Data Processing Agreement (DPA)

Last updated: 13/03/2026

1 – Parties

This Data Processing Agreement (“DPA”) is entered into between:

Data Controller: The church or organisation whose administrator enters congregation data into the Pastors Network Members Database (the “Church”).

Data Processor: Concentric IT Ltd, operating the Pastors Network platform at www.pastorsnetwork.co.uk (the “Processor”).
Concentric IT Ltd, Company Number 05012213, Registered Address: 179 Walmersley Road, Bury, Lancs, BL9 5DF.

This DPA is incorporated into and forms part of the agreement between the Church and the Processor for use of the Pastors Network platform. By creating an administrator account or by continued use of the platform, the Church agrees to be bound by this DPA on behalf of itself and its authorised users. This DPA satisfies the requirements of Article 28(3) of UK GDPR.

 

2 – Background

The Church uses the Pastors Network platform to manage its congregation records, pastoral visits, and related church administration. In doing so, the Church enters personal data about its members, attenders, and contacts into the platform. Under UK GDPR, the Church is the data controller for this data, and Concentric IT Ltd is the data processor. This DPA sets out the obligations of both parties in relation to this personal data, in accordance with Article 28 of UK GDPR.

 

3  -Scope of Processing

 

3.1 – Data Subjects

The personal data processed under this agreement relates to:

  • Members, attenders, and contacts of the Church as entered into the Members Database by the Church’s authorised administrators.
  • Individuals recorded in the Church’s pastoral visit log.

     

    3.2 – Categories of Personal Data

    • Names and contact details (address, phone number, email)
    • Member type (member, attender, contact) and active/inactive status
    • Age bracket, gender, marital status
    • Key dates (birthdays, anniversaries, baptism dates, membership dates)
    • Tags and categories assigned by the Church
    • Pastoral visit records (dates, notes, follow-up actions, prayer points)
    • Any other information the Church’s administrators choose to enter into free-text fields

     

    3.3 – Special Category Data

    The data may include special category data within the meaning of Article 9 UK GDPR, including:

    • Religious beliefs (implied by church membership/attendance)
    • Health information (if recorded in pastoral visit notes or member records)

    The Church, as data controller, is responsible for ensuring it has a valid legal basis for processing this special category data and for sharing it with the Processor. Where the Church is uncertain whether its processing of special category data requires a Data Protection Impact Assessment, the Processor will provide reasonable assistance as set out in Section 4.

     

    3.4 – Purpose of Processing

    The Processor will process the personal data only for the purpose of providing the Pastors Network platform services to the Church, specifically:

    • Storing and displaying congregation records to the Church’s authorised users
    • Enabling the Church to record and review pastoral visits
    • Generating reports, prayer lists, and key date reminders for the Church’s authorised users
    • Maintaining backups for disaster recovery

    3.5 – Data Retention

    The Church, as data controller, is responsible for setting and enforcing its own data retention policy for personal data entered into the platform. The Processor will hold personal data for as long as the Church’s account remains active and will not independently delete data during the term of this agreement except at the Church’s documented instruction or as required by law. Upon termination of services, Section 8 applies. The Church is encouraged to maintain a retention schedule covering each category of data listed in Section 3.2 and to periodically review and delete data that is no longer required.

       

      4 – Obligations of the Processor

      The Processor shall:

      1. (a) Documented instructions. Process the personal data only on documented instructions from the Church, unless required to do so by UK law. For the purposes of this DPA, the Church’s use of the Pastors Network platform (including data entry, configuration, and instruction of the Processor via the platform’s interface or in writing) constitutes documented instructions. Any instruction that falls outside the normal scope of the platform services must be provided by the Church in writing (including by email). The Processor shall promptly notify the Church if, in its opinion, an instruction infringes UK GDPR or other applicable data protection law.

        (b) Confidentiality. Ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

        (c) Security. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encrypted connections (HTTPS/TLS), role-based access controls, and secure password storage, in accordance with Article 32 of UK GDPR.

        (d) Sub-processors. Not engage any new sub-processor without prior written consent of the Church. The Church consents to the use of the following existing sub-processors:

        The Processor shall notify the Church in writing (including by email to the Church’s registered administrator email address) of any proposed addition or replacement of sub-processors at least 30 days before the change takes effect. The Church may object to a proposed new sub-processor in writing within 14 days of receiving notice. If the Church objects and the parties cannot resolve the objection, either party may terminate this DPA and the associated platform agreement on 30 days’ written notice without liability for the termination itself. If the Church does not object within 14 days, consent shall be deemed given. The Processor shall ensure all sub-processors are bound by data protection obligations equivalent to those in this DPA.

        (e) Data subject rights. Assist the Church in responding to requests from data subjects exercising their rights under UK GDPR (access, rectification, erasure, restriction, portability, and objection), taking into account the nature of the processing.

        (f) Compliance assistance. Assist the Church in ensuring compliance with its obligations regarding data security, breach notification, and data protection impact assessments, taking into account the nature of the processing and the information available to the Processor.

        (g) Data Protection Impact Assessments (DPIAs). Given that the data processed under this agreement is likely to include special category data (including health information and religious beliefs), the Church should consider whether a DPIA is required before commencing or materially changing its processing activities. The Processor will, upon written request and within a reasonable timeframe, provide the Church with all information in its possession that is reasonably necessary to assist the Church in completing a DPIA, including information about the technical and organisational security measures in place, sub-processor arrangements, and data flows.

        (h) End of services. At the Church’s choice, delete or return all personal data at the end of the provision of services, unless UK law requires continued storage. Deletion will be confirmed to the Church by written certification (including by email) within 30 days of the request or termination, specifying the data deleted and the method of deletion.

