Customer's instructions.

4.4. Customer is responsible for the accuracy, quality, and lawfulness of Customer Personal Data, for the means by which it was acquired, and for establishing a lawful basis for the processing, including any required notices and consents.

5. Special category data

5.1. The services are designed for churches and ministry organizations. Records maintained in the services can inherently reveal religious beliefs or affiliation, and Customer may choose to record other special categories of personal data, such as health information relevant to children's check-in (for example, allergies) or pastoral care notes.

5.2. Customer instructs Cendance to process such special category data as part of Customer Personal Data, and Customer is responsible for ensuring that a valid condition for processing applies under Data Protection Laws, such as Article 9(2)(d) GDPR for not-for-profit bodies with a religious aim in respect of their members and regular contacts, or explicit consent.

5.3. Cendance applies the security measures in Schedule 2 to all Customer Personal Data, including special category data.

6. Confidentiality

6.1. Cendance ensures that all personnel authorized to process Customer Personal Data are bound by written or statutory obligations of confidentiality, are granted access on a need-to-know basis under a deny-by-default access model, and receive appropriate training on data protection.

7. Security

7.1. Cendance implements and maintains appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing. The current measures are described in Schedule 2.

7.2. Cendance may update the measures in Schedule 2 from time to time, provided that updates do not materially reduce the overall protection of Customer Personal Data during a subscription term.

7.3. Customer is responsible for its own secure use of the services, including managing its administrators and roles, configuring available security features (such as required secure sign-in for its workspace), and protecting the credentials of its users.

8. Subprocessors

8.1. Customer provides a general authorization for Cendance to engage Subprocessors to provide the services. The current list of Subprocessors, including their location, is published at cendance.com/legal/subprocessors. Details of the processing each Subprocessor performs are available to Customer on request.

8.2. Before adding or replacing a Subprocessor, Cendance will update the published list and provide at least 30 days' notice through the services, the legal changelog, or email to Customer's administrators.

8.3. Customer may object to a new Subprocessor on reasonable, documented data protection grounds within 30 days of the notice. The parties will work together in good faith to resolve the objection, which may include Cendance offering a reasonable alternative. If no resolution is reached, Customer may terminate the affected services and receive a pro-rated refund of prepaid fees for the remaining unused term.

8.4. Cendance will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, to the extent applicable to the services the Subprocessor provides, and remains liable to Customer for its Subprocessors' performance of those obligations.

9. Assistance with data subject requests

9.1. The services provide administrative tools that allow Customer to access, correct, export, and delete Customer Personal Data, which Customer should use as its primary means of responding to data subject requests.

9.2. Taking into account the nature of the processing, Cendance will provide reasonable additional assistance to Customer in fulfilling its obligation to respond to data subject requests under Data Protection Laws where Customer cannot fulfill a request through the services.

9.3. If a data subject contacts Cendance directly with a request concerning Customer Personal Data, Cendance will direct the data subject to Customer without responding substantively, except where required by law.

10. Personal data breaches

10.1. Cendance will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

10.2. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Cendance may provide information in phases as it becomes available.

10.3. Cendance will take reasonable steps to contain and investigate the breach and will provide reasonable cooperation to support Customer's own notification obligations. Cendance's notification of a breach is not an acknowledgement of fault or liability.

11. Impact assessments and consultations

11.1. Taking into account the nature of the processing and the information available to Cendance, Cendance will provide reasonable assistance to Customer with data protection impact assessments and with prior consultations with supervisory authorities, where required of Customer by Data Protection Laws and where the required information is not already available through this DPA, the security overview, or the subprocessor list.

12. Return and deletion of customer data

12.1. During the subscription term, Customer can export Customer Personal Data through the services' administrative tools, and may contact Cendance for reasonable assistance with exports the tools do not cover.

12.2. Upon termination or expiration of the Agreement, Cendance will, at Customer's choice, return or delete Customer Personal Data, and will in any event delete it from production systems within 90 days of termination, unless retention is required by law. Data in encrypted backups is deleted in the ordinary course of Cendance's backup rotation cycle following deletion from production.

13. Audits and compliance information

13.1. Cendance will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable security and privacy questionnaires, the security overview, and, when available, third-party audit reports and certifications under a non-disclosure agreement.

