1. Data Controller and Processor
Data Controller: The church organisation that has registered an account on the Safan platform is the data controller for the personal data of its members, staff, and other data subjects. Each church determines the purposes and means of processing its members' personal data.
Data Processor: Safan, operated by [YOUR FULL NAME], micro-entrepreneur registered in France (SIRET: [SIRET NUMBER]), processes personal data on behalf of each church organisation under the terms of a Data Processing Agreement (Art. 28 GDPR).
Contact: For privacy-related enquiries: contact@safan.app
2. Categories of Personal Data
2.1 Standard personal data (Art. 6)
- Identity: first name, last name, date of birth, gender, nationality
- Contact: email address, phone number, postal address
- Account: username, hashed password, role, language preference
- Financial: transaction amounts, dates, and categories linked to members
- Technical: IP address, user-agent, login timestamps, audit trail
2.2 Special category data (Art. 9)
Safan processes data revealing religious beliefs, which is classified as special category data under Article 9(1) GDPR. This includes:
- Baptism date, baptism church, baptism pastor
- Church membership status and dates
- Ministry and group assignments
- Holy Spirit baptism status
3. Legal Basis for Processing
| Processing | Art. 6 basis | Art. 9 basis |
|---|---|---|
| Member management | 6(1)(f) legitimate interest of the church | 9(2)(d) — religious not-for-profit processing own members |
| Financial records | 6(1)(c) legal obligation (accounting law) | N/A |
| Sunday School | 6(1)(f) legitimate interest of the church | 9(2)(d) + Art. 8 parental consent for minors |
| Audit logging | 6(1)(f) security and accountability | N/A |
| Email notifications | 6(1)(b) contract performance | N/A |
| Authentication | 6(1)(b) contract performance | N/A |
Article 9(2)(d) explained: Each church using Safan is a not-for-profit body with a religious aim. Processing of religious belief data relates solely to its members or former members, and no data is disclosed outside the church organisation without the data subject's explicit consent. Each church confirms this eligibility in the Data Processing Agreement signed at registration.
4. Retention Periods
| Data category | Retention |
|---|---|
| Active member records | Duration of church membership |
| Soft-deleted member records | 2 years, then permanently erased |
| Financial transactions | 10 years (FR/RO accounting law) |
| Audit logs | 180 days |
| Sunday School records | Duration of enrollment + 3 years |
| Authentication tokens | 24 hours after expiry |
| Import files | 30 days |
| Database backups | 7 days |
5. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of all personal data held about you. You can export your account data directly from your account settings.
- Right to rectification (Art. 16): Request correction of inaccurate personal data. Contact your church administrator or update your profile directly.
- Right to erasure (Art. 17): Request deletion of your personal data. You can delete your account from your account settings. Church administrators can erase or anonymise member records.
- Right to restriction (Art. 18): Request that processing of your data be restricted in certain circumstances.
- Right to data portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON).
- Right to object (Art. 21): Object to processing based on legitimate interests.
To exercise your rights, contact your church administrator (the data controller) or email us at contact@safan.app. We will respond within 30 days.
6. Children's Data
Safan processes personal data of minors enrolled in Sunday School programmes. This data includes the child's identity, class enrollment, and attendance records.
In accordance with Article 8 GDPR and applicable national law:
- In France: parental or guardian consent is required for children under the age of 15.
- In Romania: parental or guardian consent is required for children under the age of 16.
Parental consent is collected and verified during the Sunday School enrollment process. Parents or guardians may request access to, correction of, or deletion of their child's data at any time by contacting their church administrator.
7. Sub-processors
We use a limited number of third-party service providers to operate the platform. All primary data is stored within the European Union. The complete list of sub-processors, including their roles, locations, and links to their Data Processing Agreements, is available on our Sub-processors page.
8. International Data Transfers
All primary data (database, uploaded files, backups) is stored on servers located in Germany (Hetzner Online GmbH, Falkenstein/Nuremberg).
Where a sub-processor is headquartered outside the European Economic Area (e.g., Cloudflare — USA), data transfers are protected by EU Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. No personal data is transferred to any country without adequate safeguards under GDPR Chapter V.
9. Security Measures
We implement appropriate technical and organisational measures to protect personal data (Art. 32 GDPR), including:
- Encryption in transit (TLS/HTTPS on all connections)
- Hashed passwords (bcrypt)
- Short-lived access tokens (60 minutes) with HTTP-only refresh cookies
- Church-scoped data isolation (multi-tenant architecture)
- Role-based access control with department-level granularity
- Comprehensive audit logging with automatic purging
- Daily encrypted backups with offsite storage
- Rate limiting and bot protection on authentication endpoints
10. Cookies and Tracking
Safan uses only strictly necessary cookies that are exempt from consent requirements under the ePrivacy Directive (Art. 5(3)):
- Authentication cookie: HTTP-only, Secure, SameSite=Strict refresh token for maintaining your login session
- UI preference: sidebar state and theme preference stored in localStorage (functional, not transmitted to servers)
We do not use any analytics, advertising, or tracking cookies. We do not use Google Analytics, Facebook Pixel, or any similar tracking technology. No cookie consent banner is required.
11. Data Protection Contact
12. Automated Decision-Making
Safan does not perform automated decision-making or profiling within the meaning of Article 22 GDPR. No decisions with legal or similarly significant effects are made about data subjects based solely on automated processing.
13. Right to Lodge a Complaint
If you believe your personal data has been processed in violation of the GDPR, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR):
- France — CNIL (Commission Nationale de l'Informatique et des Libertés) — www.cnil.fr/fr/plaintes
- Romania — ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) — www.dataprotection.ro
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by email and request renewed consent where required. The version number and effective date at the top of this page indicate the most recent revision.