        (i) Audit rights. Make available to the Church all information necessary to demonstrate compliance with these obligations, and allow for and contribute to audits and inspections conducted by the Church or an auditor mandated by the Church, subject to the following conditions:

        • The Church shall give the Processor no less than 30 days’ prior written notice of any audit, except where an audit is required urgently following a confirmed personal data breach.
        • Audits shall be conducted no more than once per calendar year, unless a personal data breach or regulatory investigation justifies an additional audit.
        • The Church shall bear the reasonable costs of any audit, including any time reasonably incurred by the Processor in facilitating the audit, unless the audit reveals a material breach of this DPA by the Processor, in which case the Processor shall bear its own costs.
        • The scope of any audit shall be limited to the Processor’s processing of personal data under this DPA and shall not unreasonably disrupt the Processor’s operations.
        • The Processor may satisfy its audit obligations in whole or in part by providing the Church with relevant third-party audit reports, certifications, or other compliance documentation.

       

      5 – Obligations of the Church (Data Controller)

      The Church shall:

      • Ensure it has a lawful basis for all personal data it enters into the platform.
      • Obtain any necessary consent from data subjects before entering their data, particularly for special category data.
      • Publish an appropriate privacy notice informing its members how their data will be processed, including disclosure to Concentric IT Ltd as data processor.
      • Ensure that only authorised persons within the church team have access to the Members Database and pastoral visit records (using the platform’s Manage Team permissions feature).
      • Promptly notify the Processor of any data subject requests or complaints it receives that relate to the Processor’s processing activities.
      • Not enter unnecessary or excessive personal data into the platform.
      • Maintain its own records of processing activities in accordance with Article 30 of UK GDPR.

         

        6 – Data Breach Notification

        In the event of a personal data breach, the Processor shall:

        • Notify the Church without undue delay, and in any event within 48 hours of becoming aware of the breach.
        • Provide the Church with sufficient information to enable it to meet its obligation to notify the ICO within 72 hours and to inform affected data subjects. Where all information is not available within the initial notification, it may be provided in phases without further undue delay.
        • Cooperate with the Church and take reasonable steps to investigate, contain, and remediate the breach.

        The Church, as data controller, remains responsible for assessing whether the breach must be reported to the ICO and/or affected data subjects.

           

          7 – Data Location

          All personal data processed under this agreement is stored on servers located in the United Kingdom. The Processor will not transfer personal data outside the UK without the prior written consent of the Church and without ensuring that an appropriate safeguard under UK GDPR is in place.

           

          8 – Duration and Termination

          This DPA shall remain in effect for as long as the Church uses the Pastors Network platform. Upon termination, the Processor will, at the Church’s election, delete or return all personal data within 30 days, unless a longer period is required by law, and will provide written certification of deletion in accordance with Section 4(h).

           

          9 – Liability and Indemnity

          (a) Each party shall be liable to the other for direct losses arising from its breach of this DPA, subject to any limitations set out in the main platform agreement between the parties.

          (b) If a data subject or the ICO brings a claim or imposes a penalty arising from a breach of UK GDPR, each party shall be liable for the part of the damage or penalty caused by its own breach. Where it is not reasonably possible to distinguish the respective contributions of the parties to the damage, liability shall be apportioned between the parties in proportion to their respective responsibility.

          (c) The Processor shall indemnify and hold harmless the Church against any losses, fines, penalties, claims, or costs (including reasonable legal costs) suffered or incurred by the Church arising directly from the Processor’s breach of this DPA or of UK GDPR in respect of the processing carried out under this agreement, except to the extent that such losses are attributable to the Church’s own breach of this DPA or its instructions.

          (d) The Church shall indemnify and hold harmless the Processor against any losses, fines, penalties, claims, or costs suffered or incurred by the Processor arising directly from the Church’s breach of this DPA, its obligations as data controller under UK GDPR, or any unlawful instruction given to the Processor.

          (e) Neither party excludes or limits its liability for fraud, death or personal injury caused by negligence, or any other liability that cannot be excluded or limited by law. 

           

          10 – Records of Processing Activities

          Both parties acknowledge their independent obligations under Article 30 of UK GDPR to maintain records of their respective processing activities. The Processor shall maintain records of all categories of processing activities carried out on behalf of the Church under this DPA, including the information required by Article 30(2) of UK GDPR, and shall make those records available to the ICO on request.

           

          11 – Governing Law

          This DPA is governed by the laws of England and Wales. Any disputes arising under or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.

           

          12 – Execution

          This DPA takes effect when the Church’s authorised representative creates an administrator account on the Pastors Network platform, or, where the Church is an existing user, upon continued use of the platform after the date of this DPA being published. By doing so, the authorised representative confirms they have authority to enter into this DPA on behalf of the Church.

          For the avoidance of doubt, the parties may also execute this DPA by signing below:

          Data Controller (The Church)

          Data Processor (Concentric IT Ltd)

          Name

          Title / Role

          Signature

          Date

           

           

          Annex A – UK GDPR Article 28(3) Checklist

          For ease of reference, the following maps this DPA’s provisions to the Article 28(3) sub-clause requirements:

          Article 28(3) requirement

          Covered in this DPA

          (a) Process only on documented instructions

          Section 4(a)

          (b) Confidentiality obligations on authorised persons

          Section 4(b)

          (c) Appropriate technical and organisational security measures

          Section 4(c)

          (d) Sub-processor restrictions and flow-down obligations

          Section 4(d)

          (e) Assist controller with data subject rights

          Section 4(e)

          (f) Assist controller with security, breach notification, DPIAs

          Sections4(f), 4(g), 6

          (g) Deletion or return of data at end of services

          Sections 4(h), 8

          (h) Provide information and allow audits

          Section 4(i)