13.2. Where Data Protection Laws grant Customer an audit right that the information in Section 13.1 does not satisfy, Customer may conduct an audit of Cendance's compliance with this DPA, no more than once per 12-month period except following a personal data breach, on at least 30 days' written notice, during normal business hours, without unreasonable disruption to Cendance's operations, and subject to confidentiality obligations. Each party bears its own costs, and audits may be conducted by a mutually agreed independent third party.

14. International data transfers

14.1. Customer Personal Data is hosted in North America, as described in Schedule 2. Customer authorizes Cendance to transfer, store, and process Customer Personal Data in the locations described in this DPA and the subprocessor list, subject to the safeguards in this Section.

14.2. Where processing involves a transfer of personal data from the European Economic Area to a country without an adequacy decision, the SCCs, Module Two (controller to processor), are incorporated into this DPA with the selections described in Schedule 4, with Customer as data exporter and Cendance as data importer.

14.3. For transfers from the United Kingdom, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, completed as described in Schedule 4.

14.4. For transfers from Switzerland, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner, including references to the FADP in place of the GDPR and Switzerland in place of the EU where applicable.

14.5. If the mechanisms in this Section are amended, replaced, or invalidated, the parties will cooperate in good faith to adopt a valid successor transfer mechanism promptly.

15. Jurisdiction-specific terms

15.1. California. To the extent the CCPA applies, Cendance acts as Customer's "service provider", processes Customer Personal Data only for the business purposes described in the Agreement, and will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship with Customer or for any purpose other than performing the services, or combine it with personal information from other sources except as permitted for service providers. Cendance will notify Customer if it determines it can no longer meet its obligations under the CCPA, and Customer may take reasonable steps to stop and remediate unauthorized use.

15.2. Canada. To the extent PIPEDA applies, Cendance provides a comparable level of protection for Customer Personal Data as required of Customer, through the commitments in this DPA.

15.3. Australia. To the extent the Privacy Act 1988 (Cth) applies, Cendance will take reasonable steps to protect Customer Personal Data as required by Australian Privacy Principle 11 and will provide reasonable assistance with Customer's obligations under the Notifiable Data Breaches scheme.

15.4. Nigeria. To the extent the NDPA applies, Cendance acts as a data processor for Customer, will process Customer Personal Data in accordance with the NDPA and this DPA, and will provide reasonable assistance with Customer's obligations to the Nigeria Data Protection Commission, including breach notification support under Section 10.

15.5. Other jurisdictions. Where other Data Protection Laws apply to Customer's use of the services, the obligations in this DPA apply to the processing of Customer Personal Data to the extent they are consistent with those laws' requirements for processor engagements.

16. Liability

16.1. Each party's liability arising out of or related to this DPA, including the SCCs, is subject to the limitations and exclusions of liability set out in the Agreement, and references in the Agreement to a party's liability mean that party's aggregate liability under the Agreement and this DPA together, except where Data Protection Laws do not permit liability for a particular obligation to be limited.

17. Term

17.1. This DPA takes effect on the effective date described above and remains in force for as long as Cendance processes Customer Personal Data under the Agreement, notwithstanding the expiration or termination of the Agreement, until all Customer Personal Data has been returned or deleted in accordance with Section 12.

18. Changes to this DPA

18.1. Cendance publishes this DPA in versions. Each version is numbered, carries a posted date and an effective date, and remains permanently available at its own address once published, so Customer can always identify the exact text that applies to it.

18.2. Version numbers follow a semantic pattern: a major version (for example, 2.0.0) indicates a material change to the parties' rights or obligations; a minor version (for example, 1.1.0) indicates a substantive but non-material change, such as an updated schedule or an additional jurisdiction; a patch version (for example, 1.0.1) indicates a clerical correction that does not change meaning.

18.3. New major versions are announced at least 30 days before their effective date through the services, the legal changelog, or email to Customer's administrators. Continued use of the services after a new version's effective date constitutes acceptance of that version, unless the parties have executed a written agreement that pins a specific version, in which case that version continues to apply.

19. Contact

19.1. Questions, notices, and requests under this DPA should be sent to privacy@cendance.com. Cendance will send notices under this DPA to Customer's administrator contact details on file, and Customer is responsible for keeping those details current.


