← Back to EvangelIT

Data Processing Agreement

Last updated: June 3, 2026

This DPA applies to church administrators and organisations using EvangelIT to process personal data of their congregation members, contacts, or other data subjects under GDPR, UK GDPR, LGPD, NDPA, or equivalent privacy laws. By using EvangelIT as a church admin, you accept this DPA. If you require a counter-signed copy, email outreach@evangelit.app.

1. Parties and Roles

This Data Processing Agreement (“DPA”) is entered into between:

  • Controller: You (the church administrator or organisation using EvangelIT)
  • Processor: Gooverio Labs LLC, operator of EvangelIT

The Controller determines the purposes and means of processing personal data of their contacts and congregation members. The Processor (Gooverio Labs) processes that personal data only on the documented instructions of the Controller, as set out in the EvangelIT Terms of Service and this DPA.

2. Subject Matter and Duration

The subject matter of processing is the operation of the EvangelIT ministry outreach platform. Duration: for the term of the Controller's EvangelIT subscription, plus any post-termination data retention or deletion period required by law.

3. Nature and Purpose of Processing

The Processor processes personal data of the Controller's contacts solely to provide the EvangelIT service: storing contact details, generating and delivering outreach messages, managing pastoral check-ins, tracking discipleship journeys, generating AI-assisted conversation responses, and providing analytics.

4. Categories of Personal Data

  • Identity data: name, email address, phone number
  • Communication data: message content sent through EvangelIT (SMS, WhatsApp, email)
  • Special category data (Article 9 GDPR): religious beliefs, spiritual condition, pastoral care information, prayer requests
  • Behavioural data: engagement signals, decision moments, journey stage
  • Consent records: SMS/communication consent timestamp and method

Note on special category data: The Controller is responsible for obtaining explicit consent (GDPR Article 9(2)(a)) from data subjects before adding them as contacts. EvangelIT’s consent-of-record is a relationship attestation — the sender confirms they personally know the contact and take responsibility for reaching out — recorded in the consentGiven / consentDate / consentSource fields and backed by absolute opt-out enforcement: a STOP request is honoured immediately and can never be overridden. The Controller warrants a genuine prior relationship for every contact added and that any additional legal consent required for a channel (e.g. TCPA prior express consent for US text messages) has been obtained.

5. Categories of Data Subjects

Contacts added by the Controller (members, prospects, newcomers, prayer requesters). The Controller's own staff who have EvangelIT user accounts.

6. Processor Obligations

The Processor (Gooverio Labs) will:

  • Process personal data only on documented instructions from the Controller, including with regard to international transfers
  • Ensure that personnel authorised to process personal data are bound by confidentiality
  • Implement appropriate technical and organisational security measures, including encryption at rest and in transit, access control, and audit logging
  • Engage subprocessors only as listed at /subprocessors, providing at least 30 days' notice of additions
  • Assist the Controller in responding to data subject rights requests (access, rectification, erasure, portability) including by providing the self-service tools described below
  • Notify the Controller without undue delay (within 72 hours where feasible) of any personal data breach
  • Delete or return all personal data to the Controller at the end of the service relationship
  • Make available all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28 and equivalent provisions

7. Subprocessors

The Controller authorises the Processor to engage the subprocessors listed at https://www.evangelit.app/subprocessors. Each subprocessor is bound by terms substantially similar to those in this DPA. The Processor remains fully liable for subprocessor performance.

8. International Transfers

For transfers of personal data outside the EEA / UK / Switzerland, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Module Two — Controller to Processor) and the UK International Data Transfer Addendum (IDTA). Subprocessors with US presence operate under SCC-compliant DPAs available at links provided in the subprocessor list.

9. Data Subject Rights Assistance

The Processor provides self-service tools that enable the Controller's contacts to exercise their rights directly:

  • Right of access / portability: Contacts can request a copy of their data via opt-in messaging to outreach@evangelit.app, which we route to the Controller
  • Right to erasure: Contacts can opt out via SMS/WhatsApp STOP keyword, which sets optedOut: true and prevents future messaging
  • Right to rectification: The Controller can edit contact details directly through the EvangelIT interface

For requests requiring Processor intervention beyond these tools, the Controller may contact outreach@evangelit.app. The Processor will respond within seven (7) business days.

10. Audit Rights

The Controller may audit the Processor's compliance with this DPA at the Controller's expense, with at least 30 days' written notice, no more than once per calendar year (except where required by a supervisory authority). The Processor will make available SOC 2 reports and other compliance documentation as they become available.

11. Liability

The liability provisions of the EvangelIT Terms of Service apply to this DPA. Liability for damages arising from breach of this DPA is allocated in accordance with GDPR Article 82.

12. Term and Termination

This DPA remains in force for as long as the Processor processes personal data on behalf of the Controller. On termination of the EvangelIT service, the Processor will delete all personal data within 60 days unless the Controller has requested a return of data in accordance with Section 6.

13. Governing Law

This DPA is governed by the laws applicable to the EvangelIT Terms of Service. Where local privacy law (GDPR, UK GDPR, LGPD, NDPA, etc.) is mandatory, that law applies and takes precedence to the extent of any conflict.

Questions? Email outreach@evangelit.app with the subject line “DPA inquiry”.