Skip to main content
Back to home

Annex 1 to the terms

Data Processing Agreement

This data processing agreement under Article 28 GDPR governs how we process your congregation’s application data in congrega Online. It automatically becomes part of the contract upon its conclusion.

Last updated: 21 August 2026

01

Preamble and incorporation

This data processing agreement (DPA) is Annex 1 to the terms of service for congrega and automatically becomes part of the contract for congrega Online upon its conclusion. It sets out the parties’ data protection obligations under Article 28 GDPR.

The controller within the meaning of the GDPR is the respective congregation (the "Controller"). The processor is Pascal Roschkowski, Bruchstraße 3, 27321 Thedinghausen, Germany (the "Processor").

For congrega Local, no processing on behalf of the Controller takes place during normal operation; this DPA then applies accordingly only where the Processor is granted temporary access for support or maintenance in an individual case.

02

§ 1 Subject matter and duration

The subject matter is the provision and operation of congrega Online, including hosting, storage, transmission, and backup of the application data entered by the Controller.

The duration corresponds to the term of the main contract. The obligations under § 11 (deletion and return) continue beyond that until they are fulfilled.

03

§ 2 Nature and purpose of the processing

The processing comprises collecting, storing, modifying, transmitting to authorised users, backing up, and deleting the application data. Its sole purpose is the organisation of the Controller’s congregation — in particular territory management, meeting planning, ministry, notifications, and internal organisation.

04

§ 3 Types of data processed

The following types of data are processed in particular, insofar as the Controller enters them or configures their collection:

Account and profile data
name, username, email address where provided, role, permissions, group and family assignment
Organisation data
assignments, schedules, availabilities, field service reports
Territory data
territory boundaries, address lists, progress, and do-not-call records with street, house number, optional note, and coordinates — including about persons who do not use congrega
Third-party contact data
profiles of public speakers and contact persons of other congregations with name, phone number, email address, and notes
Location data
temporary live locations during an active territory session (only within the territory plus a buffer)
Technical data
push tokens, device and session data, security-related logs (audit log)

The data may reveal religious affiliation and may therefore constitute special-category data under Article 9 GDPR. The Controller alone decides whether and on what legal basis such data is entered.

05

§ 4 Categories of data subjects

  • Users of the application (publishers, administrators) and, where applicable, their family members
  • Householders about whom do-not-call records are kept (non-users)
  • Public speakers and contact persons of other congregations (non-users)
06

§ 5 Controller’s right to issue instructions

The Processor processes the data only on documented instructions from the Controller, unless required to do so by Union or Member State law; in that case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits it.

Instructions must be given in text form. Use of the application by the Controller and its users constitutes an instruction within the intended range of features. If the Processor considers an instruction unlawful, it informs the Controller without delay and may suspend its execution until clarified.

07

§ 6 Confidentiality

The Processor ensures that all persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This also applies to personnel engaged in the future.

08

§ 7 Technical and organisational measures (Article 32 GDPR)

The Processor implements in particular the following measures and develops them in line with the state of the art:

  • Encrypted transmission of all data (TLS/HTTPS)
  • Passwords stored exclusively as bcrypt hashes
  • Token-based sign-in with rotating refresh tokens, stored only as hashes
  • Role- and permission-based access control per congregation (tenant separation)
  • Logging of security-relevant events (audit log) without storing the underlying content data
  • Hosting and data storage on servers within the European Union
  • Regular backups and prompt installation of security updates
  • Database access only from the internal system, not publicly reachable
09

§ 8 Sub-processors

The Controller grants general authorisation for the engagement of the sub-processors listed below. The Processor informs the Controller in text form of intended changes (addition or replacement); the Controller may object within four weeks on justified data protection grounds. The obligations required by Article 28(4) GDPR are agreed with each sub-processor.

Sub-processors currently engaged:

Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
Operation of the server hosting the application and database (data centres in Germany/EU)
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Delivery of push notifications to Android devices via Firebase Cloud Messaging (push token and minimal notification payload)
Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland
Delivery of push notifications to iOS devices via the Apple Push Notification service (push token and minimal notification payload)

Map display (OpenStreetMap tile servers) and the loading of map libraries take place directly from the user’s device and do not constitute sub-processing; details are provided in the privacy notice. Server-side geocoding requests (Nominatim/Overpass) transmit address data without any link to a user account.

10

§ 9 Assistance with data subject rights

The Processor assists the Controller with appropriate technical and organisational measures in responding to requests from data subjects under Articles 12 to 23 GDPR (in particular access, rectification, erasure, restriction, and data portability). Requests received directly by the Processor are forwarded to the Controller without delay.

11

§ 10 Breach notification and data protection impact assessment

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach and provides the information required for notification under Articles 33 and 34 GDPR, insofar as it is available to the Processor.

Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in complying with the obligations under Articles 32 to 36 GDPR, in particular with a data protection impact assessment.

12

§ 11 Deletion and return

After the main contract ends, the Processor returns the application data to the Controller in a common format on request. Subsequently — no later than 90 days after the contract ends — the Processor deletes all application data, including backup copies, unless statutory retention obligations require continued storage.

13

§ 12 Evidence and audit rights

The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR. Audits are primarily conducted through the provision of suitable documentation; further reviews, including inspections, are announced with reasonable notice and carried out so as not to disrupt operations disproportionately.

14

§ 13 Final provisions

The law of the Federal Republic of Germany applies. With regard to data protection matters, this DPA takes precedence over the terms of service.

This DPA is available in German and English. In the event of discrepancies, only the German version is authoritative.

Questions about data processing?

Get in touch.

If your congregation needs a signed copy or further evidence, write to us.

Send an email