Schedule 1: Details of processing

TopicDescription
Subject matterCustomer's use of the Cendance church management platform, including people and household records, groups, check-in, forms, communications, giving and commerce, events, media, and related workflows.
DurationThe term of the Agreement, plus the return and deletion period in Section 12.
Nature and purposeHosting, storage, transmission, display, organization, analysis for Customer's own reporting, communication delivery, payment facilitation, backup, and related processing necessary to provide the services Customer configures and uses.
Categories of data subjectsCustomer's members, regular attendees, visitors, donors, volunteers, staff, event registrants, form respondents, storefront customers, and children registered by a parent or guardian for check-in and related programs.
Categories of personal dataNames, contact details, dates of birth, household and family relationships, photographs and media, attendance and participation records, group memberships, serving assignments, form responses, notes, communication history, giving and transaction records (payment card data is processed by payment Subprocessors and does not touch Cendance servers), and device and usage data generated by use of the services.
Special categoriesReligious beliefs or affiliation inherent in church membership records; health information Customer chooses to record (for example, allergies for children's check-in); and other special categories Customer chooses to collect through notes, forms, or pastoral care workflows. Processed subject to Section 5.
FrequencyContinuous, for the duration of the Agreement.

Schedule 2: Technical and organizational measures

The measures below summarize Cendance's current security program. The security overview provides additional detail for procurement and security reviews.

  1. Encryption. Traffic between users and the services, and between internal services, is encrypted with TLS (minimum TLS 1.2, TLS 1.3 where supported). Customer data is encrypted at rest using provider-managed encryption. Application secrets are stored in dedicated cloud secret vaults, with credentials for critical systems rotated automatically.

  2. Access control. Access is deny-by-default and granted on a need-to-have basis, for both Customer's users within the services and Cendance's internal systems. Production access is restricted to a minimal set of designated operators, protected by phishing-resistant two-factor authentication, and audit logged.

  3. Tenant isolation. All customer data is scoped to the owning organization, enforced at the application layer on every request and reinforced by database-level tenant-key constraints.

  4. Authentication. Passwords are stored only as one-way adaptive hashes, screened against known-breach corpora, and governed by a NIST-aligned password policy enforced through a single shared implementation across all surfaces. Repeated failed sign-ins progressively lock accounts. Users can protect accounts with authenticator apps or passkeys, organizations can require secure sign-in workspace-wide, and sensitive actions require step-up re-authentication.

  5. Availability and recovery. Customer data is backed up automatically every day with a rolling retention window, and restore exercises are performed monthly to validate recoverability.

  6. Change management. Production deployments are permission-gated with required approvals and blocked until continuous integration checks pass, including automated tests and static and dynamic application security testing.

  7. Payments. Online payments are processed by PCI DSS certified payment providers; payment card data is captured and stored entirely within those providers' environments and never touches Cendance servers.

  8. Hosting. Customer data is hosted with managed infrastructure providers in North America.

  9. Personnel. Personnel access follows least privilege, personnel are bound by confidentiality obligations, and security responsibilities are reviewed as the platform evolves.

Schedule 3: Subprocessors

Cendance's current Subprocessors, including each Subprocessor's location, are listed at cendance.com/legal/subprocessors. That list forms part of this DPA. Details of the processing each Subprocessor performs are available to Customer on request, at privacy@cendance.com. Changes to the list are made in accordance with Section 8, including advance notice and Customer's right to object.

Schedule 4: International transfer mechanisms

Where the SCCs apply under Section 14, they are completed as follows:

  1. Module. Module Two (controller to processor) applies, with Customer as data exporter and Cendance as data importer.
  2. Clause 7 (Docking). The optional docking clause does not apply.
  3. Clause 9 (Subprocessors). Option 2 (general written authorization) applies, with the notice period in Section 8.2.
  4. Clause 11 (Redress). The optional independent dispute resolution language does not apply.
  5. Clause 13 (Supervision). The competent supervisory authority is the authority determined in accordance with Clause 13 based on the data exporter's establishment or representative.
  6. Clauses 17 and 18 (Governing law and forum). The SCCs are governed by the law of Ireland, and disputes are resolved before the courts of Ireland, unless the data exporter's Data Protection Laws require otherwise.
  7. Annex I. The parties, categories of data subjects, categories of personal data, and processing details are as described in this DPA, including Schedule 1.
  8. Annex II. The technical and organizational measures are as described in Schedule 2.
  9. Annex III. The list of Subprocessors is as described in Schedule 3.
  10. UK Addendum. For UK transfers, the UK International Data Transfer Addendum is completed with the parties' details from this DPA, Tables 1 to 3 populated by reference to the SCCs as completed above, and neither party may terminate the Addendum under its Section 19.

Version history